Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
9809 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.52% | — | Anti-malware Security AND Brute-force FirewallAIPHPAI | 15/6/2026 | 17/6/2026 | Contributor PHP Object Injection in Anti-Malware Security and Brute-Force Firewall <= 4.23.87 versions. | |
| Aplazada | Alta (7.2) | 0.54% | — | CTX FeedAIPHPAI | 15/6/2026 | 17/6/2026 | Shop manager PHP Object Injection in CTX Feed <= 6.6.26 versions. | |
| Aplazada | Media (5.9) | 0.25% | — | PhpbbAI | 12/6/2026 | 23/6/2026 | SQL injection vulnerability in phpBB profile field migration due to improper handling of user-supplied profile field data during migration, allowing execution of arbitrary SQL queries. Only applies to phpBB forums that had been updated from versions prior to phpBB 3.3.8 and have not been updated to 3.3.11 or newer yet. | |
| Analizada | Media (5.3) | 0.31% | — | Guzzlephp Psr-7 | 11/6/2026 | 17/6/2026 | guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control characters, whitespace, or DEL in first-party URI host components. A vulnerable flow is: First, an application accepts a user-controlled URL. Second, the URL is used to construct a PSR-7 `Uri`… | |
| Analizada | Media (5.3) | 0.31% | — | Guzzlephp Psr-7 | 11/6/2026 | 17/6/2026 | guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host header validation when parsing raw HTTP request messages and when deriving a server request URI from server variables. An attacker can provide a malformed Host header containing URI authority… | |
| Aplazada | Alta (8.1) | 0.75% | — | Maian SearchAIFrankenphpAI | 10/6/2026 | 17/6/2026 | FrankenPHP is a modern application server for PHP. From version 1.11.2 to before version 1.12.3, the splitPos() function in cgi.go misuses golang.org/x/text/search with search.IgnoreCase when the request path contains a non-ASCII byte. Two distinct flaws in that fallback let an attacker mislead FrankenPHP into… | |
| Aplazada | Alta (8.6) | 0.62% | — | Simplesamlphp-module-casserverAI | 10/6/2026 | 23/7/2026 | SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. Prior to version 7.0.3, simplesamlphp-module-casserver builds file paths for the file-based CAS ticket store by directly concatenating the configured ticket directory with an attacker-controlled ticket identifier.… | |
| Aplazada | Media (5.1) | 0.33% | — | Evoluted PHP Directory Listing ScriptAI | 9/6/2026 | 23/7/2026 | Evoluted PHP Directory Listing Script through 4.0.5 contains a reflected cross-site scripting vulnerability in index.php where the dir parameter value is reflected without HTML encoding inside the HTML title element and inside anchor href attributes in the breadcrumb navigation. Attackers can inject arbitrary… | |
| Aplazada | Crítica (9.3) | 0.56% | 💥 PoC | Insert PHPAI | 9/6/2026 | 21/7/2026 | WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by injecting malicious shortcodes through the WordPress REST API. Attackers can send POST requests to the wp-json/wp/v2/posts endpoint with crafted content… | |
| Pendiente de análisis | Media (4.2) | 0.17% | — | SAP Fiori LaunchpadAI | 9/6/2026 | 23/7/2026 | SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service calls on the Fiori domain, this when opened by the user could compromise accounts by stealing user credentials. Successful exploitation requires adversaries to possess advanced knowledge of the system causing low impact on… | |
| Aplazada | Baja (2.7) | 0.28% | — | PhpmyfaqAI | 8/6/2026 | 23/7/2026 | phpMyFAQ is an open source FAQ web application. Prior to version 4.1.4, attachment passwords are hashed using SHA-1, a cryptographically broken algorithm. SHA-1 has been vulnerable to collision attacks since 2017 (SHAttered). Version 4.1.4 fixes the issue. | |
| Aplazada | Baja (1.9) | 0.11% | — | Secureage CatchpulseAI | 7/6/2026 | 23/7/2026 | A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. Impacted is an unknown function in the library saappctl.sys of the component IOCTL Handler. The manipulation leads to information disclosure. Local access is required to approach this attack. The exploit has been disclosed publicly and… | |
