Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1016 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.2)0.34%—Pribai Privategpt6/6/202417/6/2026
A Server-Side Request Forgery (SSRF) vulnerability exists in the file upload section of imartinez/privategpt version 0.5.0. This vulnerability allows attackers to send crafted requests that could result in unauthorized access to the local network and potentially sensitive information. Specifically, by manipulating the…
ModificadaCrítica (10)1.3%—Aomedia Libaom5/6/202417/6/2026
Integer overflow in libaom internal function img_alloc_helper can lead to heap buffer overflow. This function can be reached via 3 callers:
AplazadaMedia (4.6)12%—DolibarrAI3/6/202417/6/2026
A Reflected Cross-site scripting (XSS) vulnerability located in htdocs/compta/paiement/card.php of Dolibarr before 19.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the facid parameter.
AnalizadaCrítica (9.1)35%💥 ExploitDolibarr Erp/crm24/5/202417/6/2026
Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters viewstatut in /dolibarr/commande/list.php.
AnalizadaCrítica (9.1)0.56%—Dolibarr Erp/crm24/5/202417/6/2026
Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters sortorder y sortfield in…
AnalizadaMedia (5.4)0.32%—Pribai Privategpt16/5/202417/6/2026
A stored Cross-Site Scripting (XSS) vulnerability exists in the 'imartinez/privategpt' repository due to improper validation of file uploads. Attackers can exploit this vulnerability by uploading malicious HTML files, such as those containing JavaScript payloads, which are then executed in the context of the victim's…
AnalizadaAlta (7.5)1.1%—Pribai Privategpt16/5/202417/6/2026
imartinez/privategpt version 0.2.0 is vulnerable to a local file inclusion vulnerability that allows attackers to read arbitrary files from the filesystem. By manipulating file upload functionality to ingest arbitrary local files, attackers can exploit the 'Search in Docs' feature or query the AI to retrieve or…
AplazadaCrítica (9.8)0.95%—Zenario Twig SnippetAITribalsystems ZenarioAI4/5/202417/6/2026
Zenario before 9.5.60437 uses Twig filters insecurely in the Twig Snippet plugin, and in the site-wide HEAD and BODY elements, enabling code execution by a designer or an administrator.
AplazadaMedia (6.5)0.55%—Tribalsystems ZenarioAI4/5/202417/6/2026
The Tree Explorer tool from Organizer in Zenario before 9.5.60602 is affected by XSS. (This component was removed in 9.5.60602.)
AplazadaAlta (8.8)0.79%💥 PoCShibang Communications IP Network Intercom Broadcasting SystemAI17/4/202417/6/2026
File Upload vulnerability in Shibang Communications Co., Ltd. IP network intercom broadcasting system v.1.0 allows a local attacker to execute arbitrary code via the my_parser.php component.
AnalizadaAlta (7.5)0.26%—Dolibarr Erp/crm17/4/202417/6/2026
Incorrect access control in Dolibarr ERP CRM versions 19.0.0 and before, allows authenticated attackers to steal victim users' session cookies and CSRF protection tokens via user interaction with a crafted web page, leading to account takeover.
AnalizadaAlta (7.8)85%—LibarchiveFedoraproject FedoraMicrosoft Windows 11 22h2Microsoft Windows 11 23h2+19/4/202417/6/2026
Libarchive Remote Code Execution Vulnerability
ModificadaAlta (8.8)0.81%—Dolibarr Erp/crm3/4/20249/7/2026
Lack of sanitization during Installation Process in Dolibarr ERP CRM up to version 19.0.0 allows an attacker with adjacent access to the network to execute arbitrary code via a specifically crafted input.
AplazadaMedia (5.4)0.65%—Shibang Communications IP Network Intercom Broadcasting SystemAI3/4/202417/6/2026
A vulnerability classified as critical has been found in Shibang Communications IP Network Intercom Broadcasting System 1.0. This affects an unknown part of the file /php/busyscreenshotpush.php. The manipulation of the argument jsondata[callee]/jsondata[imagename] leads to path traversal: '../filedir'. It is possible…
AplazadaMedia (4.3)0.26%—Klbtheme ClotyaAIKlbtheme CosmetsyAIKlbtheme FurnobAIKlbtheme BacolaAI+326/3/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in KlbTheme Clotya theme, KlbTheme Cosmetsy theme, KlbTheme Furnob theme, KlbTheme Bacola theme, KlbTheme Partdo theme, KlbTheme Medibazar theme, KlbTheme Machic theme.This issue affects Clotya theme: from n/a through 1.1.6; Cosmetsy theme: from n/a through 1.7.7; Furnob…
AplazadaAlta (7.1)0.46%—Klbtheme CosmetsyAIKlbtheme PartdoAIKlbtheme BacolaAIKlbtheme MedibazarAI+226/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KlbTheme Cosmetsy theme (core plugin), KlbTheme Partdo theme (core plugin), KlbTheme Bacola theme (core plugin), KlbTheme Medibazar theme (core plugin), KlbTheme Furnob theme (core plugin), KlbTheme Clotya theme (core…
ModificadaMedia (6.5)0.50%—Elastic Kibana7/2/202417/6/2026
An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DLS) or Field-level security (FLS) when querying the .alerts-security.alerts-{space_id} indices. Users who are authorized to call this API may obtain unauthorized access to documents if their roles are…
ModificadaMedia (6.1)0.56%—Dolibarr Erp/crm25/1/202417/6/2026
Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Version 18.0.4 has a HTML Injection vulnerability in the Home page of the Dolibarr Application. This vulnerability allows an attacker to inject arbitrary HTML tags and manipulate the rendered content in the…
ModificadaMedia (6.5)0.69%—Elastic Kibana13/12/202317/6/2026
An issue was discovered by Elastic whereby sensitive information may be recorded in Kibana logs in the event of an error or in the event where debug level logging is enabled in Kibana. Elastic has released Kibana 8.11.2 which resolves this issue. The messages recorded in the log may contain Account credentials for the…
ModificadaMedia (6.5)0.66%—Elastic Kibana13/12/202317/6/2026
An issue was discovered by Elastic whereby sensitive information may be recorded in Kibana logs in the event of an error. Elastic has released Kibana 8.11.1 which resolves this issue. The error message recorded in the log may contain account credentials for the kibana_system user, API Keys, and credentials of Kibana…
ModificadaCrítica (9.8)0.80%—Veribase23/11/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Veribilim Software Computer Veribase allows SQL Injection. This issue affects Veribase: through 20231123. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
ModificadaMedia (4.3)0.70%—Elastic Kibana22/11/202317/6/2026
It was discovered that Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a malicious user could arbitrarily traverse the Kibana host to load internal files ending in the .pbf extension.
ModificadaAlta (7.2)1.2%—Elastic Kibana22/11/202317/6/2026
It was discovered that a user with Fleet admin permissions could upload a malicious package. Due to using an older version of the js-yaml library, this package would be loaded in an insecure manner, allowing an attacker to execute commands on the Kibana server.
ModificadaAlta (8.8)1.0%—Elastic Kibana22/11/202317/6/2026
Kibana contains an embedded version of the Chromium browser that the Reporting feature uses to generate the downloadable reports. If a user with permissions to generate reports is able to render arbitrary HTML with this browser, they may be able to leverage known Chromium vulnerabilities to conduct further attacks.…
ModificadaMedia (6.5)0.56%—Dolibarr Erp/crm1/11/202317/6/2026
Improper Access Control in Dolibarr ERP CRM <= v17.0.3 allows an unauthorized authenticated user to read a database table containing customer data
Orbitaley — Vulnerabilidades