Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
23.383 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.3) | 0.43% | — | Djangoproject Django | 7/7/2026 | 9/7/2026 | An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()` decorator cache responses that vary on cookies when the incoming request carries unrelated cookies, which allows remote attackers to read private data from the shared cache. Earlier, unsupported… | |
| Modificada | Media (4.7) | 0.13% | — | Zephyrproject Zephyr | 7/7/2026 | 1/9/2026 | The Dhara flash translation layer disk driver (drivers/disk/ftl_dhara.c) implemented the dhara_nand_ callbacks so that, on a flash error, the error code was written unconditionally through the caller-supplied dhara_error_t err pointer (e.g. *err = DHARA_E_ECC in dhara_nand_read, and similar in… | |
| Pendiente de análisis | Alta (8.8) | 0.49% | — | 389 Project 389 Directory ServerAIFreeipaAIRedhat Identity ManagementAI | 7/7/2026 | 8/7/2026 | A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds… | |
| Modificada | Media (5.3) | 0.40% | — | Zephyrproject Zephyr | 5/7/2026 | 14/7/2026 | Zephyr's DNS resolver detects mDNS (.local) queries in dns_resolve_name_internal() (subsys/net/lib/dns/resolve.c) with memcmp(strrchr(query, '.'), ".local", 7), which always reads a fixed 7 bytes from the suffix pointer. When the resolved hostname's final label is shorter than 7 bytes (e.g. names ending in .org, .com,… | |
| Modificada | Media (4.6) | 0.28% | — | Zephyrproject Zephyr | 5/7/2026 | 14/7/2026 | The MAX32xxx USB device controller driver (drivers/usb/udc/udc_max32.c, compatible adi_max32_usbhs) dereferenced an endpoint buffer in its OUT and IN transfer-completion handlers without checking it for NULL. udc_event_xfer_out_done() called net_buf_add(buf, ep_request->actlen) immediately after buf =… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Real State ServicesAI | 5/7/2026 | 7/7/2026 | A security vulnerability has been detected in code-projects Real State Services 1.0. This issue affects some unknown processing of the file /pay.php. Such manipulation of the argument Bankname leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Real State ServicesAI | 5/7/2026 | 6/7/2026 | A weakness has been identified in code-projects Real State Services 1.0. This vulnerability affects unknown code of the file /builderHome.php. This manipulation of the argument loc causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Hotel AND Tourism ReservationAI | 5/7/2026 | 6/7/2026 | A vulnerability has been found in code-projects Hotel and Tourism Reservation 1.0. This impacts an unknown function of the file /admin/add_event.php of the component Event Management Page. Such manipulation of the argument fdetails leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Hotel AND Tourism ReservationAI | 5/7/2026 | 6/7/2026 | A flaw has been found in code-projects Hotel and Tourism Reservation 1.0. This affects an unknown function of the file /admin/tour_reserves.php of the component Tour Reservations Page. This manipulation of the argument tour causes sql injection. The attack can be initiated remotely. The exploit has been published and… | |
| Aplazada | Media (5.5) | 0.43% | 💥 PoC | Code-projects Hotel AND Tourism ReservationAI | 5/7/2026 | 7/7/2026 | A vulnerability was detected in code-projects Hotel and Tourism Reservation 1.0. The impacted element is an unknown function of the file /admin/rooms.php of the component Room Management Page. The manipulation of the argument delete results in sql injection. It is possible to launch the attack remotely. The exploit is… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Hotel AND Tourism ReservationAI | 5/7/2026 | 7/7/2026 | A vulnerability was found in code-projects Hotel and Tourism Reservation 1.0. Affected by this issue is some unknown functionality of the file /admin/add_tour.php of the component Tour Management Page. The manipulation of the argument delete_image results in sql injection. The attack may be launched remotely. The… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Hotel AND Tourism ReservationAI | 5/7/2026 | 6/7/2026 | A vulnerability has been found in code-projects Hotel and Tourism Reservation 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/reservations.php of the component Reservations Management Page. The manipulation of the argument delete leads to sql injection. The attack may be initiated… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Hotel AND Tourism ReservationAI | 5/7/2026 | 6/7/2026 | A flaw has been found in code-projects Hotel and Tourism Reservation 1.0. Affected is an unknown function of the file /admin/add_room.php. Executing a manipulation of the argument delete_image/edit/description/number/price/rooms/type can lead to sql injection. The attack can be launched remotely. The exploit has been… | |
