Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2768 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.7) | 0.30% | — | Oracle Database Server | 21/10/2025 | 17/6/2026 | Vulnerability in the RDBMS Functional Index component of Oracle Database Server. Supported versions that are affected are 23.4-23.9. Easily exploitable vulnerability allows high privileged attacker having SYSDBA privilege with network access via Oracle Net to compromise RDBMS Functional Index. Successful attacks of… | |
| Analizada | Media (5.8) | 0.32% | — | Oracle Database Server | 21/10/2025 | 17/6/2026 | Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.28, 21.3-21.19 and 23.4-23.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via Bonjour to compromise Portable Clusterware. While the vulnerability is… | |
| Analizada | Baja (2.7) | 0.27% | — | Oracle Database Server | 21/10/2025 | 30/9/2026 | Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 23.4-23.9. Easily exploitable vulnerability allows high privileged attacker having DBA privilege with network access via Oracle Net to compromise Unified Audit. Successful attacks of this vulnerability can… | |
| Aplazada | Media (5.4) | 0.26% | — | Base Digitale Group SPA Centrax Open PsimAI | 16/10/2025 | 17/6/2026 | Boolean SQL injection vulnerability in the web app of Base Digitale Group spa product Centrax Open PSIM version 6.1 allows a low level priviliged user that has access to the platform, to execute arbitrary SQL commands via the datafine parameter. | |
| Aplazada | Media (5.4) | 0.28% | — | Base Digitale Group SPA Centrax Open PsimAI | 16/10/2025 | 17/6/2026 | SQL injection vulnerability in the cmd component of Base Digitale Group spa product Centrax Open PSIM version 6.1 allows an unauthenticated user to execute arbitrary SQL commands via the sender parameter. | |
| Aplazada | Alta (8.6) | 0.58% | — | Ragic Enterprise Cloud DatabaseAI | 13/10/2025 | 17/6/2026 | Enterprise Cloud Database developed by Ragic has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | |
| Analizada | Baja (2.1) | 0.40% | — | Fabian Web-based Inventory AND POS System | 8/10/2025 | 17/6/2026 | A vulnerability was determined in code-projects Web-Based Inventory and POS System 1.0. The impacted element is an unknown function of the file /transaction.php. This manipulation of the argument shopid causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and… | |
| Analizada | Media (5.5) | 0.48% | — | Fabian Web-based Inventory AND POS System | 8/10/2025 | 17/6/2026 | A vulnerability was determined in code-projects Web-Based Inventory and POS System 1.0. This impacts an unknown function of the file /login.php. Executing manipulation of the argument emailid can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Baja (2.1) | 0.26% | — | Kaifangqian-baseAI | 7/10/2025 | 17/6/2026 | A security flaw has been discovered in kaifangqian kaifangqian-base up to 7b3faecda13848b3ced6c17c7423b76c5b47b8ab. This issue affects the function getAllUsers of the file kaifangqian-parent/kaifangqian-system/src/main/java/com/kaifangqian/modules/system/controller/SysUserController.java. The manipulation results in… | |
| Analizada | Media (6.1) | 0.23% | — | Senior-walter Web-based Pharmacy Product Management System | 30/9/2025 | 17/6/2026 | SourceCodester Web-based Pharmacy Product Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in Category Management via the category name field. | |
| Aplazada | Media (5.3) | 0.27% | — | Sumit Singh Classic Widgets With Block Based WidgetsAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Sumit Singh Classic Widgets with Block-based Widgets classic-widgets-with-block-based-widgets allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Classic Widgets with Block-based Widgets: from n/a through <= 1.0.1. | |
| Aplazada | Media (5.9) | 0.22% | — | Brijeshk89 Ip-based-loginAI | 22/9/2025 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brijeshk89 IP Based Login ip-based-login allows Stored XSS.This issue affects IP Based Login: from n/a through <= 2.4.3. | |
| Aplazada | Media (6.5) | 0.21% | — | Xnau Participants DatabaseAI | 22/9/2025 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xnau webdesign Participants Database participants-database allows Stored XSS.This issue affects Participants Database: from n/a through <= 2.7.6.3. | |
