Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
21.612 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.4) | 0.37% | — | Snipeitapp Snipe-it | 9/9/2026 | 14/9/2026 | Snipe-IT before 8.7.0 fails to properly sanitize markdown image syntax in note fields, allowing authenticated users to read arbitrary server files and issue server-side HTTP requests. Attackers can submit markdown image syntax in checkout acceptance notes that survive HTML escaping, are expanded by CommonMark parser,… | |
| Analizada | Alta (8.3) | 0.33% | — | Snipeitapp Snipe-it | 9/9/2026 | 14/9/2026 | Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not validate company assignment authorization before persisting user records via the REST API. In Api\UsersController::store() and ::update(), the user record is filled from the request and saved before the requested company_id / company_ids[] values are filtered against… | |
| Analizada | Media (6.9) | 0.40% | — | Snipeitapp Snipe-it | 9/9/2026 | 14/9/2026 | Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint. Superusers uploading corrupted or invalid zip files trigger permanent data loss with no recovery path or rollback mechanism. | |
| Analizada | Media (5.3) | 0.25% | — | Snipeitapp Snipe-it | 9/9/2026 | 14/9/2026 | Snipe-IT is an open source IT asset management system. In versions up to and including 8.6.3, the report acceptance endpoints POST /reports/unaccepted_assets/sent_reminder (ReportsController::sentAssetAcceptanceReminder) and DELETE /reports/unaccepted_assets/{acceptanceId}/delete… | |
| Analizada | Alta (7.4) | 0.29% | — | Snipeitapp Snipe-it | 9/9/2026 | 14/9/2026 | Snipe-IT before 8.7.0 contains an authorization bypass vulnerability in Livewire components that enforce authorization only at the route level, not within component lifecycle methods. Attackers with a valid authenticated session can replay signed component snapshots via POST /livewire/update to invoke protected… | |
| Analizada | Media (5.1) | 0.36% | — | Snipeitapp Snipe-it | 9/9/2026 | 14/9/2026 | Snipe-IT is an IT asset management application. In Snipe-IT master-branch builds after 8.6.3 (the code was never included in a tagged release), SettingsController::downloadLocationScopingReport streams the FMCS location-scoping mismatch report (GET /admin/settings/location-scoping-report.csv) through a bare fputcsv()… | |
| Analizada | Media (5.3) | 0.29% | — | Snipeitapp Snipe-it | 9/9/2026 | 14/9/2026 | Snipe-IT versions before 8.7.0 fail to properly scope asset acceptance report queries by company, allowing authenticated reports.view users to read pending acceptances across all companies. Attackers can access the unaccepted_assets report page or CSV export to disclose cross-company inventory details and assignee… | |
| Analizada | Media (5.1) | 0.41% | — | Snipeitapp Snipe-it | 9/9/2026 | 14/9/2026 | Snipe-IT through 8.6.3 does not neutralize formula elements in the "unaccepted assets" acceptance report CSV export. ReportsController::postAssetAcceptanceReport builds the CSV by hand (stripping commas and joining rows manually) and, unlike the six sibling exports in the same controller, never applies… | |
| Analizada | Alta (8.4) | 0.35% | — | Snipeitapp Snipe-it | 9/9/2026 | 14/9/2026 | Snipe-IT versions before 8.7.0 fail to sanitize the category EULA text field before rendering it in checkout confirmation emails. Attackers with low-privilege permissions can inject markdown image syntax or raw HTML img tags pointing to local files or remote URLs, which the mail auto-embed library resolves server-side… | |
| Analizada | Media (5.1) | 0.29% | — | Snipeitapp Snipe-it | 9/9/2026 | 14/9/2026 | Snipe-IT before 8.7.0 fails to check the return value of Storage::delete() in UploadedFilesController::destroy() and Api\\UploadedFilesController::destroy(), allowing deletion requests to report success while files remain on disk. Administrators performing attachment deletions receive success responses and see files… | |
| Pendiente de análisis | Alta (8.7) | 0.39% | — | Zstd-jniAI | 9/9/2026 | 19/9/2026 | zstd-jni before 1.5.7-14 fails to validate the samples buffer capacity in Zstd.trainFromBufferDirect, allowing attackers to read past buffer boundaries by supplying oversized per-sample lengths. Attackers can trigger out-of-bounds memory access by providing crafted sample length arrays that cause the native… | |
| Analizada | Media (5.3) | 0.29% | — | Snipeitapp Snipe-it | 9/9/2026 | 19/9/2026 | Snipe-IT versions before 8.7.0 contain a broken access control vulnerability in AssetModelPolicy where the files() method cascades from assets.files permission, allowing authenticated users to upload and delete file attachments on Asset Model records without the required models.files permission. Attackers with only… | |
