Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.53% | — | Fabian Simple Food Ordering System | 27/10/2025 | 17/6/2026 | A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Impacted is an unknown function of the file /editproduct.php. Such manipulation of the argument photo leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. | |
| Analizada | Baja (2.1) | 0.40% | — | Fabian Simple Food Ordering System | 27/10/2025 | 17/6/2026 | A weakness has been identified in code-projects Simple Food Ordering System 1.0. This issue affects some unknown processing of the file /addcategory.php. This manipulation of the argument cname causes cross site scripting. The attack can be initiated remotely. The exploit has been made available to the public and… | |
| Analizada | Baja (2.1) | 0.39% | — | Fabian Simple Food Ordering System | 27/10/2025 | 17/6/2026 | A vulnerability was identified in code-projects Simple Food Ordering System 1.0. This affects an unknown part of the file /editcategory.php. The manipulation of the argument pname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. | |
| Analizada | Baja (2.1) | 0.40% | — | Fabian Simple Food Ordering System | 27/10/2025 | 1/10/2026 | A security flaw has been discovered in code-projects Simple Food Ordering System 1.0. This vulnerability affects unknown code of the file /addproduct.php. The manipulation of the argument pname/category/price results in cross site scripting. It is possible to launch the attack remotely. The exploit has been released… | |
| Aplazada | Alta (8.4) | 0.43% | — | Centreon Infra MonitoringAI | 27/10/2025 | 17/6/2026 | Incorrect Default Permissions vulnerability in Centreon Infra Monitoring (MBI modules) allows Embedding Scripts within Scripts by CentreonBI user account on the MBI server This issue affects Infra Monitoring: from 24.10.0 before 24.10.6, from 24.04.0 before 24.04.9, from 23.10.0 before 23.10.15. | |
| Aplazada | Crítica (9.8) | 0.29% | — | TM2 MonitoringAI | 22/10/2025 | 5/7/2026 | TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure. | |
| Aplazada | Media (6.9) | 1.1% | — | Wikimedia Mediawiki Springboard ExtensionAI | 21/10/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in The Wikimedia Foundation Mediawiki Foundation - Springboard Extension allows Command Injection.This issue affects Mediawiki Foundation - Springboard Extension: master. | |
| Aplazada | Crítica (9.2) | 0.67% | — | Flowring AgentflowAI | 17/10/2025 | 17/6/2026 | Agentflow developed by Flowring has an Use of Hard-coded Cryptographic Key vulnerability, allowing unauthenticated remote attackers to exploit the fixed key to generate verification information, thereby logging into the system as any user. Attacker must first obtain an user ID in order to exploit this vulnerability. | |
| Aplazada | Alta (8.7) | 0.83% | — | Flowring AgentflowAI | 17/10/2025 | 17/6/2026 | Agentflow developed by Flowring has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files. | |
| Aplazada | Media (4.3) | 0.31% | — | Vmware Spring FrameworkAI | 16/10/2025 | 17/6/2026 | STOMP over WebSocket applications may be vulnerable to a security bypass that allows an attacker to send unauthorized messages. Affected Spring Products and VersionsSpring Framework: MitigationUsers of affected versions should upgrade to the corresponding fixed version. Affected version(s)Fix… | |
| Analizada | Media (6.5) | 0.31% | — | IBM Engineering Requirements Management Doors Next | 12/10/2025 | 17/6/2026 | IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user to cause a denial of service by uploading specially crafted files using uncontrolled recursion. | |
| Analizada | Media (5.7) | 0.12% | — | IBM Engineering Requirements Management Doors Next | 12/10/2025 | 17/6/2026 | IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to spoof email identity of the sender due to improper verification of source data. | |
| Analizada | Baja (3.5) | 0.18% | — | IBM Engineering Requirements Management Doors Next | 12/10/2025 | 17/6/2026 | IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to delete reviews from other users due to client-side enforcement of server-side security. | |
| Analizada | Baja (3.5) | 0.18% | — | IBM Engineering Requirements Management Doors Next | 12/10/2025 | 17/6/2026 | IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to delete comments from other users due to client-side enforcement of server-side security. | |
| Analizada | Baja (2.1) | 0.34% | — | Fabian Simple Food Ordering System | 11/10/2025 | 17/6/2026 | A vulnerability was found in code-projects Simple Food Ordering System 1.0. Affected is an unknown function of the file /addcategory.php. The manipulation of the argument cname results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used. | |
| Analizada | Baja (2.1) | 0.34% | — | Fabian Simple Food Ordering System | 11/10/2025 | 17/6/2026 | A vulnerability has been found in code-projects Simple Food Ordering System 1.0. This impacts an unknown function of the file /addproduct.php. The manipulation of the argument Category leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (5.5) | 0.42% | — | Projectworlds Online Food Ordering System | 11/10/2025 | 17/6/2026 | A vulnerability was determined in projectworlds Online Ordering Food System 1.0. This issue affects some unknown processing of the file /all-orders.php. This manipulation of the argument Status causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be… | |
| Analizada | Baja (2.1) | 0.38% | — | Fabian Simple Food Ordering System | 11/10/2025 | 17/6/2026 | A vulnerability was found in code-projects Simple Food Ordering System 1.0. This vulnerability affects unknown code of the file /editproduct.php. The manipulation of the argument Category results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used. | |
| Analizada | Baja (2.1) | 0.34% | — | Fabian Simple Food Ordering System | 11/10/2025 | 17/6/2026 | A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Affected is an unknown function of the file editcategory.php. Such manipulation of the argument cname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be… | |
| Analizada | Media (5.5) | 0.42% | — | Fabian Project Monitoring System | 10/10/2025 | 17/6/2026 | A vulnerability was found in code-projects Project Monitoring System 1.0. The impacted element is an unknown function of the file /useredit.php. The manipulation of the argument uid results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used. | |
| Analizada | Media (5.5) | 0.48% | — | Fabian Simple Food Ordering System | 7/10/2025 | 30/9/2026 | A vulnerability was identified in code-projects Simple Food Ordering System 1.0. Impacted is an unknown function of the file /product.php. Such manipulation of the argument Category leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used. | |
| Aplazada | Alta (7) | 0.19% | — | QOS Logback-coreAIJaninoAIVmware Spring FrameworkAI | 1/10/2025 | 25/6/2026 | ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.18 in Java applications, allows an attacker to execute arbitrary code by compromising an existing logback configuration file or by injecting an environment variable before program execution. A… | |
| Analizada | Baja (2) | 0.29% | — | Fabian Project Monitoring System | 28/9/2025 | 17/6/2026 | A vulnerability has been found in code-projects Project Monitoring System 1.0. Affected is an unknown function of the file /onlineJobSearchEngine/postjob.php. Such manipulation of the argument txtapplyto leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.5) | 0.48% | — | Fabian Project Monitoring System | 27/9/2025 | 17/6/2026 | A flaw has been found in code-projects Project Monitoring System 1.0. The impacted element is an unknown function of the file /login.php. This manipulation of the argument username/password causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. | |
| Analizada | Baja (2) | 0.24% | — | Fabian Simple Food Ordering System | 23/9/2025 | 17/6/2026 | A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /ordersimple/order.php. The manipulation of the argument ID leads to cross site scripting. The attack may be initiated remotely. The exploit has been… |