Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
2109 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.41% | — | Sourcecodester Online Food Ordering SystemAI | 8/4/2026 | 24/7/2026 | A vulnerability was identified in SourceCodester Online Food Ordering System 1.0. Affected by this issue is the function save_product of the file /Actions.php of the component POST Parameter Handler. Such manipulation of the argument price leads to business logic errors. The attack may be performed from remote. The… | |
| Analizada | Alta (7.7) | 0.98% | — | Amazon Research AND Engineering Studio | 6/4/2026 | 24/7/2026 | Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands on the cluster-manager EC2 instance via crafted input when using the FileBrowser functionality. To remediate this issue, users… | |
| Analizada | Alta (8.7) | 0.74% | — | Amazon Research AND Engineering Studio | 6/4/2026 | 24/7/2026 | Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Studio (RES) prior to version 2026.03 could allow an authenticated remote user to escalate privileges, assume the virtual desktop host instance profile permissions, and interact with AWS resources and… | |
| Analizada | Alta (8.7) | 0.98% | — | Amazon Research AND Engineering Studio | 6/4/2026 | 24/7/2026 | Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands as root on the virtual desktop host via a crafted session name. To remediate this issue,… | |
| Aplazada | Baja (2.1) | 0.34% | — | Hcengineering Huly PlatformAI | 6/4/2026 | 24/7/2026 | A vulnerability was identified in hcengineering Huly Platform 0.7.382. This affects an unknown part of the file server/front/src/index.ts of the component Import Endpoint. Such manipulation leads to server-side request forgery. The attack can be launched remotely. The exploit is publicly available and might be used.… | |
| Aplazada | Baja (2.9) | 0.39% | — | Hcengineering Huly PlatformAI | 6/4/2026 | 24/7/2026 | A vulnerability was determined in hcengineering Huly Platform 0.7.382. Affected by this issue is some unknown functionality of the file foundations/core/packages/token/src/token.ts of the component JWT Token Handler. This manipulation of the argument SERVER_SECRET with the input secret causes use of hard-coded… | |
| Analizada | Media (6.9) | 0.19% | — | River Past Ringtone Converter Project River Past Ringtone Converter | 5/4/2026 | 24/7/2026 | River Past Ringtone Converter 2.7.6.1601 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying oversized input to activation fields. Attackers can paste 300 bytes of data into the Email textbox and Activation code textarea via the Help menu's Activate dialog to… | |
| Analizada | Crítica (9.9) | 0.29% | 💥 PoC | Percona Monitoring AND Management | 2/4/2026 | 24/7/2026 | An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker with pmm-admin rights can abuse the "Add data source" feature to break out of the database context and execute shell commands on the underlying operating system. | |
| Modificada | Crítica (9.8) | 0.80% | — | Peaksel Animal Sounds AND Ringtones | 31/3/2026 | 24/7/2026 | An arbitrary file overwrite vulnerability in PEAKSEL D.O.O. NIS Animal Sounds and Ringtones v1.3.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure. | |
| Aplazada | Baja (2.1) | 0.45% | — | Code-projects Online Food Ordering SystemAI | 31/3/2026 | 17/6/2026 | A vulnerability was identified in code-projects Online Food Ordering System 1.0. Affected is an unknown function of the file /form/order.php of the component Order Module. Such manipulation of the argument cust_id leads to cross site scripting. The attack may be performed from remote. The exploit is publicly available… | |
| Analizada | Media (6.9) | 0.16% | — | Hhdsoftware Device Monitoring Studio | 30/3/2026 | 17/6/2026 | Device Monitoring Studio 8.10.00.8925 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string to the server connection dialog. Attackers can trigger the crash by entering a malformed server name or address containing repeated characters… | |
| Modificada | Crítica (9.1) | 0.89% | — | Redhat Build OF Apache Camel - HawtioRedhat Build OF Apache Camel FOR Spring BootRedhat Data GridRedhat Fuse+6 | 27/3/2026 | 21/9/2026 | A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP standards, can be exploited by a remote attacker to perform request smuggling.… | |
