Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2847▼ 151 respecto a la semana anterior
Críticas / altas1373▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 257 respecto a la semana anterior
–

1742 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.47%—Continew AdminAI16/9/202624/9/2026
ContiNew Admin through 4.1.0 contains an authorization bypass vulnerability in the personal message delete endpoint that allows authenticated users to delete other users' messages and announcements. Attackers can supply arbitrary message identifiers in the IdsReq parameter to remove any message row and purge all…
AplazadaMedia (4.3)0.28%—Smartadmin APIAIOracle JavaAIVmware Spring BootAI15/9/202622/9/2026
SmartAdmin API Java17 SpringBoot3 version 3.30.0 contains an improper authorization vulnerability in the /employee/queryAll endpoint. The endpoint does not enforce the required function-level permission or data-scope authorization, allowing an authenticated low-privileged employee to retrieve employee records…
AplazadaAlta (8.1)0.36%—Lab1024 SmartadminAI15/9/202622/9/2026
1024-lab SmartAdmin v3.30.0 contains a missing authorization vulnerability in the scheduled-job management module. The AdminSmartJobController exposes scheduled-job management endpoints without method-level permission checks, allowing a low-privileged authenticated user to access functionality intended for authorized…
AplazadaMedia (6.5)0.34%—Lab1024 SmartadminAI15/9/202622/9/2026
1024-lab SmartAdmin v3.30.0 contains a stored cross-site scripting vulnerability in its file upload functionality. This allows a remote attacker to execute arbitrary code.
AplazadaCrítica (9.8)0.61%—Lab1024 SmartadminAI15/9/202622/9/2026
SmartAdmin v3.30.0 contains an authorization flaw in the configuration query endpoint. This allows a remote attacker to escalate privileges.
AplazadaAlta (7.6)0.40%—EasyadminAISymfonyAI14/9/202630/9/2026
EasyAdmin is a fast and modern admin generator for Symfony applications. From 5.0.0 until 5.0.13, FileField and ImageField can accept browser-executable uploads while templates/crud/field/file.html.twig links to stored files for inline same-origin rendering without a download attribute or Content-Disposition…
Pendiente de análisisMedia (5.3)0.38%—SqladminAI14/9/202630/9/2026
SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to 0.27.1, ModelView.sort_query in sqladmin/models.py accepts the attacker-controlled sortBy list-view query parameter without enforcing the configured column_sortable_list server-side allow-list in self._sort_fields. The value is resolved with…
AplazadaMedia (5.3)0.33%—Starlette-adminAI12/9/202623/9/2026
starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attackers can submit structured filter queries via the list API's where parameter to perform equality and comparison…
AplazadaBaja (2.1)0.47%—FastadminAI7/9/202628/9/2026
A security vulnerability has been detected in FastAdmin up to 1.2.0.20210401_beta. Affected is the function register/login of the file application/index/controller/User.php of the component User Controller. Such manipulation of the argument url leads to cross site scripting. The attack may be performed from remote.…
AplazadaCrítica (9.8)0.91%—Dynamiapps Frontend AdminAI6/9/20268/9/2026
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value function lacking any capability or ownership check, and ActionPost::conditions_logic() short-circuiting its…
AplazadaCrítica (9.8)0.86%—EasyadminAI4/9/20269/9/2026
easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted file upload.
AplazadaAlta (7.4)0.45%—Zhao-github ApiadminAI4/9/20269/9/2026
SQL injection vulnerability in Zhao-github APiAdmin v.5.0.1 allows a remote attacker to obtain sensitive information via the User.php component
AplazadaAlta (8.1)0.61%—Zhao-github ApiadminAI4/9/202614/9/2026
File Upload vulnerability in Zhao-github ApiAdmin v.5.0.1 allows a remote attacker to execute arbitrary code via a crafted .php file
AplazadaMedia (5.1)0.24%—Getgrav Grav-plugin-admin2AI4/9/20268/9/2026
Grav Admin (getgrav/grav-plugin-admin2) versions <= 2.0.19 contain a stored cross-site scripting vulnerability in the tHtml() function (src/lib/stores/i18n.svelte.ts), which substitutes untrusted parameters such as usernames into translation templates before parsing the result as markdown. Grav's server-side username…
AplazadaMedia (5.9)0.38%—Dynamiapps Frontend AdminAI4/9/20268/9/2026
The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllable directory path before deleting files within it, allowing unauthenticated attackers to delete index.php and .htaccess files outside the intended directory, including the WordPress root, which can render the…
AplazadaAlta (7.5)0.96%—Dynamiapps Frontend AdminAI1/9/20261/9/2026
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the move_folders function in all versions up to, and including, 3.29.12. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can…
AplazadaMedia (6.4)0.20%—Dynamiapps Frontend AdminAI1/9/20261/9/2026
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tag' Shortcode Attribute in all versions up to, and including, 3.29.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
AplazadaAlta (8.1)0.45%—EasyadminAISymfonyAI31/8/20269/9/2026
EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single dashboard route and, for custom actions (Action::linkToRoute() and MenuItem::linkToRoute()), swaps the executed controller based on the routeName query…
AplazadaBaja (2.1)0.38%—Caoqianming Django-vue-adminAI31/8/20261/9/2026
A weakness has been identified in caoqianming django-vue-admin 1.0. This vulnerability affects unknown code of the file /api/file/. Executing a manipulation of the argument file_id can lead to improper access controls. The attack can be executed remotely. The exploit has been made available to the public and could be…
AplazadaAlta (8.3)0.47%—Ash-project ASH AdminAI31/8/20261/9/2026
Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_admin lets any client that can reach the admin LiveView exhaust the BEAM atom table and crash the entire node. Two LiveView event handlers interned atoms from unvalidated client input: AshAdmin.PageLive's set_actor built modules from…
AplazadaBaja (2)0.47%—Ash-project ASH AdminAI31/8/20261/9/2026
Improper Encoding or Escaping of Output vulnerability in ash-project ash_admin lets an attacker who controls a record's string primary key rewrite the target of AshAdmin's row-action links. The Table, DataTable, and Show components built row-action URLs by raw string interpolation, splicing the primary key (and table,…
AplazadaAlta (8.3)0.79%—Ash-project ASH AdminAI31/8/20261/9/2026
Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in ash-project ash_admin allows writing attacker-controlled bytes to arbitrary paths on the server. AshAdmin.Components.Resource.Form.consume_file_uploads/1 builds the destination as Path.join([tmp_dir, entry.client_name]) and…
AplazadaBaja (2.3)0.45%—Ash-project ASH AdminAI31/8/20261/9/2026
Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_admin turns a record-lookup URL into an equality oracle over sensitive attributes. AshAdmin.Helpers.decode_primary_key/2 decodes the composite-primary-key form (Base64 plus ETF) and returns the decoded map verbatim as the lookup filter,…
AplazadaBaja (2.1)0.53%—Ash-project ASH AdminAI31/8/20261/9/2026
Use of Insufficiently Random Values vulnerability in ash-project ash_admin ships a hardcoded, publicly known CSP nonce, defeating nonce-based Content-Security-Policy protection. When mounted without :csp_nonce_assign_key, AshAdmin.Router.ash_admin/2 defaulted the img, style, and script nonces to the literal constant…
AplazadaAlta (8.4)0.48%—Ash-project ASH AdminAI31/8/20261/9/2026
Stored Cross-site Scripting vulnerability in ash-project ash_admin executes attacker-supplied record content as script in an administrator's browser. The relationship typeahead components AshAdmin.Components.Resource.RelationshipField and AshAdmin.Components.Resource.ManagedRelationshipSelectField highlight the…