Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

88 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.8)0.29%—Openwrt LuciOpenwrt19/3/202617/6/2026
LuCI is the OpenWrt Configuration Interface. Versions prior to both 24.10.5 and 25.12.0, contain a stored XSS vulnerability in the wireless scan modal, where SSID values from scan results are rendered as raw HTML without any sanitization. The wireless.js file in the luci-mod-network package passes SSIDs via a template…
AplazadaAlta (8.2)0.54%—Adonisjs LucidAI13/1/202617/6/2026
@adonisjs/lucid is an SQL ORM for AdonisJS built on top of Knex. Prior to 21.8.2 and 22.0.0-next.6, there is a Mass Assignment vulnerability in AdonisJS Lucid which may allow a remote attacker who can influence data that is passed into Lucid model assignments to overwrite the internal ORM state. This may lead to logic…
AplazadaBaja (2.7)0.38%—Atisoluciones Ciges ApplicationAI24/11/202517/6/2026
A sensitive information disclosure vulnerability exists in the error handling component of ATISoluciones CIGES Application version 2.15.6 and earlier. When certain unexpected conditions trigger unhandled exceptions, the application returns detailed error messages and stack traces to the client. This may expose…
AplazadaMedia (5.4)0.18%💥 PoCOpenwrt LuciAI1/10/202517/6/2026
A reflected cross-site scripting (XSS) vulnerability in the /admin/system/packages endpoint of Luci OpenWRT v18.06.2 allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload. This vulnerability was fixed in OpenWRT v19.07.0.
AplazadaAlta (7.6)0.32%—Lucidcrew WP Forum ServerAI27/6/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in lucidcrew WP Forum Server forum-server allows SQL Injection.This issue affects WP Forum Server: from n/a through <= 1.8.2.
AplazadaAlta (7.1)0.12%—Lucidcrew WP Forum ServerAI27/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in lucidcrew WP Forum Server forum-server allows Stored XSS.This issue affects WP Forum Server: from n/a through <= 1.8.2.
AplazadaAlta (7.1)0.29%—Dan-lucian Stefancu Empty-tags-removerAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan-Lucian Stefancu Empty Tags Remover empty-tags-remover allows Reflected XSS.This issue affects Empty Tags Remover: from n/a through <= 1.0.
AplazadaCrítica (9.8)0.49%—Atisoluciones CigesAI27/2/202517/6/2026
A SQL Injection vulnerability has been found in Ciges 2.15.5 from ATISoluciones. This vulnerability allows an attacker to retrieve, create, update and delete database via $idServicio parameter in /modules/ajaxBloqueaCita.php endpoint.
AplazadaAlta (7.1)0.26%—N3wnormal LucidlmsAI13/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in N3wNormal LucidLMS lucidlms allows Reflected XSS.This issue affects LucidLMS: from n/a through <= 1.0.5.
AplazadaMedia (6.5)0.21%—Lucia.intelisano Live Flight RadarAI9/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lucia.intelisano Live Flight Radar live-flight-radar allows Stored XSS.This issue affects Live Flight Radar: from n/a through <= 1.0.
AplazadaAlta (8)0.26%—Openwrt Luci-mod-rpcAI5/11/202417/6/2026
An issue in the luci-mod-rpc package in OpenWRT Luci LTS allows for privilege escalation from an admin account to root via the JSON-RPC-API, which is exposed by the luci-mod-rpc package
AplazadaCrítica (9.8)0.49%—Atisoluciones CigesAI26/8/202417/6/2026
SQL injection vulnerability in ATISolutions CIGES affecting versions lower than 2.15.5. This vulnerability allows a remote attacker to send a specially crafted SQL query to the /modules/ajaxServiciosCentro.php point in the idCentro parameter and retrieve all the information stored in the database.
AplazadaMedia (6.3)0.95%—Luci-app-sms-toolAI27/6/202417/6/2026
luci-app-sms-tool v1.9-6 was discovered to contain a command injection vulnerability via the score parameter.
AplazadaCrítica (9.8)0.58%—Luci-app-luckyAI27/6/202417/6/2026
luci-app-lucky v2.8.3 was discovered to contain hardcoded credentials.
AplazadaMedia (5.4)0.29%—GT3 Soluciones SwalAI29/4/202417/6/2026
A Cross-Site Scripting XSS vulnerability has been detected on GT3 Soluciones SWAL. This vulnerability consists in a reflected XSS in the Titular parameter inside Gestion 'Documental > Seguimiento de Expedientes > Alta de Expedientes'.
AnalizadaMedia (5.5)0.16%—Atisoluciones Ciges22/3/202417/6/2026
Information exposure vulnerability in the CIGESv2 system. This vulnerability could allow a local attacker to intercept traffic due to the lack of proper implementation of the TLS protocol.
AnalizadaMedia (6.1)0.31%—Atisoluciones Ciges22/3/202417/6/2026
HTML injection vulnerability affecting the CIGESv2 system, which allows an attacker to inject arbitrary code and modify elements of the website and email confirmation message.
AnalizadaMedia (6.1)0.31%—Atisoluciones Ciges22/3/202417/6/2026
Stored Cross-Site Scripting (Stored-XSS) vulnerability affecting the CIGESv2 system, allowing an attacker to execute and store malicious javascript code in the application form without prior registration.
AnalizadaAlta (7.5)0.62%—Atisoluciones Ciges22/3/202417/6/2026
Information exposure vulnerability in the CIGESv2 system. A remote attacker might be able to access /vendor/composer/installed.json and retrieve all installed packages used by the application.
AnalizadaAlta (7.5)0.68%—Atisoluciones Ciges22/3/202417/6/2026
SQL injection vulnerability in the CIGESv2 system, through /ajaxServiciosAtencion.php, in the 'idServicio' parameter. The exploitation of this vulnerability could allow a remote user to retrieve all data stored in the database by sending a specially crafted SQL query.
AnalizadaAlta (7.5)0.68%—Atisoluciones Ciges22/3/202417/6/2026
SQL injection vulnerability in the CIGESv2 system, through /ajaxSubServicios.php, in the 'idServicio' parameter. The exploitation of this vulnerability could allow a remote user to retrieve all data stored in the database by sending a specially crafted SQL query.
AnalizadaAlta (7.5)0.68%—Atisoluciones Ciges22/3/202417/6/2026
SQL injection vulnerability in the CIGESv2 system, through /ajaxConfigTotem.php, in the 'id' parameter. The exploitation of this vulnerability could allow a remote user to retrieve all data stored in the database by sending a specially crafted SQL query.
ModificadaMedia (6.5)0.59%💥 PoCEllucian Banner13/2/202417/6/2026
Ellucian Banner 9.17 allows Insecure Direct Object Reference (IDOR) via a modified bannerId to the /StudentSelfService/ssb/studentCard/retrieveData endpoint.
ModificadaMedia (6.1)0.49%—X-wrt Luci3/6/202317/6/2026
A vulnerability, which was classified as problematic, has been found in X-WRT luci up to 22.10_b202303061504. This issue affects the function run_action of the file modules/luci-base/ucode/dispatcher.uc of the component 404 Error Template Handler. The manipulation of the argument request_path leads to cross site…
ModificadaMedia (5.4)0.52%—Tsolucio Corebos2/6/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8.
Orbitaley — Vulnerabilidades