Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
63 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.45% | — | Opensourcelabs ThermakubeAI | 11/3/2026 | 17/6/2026 | An issue pertaining to CWE-259: Use of Hard-coded Password was discovered in oslabs-beta ThermaKube master. | |
| Analizada | Crítica (9.8) | 0.33% | — | Opensourcelabs Thermakube | 9/3/2026 | 17/6/2026 | An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in oslabs-beta ThermaKube master. | |
| Analizada | Alta (8.8) | 0.82% | — | Opensourcepos Open Source Point OF Sale | 20/2/2026 | 17/6/2026 | OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files on the web server by manipulating the Invoice Type configuration. This issue can be chained with the file upload functionality to achieve Remote Code Execution (RCE). | |
| Analizada | Media (5.3) | 0.43% | — | Opensourcepos Open Source Point OF Sale | 20/2/2026 | 17/6/2026 | OpenSourcePOS 3.4.1 has a second order SQL Injection vulnerability in the handling of the currency_symbol configuration field. Although the input is initially stored without immediate execution, it is later concatenated into a dynamically constructed SQL query without proper sanitization or parameter binding. This… | |
| Analizada | Media (6.5) | 0.17% | — | Opensourcepos Open Source Point OF Sale | 13/2/2026 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the item management and sales invoice function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload. | |
| Analizada | Media (6.5) | 0.17% | — | Opensourcepos Open Source Point OF Sale | 13/2/2026 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the Generate Item Barcode function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Item Category parameter. | |
| Analizada | Alta (7.4) | 0.36% | — | Opensourcepos Open Source Point OF Sale | 13/2/2026 | 17/6/2026 | An issue in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code via returning a crafted AJAX response. | |
| Analizada | Media (6.5) | 0.17% | — | Opensourcepos Open Source Point OF Sale | 13/2/2026 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the Customers function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Phone Number parameter. | |
| Analizada | Media (5.5) | 0.21% | — | Opensourcepos Open Source Point OF Sale | 12/2/2026 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the Item Kits function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Item Name parameter. | |
| Analizada | Media (5.1) | 0.30% | — | Opensourcecms 60cyclecms | 3/2/2026 | 17/6/2026 | 60CycleCMS 2.5.2 contains a cross-site scripting (XSS) vulnerability in news.php that allows attackers to inject malicious scripts through GET parameters. Attackers can craft malicious URLs with XSS payloads targeting the 'etsu' and 'ltsu' parameters to execute arbitrary scripts in victim's browsers. This issue does… | |
| Analizada | Alta (8.8) | 0.40% | — | Opensourcecms 60cyclecms | 3/2/2026 | 17/6/2026 | 60CycleCMS 2.5.2 contains an SQL injection vulnerability in news.php and common/lib.php that allows attackers to manipulate database queries through unvalidated user input. Attackers can exploit vulnerable query parameters like 'title' to inject malicious SQL code and potentially extract or modify database contents.… | |
| Aplazada | Alta (8.7) | 0.14% | — | Anyrtc-rtmp-opensourceAI | 27/1/2026 | 17/6/2026 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in anyrtcIO-Community anyRTC-RTMP-OpenSource (third_party/faad2-2.7/libfaad modules). This vulnerability is associated with program files bits.C, syntax.C. This issue affects anyRTC-RTMP-OpenSource: before 1.0. | |
| Analizada | Media (4.8) | 0.21% | — | Opensourcepos Open Source Point OF Sale | 13/1/2026 | 17/6/2026 | Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. opensourcepos 3.4.0 and 3.4.1 has a stored XSS vulnerability exists in the Configuration (Information) functionality. An authenticated user with the permission “Configuration: Change OSPOS's… | |
| Analizada | Alta (8.8) | 0.28% | — | Opensourcepos Open Source Point OF Sale | 17/12/2025 | 17/6/2026 | Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and prior to version 3.4.2, a Cross-Site Request Forgery (CSRF) vulnerability exists in the application's filter configuration. The CSRF protection mechanism was… | |
| Analizada | Alta (8.1) | 0.38% | — | Opensourcepos Open Source Point OF Sale | 17/12/2025 | 17/6/2026 | Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and prior to version 3.4.2, a Stored Cross-Site Scripting (XSS) vulnerability exists in the "Return Policy" configuration field. The application does not properly… | |
| Analizada | Media (6.1) | 0.26% | — | Opensourcepos Open Source Point OF Sale | 17/12/2025 | 17/6/2026 | A Cross-site scripting (XSS) vulnerability in Create/Update Item Kit(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the "name" parameter. | |
| Analizada | Alta (7.2) | 0.55% | — | Opensourcepos Open Source Point OF Sale | 17/12/2025 | 17/6/2026 | A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the phone_number parameter. | |
| Analizada | Alta (7.2) | 0.55% | — | Opensourcepos Open Source Point OF Sale | 17/12/2025 | 17/6/2026 | A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the "name" parameter. | |
| Analizada | Alta (7.5) | 0.45% | — | Opensourcepos Open Source Point OF Sale | 18/11/2025 | 17/6/2026 | The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing server-side validation. When an authenticated user omits or leaves the `password` and `repeat_password` parameters empty in the password change request, the backend still returns… | |
| Analizada | Media (6.5) | 0.19% | — | Opensource-socialnetwork Open Source Social Network | 5/11/2025 | 17/6/2026 | OSSN (Open Source Social Network) 8.6 is vulnerable to SQL Injection in /action/rtcomments/status via the timestamp parameter. | |
| Analizada | Alta (7.3) | 0.29% | — | Opensource-socialnetwork Open Source Social Network | 3/11/2025 | 17/6/2026 | Open Source Social Network (OSSN) 8.6 is vulnerable to Cross Site Scripting (XSS) via the parameter param` at endpoint u/administrator/friends. | |
| Modificada | Alta (7.5) | 0.17% | — | Opensourcelabs Skyscraper | 7/6/2024 | 17/6/2026 | SkyScrape is a GUI Dashboard for AWS Infrastructure and Managing Resources and Usage Costs. SkyScrape's API requests are currently unsecured HTTP requests, leading to potential vulnerabilities for the user's temporary credentials and data. This affects version 1.0.0. | |
| Modificada | Crítica (9.8) | 0.94% | — | Fhs-opensource Iparking | 8/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in fhs-opensource iparking 1.5.22.RELEASE. This issue affects some unknown processing of the file /vueLogin. The manipulation leads to deserialization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Crítica (9.8) | 0.71% | — | Fhs-opensource Iparking | 8/1/2024 | 17/6/2026 | A vulnerability classified as critical was found in fhs-opensource iparking 1.5.22.RELEASE. This vulnerability affects the function getData of the file src/main/java/com/xhb/pay/action/PayTempOrderAction.java. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed… | |
| Modificada | Alta (8.8) | 0.60% | — | Feiqu-opensource Project Feiqu-opensource | 8/3/2023 | 17/6/2026 | feiqu-opensource Background Vertical authorization vulnerability exists in IndexController.java. demo users with low permission can perform operations within the permission of the admin super administrator and can use this vulnerability to change the blacklist IP address in the system at will. |