| Aplazada | Media (6.9) | 0.43% | — | Code-projects Real State ServicesAI | 5/7/2026 | 6/7/2026 | A vulnerability was detected in code-projects Real State Services 1.0. Affected by this vulnerability is an unknown functionality of the file /addprojectsale.php. The manipulation of the argument amen results in sql injection. The attack can be launched remotely. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Real State ServicesAI | 5/7/2026 | 6/7/2026 | A security vulnerability has been detected in code-projects Real State Services 1.0. Affected is an unknown function of the file /addprojectrent.php. The manipulation of the argument amen leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Real State ServicesAI | 5/7/2026 | 6/7/2026 | A weakness has been identified in code-projects Real State Services 1.0. This impacts an unknown function of the file /single-list_rent.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Real State ServicesAI | 5/7/2026 | 7/7/2026 | A security flaw has been discovered in code-projects Real State Services 1.0. This affects an unknown function of the file /normalHomeRent.php. Performing a manipulation of the argument loc results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Real State ServicesAI | 5/7/2026 | 6/7/2026 | A vulnerability was identified in code-projects Real State Services 1.0. The impacted element is an unknown function of the file /normalHomeSale.php. Such manipulation of the argument loc leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Smart Parking SystemAI | 5/7/2026 | 7/7/2026 | A vulnerability has been found in code-projects Smart Parking System 1.0. The affected element is an unknown function of the file /parkings/parkings.php. Such manipulation of the argument street/city/status leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and… | |
| Aplazada | Baja (2.1) | 0.33% | — | Code-projects Online ExaminationAI | 5/7/2026 | 6/7/2026 | A vulnerability was identified in code-projects Online Examination 1.0. This affects an unknown part of the file /update.php?q=addquiz of the component Quiz Creation Feature. The manipulation of the argument name/total/right/wrong/time/tag/desc leads to sql injection. The attack can be initiated remotely. The exploit… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Online ExaminationAI | 5/7/2026 | 6/7/2026 | A vulnerability was determined in code-projects Online Examination 1.0. Affected by this issue is some unknown functionality of the file head.php. Executing a manipulation of the argument uname/password can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and… | |
| Aplazada | Baja (2.1) | 0.33% | — | Code-projects Internship Management SystemAI | 5/7/2026 | 6/7/2026 | A vulnerability was detected in code-projects Internship Management System 1.0. This affects an unknown function of the file employer/details/change_password.php of the component Password Change Endpoint. The manipulation of the argument Current results in sql injection. The attack can be executed remotely. The… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Internship Management SystemAI | 5/7/2026 | 6/7/2026 | A security vulnerability has been detected in code-projects Internship Management System 1.0. The impacted element is an unknown function of the file employer/login.php of the component Employer Login Endpoint. The manipulation of the argument email/password leads to sql injection. Remote exploitation of the attack is… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Online JOB PortalAI | 4/7/2026 | 6/7/2026 | A vulnerability was found in code-projects Online Job Portal 1.0. The affected element is an unknown function of the file login.php. Performing a manipulation of the argument txtUser/txtPass results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used. | |
| Aplazada | Baja (2.1) | 0.33% | — | Code-projects Assessment ManagementAI | 4/7/2026 | 6/7/2026 | A vulnerability was detected in code-projects Assessment Management 1.0. This vulnerability affects unknown code of the file /lecturer/marking-scheme.php. The manipulation of the argument smarksrange[] results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used. |