Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
61 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.65% | — | Uatech Badaso | 26/8/2025 | 17/6/2026 | An arbitrary code execution vulnerability in Badaso CMS 2.9.11. The Media Manager allows authenticated users to upload files containing embedded PHP code via the file-upload endpoint, bypassing content-type validation. When such a file is accessed via its URL, the server executes the PHP payload, enabling an attacker… | |
| Analizada | Crítica (9.8) | 0.41% | — | Vishnusivadas Login-signup | 22/8/2025 | 17/6/2026 | The LogIn-SignUp project by VishnuSivadasVS is vulnerable to SQL Injection due to unsafe construction of SQL queries in DataBase.php. The functions logIn() and signUp() build queries by directly concatenating user input and unvalidated table names without using prepared statements. While a prepareData() function… | |
| Aplazada | Media (6.8) | 0.65% | — | RadashiAI | 27/5/2025 | 17/6/2026 | Radashi is a TypeScript utility toolkit. Prior to version 12.5.1, the set function within the Radashi library is vulnerable to prototype pollution. If an attacker can control parts of the path argument to the set function, they could potentially modify the prototype of all objects in the JavaScript runtime, leading to… | |
| Analizada | Media (5.1) | 6.2% | — | Westboy Cicadascms | 19/4/2025 | 17/6/2026 | A vulnerability classified as critical was found in westboy CicadasCMS 2.0. This vulnerability affects unknown code of the file /system/schedule/save of the component Scheduled Task Handler. The manipulation leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.57% | — | Westboy Cicadascms | 14/4/2025 | 17/6/2026 | A vulnerability classified as critical has been found in westboy CicadasCMS 1.0. This affects an unknown part of the file /upload/ of the component JSP Parser. The manipulation of the argument File leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Aplazada | Media (5.9) | 0.28% | — | Erez Hadas-sonnenschein Smartarget PopupAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Erez Hadas-Sonnenschein Smartarget Popup smartarget-popup allows Stored XSS.This issue affects Smartarget Popup: from n/a through <= 1.5. | |
| Analizada | Media (5.3) | 0.37% | — | Westboy Cicadascms | 22/3/2025 | 17/6/2026 | A vulnerability classified as critical has been found in westboy CicadasCMS 1.0. This affects an unknown part of the file /system/cms/content/page. The manipulation of the argument orderField/orderDirection leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.36% | — | Westboy Cicadascms | 22/3/2025 | 17/6/2026 | A vulnerability was found in westboy CicadasCMS 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /system/cms/content/save. The manipulation of the argument content/fujian/laiyuan leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Analizada | Media (5.1) | 0.33% | — | Westboy Cicadascms | 22/3/2025 | 17/6/2026 | A vulnerability was found in westboy CicadasCMS 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /system/cms/content/save. The manipulation of the argument title/content/laiyuan leads to cross site scripting. The attack can be launched remotely. The… | |
| Analizada | Media (5.1) | 0.69% | — | Westboy Cicadascms | 22/2/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in westboy CicadasCMS 1.0. This issue affects some unknown processing of the file /system of the component Template Management. The manipulation leads to deserialization. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Aplazada | Media (6.5) | 0.23% | — | Erez Hadas-sonnenschein SmartargetAI | 18/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Erez Hadas-Sonnenschein Smartarget smartarget-contact-us allows Stored XSS.This issue affects Smartarget: from n/a through <= 1.5.3. | |
| Aplazada | Media (5.9) | 0.28% | — | Erez Hadas-sonnenschein Smartarget Message BARAI | 2/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Erez Hadas-Sonnenschein Smartarget Message Bar smartarget-message-bar.This issue affects Smartarget Message Bar: from n/a through <= 1.5. | |
| Modificada | Alta (7.2) | 0.72% | — | Adastracrypto Cryptocurrency Payment & Donation BOX | 20/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adastra Crypto Cryptocurrency Payment & Donation Box – Accept Payments in any Cryptocurrency on your WP Site for Free.This issue affects Cryptocurrency Payment & Donation Box – Accept Payments in any Cryptocurrency on… | |
| Modificada | Media (5.4) | 0.68% | — | Uatech Badaso | 30/8/2023 | 17/6/2026 | Cross Site Scripting vulnerabiltiy in Badaso v.0.0.1 thru v.2.9.7 allows a remote attacker to execute arbitrary code via a crafted payload to the Name of member parameter in the add new member function. | |
| Modificada | Media (5.4) | 0.66% | — | Uatech Badaso | 29/8/2023 | 17/6/2026 | Cross Site Scripting vulnerabiltiy in Badaso v.0.0.1 thru v.2.9.7 allows a remote attacker to execute arbitrary code via a crafted payload to the rack number parameter in the add new rack function. | |
| Modificada | Media (5.4) | 0.66% | — | Uatech Badaso | 28/8/2023 | 17/6/2026 | Cross Site Scripting vulnerabiltiy in Badaso v.2.9.7 allows a remote attacker to execute arbitrary code via a crafted payload to the title parameter in the new book and edit book function. | |
| Modificada | Media (5.4) | 0.46% | — | Uatech Badaso | 25/8/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Edit Category function of Badaso v2.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter. | |
| Modificada | Media (5.4) | 0.38% | — | Uatech Badaso | 25/8/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Add Tag function of Badaso v2.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter. | |
| Modificada | Crítica (9.8) | 2.0% | — | Uatech Badaso | 25/11/2022 | 17/6/2026 | Badaso version 2.6.3 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because the application does not properly validate the data uploaded by users. | |
| Modificada | Crítica (9.8) | 1.7% | — | Uatech Badaso | 25/10/2022 | 17/6/2026 | Badaso version 2.6.0 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because the application does not properly validate the data uploaded by users. | |
| Modificada | Media (6.7) | 0.32% | — | Intel Adas IE | 12/11/2020 | 17/6/2026 | Improper input validation in the Intel(R) ADAS IE before version ADAS_IE_1.0.766 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.5) | 4.1% | — | Ionadas History Collection | 10/10/2019 | 17/6/2026 | The history-collection plugin through 1.1.1 for WordPress has directory traversal via the download.php var parameter. | |
| Modificada | Alta (8.8) | 0.57% | — | Prise Adas | 20/9/2019 | 17/6/2026 | An issue was discovered in PRiSE adAS 1.7.0. Forms have no CSRF protection, letting an attacker execute actions as the administrator. | |
| Modificada | Crítica (9.8) | 1.7% | — | Prise Adas | 20/9/2019 | 17/6/2026 | An issue was discovered in PRiSE adAS 1.7.0. Password hashes are compared using the equality operator. Thus, under specific circumstances, it is possible to bypass login authentication. | |
| Modificada | Alta (7.2) | 3.3% | — | Prise Adas | 20/9/2019 | 17/6/2026 | An issue was discovered in PRiSE adAS 1.7.0. An authenticated user can change the function used to hash passwords to any function, leading to remote code execution. |