Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
349 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.26% | — | Itsourcecode Online House Rental SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability was detected in itsourcecode Online House Rental System 1.0. This impacts an unknown function of the file /manage_payment.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used. | |
| Aplazada | Media (5.5) | 0.26% | — | Itsourcecode Online House Rental SystemAI | 1/6/2026 | 22/7/2026 | A security vulnerability has been detected in itsourcecode Online House Rental System 1.0. This affects an unknown function of the file /manage_tenant.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. | |
| Aplazada | Media (5.5) | 0.26% | — | Itsourcecode Online House Rental SystemAI | 1/6/2026 | 22/7/2026 | A weakness has been identified in itsourcecode Online House Rental System 1.0. The impacted element is an unknown function of the file /ajax.php?action=login. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the… | |
| Aplazada | Alta (8.7) | 0.32% | — | AgnoAIClickhouseAI | 29/5/2026 | 21/7/2026 | agno 2.6.5 contains a SQL injection vulnerability in the ClickHouse vector database backend that allows attackers to inject arbitrary SQL expressions by supplying malicious metadata keys and values to the delete_by_metadata() method. Attackers can exploit the unsafe f-string interpolation in clickhousedb.py to delete… | |
| Pendiente de análisis | Crítica (9.9) | 0.55% | — | SAP Business Planning AND ConsolidationAISAP Business WarehouseAI | 14/4/2026 | 17/6/2026 | Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authenticated user can execute crafted SQL statements to read, modify, and delete database data. This leads to a high impact on the confidentiality, integrity, and availability of the system. | |
| Pendiente de análisis | Alta (7) | 0.26% | — | Green House Gh-wdf10aAI | 26/3/2026 | 17/6/2026 | Digital Photo Frame GH-WDF10A provided by GREEN HOUSE CO., LTD. contains an active debug code vulnerability. If this vulnerability is exploited, files or configurations on the affected device may be read or written, or arbitrary files may be executed with root privileges. | |
| Aplazada | Media (5.3) | 0.29% | — | Wpradiant Chocolate HouseAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in wpradiant Chocolate House chocolate-house allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chocolate House: from n/a through <= 1.1.5. | |
| Pendiente de análisis | Media (5.9) | 0.29% | — | SAP Business WarehouseAI | 10/3/2026 | 17/6/2026 | Due to a Missing Authorization Check in SAP Business Warehouse (Service API), an authenticated attacker could perform unauthorized actions via an affected RFC function module. Successful exploitation could enable unauthorized configuration and control changes, potentially disrupting request processing and causing… | |
| Aplazada | Crítica (9.8) | 0.63% | — | Themerex PizzahouseAI | 5/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Pizza House pizzahouse allows Object Injection.This issue affects Pizza House: from n/a through <= 1.4.0. | |
| Analizada | Baja (2.1) | 0.40% | — | Yeqifu Warehouse | 20/2/2026 | 17/6/2026 | A vulnerability was identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This issue affects the function addSales/updateSales/deleteSales of the file dataset\repos\warehouse\src\main\java\com\yeqifu\bus\controller\SalesController.java of the component Sales Endpoint. The manipulation leads to… | |
| Analizada | Baja (2.1) | 0.36% | — | Yeqifu Warehouse | 20/2/2026 | 17/6/2026 | A vulnerability was determined in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This vulnerability affects the function addInport/updateInport/deleteInport of the file dataset\repos\warehouse\src\main\java\com\yeqifu\bus\controller\InportController.java of the component Inport Endpoint. Executing a… | |
| Analizada | Baja (2.1) | 0.36% | — | Yeqifu Warehouse | 20/2/2026 | 17/6/2026 | A vulnerability was found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function addCustomer/updateCustomer/deleteCustomer of the file dataset\repos\warehouse\src\main\java\com\yeqifu\bus\controller\CustomerController.java of the component Customer Endpoint. Performing a… | |
