Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
272 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.32% | — | Codeastro Membership Management SystemAI | 30/7/2026 | 5/10/2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1. | |
| Aplazada | Media (4.3) | 0.37% | — | AstroAI | 27/7/2026 | 28/7/2026 | Astro is a web framework for content-driven websites. In versions 1.0.0 through 4.0.18, the source.title and enclosure.type item fields in packages/astro-rss/src/index.ts are interpolated directly into XML template strings without XML-character escaping before being parsed by fast-xml-parser. Both fields are validated… | |
| Aplazada | Media (5.1) | 0.54% | — | AstroAI | 27/7/2026 | 28/7/2026 | Astro is a web framework for content-driven websites. Versions prior to 7.0.6 are vulnerable to XSS through unescaped spread attribute names in renderHTMLElement. The fix for CVE-2026-54298 (GHSA-jrpj-wcv7-9fh9) added an INVALID_ATTR_NAME_CHAR guard to addAttribute() so that spread-prop attribute names containing "'… | |
| Aplazada | Baja (2.1) | 0.54% | — | AstroAI | 27/7/2026 | 28/7/2026 | Astro is a web framework for content-driven websites. In versions 3.10.0 through 7.0.3, when a transition:persist, transition:scope, or transition:persist-props directive is applied to a client-hydrated (client:*) component, Astro copied the directive value onto the rendered <astro-island> element without… | |
| Aplazada | Media (5.5) | 0.43% | — | Codeastro Online ClassroomAI | 23/7/2026 | 24/7/2026 | A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected by this issue is some unknown functionality of the file /OnlineClassroom/loginlinkadmin.php. Executing a manipulation of the argument aid can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed… | |
| Aplazada | Baja (2.1) | 0.33% | — | Codeastro Simple Online Leave Management SystemAI | 13/7/2026 | 13/7/2026 | A vulnerability was detected in CodeAstro Simple Online Leave Management System 1.0. This affects an unknown part of the file /SimpleOnlineLeave/admin/accept.php of the component POST Handler. Performing a manipulation of the argument appid results in sql injection. The attack is possible to be carried out remotely.… | |
| Aplazada | Baja (2.1) | 0.33% | — | Codeastro Simple Online Leave Management SystemAI | 13/7/2026 | 13/7/2026 | A security vulnerability has been detected in CodeAstro Simple Online Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /SimpleOnlineLeave/admin/deletemp.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 0.33% | — | Coderastro Simple Online Leave Management SystemAI | 13/7/2026 | 14/7/2026 | A weakness has been identified in CodeAstro Simple Online Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /SimpleOnlineLeave/admin/dashboard.php. This manipulation of the argument Name causes sql injection. The attack can be initiated remotely. The exploit has been made… | |
| Aplazada | Media (5.5) | 0.43% | — | Codeastro Simple Online Leave Management SystemAI | 9/7/2026 | 9/7/2026 | A vulnerability was determined in CodeAstro Simple Online Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /SimpleOnlineLeave/index.php. Executing a manipulation of the argument email can lead to sql injection. The attack may be performed from remote. The exploit has… | |
| Aplazada | Alta (8.2) | 0.47% | — | AstroAI | 8/7/2026 | 9/7/2026 | Astro is a web framework for content-driven websites. Version 6.4.7 performs authorization decisions on a partially decoded pathname after reaching the iterative URL decoder limit, while later rewrite route matching performs an additional decodeURI() operation and can resolve the request to a protected route. This… | |
| Aplazada | Baja (2.1) | 0.33% | — | Codeastro Ecommerce WebsiteAI | 6/7/2026 | 6/7/2026 | A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. Impacted is an unknown function of the file /customer/my_account.php?my_wishlist. The manipulation of the argument delete_wishlist results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may… | |
| Aplazada | Baja (2.1) | 0.33% | — | Codeastro Apartment Visitor Management SystemAI | 6/7/2026 | 7/7/2026 | A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. This issue affects some unknown processing of the file /apartment-visitor/visitor-entry.php. The manipulation of the argument visname leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and… | |