| Aplazada | Alta (8.1) | 0.37% | — | Miniorange OTP Verification With FirebaseAI | 19/9/2025 | 17/6/2026 | The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the 'handle_mofirebase_form_options' function in versions 3.1.0 to 3.6.2. This makes it possible for unauthenticated attackers to update the default role to Administrator.… | |
| Analizada | Media (5.5) | 0.48% | — | Itsourcecode Web-based Internet Laboratory Management System | 17/9/2025 | 25/9/2026 | A security flaw has been discovered in itsourcecode Web-Based Internet Laboratory Management System 1.0. Impacted is the function User::AuthenticateUser of the file login.php. Performing manipulation of the argument user_email results in sql injection. Remote exploitation of the attack is possible. The exploit has… | |
| Analizada | Alta (8.1) | 0.39% | — | Executeautomation MCP Database Server | 16/9/2025 | 17/6/2026 | The mcp-database-server (MCP Server) 1.1.0 and earlier, as distributed via the npm package @executeautomation/database-server, fails to implement adequate security controls to properly enforce a "read-only" mode. This vulnerability affects only the npm distribution; other distributions are not impacted. As a result,… | |
| Analizada | Media (6.1) | 0.28% | — | Askar634 Computer Base Test | 16/9/2025 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the /users/adminpanel/admin/home.php?page=feedbacks file of Kashipara Computer Base Test v1.0. Attackers can inject malicious scripts via the smyFeedbacks POST parameter in /users/home.php. | |
| Aplazada | Baja (2.3) | 0.33% | — | Form TO DatabaseAI | 16/9/2025 | 17/6/2026 | The extension "Form to Database" is susceptible to Cross-Site Scripting. This issue affects the following versions: before 2.2.5, from 3.0.0 before 3.2.2, from 4.0.0 before 4.2.3, from 5.0.0 before 5.0.2. | |
| Modificada | Alta (8.1) | 0.43% | — | Senior-walter Web-based Pharmacy Product Management System | 15/9/2025 | 5/7/2026 | SourceCodester Web-based Pharmacy Product Management System 1.0 is vulnerable to Incorrect Access Control, which allows low-privileged users to forge high privileged (such as admin) sessions and perform sensitive operations such as adding new users. | |
| Aplazada | Crítica (9.3) | 0.64% | — | Gotac Statistical Database SystemAI | 15/9/2025 | 17/6/2026 | Statistical Database System developed by Gotac has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify, and delete database contents with high-level privileges. | |
| Aplazada | Baja (2.7) | 0.40% | — | Matrix-sdk-baseAI | 11/9/2025 | 17/6/2026 | matrix-sdk-base is the base component to build a Matrix client library. In matrix-sdk-base before 0.14.1, calling the `RoomMember::normalized_power_level()` method can cause a panic if a room member has a power level of `Int::Min`. The issue is fixed in matrix-sdk-base 0.14.1. The affected method isn’t used… | |
| Aplazada | Alta (7.6) | 0.28% | — | Presstigers ZIP Code Based Content ProtectionAI | 9/9/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PressTigers ZIP Code Based Content Protection zip-code-based-content-protection allows SQL Injection.This issue affects ZIP Code Based Content Protection: from n/a through <= 1.0.0. | |
| Aplazada | Alta (7.1) | 0.13% | — | Subhash Kumar Database TO ExcelAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Subhash Kumar Database to Excel database-to-excel allows Stored XSS.This issue affects Database to Excel: from n/a through <= 1.0. | |
| Aplazada | Media (4.2) | 0.23% | — | Basecamp Google Sign INAI | 29/8/2025 | 17/6/2026 | Basecamp's Google Sign-In adds Google sign-in to Rails applications. Prior to version 1.3.1, it is possible to redirect a user to another origin if the "proceed_to" value in the session store is set to a protocol-relative URL. Normally the value of this URL is only written and read by the library or the calling… | |
| Aplazada | Media (4.2) | 0.24% | — | Basecamp Google Sign INAIRubyonrails RailsAI | 27/8/2025 | 17/6/2026 | Basecamp's Google Sign-In adds Google sign-in to Rails applications. Prior to version 1.3.0, it is possible to craft a malformed URL that passes the "same origin" check, resulting in the user being redirected to another origin. Rails applications configured to store the flash information in a session cookie may be… |