Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
149 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.41% | — | Lfprojects MinderAI | 20/5/2024 | 17/6/2026 | Minder is a software supply chain security platform. Prior to version 0.0.50, Minder engine is susceptible to a denial of service from memory exhaustion that can be triggered from maliciously created templates. Minder engine uses templating to generate strings for various use cases such as URLs, messages for pull… | |
| Aplazada | Media (5.3) | 0.46% | — | Lfprojects MinderAI | 16/5/2024 | 17/6/2026 | Minder is a software supply chain security platform. Prior to version 0.0.49, the Minder REST ingester is vulnerable to a denial of service attack via an attacker-controlled REST endpoint that can crash the Minder server. The REST ingester allows users to interact with REST endpoints to fetch data for rule evaluation.… | |
| Aplazada | Alta (7.5) | 0.59% | — | Lfprojects MinderAI | 7/5/2024 | 17/6/2026 | Minder's `HandleGithubWebhook` is susceptible to a denial of service attack from an untrusted HTTP request. The vulnerability exists before the request has been validated, and as such the request is still untrusted at the point of failure. This allows an attacker with the ability to send requests to… | |
| Aplazada | Media (4.3) | 0.77% | — | Lfprojects MinderAI | 9/4/2024 | 17/6/2026 | Minder by Stacklok is an open source software supply chain security platform. A refactoring in commit `5c381cf` added the ability to get GitHub repositories registered to a project without specifying a specific provider. Unfortunately, the SQL query for doing so was missing parenthesis, and would select a random… | |
| Analizada | Alta (8.2) | 0.63% | — | Zoneminder | 4/4/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in ZoneMinder before version 1.34.21, allows remote attackers execute arbitrary code, escalate privileges, and obtain sensitive information via PHP_SELF component in classic/views/download.php. | |
| Analizada | Media (4.3) | 0.67% | — | Lfprojects Minder | 21/3/2024 | 17/6/2026 | Minder is a software supply chain security platform. Prior to version 0.0.33, a Minder user can use the endpoints `GetRepositoryByName`, `DeleteRepositoryByName`, and `GetArtifactByName` to access any repository in the database, irrespective of who owns the repo and any permissions present. The database query checks… | |
| Analizada | Crítica (9.8) | 0.62% | — | Prestashop Abandoned Cart Reminder PRO | 20/3/2024 | 17/6/2026 | SQL injection vulnerability in pscartabandonmentpro v.2.0.11 and before allows a remote attacker to escalate privileges via the pscartabandonmentproFrontCAPUnsubscribeJobModuleFrontController::setEmailVisualized() method. | |
| Analizada | Alta (7.5) | 0.55% | — | Lfprojects Minder | 26/2/2024 | 17/6/2026 | Minder is a Software Supply Chain Security Platform. In version 0.0.31 and earlier, it is possible for an attacker to register a repository with a invalid or differing upstream ID, which causes Minder to report the repository as registered, but not remediate any future changes which conflict with policy (because the… | |
| Modificada | Crítica (9.8) | 0.42% | — | Task Reminder System Project Task Reminder System | 28/10/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Task Reminder System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file classes/Users.php?f=delete. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The identifier of this… | |
| Modificada | Alta (8.8) | 0.44% | — | Oretnom23 Task Reminder System | 27/10/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Task Reminder System 1.0. It has been classified as critical. This affects an unknown part of the file /classes/Master.php?f=save_reminder. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The identifier VDB-243645… | |
| Modificada | Alta (8.8) | 0.44% | — | Oretnom23 Task Reminder System | 27/10/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Task Reminder System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /classes/Master.php?f=delete_reminder. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The identifier of… | |
| Modificada | Media (5.4) | 0.52% | 💥 PoC | Task Reminder System Project Task Reminder System | 13/7/2023 | 17/6/2026 | A Reflected Cross-site scripting (XSS) vulnerability in Sourcecodester Task Reminder System 1.0 allows an authenticated user to inject malicious javascript into the page parameter. | |
| Modificada | Media (5.4) | 0.34% | — | Teamlead Reminder | 16/6/2023 | 17/6/2026 | The Teamlead Reminder plugin through 2.6.5 for Jira allows persistent XSS via the message parameter. | |
| Modificada | Media (5.4) | 3.1% | 💥 Exploit | Broadcom Symantec Siteminder Webagent | 30/5/2023 | 17/6/2026 | A user can supply malicious HTML and JavaScript code that will be executed in the client browser | |
| Modificada | Media (6.1) | 0.51% | — | Task Reminder System Project Task Reminder System | 21/4/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Task Reminder System 1.0 and classified as problematic. This issue affects some unknown processing of the file /classes/Users.php. The manipulation of the argument id leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Modificada | Crítica (9.8) | 0.66% | — | Task Reminder System Project Task Reminder System | 21/4/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Task Reminder System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/user/manage_user.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Modificada | Crítica (9.8) | 0.66% | — | Task Reminder System Project Task Reminder System | 21/4/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Task Reminder System 1.0. This affects an unknown part of the file /admin/reminders/manage_reminder.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Alta (7.2) | 0.74% | — | Task Reminder System Project Task Reminder System | 18/4/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Task Reminder System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/?page=reminders/view_reminder. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Alta (7.2) | 0.74% | — | Task Reminder System Project Task Reminder System | 18/4/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Task Reminder System 1.0. This issue affects some unknown processing of the file Master.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public… | |
| Modificada | Alta (8.8) | 1.3% | 💥 PoC | Zoneminder | 25/2/2023 | 17/6/2026 | ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain an OS Command Injection via daemonControl() in (/web/api/app/Controller/HostController.php). Any authenticated user can construct an api… | |
| Modificada | Media (6.5) | 0.51% | — | Zoneminder | 25/2/2023 | 17/6/2026 | ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain a Local File Inclusion (Untrusted Search Path) vulnerability via web/ajax/modal.php, where an arbitrary php file path can be passed in the… | |
| Modificada | Crítica (9.8) | 0.61% | — | Zoneminder | 25/2/2023 | 17/6/2026 | ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain an SQL Injection. The minTime and maxTime request parameters are not properly validated and could be used execute arbitrary SQL. This issue… | |
| Modificada | Crítica (9.8) | 0.90% | — | Zoneminder | 25/2/2023 | 17/6/2026 | ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain a Local File Inclusion (Untrusted Search Path) vulnerability via /web/index.php. By controlling $view, any local file ending in .php can be… | |
| Modificada | Crítica (9.8) | 80% | 💥 Exploit | Zoneminder | 25/2/2023 | 17/6/2026 | ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 are vulnerable to Unauthenticated Remote Code Execution via Missing Authorization. There are no permissions check on the snapshot action, which… | |
| Modificada | Alta (8.8) | 1.6% | — | Zoneminder | 25/2/2023 | 17/6/2026 | ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 are affected by a SQL Injection vulnerability. The (blind) SQL Injection vulnerability is present within the `filter[Query][terms][0][attr]` query… |