Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
5401 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 2.6% | 💥 Exploit | Nextcloud FlowWindmill | 7/4/2026 | 17/6/2026 | Windmill versions 1.56.0 through 1.614.0 contain a missing authorization vulnerability that allows users with the Operator role to perform prohibited entity creation and modification actions via the backend API. Although Operators are documented and priced as unable to create or modify entities, the API does not… | |
| Aplazada | Baja (2.9) | 0.40% | — | Kodcloud KodboxAI | 6/4/2026 | 24/7/2026 | A vulnerability was detected in kalcaddle kodbox up to 1.64. This affects an unknown function of the component shareMake/shareCheck. Performing a manipulation of the argument siteFrom/siteTo results in server-side request forgery. The attack is possible to be carried out remotely. The complexity of an attack is rather… | |
| Aplazada | Media (5.5) | 0.48% | — | Acrel Electrical Prepaid Cloud PlatformAI | 5/4/2026 | 24/7/2026 | A vulnerability was found in Acrel Electrical Prepaid Cloud Platform 1.0. This issue affects some unknown processing of the file /bin.rar of the component Backup File Handler. The manipulation results in information disclosure. The attack can be launched remotely. The exploit has been made public and could be used.… | |
| Aplazada | Baja (2.1) | 0.35% | — | Dromara Lamp-cloudAI | 5/4/2026 | 24/7/2026 | A vulnerability was detected in Dromara lamp-cloud up to 5.8.1. This vulnerability affects the function pageUser of the file /defUser/pageUser of the component DefUserController. Performing a manipulation results in improper authorization. The attack can be initiated remotely. The exploit is now public and may be… | |
| Analizada | Media (6.9) | 0.44% | 💥 PoC | Mygardyn Cloud API | 3/4/2026 | 24/7/2026 | Development and test API endpoints are present that mirror production functionality. | |
| Analizada | Alta (8.7) | 0.68% | 💥 PoC | Mygardyn Cloud API | 3/4/2026 | 24/7/2026 | A specific administrative endpoint is accessible without proper authentication, exposing device management functions. | |
| Analizada | Media (6.9) | 0.53% | 💥 PoC | Mygardyn Cloud API | 3/4/2026 | 24/7/2026 | A specific administrative endpoint notifications is accessible without proper authentication. | |
| Analizada | Crítica (9.2) | 0.60% | 💥 PoC | Mygardyn Cloud API | 3/4/2026 | 24/7/2026 | A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication. | |
| Analizada | Crítica (9.3) | 0.29% | 💥 PoC | Mygardyn Cloud API | 3/4/2026 | 24/7/2026 | A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call. | |
| Analizada | Crítica (9.8) | 0.50% | — | Cloudreve | 3/4/2026 | 24/7/2026 | Cloudreve is a self-hosted file management and sharing system. Prior to version 4.13.0, the application uses the weak pseudo-random number generator math/rand seeded with time.Now().UnixNano() to generate critical security secrets, including the secret_key, and hash_id_salt. These secrets are generated upon first… | |
| Aplazada | Media (5.5) | 0.47% | — | Huimeicloud HM EditorAI | 2/4/2026 | 24/7/2026 | A vulnerability was determined in huimeicloud hm_editor up to 2.2.3. Impacted is the function client.get of the file src/mcp-server.js of the component image-to-base64 Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery. It is possible to launch the attack remotely. The… | |
| Aplazada | Baja (2) | 0.33% | — | Iocoder Yudao-cloudAI | 30/3/2026 | 17/6/2026 | A weakness has been identified in YunaiV yudao-cloud up to 2026.01. This vulnerability affects unknown code of the file /admin-api/system/mail-log/page. This manipulation of the argument toMail causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be… | |
| Aplazada | Media (5.5) | 0.41% | 💥 PoC | Iocoder Yudao-cloudAI | 30/3/2026 | 17/6/2026 | A security flaw has been discovered in YunaiV yudao-cloud up to 2026.01. This affects an unknown part of the file /admin-api/system/tenant/get-by-website. The manipulation of the argument Website results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may… | |
| Analizada | Alta (7.6) | 0.39% | 💥 PoC | Cloudark Kubeplus | 30/3/2026 | 17/6/2026 | In KubePlus 4.1.4, the mutating webhook and kubeconfiggenerator components have an SSRF vulnerability when processing the chartURL field of ResourceComposition resources. The field is only URL-encoded without validating the target address. More critically, when kubeconfiggenerator uses wget to download charts, the… | |
| Analizada | Media (5.5) | 0.12% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow attacker to access to a session, then they can maintain control over the account despite the password change leading to account takeover. | |
| Analizada | Alta (7.5) | 0.19% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by Hardcoded Sensitive Data which allows attacker to gain access to the source code or if it is stored in insecure repositories, they can easily retrieve these hardcoded secrets. | |
| Analizada | Alta (7.5) | 0.27% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by SQL Injection which allows attacker to exploit this vulnerability to retrieve sensitive information from the database. | |
| Analizada | Crítica (9.8) | 0.32% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by Missing Functional Level Access Control which will allow attacker to escalate his privileges and may compromise the application and may steal and manipulate the data. | |
| Analizada | Media (6.5) | 0.18% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by Use of Vulnerable/Outdated Versions vulnerability using which an attacker may make use of the exploits available across the internet and craft attacks against the application. | |
| Analizada | Media (5.3) | 0.20% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by Internal IP Disclosure vulnerability will give attackers a clearer map of the organization’s network layout. | |
| Analizada | Alta (8.1) | 0.22% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by Admin Session Concurrency vulnerability using which an attacker can exploit concurrent sessions to hijack or impersonate an admin user. | |
| Analizada | Media (4.3) | 0.18% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerability. CORS misconfigurations includes the exposure of sensitive user information to attackers, unauthorized access to APIs, and possible data manipulation or leakage. If an attacker to exploit CORS misconfiguration, they could steal sensitive… | |
| Analizada | Media (4.3) | 0.23% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerability where an attacker using external scripts can tamper with the DOM, altering the content or behavior of the application. Malicious scripts can steal cookies or session tokens, leading to session hijacking. | |
| Analizada | Media (5.3) | 0.22% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by Banner Disclosure vulnerability where attackers gain insights into the system’s software and version details which would allow them to craft software specific attacks. | |
| Analizada | Alta (8.8) | 0.32% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerability where in depending on how the web application handles the split response, an attacker may be able to execute arbitrary commands or inject harmful content into the response.. |