Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1016 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.59%—Arajajyothibabu School Management System20/8/202417/6/2026
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the sid parameter at /search.php?action=2.
AnalizadaCrítica (9.8)0.58%—Arajajyothibabu School Management System20/8/202417/6/2026
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the password parameter at login.php
AnalizadaAlta (7.2)1.6%—Elastic Kibana13/8/202417/6/2026
A flaw allowing arbitrary code execution was discovered in Kibana. An attacker with access to ML and Alerting connector features, as well as write access to internal ML indices can trigger a prototype pollution vulnerability, ultimately leading to arbitrary code execution.
ModificadaCrítica (10)1.3%—Veribase Order Management12/8/202417/6/2026
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Veribilim Software Veribase Order Management allows OS Command Injection. This issue affects Veribase Order Management: before v4.010.2.
AnalizadaMedia (6.5)0.41%—Elastic Kibana30/7/202417/6/2026
An issue was discovered in Kibana where a user with Viewer role could cause a Kibana instance to crash by sending a large number of maliciously crafted requests to a specific endpoint.
AplazadaMedia (5.5)0.68%—Dolibarr ERP CRMAI24/7/202417/6/2026
Dolibarr ERP CRM before 19.0.2-php8.2 was discovered to contain a remote code execution (RCE) vulnerability via the Computed field parameter under the Users Module Setup function.
AplazadaMedia (6.5)0.27%—Labibahmed Tabs FOR Wpbakery Page BuilderAI20/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in labibahmed Tabs For WPBakery Page Builder allows Stored XSS.This issue affects Tabs For WPBakery Page Builder: from n/a through 1.2.
AnalizadaMedia (6.1)30%💥 ExploitPribai Privategpt27/6/202417/6/2026
An open redirect vulnerability exists in imartinez/privategpt version 0.5.0 due to improper handling of the 'file' parameter. This vulnerability allows attackers to redirect users to a URL specified by user-controlled input without proper validation or sanitization. The impact of this vulnerability includes potential…
AnalizadaMedia (5.4)0.18%—Pribai Privategpt27/6/202417/6/2026
A Cross-Site Request Forgery (CSRF) vulnerability in version 0.5.0 of imartinez/privategpt allows an attacker to delete all uploaded files on the server. This can lead to data loss and service disruption for the application's users.
ModificadaMedia (4.9)1.8%💥 PoCElastic Kibana19/6/202417/6/2026
A high-privileged user, allowed to create custom osquery packs 17 could affect the availability of Kibana by uploading a maliciously crafted osquery pack.
ModificadaAlta (8.8)0.76%—Dolibarr Erp/crm18/6/20249/7/2026
An arbitrary file upload vulnerability in the Upload Template function of Dolibarr ERP CRM up to v19.0.1 allows attackers to execute arbitrary code via uploading a crafted .SQL file.
AnalizadaMedia (6.1)0.34%—Ibarn Project Ibarn17/6/202417/6/2026
zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /own.php.
AnalizadaMedia (6.3)0.35%—Ibarn Project Ibarn17/6/202417/6/2026
zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /pay.php.
ModificadaMedia (6.1)0.35%—Zhimengzhel Ibarn17/6/202417/6/2026
zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /index.php.
ModificadaMedia (6.1)0.34%—Elastic Kibana14/6/202417/6/2026
An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL.
ModificadaMedia (5.4)0.31%—Andibauer Svgmagic14/6/202417/6/2026
The SVGMagic WordPress plugin through 1.1 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.
AplazadaAlta (8.8)0.74%—Toshiba PrinterAI14/6/202417/6/2026
Path traversal vulnerability in the web server of the Toshiba printer enables attacker to overwrite orginal files or add new ones to the printer. As for the affected products/models/versions, see the reference URL.
AplazadaAlta (7.2)1.5%—ToshibatecAI14/6/202417/6/2026
An attacker can get Remote Code Execution by overwriting files. Overwriting files is enable by falsifying file name variable. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in…
AplazadaAlta (7.2)1.5%—Toshiba TECAI14/6/202417/6/2026
An attacker can get Remote Code Execution by overwriting files. Overwriting files is enable by falsifying package name variable. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in…
AplazadaAlta (7.2)1.5%—ToshibatecAI14/6/202417/6/2026
An attacker can get Remote Code Execution by overwriting files. Overwriting files is enable by falsifying session ID variable. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in…
AplazadaCrítica (9.8)1.6%—Toshibatec Remote Command ProgramAI14/6/202417/6/2026
Remote Command program allows an attacker to get Remote Code Execution. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vulnerability. For detail on…
AplazadaCrítica (9.8)3.2%💥 PoCToshibatec Remote CommandAI14/6/202417/6/2026
Remote Command program allows an attacker to get Remote Code Execution by overwriting existing Python files containing executable code. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score…
AplazadaAlta (7.4)0.27%—Toshiba PrinterAI14/6/202417/6/2026
It was observed that all the Toshiba printers contain credentials used for WebDAV access in the readable file. Then, it is possible to get a full access with WebDAV to the printer. As for the affected products/models/versions, see the reference URL.
AplazadaAlta (8.4)0.30%—Toshiba PrintersAI14/6/202417/6/2026
Toshiba printers provides API without authentication for internal access. A local attacker can bypass authentication in applications, providing administrative access. As for the affected products/models/versions, see the reference URL.
AplazadaAlta (7.4)0.25%—Toshiba PrintersAISendmailAI14/6/202417/6/2026
Toshiba printers use Sendmail to send emails to recipients. Sendmail is used with several insecure directories. A local attacker can inject a malicious Sendmail configuration file. As for the affected products/models/versions, see the reference URL.
Orbitaley — Vulnerabilidades