Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2563▼ 389 respecto a la semana anterior
Críticas / altas1328▲ 46 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 468 respecto a la semana anterior
401.230 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (4.3) | — | — | Joomsky JS Support TicketAI | 5/10/2026 | 5/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Ahmad JS Help Desk js-support-ticket allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk: from n/a through 4.0.0. | |
| Recibida | Media (6.5) | — | — | Brainstormforce Presto PlayerAI | 5/10/2026 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Presto Player presto-player allows Stored XSS.This issue affects Presto Player: from n/a through 4.5.2. | |
| Recibida | Media (6.5) | — | — | Brainstormforce Astra SitesAI | 5/10/2026 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Starter Templates astra-sites allows Stored XSS.This issue affects Starter Templates: from n/a through 4.7.7. | |
| Recibida | Crítica (10) | — | — | Perforce P4 SearchAI | 5/10/2026 | 5/10/2026 | Perforce P4 Search container images prior to 2026.4.2 reset the service authentication token to a publicly documented default value. An unauthenticated attacker with network access can obtain the highest application privilege, potentially leading to arbitrary code execution and compromise of the connected P4 Server. | |
| Recibida | Crítica (9.5) | — | — | Perforce P4 SearchAI | 5/10/2026 | 5/10/2026 | Perforce P4 Search container images prior to 2026.4.2 enable an unauthenticated Java debug interface. An attacker with network access to this interface can execute arbitrary code as the P4 Search service account, potentially leading to compromise of the connected P4 Server. | |
| Recibida | Alta (7.5) | — | — | PapermergeAI | 5/10/2026 | 5/10/2026 | Papermerge 3.5.3 allows remote code execution by a standard user via directory traversal in a /api/documents/upload call. A Python .pth file can be written to site-packages, and its code is executed upon the next start of the Python interpreter. | |
| Recibida | Media (5.3) | — | — | VgmstreamAI | 5/10/2026 | 5/10/2026 | A security vulnerability has been detected in vgmstream up to r2117. Affected is the function decode_ms_ima of the file src/coding/ima_decoder.c of the component Microsoft IMA Decoder. Such manipulation leads to divide by zero. The attack can be executed remotely. | |
| Recibida | Baja (2.4) | — | — | VgmstreamAI | 5/10/2026 | 5/10/2026 | A weakness has been identified in vgmstream up to r2117. This impacts the function make_group_random of the file src/meta/txtp_process.c of the component TXTP File Handler. This manipulation causes use after free. The attack needs to be launched locally. Patch name: ae37662ad626254ddd96ad69ac263792d7a92024. It is… | |
| Recibida | Media (5.3) | — | — | VgmstreamAI | 5/10/2026 | 5/10/2026 | A security flaw has been discovered in vgmstream up to r2117. This affects the function parse_params/txtp_parse of the file src/meta/txtp_parser.c of the component TXTP File Handler. The manipulation results in out-of-bounds write. The attack may be launched remotely. The patch is identified as… | |
| Recibida | Media (5.5) | — | — | Sourcecodester Online Reviewer Management SystemAI | 5/10/2026 | 5/10/2026 | A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/Subject/btn_functions.php?action=course. Executing a manipulation of the argument Subject can lead to sql injection. The attack can be launched… | |
| Recibida | Sin puntuar | — | — | NET Whois RAWAI | 5/10/2026 | 5/10/2026 | Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names. pwhois encodes each non-ASCII label directly using Net::IDN::Punycode and prepends xn--. Apart from lowercasing ASCII and Cyrillic letters, it skips the IDNA mapping and… | |
| Recibida | Media (5.5) | — | — | Sourcecodester Online Reviewer Management SystemAI | 5/10/2026 | 5/10/2026 | A vulnerability was found in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/Subject/btn_functions.php?action=update. Performing a manipulation of the argument Subject results in sql injection. The attack can be initiated remotely. The… | |
| Aplazada | Baja (2.9) | — | — | Lmsys SglangAI | 5/10/2026 | 5/10/2026 | A vulnerability has been found in sgl-project sglang up to 0.5.21. This issue affects the function server_info of the file python/sglang/srt/entrypoints/http_server.py of the component HTTP Endpoint. Such manipulation of the argument api_key leads to cleartext transmission of sensitive information. It is possible to… | |
