Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

5178 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.52%—Pharmacy/medical Store Point OF Sale System Project Pharmacy/medical Store Point OF Sale System7/6/202417/6/2026
Sourcecodester Pharmacy/Medical Store Point of Sale System 1.0 is vulnerable SQL Injection via login.php. This vulnerability stems from inadequate validation of user inputs for the email and password parameters, allowing attackers to inject malicious SQL queries.
ModificadaMedia (6.5)0.26%—Canonical Netplan7/6/202417/6/2026
netplan leaks the private key of wireguard to local users. Versions after 1.0 are not affected.
ModificadaMedia (5.4)0.31%—Wpthemespace Magical Addons FOR Elementor6/6/202417/6/2026
The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 1.1.39 due to insufficient input sanitization and output escaping. This makes…
ModificadaMedia (5.5)0.20%—Apport Project ApportCanonical Ubuntu Linux4/6/202417/6/2026
Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing
ModificadaAlta (7.8)0.23%—Apport Project ApportCanonical Ubuntu Linux4/6/202417/6/2026
Apport does not disable python crash handler before entering chroot
ModificadaMedia (5.5)0.20%—Apport Project ApportCanonical Ubuntu Linux4/6/202417/6/2026
is_closing_session() allows users to consume RAM in the Apport process
ModificadaAlta (7.1)0.21%—Apport Project ApportCanonical Ubuntu Linux4/6/202417/6/2026
is_closing_session() allows users to create arbitrary tcp dbus connections
ModificadaMedia (5.5)0.25%—Apport Project ApportCanonical Ubuntu Linux4/6/202417/6/2026
is_closing_session() allows users to fill up apport.log
ModificadaMedia (5.5)0.20%—Apport Project ApportCanonical Ubuntu Linux4/6/202417/6/2026
~/.config/apport/settings parsing is vulnerable to "billion laughs" attack
AnalizadaAlta (7.8)0.23%—Canonical ApportCanonical Ubuntu Linux3/6/202417/6/2026
Apport can be tricked into connecting to arbitrary sockets as the root user
AnalizadaAlta (8.4)0.28%—Canonical Subiquity3/6/202417/6/2026
Subiquity Shows Guided Storage Passphrase in Plaintext with Read-all Permissions
AnalizadaAlta (7.8)0.38%💥 PoCCanonical ApportCanonical Ubuntu Linux3/6/202417/6/2026
There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an attacker to execute arbitrary code as root.
AnalizadaAlta (8.1)0.83%—Canonical Snapd31/5/202417/6/2026
The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. It was found that snapctl did not properly parse command-line arguments, allowing an unprivileged user to trigger an authorised action on behalf of the snap that would…
AplazadaAlta (8.2)0.36%—Quanticalabs Chauffeur Taxi Booking SystemAI17/5/202417/6/2026
Missing Authorization vulnerability in QuanticaLabs Chauffeur Taxi Booking System for WordPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Chauffeur Taxi Booking System for WordPress: from n/a through 6.9.
ModificadaMedia (5.4)0.27%—Wpthemespace Magical Addons FOR Elementor14/5/202417/6/2026
The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's text effect widget in all versions up to, and including, 1.1.37 due to insufficient input sanitization and output escaping…
AnalizadaCrítica (9.8)0.84%—Bluenettechnology Clinical Browsing System8/5/202417/6/2026
A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1. It has been classified as critical. This affects an unknown part of the file /xds/cloudInterface.php. The manipulation of the argument INSTI_CODE leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…
AnalizadaAlta (7.5)0.66%—Bluenettechnology Clinical Browsing System8/5/202417/6/2026
A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1 and classified as critical. Affected by this issue is some unknown functionality of the file /xds/outIndex.php. The manipulation of the argument name leads to sql injection. The attack may be launched remotely. The exploit has been…
ModificadaMedia (5.4)0.27%—Wpthemespace Magical Addons FOR Elementor8/5/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor alam Magical Addons For Elementor allows Stored XSS.This issue affects Magical Addons For Elementor: from n/a through 1.1.34.
AplazadaAlta (7.6)0.43%—Shortpixel Critical CSSAI3/5/202417/6/2026
Missing Authorization vulnerability in ShortPixel ShortPixel Critical CSS.This issue affects ShortPixel Critical CSS: from n/a through 1.0.2.
AnalizadaMedia (6.5)12%💥 ExploitBluenettechnology Clinical Browsing System27/4/202417/6/2026
A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1. It has been classified as critical. This affects an unknown part of the file /xds/deleteStudy.php. The manipulation of the argument documentUniqueId leads to sql injection. It is possible to initiate the attack remotely. The exploit has…
AnalizadaMedia (4.3)0.38%—Oracle Customer Relationship Management Technical Foundation16/4/202417/6/2026
Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation.…
AplazadaMedia (6.5)0.31%—I13websolution WP Responsive Tabs Horizontal Vertical AND Accordion TabsAI11/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in I Thirteen Web Solution WP Responsive Tabs horizontal vertical and accordion Tabs allows Stored XSS.This issue affects WP Responsive Tabs horizontal vertical and accordion Tabs: from n/a through 1.1.17.
AnalizadaMedia (6.5)0.20%—Canonical Pebble4/4/202417/6/2026
It was discovered that Canonical's Pebble service manager read-file API and the associated pebble pull command, before v1.10.2, allowed unprivileged local users to read files with root-equivalent permissions when Pebble was running as root. Fixes are also available as backports to v1.1.1, v1.4.2, and v1.7.4.
AplazadaMedia (5.5)0.29%—Bestpractical RTAI4/4/202417/6/2026
Information exposure vulnerability in RT software affecting version 4.4.1. This vulnerability allows an attacker with local access to the device to retrieve sensitive information about the application, such as vulnerability tickets, because the application stores the information in the browser cache, leading to…
AplazadaCrítica (10)0.63%—Quanticalabs Chauffeur Taxi Booking SystemAI31/3/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in QuanticaLabs Chauffeur Taxi Booking System for WordPress.This issue affects Chauffeur Taxi Booking System for WordPress: from n/a through 7.2.