| Analizada | Baja (2.1) | 0.40% | — | Yeqifu Warehouse | 20/2/2026 | 17/6/2026 | A vulnerability has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this issue is the function deleteCache/removeAllCache/syncCache of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\CacheController.java of the component Cache Sync Handler. Such… | |
| Analizada | Baja (2.1) | 0.37% | — | Yeqifu Warehouse | 7/2/2026 | 17/6/2026 | A vulnerability was found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function loadAllLoginfo/deleteLoginfo/batchDeleteLoginfo of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\LoginfoController.java of the component Log Info Handler. The manipulation… | |
| Analizada | Baja (2.1) | 0.37% | — | Yeqifu Warehouse | 7/2/2026 | 17/6/2026 | A vulnerability has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. The impacted element is the function addNotice/updateNotice/deleteNotice/batchDeleteNotice of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\NoticeController.java of the component Notice… | |
| Analizada | Baja (2.1) | 0.32% | — | Yeqifu Warehouse | 7/2/2026 | 17/6/2026 | A flaw has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. The affected element is the function addDept/updateDept/deleteDept of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\DeptController.java of the component Department Management. Executing a manipulation… | |
| Analizada | Baja (2.1) | 0.30% | — | Yeqifu Warehouse | 7/2/2026 | 17/6/2026 | A flaw has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This vulnerability affects the function addMenu/updateMenu/deleteMenu of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\MenuController.java of the component Menu Management. Executing a manipulation can… | |
| Analizada | Baja (2.1) | 0.30% | — | Yeqifu Warehouse | 7/2/2026 | 17/6/2026 | A vulnerability was detected in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function addPermission/updatePermission/deletePermission of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\PermissionController.java of the component Permission Management.… | |
| Analizada | Baja (2.1) | 0.30% | — | Yeqifu Warehouse | 7/2/2026 | 17/6/2026 | A security vulnerability has been detected in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this issue is the function addRole/updateRole/deleteRole of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\RoleController.java of the component Role Management Handler.… | |
| Analizada | Baja (2.1) | 0.30% | — | Yeqifu Warehouse | 7/2/2026 | 17/6/2026 | A weakness has been identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this vulnerability is the function addUser/updateUser/deleteUser of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\UserController.java of the component User Management Endpoint. This… | |
| Analizada | Baja (2.1) | 0.35% | — | Yeqifu Warehouse | 7/2/2026 | 17/6/2026 | A security flaw has been discovered in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected is the function saveRolePermission of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\RoleController.java of the component Role-Permission Binding Handler. The manipulation results… | |
| Aplazada | Media (5.1) | 0.25% | — | Millhouse-projectAI | 6/2/2026 | 17/6/2026 | Millhouse-Project 1.414 contains a persistent cross-site scripting vulnerability in the comment submission functionality that allows attackers to inject malicious scripts. Attackers can post comments with embedded JavaScript through the 'content' parameter in add_comment_sql.php to execute arbitrary scripts in victim… | |
| Analizada | Baja (2) | 0.26% | — | Projectworlds House Rental AND Property Listing Project | 30/1/2026 | 17/6/2026 | A weakness has been identified in projectworlds House Rental and Property Listing 1.0. This vulnerability affects unknown code of the file /app/sms.php. This manipulation of the argument Message causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the… | |
| Aplazada | Alta (8.1) | 0.47% | — | Ancorathemes Modern HousewifeAI | 22/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Modern Housewife modernhousewife allows PHP Local File Inclusion.This issue affects Modern Housewife: from n/a through <= 1.0.12. | |
| Analizada | Media (5.5) | 0.45% | — | Feminer Warehouse Management System | 17/1/2026 | 17/6/2026 | A security vulnerability has been detected in FeMiner wms up to 9cad1f1b179a98b9547fd003c23b07c7594775fa. Affected by this vulnerability is an unknown functionality of the file /src/chkuser.php. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely. The… |