| Modificada | Crítica (9.1) | 0.89% | — | Redhat Build OF Apache Camel - HawtioRedhat Build OF Apache Camel FOR Spring BootRedhat Data GridRedhat Fuse+6 | 27/3/2026 | 21/9/2026 | A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exploited to launch request smuggling attacks, potentially bypassing… | |
| Modificada | Crítica (9.1) | 0.89% | — | Redhat Build OF Apache Camel - HawtioRedhat Build OF Apache Camel FOR Spring BootRedhat Data GridRedhat Fuse+5 | 27/3/2026 | 21/9/2026 | A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions of Apache Traffic Server and Google Cloud Classic Application Load Balancer, potentially leading to… | |
| Analizada | Alta (8.3) | 0.39% | — | Oretnom23 Online Food Ordering System | 27/3/2026 | 17/6/2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in admin/manage_category.php via the "id" parameter. | |
| Analizada | Crítica (9.8) | 0.50% | — | Oretnom23 Online Food Ordering System | 27/3/2026 | 17/6/2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/manage_product.php file via the "id" parameter. | |
| Analizada | Crítica (9.8) | 0.50% | — | Oretnom23 Online Food Ordering System | 27/3/2026 | 17/6/2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/view_product.php file via the "id" parameter. | |
| Analizada | Alta (8.8) | 0.46% | — | Oretnom23 Online Food Ordering System | 27/3/2026 | 17/6/2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_category action). The application fails to properly sanitize user input supplied to the "name" parameter. This allows an authenticated attacker to inject malicious SQL commands. | |
| Analizada | Crítica (9.8) | 0.50% | — | Oretnom23 Online Food Ordering System | 27/3/2026 | 17/6/2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_customer action). The application fails to properly sanitize user input supplied to the "username" parameter. This allows an attacker to inject malicious SQL commands. | |
| Analizada | Alta (8.8) | 0.46% | — | Oretnom23 Online Food Ordering System | 27/3/2026 | 17/6/2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_user action). The application fails to properly sanitize user input supplied to the "username" parameter. This allows an authenticated attacker to inject malicious SQL commands. | |
| Modificada | Media (5.4) | 0.24% | — | Oretnom23 Online Food Ordering System | 27/3/2026 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Category management module within the admin panel. The application fails to properly sanitize user input supplied to the "Category Name" field when creating or updating a category. When an administrator… | |
| Modificada | Alta (7.5) | 0.25% | — | Vmware Spring AI | 27/3/2026 | 17/6/2026 | In RedisFilterExpressionConverter of spring-ai-redis-store, when a user-controlled string is passed as a filter value for a TAG field, stringValue() inserts the value directly into the @field:{VALUE} RediSearch TAG block without escaping characters.This issue affects Spring AI: from 1.0.0 before 1.0.5, from 1.1.0… | |
| Analizada | Alta (7.5) | 0.25% | — | Vmware Spring AI | 27/3/2026 | 17/6/2026 | Spring AI's spring-ai-neo4j-store contains a Cypher injection vulnerability in Neo4jVectorFilterExpressionConverter. When a user-controlled string is passed as a filter expression key in Neo4jVectorFilterExpressionConverter of spring-ai-neo4j-store, doKey() embeds the key into a backtick-delimited Cypher property… | |
| Modificada | Alta (8.6) | 0.35% | — | Vmware Spring AI | 27/3/2026 | 17/6/2026 | Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing multimodal messages that include user-supplied media URLs. Insufficient validation of those URLs allows an attacker to induce the server to issue HTTP requests to unintended… | |
| Modificada | Crítica (9.8) | 1.1% | 💥 PoC | Vmware Spring AI | 27/3/2026 | 17/6/2026 | In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter expression key. A malicious actor could exploit this to execute arbitrary code. Only applications that use SimpleVectorStore and pass user-supplied input as a filter expression key are affected. This… |