| Aplazada | Baja (2.1) | 0.33% | — | Codeastro Apartment Visitor Management SystemAI | 6/7/2026 | 6/7/2026 | A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. This vulnerability affects unknown code of the file /apartment-visitor/edit-apartment.php. Executing a manipulation of the argument editid can lead to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.33% | — | Codeastro Apartment Visitor Management SystemAI | 6/7/2026 | 6/7/2026 | A vulnerability was found in CodeAstro Apartment Visitor Management System 1.0. This affects an unknown part of the file /apartment-visitor/report.php. Performing a manipulation of the argument fromdate results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could… | |
| Aplazada | Baja (2.1) | 0.33% | — | Codeastro Apartment Visitor Management SystemAI | 6/7/2026 | 6/7/2026 | A vulnerability has been found in CodeAstro Apartment Visitor Management System 1.0. Affected by this issue is some unknown functionality of the file /apartment-visitor/action-visitor.php. Such manipulation of the argument remark leads to sql injection. The attack may be performed from remote. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.33% | — | Codeastro Ecommerce WebsiteAI | 5/7/2026 | 6/7/2026 | A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. This affects an unknown part of the file /ecommerce-website-php/customer/confirm.php of the component POST Parameter Handler. The manipulation of the argument invoice_no results in sql injection. The attack can be executed remotely. The exploit… | |
| Aplazada | Baja (2.1) | 0.33% | — | Codeastro Apartment Visitor Management SystemAI | 5/7/2026 | 6/7/2026 | A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. Affected by this issue is some unknown functionality of the file /apartment-visitor/search-result.php of the component POST Parameter Handler. The manipulation of the argument searchdata leads to sql injection. Remote exploitation of… | |
| Aplazada | Baja (2.1) | 0.33% | — | Codeastro Apartment Visitor Management SystemAI | 5/7/2026 | 7/7/2026 | A security flaw has been discovered in CodeAstro Apartment Visitor Management System 1.0. The impacted element is an unknown function of the file /apartment-visitor/add-apartment.php. The manipulation of the argument apartmentno results in sql injection. The attack may be launched remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.43% | — | Codeastro Apartment Visitor Management SystemAI | 4/7/2026 | 6/7/2026 | A vulnerability was found in CodeAstro Apartment Visitor Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation of the argument Username results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and… | |
| Aplazada | Baja (2.1) | 0.33% | — | Codeastro Ecommerce WebsiteAI | 4/7/2026 | 7/7/2026 | A vulnerability has been found in CodeAstro Ecommerce Website 1.0. This impacts an unknown function of the file /ecommerce-website-php/customer/my_account.php?edit_account. Such manipulation of the argument c_name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public… | |
| Aplazada | Baja (2.1) | 0.51% | — | Coderastro Complaint Management SystemAI | 29/6/2026 | 29/6/2026 | A security flaw has been discovered in CodeAstro Complaint Management System 1.0. The affected element is the function deletereport of the file application/controllers/Report.php of the component Report Endpoint. The manipulation results in authorization bypass. The attack can be executed remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 0.23% | — | Codeastro Human Resource Management SystemAI | 29/6/2026 | 29/6/2026 | A vulnerability was found in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function. The manipulation results in cross-site request forgery. The attack may be launched remotely. The exploit has been made public and could be used. | |
| Aplazada | Baja (2.1) | 0.33% | — | Codeastro Human Resource Management SystemAI | 29/6/2026 | 29/6/2026 | A flaw has been found in CodeAstro Human Resource Management System 1.0. This vulnerability affects the function GetFileInfo of the file hrsystem/application/models/Employee_model.php of the component View Endpoint. Executing a manipulation of the argument ID can lead to sql injection. The attack can be launched… | |
| Aplazada | Baja (2.1) | 0.33% | — | Codeastro Human Resource Management SystemAI | 29/6/2026 | 29/6/2026 | A vulnerability was detected in CodeAstro Human Resource Management System 1.0. This issue affects the function emselectByCode of the file application/models/Employee_model.php of the component Update_Earn_Leave Endpoint. The manipulation of the argument emid results in sql injection. The attack can be launched… | |
| Aplazada | Media (5.3) | 0.31% | — | Astrojs NetlifyAI | 22/6/2026 | 23/6/2026 | @astrojs/netlify is an adapter that allows Astro to deploy your hybrid or server rendered site to Netlify. Prior to 7.0.13, @astrojs/netlify converts Astro image.remotePatterns into Netlify Image CDN images.remote_images regular expressions with broader semantics than Astro's canonical matcher. A single wildcard… |