Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2865▼ 160 respecto a la semana anterior
Críticas / altas1384▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

244 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.5)0.34%—F5 Nginx PlusF5 Nginx Open Source24/3/202615/7/2026
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, using a specially crafted MP4 file. This issue affects NGINX Open Source…
AnalizadaMedia (5.3)0.15%—F5 Nginx PlusF5 Nginx Open Source24/3/202617/6/2026
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake to succeed even after an OCSP check identifies the certificate as revoked.…
AnalizadaMedia (6.3)0.26%—F5 Nginx PlusF5 Nginx Open Source24/3/202617/6/2026
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary headers into SMTP upstream requests, leading to potential request manipulation. Note: Software…
ModificadaAlta (8.5)1.0%—F5 Nginx Open Source24/3/202615/7/2026
The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its termination, using a specially crafted MP4 file. The issue only affects 32-bit NGINX Open Source if it is built with the…
ModificadaAlta (8.8)25%—F5 Nginx PlusF5 Nginx Open Source24/3/202615/7/2026
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or destination file names outside the…
ModificadaAlta (8.7)0.94%—F5 Nginx Open SourceF5 Nginx Plus24/3/202615/7/2026
When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header.…
AnalizadaAlta (8.8)0.46%—Opensourcepos Open Source Point OF Sale20/3/202617/6/2026
Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Versions contain an SQL Injection in the Items search functionality. When the custom attribute search feature is enabled (search_custom filter), user-supplied input from the search GET parameter is…
AnalizadaAlta (8.8)0.82%—Opensourcepos Open Source Point OF Sale20/2/202617/6/2026
OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files on the web server by manipulating the Invoice Type configuration. This issue can be chained with the file upload functionality to achieve Remote Code Execution (RCE).
AnalizadaMedia (5.3)0.43%—Opensourcepos Open Source Point OF Sale20/2/202617/6/2026
OpenSourcePOS 3.4.1 has a second order SQL Injection vulnerability in the handling of the currency_symbol configuration field. Although the input is initially stored without immediate execution, it is later concatenated into a dynamically constructed SQL query without proper sanitization or parameter binding. This…
AnalizadaMedia (6.5)0.17%—Opensourcepos Open Source Point OF Sale13/2/202617/6/2026
A cross-site scripting (XSS) vulnerability in the item management and sales invoice function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.
AnalizadaMedia (6.5)0.17%—Opensourcepos Open Source Point OF Sale13/2/202617/6/2026
A cross-site scripting (XSS) vulnerability in the Generate Item Barcode function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Item Category parameter.
AnalizadaAlta (7.4)0.36%—Opensourcepos Open Source Point OF Sale13/2/202617/6/2026
An issue in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code via returning a crafted AJAX response.
AnalizadaMedia (6.5)0.17%—Opensourcepos Open Source Point OF Sale13/2/202617/6/2026
A cross-site scripting (XSS) vulnerability in the Customers function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Phone Number parameter.
AnalizadaMedia (5.5)0.21%—Opensourcepos Open Source Point OF Sale12/2/202617/6/2026
A cross-site scripting (XSS) vulnerability in the Item Kits function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Item Name parameter.
AnalizadaAlta (8.2)0.39%—F5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance ManagerF5 Nginx Open Source+14/2/202617/6/2026
A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with conditions beyond the attacker's control—may be able to inject plain text data into the response…
AplazadaAlta (7.2)0.38%—I-doit Open Source CmdbAI3/2/202617/6/2026
i-doit Open Source CMDB 1.14.1 contains a file deletion vulnerability in the import module that allows authenticated attackers to delete arbitrary files by manipulating the delete_import parameter. Attackers can send a POST request to the import module with a crafted filename to remove files from the server's…
AnalizadaMedia (4.8)0.21%—Opensourcepos Open Source Point OF Sale13/1/202617/6/2026
Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. opensourcepos 3.4.0 and 3.4.1 has a stored XSS vulnerability exists in the Configuration (Information) functionality. An authenticated user with the permission “Configuration: Change OSPOS's…
AnalizadaAlta (8.8)0.28%—Opensourcepos Open Source Point OF Sale17/12/202517/6/2026
Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and prior to version 3.4.2, a Cross-Site Request Forgery (CSRF) vulnerability exists in the application's filter configuration. The CSRF protection mechanism was…
AnalizadaAlta (8.1)0.38%—Opensourcepos Open Source Point OF Sale17/12/202517/6/2026
Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and prior to version 3.4.2, a Stored Cross-Site Scripting (XSS) vulnerability exists in the "Return Policy" configuration field. The application does not properly…
AnalizadaMedia (6.1)0.26%—Opensourcepos Open Source Point OF Sale17/12/202517/6/2026
A Cross-site scripting (XSS) vulnerability in Create/Update Item Kit(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the "name" parameter.
AnalizadaAlta (7.2)0.55%—Opensourcepos Open Source Point OF Sale17/12/202517/6/2026
A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the phone_number parameter.
AnalizadaAlta (7.2)0.55%—Opensourcepos Open Source Point OF Sale17/12/202517/6/2026
A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the "name" parameter.
AnalizadaAlta (7.5)0.45%—Opensourcepos Open Source Point OF Sale18/11/202517/6/2026
The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing server-side validation. When an authenticated user omits or leaves the `password` and `repeat_password` parameters empty in the password change request, the backend still returns…
AplazadaAlta (8.7)0.45%—Zentao BIZAIZentao MAXAIZentao Open Source EditionAI13/11/202517/6/2026
ZenTao Biz < 6.5, ZenTao Max < 3.0, ZenTao Open Source Edition < 16.5, and ZenTao Open Source Edition < 16.5.beta1 contain an SQL injection vulnerability in the login functionality. The application does not properly validate the account parameter on /zentao/user-login.html before using it in a database query. A remote…
AnalizadaMedia (6.5)0.19%—Opensource-socialnetwork Open Source Social Network5/11/202517/6/2026
OSSN (Open Source Social Network) 8.6 is vulnerable to SQL Injection in /action/rtcomments/status via the timestamp parameter.