Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
212 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.40% | — | Snipeitapp Snipe-it | 9/9/2026 | 14/9/2026 | Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint. Superusers uploading corrupted or invalid zip files trigger permanent data loss with no recovery path or rollback mechanism. | |
| Analizada | Media (5.3) | 0.25% | — | Snipeitapp Snipe-it | 9/9/2026 | 14/9/2026 | Snipe-IT is an open source IT asset management system. In versions up to and including 8.6.3, the report acceptance endpoints POST /reports/unaccepted_assets/sent_reminder (ReportsController::sentAssetAcceptanceReminder) and DELETE /reports/unaccepted_assets/{acceptanceId}/delete… | |
| Analizada | Alta (7.4) | 0.29% | — | Snipeitapp Snipe-it | 9/9/2026 | 14/9/2026 | Snipe-IT before 8.7.0 contains an authorization bypass vulnerability in Livewire components that enforce authorization only at the route level, not within component lifecycle methods. Attackers with a valid authenticated session can replay signed component snapshots via POST /livewire/update to invoke protected… | |
| Analizada | Media (5.1) | 0.36% | — | Snipeitapp Snipe-it | 9/9/2026 | 14/9/2026 | Snipe-IT is an IT asset management application. In Snipe-IT master-branch builds after 8.6.3 (the code was never included in a tagged release), SettingsController::downloadLocationScopingReport streams the FMCS location-scoping mismatch report (GET /admin/settings/location-scoping-report.csv) through a bare fputcsv()… | |
| Analizada | Media (5.3) | 0.29% | — | Snipeitapp Snipe-it | 9/9/2026 | 14/9/2026 | Snipe-IT versions before 8.7.0 fail to properly scope asset acceptance report queries by company, allowing authenticated reports.view users to read pending acceptances across all companies. Attackers can access the unaccepted_assets report page or CSV export to disclose cross-company inventory details and assignee… | |
| Analizada | Media (5.1) | 0.41% | — | Snipeitapp Snipe-it | 9/9/2026 | 14/9/2026 | Snipe-IT through 8.6.3 does not neutralize formula elements in the "unaccepted assets" acceptance report CSV export. ReportsController::postAssetAcceptanceReport builds the CSV by hand (stripping commas and joining rows manually) and, unlike the six sibling exports in the same controller, never applies… | |
| Analizada | Alta (8.4) | 0.35% | — | Snipeitapp Snipe-it | 9/9/2026 | 14/9/2026 | Snipe-IT versions before 8.7.0 fail to sanitize the category EULA text field before rendering it in checkout confirmation emails. Attackers with low-privilege permissions can inject markdown image syntax or raw HTML img tags pointing to local files or remote URLs, which the mail auto-embed library resolves server-side… | |
| Analizada | Media (5.1) | 0.29% | — | Snipeitapp Snipe-it | 9/9/2026 | 14/9/2026 | Snipe-IT before 8.7.0 fails to check the return value of Storage::delete() in UploadedFilesController::destroy() and Api\\UploadedFilesController::destroy(), allowing deletion requests to report success while files remain on disk. Administrators performing attachment deletions receive success responses and see files… | |
| Analizada | Media (5.3) | 0.29% | — | Snipeitapp Snipe-it | 9/9/2026 | 19/9/2026 | Snipe-IT versions before 8.7.0 contain a broken access control vulnerability in AssetModelPolicy where the files() method cascades from assets.files permission, allowing authenticated users to upload and delete file attachments on Asset Model records without the required models.files permission. Attackers with only… | |
| Analizada | Media (5.3) | 0.28% | — | Snipeitapp Snipe-it | 9/9/2026 | 19/9/2026 | Snipe-IT versions before 8.7.0 contain an improper ownership management vulnerability in the consumables checkout API endpoint that records the checkout target user's id in the created_by column instead of the authenticated caller's id. Authenticated attackers with consumables.checkout permission can perform checkouts… | |
| Analizada | Alta (7.1) | 0.37% | — | Snipeitapp Snipe-it | 9/9/2026 | 19/9/2026 | Snipe-IT through 8.6.4 (fixed in 8.7.0) does not enforce the components.view permission on the authenticated endpoint GET /api/v1/hardware/<asset-id>/assigned/components. The endpoint authorizes only assets.view on the parent asset before returning linked component details; the components.view check is applied only to… | |
| Analizada | Alta (7.1) | 0.37% | — | Snipeitapp Snipe-it | 9/9/2026 | 19/9/2026 | Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/history endpoint, allowing any authenticated user to reassign arbitrary assets and modify audit logs. Attackers can submit a CSV file to reassign assets across companies and inject fraudulent audit trail entries, compromising inventory integrity and… | |