| Analizada | Media (5.3) | 0.28% | — | Snipeitapp Snipe-it | 9/9/2026 | 19/9/2026 | Snipe-IT versions before 8.7.0 contain an improper ownership management vulnerability in the consumables checkout API endpoint that records the checkout target user's id in the created_by column instead of the authenticated caller's id. Authenticated attackers with consumables.checkout permission can perform checkouts… | |
| Analizada | Alta (7.1) | 0.37% | — | Snipeitapp Snipe-it | 9/9/2026 | 19/9/2026 | Snipe-IT through 8.6.4 (fixed in 8.7.0) does not enforce the components.view permission on the authenticated endpoint GET /api/v1/hardware/<asset-id>/assigned/components. The endpoint authorizes only assets.view on the parent asset before returning linked component details; the components.view check is applied only to… | |
| Analizada | Alta (7.1) | 0.37% | — | Snipeitapp Snipe-it | 9/9/2026 | 19/9/2026 | Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/history endpoint, allowing any authenticated user to reassign arbitrary assets and modify audit logs. Attackers can submit a CSV file to reassign assets across companies and inject fraudulent audit trail entries, compromising inventory integrity and… | |
| Analizada | Alta (8.5) | 0.34% | — | Snipeitapp Snipe-it | 9/9/2026 | 19/9/2026 | Snipe-IT before 8.7.0 fails to properly gate Laravel Passport's OAuth client management routes, allowing any authenticated user to register OAuth clients with attacker-controlled redirect URIs. Attackers can trick administrators into approving consent screens, then exchange authorization codes for bearer tokens… | |
| Analizada | Alta (7) | 0.34% | — | Snipeitapp Snipe-it | 9/9/2026 | 19/9/2026 | Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not check the return value of storage write operations in ImageUploadRequest::handleImages(). Because Laravel's default disk mode does not throw on failure, a silently failed Storage::disk('public')->put(...) call still caused the application to delete the previous image… | |
| Analizada | Baja (2.1) | 0.27% | — | Snipeitapp Snipe-it | 9/9/2026 | 18/9/2026 | Snipe-IT 8.6.3 and earlier (and develop pre-release commits prior to the fix) contain a race condition in the asset checkout paths. Api\AssetsController::checkout() and Assets\AssetCheckoutController::store() call Asset::availableForCheckout() outside the mutation path and then invoke Asset::checkOut() without taking… | |
| Analizada | Baja (2.3) | 0.36% | — | Snipeitapp Snipe-it | 9/9/2026 | 18/9/2026 | Snipe-IT 8.6.3 and earlier do not check the return value of Storage::put() when writing the signature PNG and the generated acceptance PDF in Account\AcceptanceController::store(). On filesystem drivers that return false instead of throwing on a write failure (for example the local disk with restrictive permissions,… | |
| Pendiente de análisis | Alta (8.8) | 0.63% | — | Zstd-jniAI | 9/9/2026 | 14/9/2026 | zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes. | |
| Aplazada | Media (6.1) | 0.24% | — | Yordam Informatics Technology Consulting Training AND Electronic Systems Industry AND Trade Library Information AND Document Automation ProgramAI | 9/9/2026 | 9/9/2026 | URL redirection to untrusted site ('open redirect') vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows Phishing. This issue affects Library Information and Document Automation Program: from v22.1… | |
| Aplazada | Media (5.3) | 0.19% | — | Yordam Informatics Technology Consulting Training AND Electronic Systems Industry AND Trade Library Information AND Document Automation ProgramAI | 9/9/2026 | 9/9/2026 | Server-Side request forgery (SSRF) vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows Server Side Request Forgery. This issue affects Library Information and Document Automation Program: before… | |
| Aplazada | Media (4.3) | 0.18% | — | Yordam Informatics Technology Consulting Training AND Electronic Systems Industry AND Trade INC Library Reservation SystemAI | 9/9/2026 | 9/9/2026 | Missing authentication for critical function vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Reservation System allows Input Data Manipulation. This issue affects Library Reservation System: before v22.2. | |
| Aplazada | Media (6.6) | 0.66% | — | Ninjaforms Ninja FormsAI | 9/9/2026 | 9/9/2026 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.6 via deserialization of untrusted input . This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP… | |
| Analizada | Alta (7) | 0.17% | — | Tanium Enforce | 9/9/2026 | 16/9/2026 | Tanium addressed an unauthorized code execution vulnerability in Enforce. |