Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
165 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.40% | — | Carmelogarcia Courier Management System | 9/10/2025 | 17/6/2026 | A weakness has been identified in code-projects Courier Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /add-courier.php. Executing manipulation of the argument Shippername can lead to sql injection. The attack can be launched remotely. The exploit has been made available… | |
| Aplazada | Media (5.3) | 0.22% | — | Conventional-changelog Git-clientAI | 22/9/2025 | 17/6/2026 | Conventional Changelog generates changelogs and release notes from a project's commit messages and metadata. Prior to version 2.0.0, @conventional-changelog/git-client has an argument injection vulnerability. This vulnerability manifests with the library's getTags() API, which allows extra parameters to be passed to… | |
| Aplazada | Alta (7.7) | 0.32% | — | OneloginAI | 14/9/2025 | 17/6/2026 | In One Identity OneLogin before 2025.3.0, a request returns the OIDC client secret with GET Apps API v2 (even though this secret should only be returned when an App is first created), | |
| Aplazada | Alta (7.2) | 0.23% | 💥 PoC | Sciencelogic SL1AI | 5/9/2025 | 17/6/2026 | index.em7 in ScienceLogic SL1 before 12.1.1 allows SQL Injection via a parameter in a request. NOTE: this is disputed by the Supplier because it "inaccurately describes the vulnerability." | |
| Modificada | Alta (7.8) | 0.24% | — | Carmelogarcia Restaurant Order System | 1/8/2025 | 5/7/2026 | SQL Injection vulnerability in Restaurant Order System 1.0 allows a local attacker to obtain sensitive information via the payment.php file | |
| Aplazada | Media (6.9) | 0.40% | — | Onelogin Ruby-samlAI | 30/7/2025 | 17/6/2026 | The Ruby SAML library is for implementing the client side of a SAML authorization. In versions 1.18.0 and below, a denial-of-service vulnerability exists in ruby-saml even with the message_max_bytesize setting configured. The vulnerability occurs because the SAML response is validated for Base64 format prior to… | |
| Aplazada | Media (4) | 0.24% | — | Oneidentity OneloginAI | 19/7/2025 | 17/6/2026 | In One Identity OneLogin before 2025.2.0, the SQL connection "application name" is set based on the value of an untrusted X-RequestId HTTP request header. | |
| Aplazada | Media (5) | 0.16% | — | Oneidentity Onelogin Active Directory ConnectorAI | 2/7/2025 | 17/6/2026 | In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken was mishandled, aka ST-812. | |
| Aplazada | Crítica (9) | 0.53% | — | Onelogin AD ConnectorAI | 1/7/2025 | 17/6/2026 | A cloud infrastructure misconfiguration in OneLogin AD Connector results in log data being sent to a hardcoded S3 bucket (onelogin-adc-logs-production) without validating bucket ownership. An attacker who registers this unclaimed bucket can begin receiving log files from other OneLogin tenants. These logs may contain… | |
| Aplazada | Crítica (10) | 0.61% | — | Onelogin AD ConnectorAI | 1/7/2025 | 17/6/2026 | A cryptographic authentication bypass vulnerability exists in OneLogin AD Connector prior to 6.1.5 due to the exposure of a tenant’s SSO JWT signing key via the /api/adc/v4/configuration endpoint. An attacker in possession of the signing key can craft valid JWT tokens impersonating arbitrary users within a OneLogin… | |
| Aplazada | Media (5.7) | 0.16% | — | Onelogin AD ConnectorAI | 1/7/2025 | 17/6/2026 | An information disclosure vulnerability exists in OneLogin AD Connector versions prior to 6.1.5 via the /api/adc/v4/configuration endpoint. An attacker with access to a valid directory_token—which may be retrievable from host registry keys or improperly secured logs—can retrieve a plaintext response disclosing… | |
| Analizada | Media (5.5) | 0.49% | — | Carmelogarcia Restaurant Order System | 16/6/2025 | 17/6/2026 | A vulnerability was found in code-projects Restaurant Order System 1.0 and classified as critical. This issue affects some unknown processing of the file /tablelow.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Media (5.5) | 0.48% | — | Carmelogarcia Restaurant Order System | 16/6/2025 | 17/6/2026 | A vulnerability has been found in code-projects Restaurant Order System 1.0 and classified as critical. This vulnerability affects unknown code of the file /payment.php. The manipulation of the argument tabidNoti leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.5) | 0.51% | — | Carmelogarcia Restaurant Order System | 10/6/2025 | 17/6/2026 | A vulnerability classified as critical was found in code-projects Restaurant Order System 1.0. This vulnerability affects unknown code of the file /order.php. The manipulation of the argument tabidNoti leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Aplazada | Media (6.6) | 0.27% | — | Agilelogix Agile Store LocatorAI | 6/6/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Agile Logix Store Locator WordPress agile-store-locator allows Upload a Web Shell to a Web Server.This issue affects Store Locator WordPress: from n/a through <= 1.5.2. | |
| Aplazada | Alta (7.6) | 0.35% | — | Agilelogix Store LocatorAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agile Logix Store Locator WordPress agile-store-locator allows SQL Injection.This issue affects Store Locator WordPress: from n/a through <= 1.5.1. | |
| Analizada | Crítica (9.8) | 0.65% | — | Carmelogarcia Matrimonial Site | 3/4/2025 | 17/6/2026 | Code-Projects Matrimonial Site V1.0 is vulnerable to SQL Injection in /view_profile.php?id=1. | |
| Modificada | Alta (7.7) | 1.5% | — | Omniauth SamlOnelogin Ruby-saml | 12/3/2025 | 17/6/2026 | ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of Service (DoS) with compressed SAML responses. ruby-saml uses zlib to decompress SAML responses in case they're compressed. It is possible to… | |
| Modificada | Crítica (9.3) | 65% | — | Omniauth SamlOnelogin Ruby-samlNetapp Storagegrid | 12/3/2025 | 17/6/2026 | ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differently, the parsers can generate entirely different document… | |
| Modificada | Crítica (9.3) | 21% | — | Omniauth SamlOnelogin Ruby-samlNetapp Storagegrid | 12/3/2025 | 17/6/2026 | ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differently; the parsers can generate entirely different document… | |
| Aplazada | Crítica (9.8) | 0.41% | — | Yukseloglu Filter B2B Login PlatformAI | 27/2/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yukseloglu Filter B2B Login Platform allows SQL Injection. This issue affects B2B Login Platform: before 16.01.2025. | |
| Analizada | Alta (7.1) | 0.35% | — | Agilelogix Post Timeline | 26/2/2025 | 17/6/2026 | The Post Timeline WordPress plugin before 2.3.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Media (5.9) | 0.29% | — | Themelogger Contact Form 7 Star Rating With Font AwesomeAI | 24/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themelogger Contact Form 7 Star Rating with font Awesome contact-form-7-star-rating-with-font-awersome allows Stored XSS.This issue affects Contact Form 7 Star Rating with font Awesome: from n/a through <= 1.3. | |
| Aplazada | Media (5.9) | 0.29% | — | Themelogger Contact Form 7 Star RatingAI | 24/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themelogger Contact Form 7 Star Rating contact-form-7-star-rating allows Stored XSS.This issue affects Contact Form 7 Star Rating: from n/a through <= 1.10. | |
| Aplazada | Alta (7.1) | 0.26% | — | Agilelogix Post TimelineAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agile Logix Post Timeline post-timeline allows Reflected XSS.This issue affects Post Timeline: from n/a through <= 2.3.9. |