| Analizada | Alta (8.5) | 0.34% | — | Snipeitapp Snipe-it | 9/9/2026 | 19/9/2026 | Snipe-IT before 8.7.0 fails to properly gate Laravel Passport's OAuth client management routes, allowing any authenticated user to register OAuth clients with attacker-controlled redirect URIs. Attackers can trick administrators into approving consent screens, then exchange authorization codes for bearer tokens… | |
| Analizada | Alta (7) | 0.34% | — | Snipeitapp Snipe-it | 9/9/2026 | 19/9/2026 | Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not check the return value of storage write operations in ImageUploadRequest::handleImages(). Because Laravel's default disk mode does not throw on failure, a silently failed Storage::disk('public')->put(...) call still caused the application to delete the previous image… | |
| Analizada | Baja (2.1) | 0.27% | — | Snipeitapp Snipe-it | 9/9/2026 | 18/9/2026 | Snipe-IT 8.6.3 and earlier (and develop pre-release commits prior to the fix) contain a race condition in the asset checkout paths. Api\AssetsController::checkout() and Assets\AssetCheckoutController::store() call Asset::availableForCheckout() outside the mutation path and then invoke Asset::checkOut() without taking… | |
| Analizada | Baja (2.3) | 0.36% | — | Snipeitapp Snipe-it | 9/9/2026 | 18/9/2026 | Snipe-IT 8.6.3 and earlier do not check the return value of Storage::put() when writing the signature PNG and the generated acceptance PDF in Account\AcceptanceController::store(). On filesystem drivers that return false instead of throwing on a write failure (for example the local disk with restrictive permissions,… | |
| Analizada | Crítica (9.3) | 0.49% | — | Snipeitapp Snipe-it | 8/9/2026 | 9/9/2026 | Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field due to incomplete sanitization that reverses HTML encoding on greater-than and double-quote characters. Superusers can plant malicious CSS payloads using @import and url() references to exfiltrate CSRF tokens from other… | |
| Analizada | Media (5.3) | 0.28% | — | Snipeitapp Snipe-it | 8/9/2026 | 10/9/2026 | snipe-it versions before 8.7.0 fail to enforce asset view authorization in the GET /hardware/{asset}/barcode endpoint. Authenticated attackers can iterate asset IDs to retrieve barcodes and enumerate asset tags across tenants, including soft-deleted and cross-company assets. | |
| Analizada | Media (5.9) | 0.31% | — | Snipeitapp Snipe-it | 8/9/2026 | 9/9/2026 | snipe-it versions before 8.7.0 contain a server-side request forgery vulnerability in the ExternalUrl validation rule that fails to detect IPv6 transition addresses encoding private IPv4 targets. Attackers with super-admin privileges can configure webhook URLs using NAT64, 6to4, or Teredo transition addresses to… | |
| Analizada | Alta (7.1) | 0.55% | — | Snipeitapp Snipe-it | 8/9/2026 | 10/9/2026 | Snipe-IT before 8.7.1 fails to validate the length of the note field in the POST /account/accept/{acceptance} endpoint, allowing authenticated users to submit unbounded input that reaches synchronous CommonMark rendering. Attackers can submit large note values to exhaust PHP worker CPU and cause denial of service… | |
| Analizada | Alta (8.6) | 0.58% | — | Snipeitapp Snipe-it | 8/9/2026 | 9/9/2026 | Snipe-IT before 8.7.0 streams the SQL entry from an uploaded backup archive directly into the MySQL/MariaDB command-line client (`mysql`) without the --binary-mode flag, so the client interprets lines beginning with backslash commands such as `\!` as local shell commands. An authenticated superadministrator who… | |
| Analizada | Media (5.3) | 0.30% | — | Snipeitapp Snipe-it | 8/9/2026 | 19/9/2026 | snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkout request handling that allows authenticated users to corrupt the assets.requests_counter through duplicate submissions and cancellations without active requests. Attackers can repeatedly call cancel endpoints without active requests to… | |
| Analizada | Alta (8.7) | 0.48% | — | Snipeitapp Snipe-it | 4/9/2026 | 16/9/2026 | snipe-it versions before 8.6.3 contain an authorization bypass vulnerability in the bulk delete functionality that allows restricted users to soft-delete users outside their authorized scope. Attackers can include unauthorized user IDs in bulk delete requests to bypass instance-level restrictions and modify or disable… | |
| Analizada | Alta (8.4) | 0.38% | — | Snipeitapp Snipe-it | 4/9/2026 | 16/9/2026 | Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerability in checkout-acceptance report actions when Full Multiple Company Support is enabled. Authenticated users with reports.view permission can enumerate sequential acceptance IDs and soft-delete or trigger reminder emails for acceptances belonging… | |
| Analizada | Media (5.3) | 0.38% | — | Snipeitapp Snipe-it | 1/9/2026 | 29/9/2026 | Snipe-IT before 8.7.0 gates the bulk asset restore endpoint on the assets.edit permission instead of assets.delete, allowing users without delete rights to restore soft-deleted assets. Attackers with edit permissions can post asset identifiers to the bulk restore endpoint to undo administrator deletions and bypass… |