Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

230 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.1%—Revenue Collection System Project Revenue Collection System26/1/202317/6/2026
An access control issue in Revenue Collection System v1.0 allows unauthenticated attackers to view the contents of /admin/DBbackup/ directory.
ModificadaCrítica (9.8)1.1%—Revenue Collection System Project Revenue Collection System26/1/202317/6/2026
Revenue Collection System v1.0 was discovered to contain a SQL injection vulnerability at step1.php.
ModificadaAlta (7.5)0.78%—Redhat AnsibleRedhat Ansible Collection28/10/202217/6/2026
A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take advantage of this issue as the module is handling the parameter insecurely, leading to the password leaking in the logs.
ModificadaCrítica (9.8)11%💥 PoCScala-lang ScalaScala-lang Scala-collection-compatFedoraproject Fedora23/9/202217/6/2026
Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction with Java object deserialization within an application. In such situations, it allows attackers to erase contents of arbitrary files, make network connections, or…
ModificadaAlta (7.5)7.2%—PythonRedhat QuayRedhat Software CollectionsFedoraproject Fedora+19/9/202217/6/2026
A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected).…
ModificadaMedia (5.3)3.2%—PythonDebian LinuxRedhat Software CollectionsRedhat Enterprise Linux+124/8/202217/6/2026
A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given…
ModificadaMedia (6.1)1.1%💥 PoCHome Owners Collection Management System Project Home Owners Collection Management System11/5/20229/7/2026
Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['page'] parameter.
ModificadaMedia (6.1)0.83%💥 PoCHome Owners Collection Management System Project Home Owners Collection Management System11/5/20229/7/2026
Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['s'] parameter.
ModificadaCrítica (9.8)1.3%—Home Owners Collection Management System Project Home Owners Collection Management System21/4/202217/6/2026
Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_phase.
ModificadaCrítica (9.8)1.3%—Home Owners Collection Management System Project Home Owners Collection Management System21/4/202217/6/2026
Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_phase.
ModificadaCrítica (9.8)1.3%—Home Owners Collection Management System Project Home Owners Collection Management System21/4/202217/6/2026
Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_collection.
ModificadaCrítica (9.8)1.2%—Home Owners Collection Management System Project Home Owners Collection Management System21/4/202217/6/2026
Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_member.
ModificadaAlta (8.8)0.66%💥 PoCLinux KernelFedoraproject FedoraRedhat Software CollectionsRedhat Openstack+224/3/202217/6/2026
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "virt_ext" field, this issue could allow a malicious L1 to disable…
ModificadaAlta (8.1)1.9%—PostgresqlFedoraproject FedoraRedhat Software CollectionsRedhat Enterprise Linux+24/3/202217/6/2026
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption.
ModificadaAlta (7.8)1.6%—Home Owners Collection Management System Project Home Owners Collection Management System2/3/202217/6/2026
A remote code execution (RCE) vulnerability in the Avatar parameter under /admin/?page=user/manage_user of Home Owners Collection Management System v1.0 allows attackers to execute arbitrary code via a crafted PNG file.
ModificadaMedia (6.5)1.4%—PostgresqlRedhat VirtualizationRedhat Enterprise LinuxRedhat Enterprise Linux FOR IBM Z Systems+32/3/202217/6/2026
A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not require the ability to create objects. If server settings include max_worker_processes=0, the known…
ModificadaAlta (7.5)17%—HaproxyRedhat Openshift Container PlatformRedhat Software CollectionsRedhat Enterprise Linux+12/3/202217/6/2026
A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability.
ModificadaCrítica (9.8)1.3%—Home Owners Collection Management System Project Home Owners Collection Management System2/3/202217/6/2026
Home Owners Collection Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel.
ModificadaCrítica (9.8)2.0%—Home Owners Collection Management System Project Home Owners Collection Management System2/3/202217/6/2026
Home Owners Collection Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /student_attendance/index.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaMedia (6.1)0.64%—Home Owners Collection Management System Project Home Owners Collection Management System28/2/202217/6/2026
Home Owners Collection Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the collected_by parameter under the List of Collections module.
ModificadaCrítica (9.8)2.1%—Home Owners Collection Management System Project Home Owners Collection Management System26/2/202217/6/2026
Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /members/view_member.php.
ModificadaCrítica (9.8)1.4%—Home Owners Collection Management System Project Home Owners Collection Management System26/2/202217/6/2026
Home Owners Collection Management System v1.0 allows unauthenticated attackers to compromise user accounts via a crafted POST request.
ModificadaAlta (8.8)23%—Home Owners Collection Management System Project Home Owners Collection Management System26/2/202217/6/2026
Home Owners Collection Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the parameter "cover" in SystemSettings.php.
ModificadaAlta (7.5)2.9%—Ruby-lang CGIRuby-lang RubyRedhat Software CollectionsRedhat Enterprise Linux+51/1/202217/6/2026
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
ModificadaAlta (7.5)3.2%—Ruby-lang DateRuby-lang RubyRedhat Software CollectionsRedhat Enterprise Linux+51/1/202217/6/2026
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.
Orbitaley — Vulnerabilidades