Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
5178 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.52% | — | Pharmacy/medical Store Point OF Sale System Project Pharmacy/medical Store Point OF Sale System | 7/6/2024 | 17/6/2026 | Sourcecodester Pharmacy/Medical Store Point of Sale System 1.0 is vulnerable SQL Injection via login.php. This vulnerability stems from inadequate validation of user inputs for the email and password parameters, allowing attackers to inject malicious SQL queries. | |
| Modificada | Media (6.5) | 0.26% | — | Canonical Netplan | 7/6/2024 | 17/6/2026 | netplan leaks the private key of wireguard to local users. Versions after 1.0 are not affected. | |
| Modificada | Media (5.4) | 0.31% | — | Wpthemespace Magical Addons FOR Elementor | 6/6/2024 | 17/6/2026 | The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 1.1.39 due to insufficient input sanitization and output escaping. This makes… | |
| Modificada | Media (5.5) | 0.20% | — | Apport Project ApportCanonical Ubuntu Linux | 4/6/2024 | 17/6/2026 | Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing | |
| Modificada | Alta (7.8) | 0.23% | — | Apport Project ApportCanonical Ubuntu Linux | 4/6/2024 | 17/6/2026 | Apport does not disable python crash handler before entering chroot | |
| Modificada | Media (5.5) | 0.20% | — | Apport Project ApportCanonical Ubuntu Linux | 4/6/2024 | 17/6/2026 | is_closing_session() allows users to consume RAM in the Apport process | |
| Modificada | Alta (7.1) | 0.21% | — | Apport Project ApportCanonical Ubuntu Linux | 4/6/2024 | 17/6/2026 | is_closing_session() allows users to create arbitrary tcp dbus connections | |
| Modificada | Media (5.5) | 0.25% | — | Apport Project ApportCanonical Ubuntu Linux | 4/6/2024 | 17/6/2026 | is_closing_session() allows users to fill up apport.log | |
| Modificada | Media (5.5) | 0.20% | — | Apport Project ApportCanonical Ubuntu Linux | 4/6/2024 | 17/6/2026 | ~/.config/apport/settings parsing is vulnerable to "billion laughs" attack | |
| Analizada | Alta (7.8) | 0.23% | — | Canonical ApportCanonical Ubuntu Linux | 3/6/2024 | 17/6/2026 | Apport can be tricked into connecting to arbitrary sockets as the root user | |
| Analizada | Alta (8.4) | 0.28% | — | Canonical Subiquity | 3/6/2024 | 17/6/2026 | Subiquity Shows Guided Storage Passphrase in Plaintext with Read-all Permissions | |
| Analizada | Alta (7.8) | 0.38% | 💥 PoC | Canonical ApportCanonical Ubuntu Linux | 3/6/2024 | 17/6/2026 | There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an attacker to execute arbitrary code as root. | |
| Analizada | Alta (8.1) | 0.83% | — | Canonical Snapd | 31/5/2024 | 17/6/2026 | The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. It was found that snapctl did not properly parse command-line arguments, allowing an unprivileged user to trigger an authorised action on behalf of the snap that would… | |
| Aplazada | Alta (8.2) | 0.36% | — | Quanticalabs Chauffeur Taxi Booking SystemAI | 17/5/2024 | 17/6/2026 | Missing Authorization vulnerability in QuanticaLabs Chauffeur Taxi Booking System for WordPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Chauffeur Taxi Booking System for WordPress: from n/a through 6.9. | |
| Modificada | Media (5.4) | 0.27% | — | Wpthemespace Magical Addons FOR Elementor | 14/5/2024 | 17/6/2026 | The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's text effect widget in all versions up to, and including, 1.1.37 due to insufficient input sanitization and output escaping… | |
| Analizada | Crítica (9.8) | 0.84% | — | Bluenettechnology Clinical Browsing System | 8/5/2024 | 17/6/2026 | A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1. It has been classified as critical. This affects an unknown part of the file /xds/cloudInterface.php. The manipulation of the argument INSTI_CODE leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Alta (7.5) | 0.66% | — | Bluenettechnology Clinical Browsing System | 8/5/2024 | 17/6/2026 | A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1 and classified as critical. Affected by this issue is some unknown functionality of the file /xds/outIndex.php. The manipulation of the argument name leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Modificada | Media (5.4) | 0.27% | — | Wpthemespace Magical Addons FOR Elementor | 8/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor alam Magical Addons For Elementor allows Stored XSS.This issue affects Magical Addons For Elementor: from n/a through 1.1.34. | |
| Aplazada | Alta (7.6) | 0.43% | — | Shortpixel Critical CSSAI | 3/5/2024 | 17/6/2026 | Missing Authorization vulnerability in ShortPixel ShortPixel Critical CSS.This issue affects ShortPixel Critical CSS: from n/a through 1.0.2. | |
| Analizada | Media (6.5) | 12% | 💥 Exploit | Bluenettechnology Clinical Browsing System | 27/4/2024 | 17/6/2026 | A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1. It has been classified as critical. This affects an unknown part of the file /xds/deleteStudy.php. The manipulation of the argument documentUniqueId leads to sql injection. It is possible to initiate the attack remotely. The exploit has… | |
| Analizada | Media (4.3) | 0.38% | — | Oracle Customer Relationship Management Technical Foundation | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation.… | |
| Aplazada | Media (6.5) | 0.31% | — | I13websolution WP Responsive Tabs Horizontal Vertical AND Accordion TabsAI | 11/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in I Thirteen Web Solution WP Responsive Tabs horizontal vertical and accordion Tabs allows Stored XSS.This issue affects WP Responsive Tabs horizontal vertical and accordion Tabs: from n/a through 1.1.17. | |
| Analizada | Media (6.5) | 0.20% | — | Canonical Pebble | 4/4/2024 | 17/6/2026 | It was discovered that Canonical's Pebble service manager read-file API and the associated pebble pull command, before v1.10.2, allowed unprivileged local users to read files with root-equivalent permissions when Pebble was running as root. Fixes are also available as backports to v1.1.1, v1.4.2, and v1.7.4. | |
| Aplazada | Media (5.5) | 0.29% | — | Bestpractical RTAI | 4/4/2024 | 17/6/2026 | Information exposure vulnerability in RT software affecting version 4.4.1. This vulnerability allows an attacker with local access to the device to retrieve sensitive information about the application, such as vulnerability tickets, because the application stores the information in the browser cache, leading to… | |
| Aplazada | Crítica (10) | 0.63% | — | Quanticalabs Chauffeur Taxi Booking SystemAI | 31/3/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in QuanticaLabs Chauffeur Taxi Booking System for WordPress.This issue affects Chauffeur Taxi Booking System for WordPress: from n/a through 7.2. |