Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
2109 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.48% | — | Code-projects Online Food Ordering SystemAI | 26/3/2026 | 17/6/2026 | A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the file /dbfood/localhost.sql. This manipulation causes files or directories accessible. The attack can be initiated remotely. The exploit has been made available to the public and could be used for… | |
| Aplazada | Baja (1.9) | 0.35% | — | Code-projects Online Food Ordering SystemAI | 26/3/2026 | 17/6/2026 | A security flaw has been discovered in code-projects Online Food Ordering System 1.0. Affected by this issue is some unknown functionality of the file /dbfood/food.php. The manipulation of the argument cuisines results in cross site scripting. It is possible to launch the attack remotely. The exploit has been released… | |
| Aplazada | Baja (2.1) | 0.45% | — | Code-projects Online Food Ordering SystemAI | 26/3/2026 | 17/6/2026 | A vulnerability was identified in code-projects Online Food Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /dbfood/contact.php. The manipulation of the argument Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly… | |
| Aplazada | Alta (8.5) | 0.15% | — | Ratoc Raid Monitoring ManagerAI | 26/3/2026 | 17/6/2026 | The installer of RATOC RAID Monitoring Manager for Windows allows to customize the installation folder. If the installation folder is customized to some non-default one, the folder may be left with un-secure ACLs and non-administrative users can alter contents of that folder. It may allow a non-administrative user to… | |
| Aplazada | Alta (8.4) | 0.18% | — | Ratoc Raid Monitoring ManagerAI | 26/3/2026 | 17/6/2026 | The installer of RATOC RAID Monitoring Manager for Windows searches the current directory to load certain DLLs. If a user is directed to place a crafted DLL with the installer, an arbitrary code may be executed with the administrator privilege. | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Online Food Ordering SystemAI | 26/3/2026 | 17/6/2026 | A vulnerability was detected in code-projects Online Food Ordering System 1.0. This issue affects some unknown processing of the file /admin.php of the component Admin Login Module. The manipulation of the argument Username results in sql injection. The attack may be performed from remote. The exploit is now public… | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Online Food Ordering SystemAI | 26/3/2026 | 17/6/2026 | A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the file form/cart.php of the component Shopping Cart Module. Executing a manipulation of the argument del can lead to sql injection. The attack can be executed remotely. The exploit has been made available… | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester Food Ordering SystemAI | 26/3/2026 | 17/6/2026 | A vulnerability has been found in SourceCodester Food Ordering System 1.0. This affects an unknown function of the file /purchase.php of the component Parameter Handler. The manipulation of the argument custom leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| En análisis | Alta (8.6) | 1.2% | 💥 Exploit | Vmware Spring Cloud Config | 24/3/2026 | 4/9/2026 | Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configured search directories.This issue affects Spring Cloud: from 3.1.X before 3.1.13,… | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester Online Catering ReservationAI | 24/3/2026 | 17/6/2026 | A vulnerability was identified in SourceCodester Online Catering Reservation 1.0. Impacted is an unknown function of the file /search.php. Such manipulation of the argument rcode leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. | |
| Aplazada | Media (5.5) | 0.41% | — | Projectworlds Online Notes Sharing SystemAI | 22/3/2026 | 17/6/2026 | A vulnerability was detected in projectworlds Online Notes Sharing System 1.0. This issue affects some unknown processing of the file /login.php of the component Parameters Handler. The manipulation of the argument User results in sql injection. The attack can be executed remotely. The exploit is now public and may be… | |
| Aplazada | Media (5.5) | 0.47% | — | Acrel Environmental Monitoring Cloud PlatformAI | 22/3/2026 | 17/6/2026 | A vulnerability was found in Acrel Environmental Monitoring Cloud Platform 1.1.0. This issue affects some unknown processing. Performing a manipulation results in unrestricted upload. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this… | |
| Analizada | Baja (2.1) | 0.50% | — | Adonesevangelista Online Frozen Foods Ordering System | 20/3/2026 | 17/6/2026 | A security vulnerability has been detected in itsourcecode Online Frozen Foods Ordering System 1.0. This vulnerability affects unknown code of the file /admin/admin_edit_supplier.php. The manipulation of the argument Supplier_Name leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Baja (2) | 0.51% | — | Adonesevangelista Online Frozen Foods Ordering System | 20/3/2026 | 17/6/2026 | A weakness has been identified in itsourcecode Online Frozen Foods Ordering System 1.0. This affects an unknown part of the file /admin/admin_edit_employee.php. Executing a manipulation of the argument First_Name can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made… | |
| Analizada | Baja (2) | 0.51% | — | Adonesevangelista Online Frozen Foods Ordering System | 20/3/2026 | 17/6/2026 | A security flaw has been discovered in itsourcecode Online Frozen Foods Ordering System 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_edit_menu.php. Performing a manipulation of the argument product_name results in sql injection. It is possible to initiate the attack remotely. The… | |
| Analizada | Baja (2) | 0.51% | — | Adonesevangelista Online Frozen Foods Ordering System | 20/3/2026 | 17/6/2026 | A vulnerability was identified in itsourcecode Online Frozen Foods Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin_edit_menu_action.php. Such manipulation of the argument product_name leads to sql injection. The attack may be performed from remote. The exploit… | |
| Analizada | Alta (8.8) | 0.71% | — | Ctfer Monitoring | 20/3/2026 | 17/6/2026 | The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, metrics and distributed traces). In versions prior to 0.2.2, the sanitizeArchivePath function in pkg/extract/extract.go (lines 248–254) is vulnerable to Path Traversal due to a missing trailing path… | |
| Analizada | Media (5.9) | 0.39% | — | Vmware Spring Framework | 20/3/2026 | 17/6/2026 | Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16,… | |
| Analizada | Baja (2.6) | 0.11% | — | Vmware Spring Framework | 20/3/2026 | 17/6/2026 | Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46. | |
| Analizada | Alta (8.1) | 0.36% | — | Vmware Spring Boot | 20/3/2026 | 17/6/2026 | Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under the path used by the CloudFoundry Actuator endpoints. This issue affects Spring Security: from 4.0.0 through 4.0.3, from 3.5.0 through 3.5.11,… | |
| Analizada | Crítica (9.1) | 0.48% | 💥 PoC | Vmware Spring Security | 19/3/2026 | 17/6/2026 | When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written. This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP Headers: : from 5.7.0 through 5.7.21, from 5.8.0 through… | |
| Analizada | Alta (8.1) | 0.33% | — | Vmware Spring Boot | 19/3/2026 | 17/6/2026 | Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under a specific path, already configured for a Health Group additional path. This issue affects Spring Boot: from 4.0 before 4.0.3, from 3.5 before… | |
| Analizada | Alta (8.8) | 0.52% | 💥 PoC | Vmware Spring AI | 18/3/2026 | 17/6/2026 | A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metadata-based access controls and execute arbitrary SQL commands. The vulnerability exists due to missing input sanitization. | |
| Analizada | Alta (8.6) | 0.53% | — | Vmware Spring AI | 18/3/2026 | 17/6/2026 | A JSONPath injection vulnerability in Spring AI's AbstractFilterExpressionConverter allows authenticated users to bypass metadata-based access controls through crafted filter expressions. User-controlled input passed to FilterExpressionBuilder is concatenated into JSONPath queries without proper escaping, enabling… | |
| Aplazada | Alta (7.1) | 0.41% | — | Ctfer.io MonitoringAI | 16/3/2026 | 17/6/2026 | The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, metrics and distributed traces). Prior to 0.2.1, due to a mis-written NetworkPolicy, a malicious actor can pivot from a component to any other namespace. This breaks the security-by-default property… |