| Recibida | Media (5.5) | — | — | NextchatAI | 5/10/2026 | 5/10/2026 | A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1. This vulnerability affects the function proxyHandler of the file app/api/proxy.ts of the component Proxy Fallback Handler. This manipulation of the argument x-base-url causes server-side request forgery. It is possible to initiate the attack remotely. The… | |
| Recibida | Media (6.9) | — | — | Weseek GrowiAI | 5/10/2026 | 5/10/2026 | An improper access control vulnerability exists in GROWI, which allow an unauthenticated attacker to read files contained in non-public pages of the affected product when the file upload setting is configured as "Local". | |
| Recibida | Sin puntuar | — | — | YamlAI | 5/10/2026 | 5/10/2026 | YAML versions before 1.27_001 for Perl allow a loaded perl/glob document to replace any package variable, which can lead to arbitrary code execution. A perl/glob document names a package and a symbol, and supplies the value assigned to it. Nothing restricts the name, so the target can be @INC or YAML's own load… | |
| Recibida | Sin puntuar | — | — | YamlAI | 5/10/2026 | 5/10/2026 | YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes. A perl/hash:Class tag blesses a hash into the class it names. The document supplies the object's fields, and Perl calls DESTROY when it goes out of scope. What DESTROY does depends on the classes the process… | |
| Recibida | Media (5.3) | — | — | UPI QR Code Payment GatewayAI | 5/10/2026 | 5/10/2026 | The UPI QR Code Payment Gateway WordPress plugin through 1.4.3 does not verify that a payment-confirmation request actually belongs to the order and customer it claims to confirm, allowing unauthenticated attackers to mark an arbitrary order as paid without making any payment. | |
| Recibida | Media (5.9) | — | — | Imaginate-solutions File Uploads Addon FOR WoocommerceAI | 5/10/2026 | 5/10/2026 | The File Uploads Addon for WooCommerce WordPress plugin before 1.7.6 does not verify that the person requesting a customer-uploaded file is the customer who uploaded it, allowing unauthenticated attackers who know or guess a file's name to download other customers' uploaded files. | |
| Recibida | Media (5.9) | — | — | Wedevs File UploadsAI | 5/10/2026 | 5/10/2026 | The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded files in a publicly web-accessible uploads directory and the access restriction it generates is ineffective, so an unauthenticated attacker who knows or guesses a file's name can retrieve customer-uploaded files directly,… | |
| Recibida | Media (6.5) | — | — | KeycloakAI | 5/10/2026 | 5/10/2026 | A flaw was found in the Dynamic Client Registration flow of the Keycloak identity and access management server. The issue occurs because the registration process fails to filter security-sensitive client attributes when a new client is created. An attacker with a valid Initial Access Token can register a client that… | |
| Recibida | Media (5.7) | — | — | KeycloakAI | 5/10/2026 | 5/10/2026 | A flaw was found in the User Session Note mapper of the Keycloak identity and access management solution. The issue occurs because the mapper does not validate whether a requested session note contains sensitive internal credentials, such as federated access tokens from external identity providers. This allows a… | |
| Recibida | Media (4) | — | — | KeycloakAI | 5/10/2026 | 5/10/2026 | A flaw was found in the X.509 client-certificate authenticator of Keycloak, a solution for identity and access management. The issue occurs when the server is configured to check certificate revocation using CRL Distribution Points or OCSP. An attacker can provide a specially crafted certificate that points to a… | |
| Recibida | Baja (2.9) | — | — | Linlinjava LitemallAI | 5/10/2026 | 5/10/2026 | A vulnerability was detected in linlinjava litemall up to 1.8.0. This affects an unknown part of the file litemall-admin-api/src/main/java/org/linlinjava/litemall/admin/web/AdminAuthController.java of the component Login Endpoint. The manipulation results in improper restriction of excessive authentication attempts.… | |
| Recibida | Baja (2.1) | — | — | Kishor-23 Food Waste Management SystemAI | 5/10/2026 | 5/10/2026 | A vulnerability has been found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This affects an unknown function of the file login.php of the component Login Flow. Such manipulation of the argument PHPSESSID leads to session fixiation. The… |