| Aplazada | Baja (2.1) | 0.21% | — | Lakshayd02 Hostel-management-system-phpAI | 4/6/2026 | 22/7/2026 | A vulnerability was found in LakshayD02 Hostel-Management-System-PHP up to f87e67c283bab6f718faf2fec6ae39a13bd7036b. This issue affects some unknown processing of the file hostel/index.php of the component Admin Dashboard Page. The manipulation of the argument ID results in missing authorization. The attack can be… | |
| Aplazada | Alta (8.8) | 0.26% | — | PHP Ei-tube ScriptAI | 4/6/2026 | 22/7/2026 | PHP EI-Tube Script 3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search parameter. Attackers can send GET requests to the search endpoint with crafted SQL payloads in the query parameter to extract sensitive… | |
| Aplazada | Alta (8.1) | 0.56% | — | PHPAICodesupplyco BlueprintAI | 2/6/2026 | 22/7/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Code Supply Co. Blueprint allows PHP Local File Inclusion. This issue affects Blueprint: from n/a before 1.1.5. | |
| Aplazada | Alta (8.1) | 0.34% | — | Axiomthemes FermentioAIPHPAI | 2/6/2026 | 22/7/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Fermentio allows PHP Local File Inclusion. This issue affects Fermentio: from n/a through 1.5.0. | |
| Aplazada | Alta (8.1) | 0.34% | — | Axiomthemes SpinAIPHPAI | 2/6/2026 | 22/7/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Spin allows PHP Local File Inclusion. This issue affects Spin: from n/a through 1.8. | |
| Aplazada | Media (5.3) | 0.23% | — | Devaslanhq DevaslanphpAI | 1/6/2026 | 22/7/2026 | A flaw has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this vulnerability is the function editComment/doDeleteComment of the file app/Filament/Resources/TicketResource/Pages/ViewTicket.php of the component Livewire Handler. Executing a manipulation can lead to improper authorization.… | |
| Aplazada | Media (5.5) | 1.4% | — | Php-censorAI | 1/6/2026 | 22/7/2026 | A vulnerability was found in php-censor up to 2.1.6. This affects an unknown function of the file src/Model/Build/GitBuild.php of the component Webhook Endpoint. Performing a manipulation of the argument commitId results in os command injection. The attack can be initiated remotely. The exploit has been made public… | |
| Aplazada | Baja (2) | 0.20% | — | Raisulislamg4 Student Management System BY PHPAI | 1/6/2026 | 22/7/2026 | A vulnerability was found in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382d16d1. The impacted element is an unknown function of the file admission_form_check.php. The manipulation of the argument Message results in cross site scripting. The attack can be executed remotely.… | |
| Aplazada | Media (5.5) | 0.26% | — | Raisulislamg4 Student Management System BY PHPAI | 1/6/2026 | 22/7/2026 | A vulnerability has been found in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382d16d1. The affected element is an unknown function of the file add_user_check.php of the component User Creation Handler. The manipulation of the argument role leads to sql injection. Remote… | |
| Aplazada | Media (5.5) | 0.26% | — | Raisulislamg4 Student Management System BY PHPAI | 1/6/2026 | 22/7/2026 | A flaw has been found in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382d16d1. Impacted is an unknown function of the file delete.php. Executing a manipulation of the argument user_id/course_id/teacher_id/student_id/application_id can lead to sql injection. The attack may be… | |
| Aplazada | Media (5.5) | 0.26% | — | Raisulislamg4 Student Management System BY PHPAI | 1/6/2026 | 22/7/2026 | A vulnerability was detected in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382d16d1. This issue affects some unknown processing of the file login_check.php of the component Login. Performing a manipulation of the argument Username results in sql injection. The attack may be… | |
| Aplazada | Media (6.9) | 0.16% | — | Phpshop Php-shopAI | 29/5/2026 | 21/7/2026 | PHP-SHOP 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to add administrative users by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting a page containing a hidden form that automatically submits POST requests to the users.php… | |
| Aplazada | Alta (7.3) | 0.51% | 💥 PoC | Falco Solutions PhppagebuilderAI | 29/5/2026 | 21/7/2026 | Falco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload vulnerability in the pagemanager/pagebuilder module that allows remote attackers to upload arbitrary files and achieve remote code execution. The vulnerability exists due to insufficient validation of uploaded file types and executable content. |