Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
3977 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.63% | — | Code-projects Online LOT Reservation SystemAI | 27/4/2026 | 17/6/2026 | A vulnerability was found in code-projects Online Lot Reservation System up to 1.0. This affects the function readfile of the file /download.php. The manipulation of the argument File results in path traversal. It is possible to launch the attack remotely. The exploit has been made public and could be used. | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Online LOT Reservation SystemAI | 27/4/2026 | 17/6/2026 | A vulnerability has been found in code-projects Online Lot Reservation System up to 1.0. The impacted element is an unknown function of the file /loginuser.php. The manipulation of the argument email/password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Aplazada | Media (5.5) | 0.51% | 💥 PoC | Codeastro Online JOB PortalAI | 27/4/2026 | 17/6/2026 | A security vulnerability has been detected in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /users/user-cvs/. The manipulation leads to file and directory information exposure. Remote exploitation of the attack is possible. The exploit has been disclosed… | |
| Aplazada | Baja (2) | 0.33% | 💥 PoC | Codeastro Online JOB PortalAI | 26/4/2026 | 17/6/2026 | A security flaw has been discovered in CodeAstro Online Job Portal 1.0. The affected element is an unknown function of the file /admin/jobs-admins/delete-jobs.php of the component All Jobs Page. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely.… | |
| Aplazada | Media (6.9) | 1.1% | 💥 Exploit | Xerte Online ToolkitsAI | 22/4/2026 | 14/7/2026 | Xerte Online Toolkits versions 3.15 and earlier contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the full server-side filesystem path of the application root. Attackers can send a GET request to the /setup page to access the exposed root_path value rendered in the HTML… | |
| Aplazada | Crítica (9.3) | 4.4% | 💥 Exploit | Xerte Online ToolkitsAI | 22/4/2026 | 14/7/2026 | Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder connector endpoint that fails to block PHP-executable extensions .php4 due to an incorrect regex pattern. Unauthenticated attackers can exploit this flaw combined with authentication bypass and path… | |
| Aplazada | Alta (7.1) | 3.6% | 💥 Exploit | Xerte Online ToolkitsAI | 22/4/2026 | 14/7/2026 | Xerte Online Toolkits versions 3.15 and earlier contain a relative path traversal vulnerability in the elFinder connector endpoint at /editor/elfinder/php/connector.php where the name parameter in rename commands is not sanitized for path traversal sequences. Attackers can supply a name value containing directory… | |
| Aplazada | Alta (8.8) | 3.1% | 💥 Exploit | Xerte Online ToolkitsAI | 22/4/2026 | 14/7/2026 | Xerte Online Toolkits versions 3.15 and earlier contain a missing authentication vulnerability in the elFinder connector endpoint at /editor/elfinder/php/connector.php where an HTTP redirect to unauthenticated callers does not call exit() or die(), allowing PHP execution to continue and process the full request… | |
| Modificada | Alta (8.5) | 0.90% | — | Linuxfoundation Tekton Pipelines | 21/4/2026 | 24/8/2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the git resolver's revision parameter is passed directly as a positional argument to git fetch without any validation that it does not begin… | |
| Modificada | Media (6.5) | 0.47% | — | Linuxfoundation Tekton Pipelines | 21/4/2026 | 17/6/2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the HTTP resolver's FetchHttpResource function calls io.ReadAll(resp.Body) with no response body size limit. Any tenant with permission to… | |
| Modificada | Media (5.4) | 0.32% | — | Linuxfoundation Tekton Pipelines | 21/4/2026 | 17/6/2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, a validation bypass in the VolumeMount path restriction allows mounting volumes under restricted /tekton/ internal paths by using .. path… | |
| Analizada | Media (5.6) | 0.14% | — | Home-assistant-ecosystem Home Assistant Command-line Interface | 21/4/2026 | 17/6/2026 | The Home Assistant Command-line interface (hass-cli) is a command-line tool for Home Assistant. Up to 1.0.0 of home-assitant-cli an unrestricted environment was used to handle Jninja2 templates instead of a sandboxed one. The user-supplied input within Jinja2 templates was rendered locally with no restrictions. This… | |
| Modificada | Media (6.5) | 0.43% | — | Linuxfoundation Tekton Pipelines | 21/4/2026 | 17/6/2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the Tekton Pipelines git resolver in API mode sends the system-configured Git API token to a user-controlled serverURL when the user omits… | |
| Modificada | Media (6.5) | 0.39% | — | Linuxfoundation Tekton Pipelines | 21/4/2026 | 17/6/2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 0.43.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, trusted resources verification policies match a resource source string (refSource.URI) against spec.resources[].pattern using… | |
| Aplazada | Baja (1.9) | 0.35% | — | Erponline ERP OnlineAI | 20/4/2026 | 17/6/2026 | A security flaw has been discovered in erponline.xyz ERP Online up to 4.0.0. This vulnerability affects unknown code of the component Inventory Edit Item Page. The manipulation of the argument Item Name results in cross site scripting. The attack may be launched remotely. The exploit has been released to the public… | |
| Analizada | Alta (7.1) | 0.34% | — | Linecorp Line | 16/4/2026 | 8/7/2026 | LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs due to insufficient safeguards when handling arbitrary URL schemes, potentially causing the iOS device to become temporarily inoperable. | |
| Aplazada | Media (4.3) | 0.11% | — | Zaytech Smart Online Order FOR CloverAI | 15/4/2026 | 7/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Cross Site Request Forgery.This issue affects Smart Online Order for Clover: from n/a through <= 1.6.0. | |
| Aplazada | Alta (8.5) | 0.36% | — | Fastlinemedia Beaver BuilderAI | 15/4/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beaver Builder Beaver Builder beaver-builder-lite-version allows Blind SQL Injection.This issue affects Beaver Builder: from n/a through <= 2.10.1.2. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 14/4/2026 | 17/6/2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 14/4/2026 | 17/6/2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 14/4/2026 | 17/6/2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 14/4/2026 | 17/6/2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.1) | 0.53% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 14/4/2026 | 17/6/2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Online Employees Work From Home Attendance SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/attendance_list.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Online Employees Work From Home Attendance SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/manage_department.php. |