Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2535▼ 358 respecto a la semana anterior
Críticas / altas1338▲ 66 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

110 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.80%—Luatex Project LuatexMiktexTUG TEX Live20/5/202317/6/2026
LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because luatex-core.lua lets the original io.popen be accessed. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5.
ModificadaAlta (7.2)0.84%—Faculty Evaluation System Project Faculty Evaluation System15/5/202317/6/2026
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_class.php?id=.
ModificadaAlta (7.2)0.84%—Faculty Evaluation System Project Faculty Evaluation System15/5/202317/6/2026
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_subject.php?id=.
ModificadaAlta (7.2)0.76%—Faculty Evaluation System Project Faculty Evaluation System15/5/202317/6/2026
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/view_faculty.php?id=.
ModificadaAlta (7.2)0.76%—Faculty Evaluation System Project Faculty Evaluation System15/5/202317/6/2026
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/index.php?page=edit_faculty&id=.
ModificadaMedia (5.5)0.37%—Luatex Project LuatexMiktexTUG TEX Live11/5/202317/6/2026
LuaTeX before 1.17.0 allows a document (compiled with the default settings) to make arbitrary network requests. This occurs because full access to the socket library is permitted by default, as stated in the documentation. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5.
ModificadaCrítica (9.8)0.72%—Faculty Evaluation System Project Faculty Evaluation System28/4/202317/6/2026
A vulnerability was found in SourceCodester Faculty Evaluation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin/manage_restriction.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed…
ModificadaCrítica (9.8)0.72%—Faculty Evaluation System Project Faculty Evaluation System28/4/202317/6/2026
A vulnerability was found in SourceCodester Faculty Evaluation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file index.php?page=manage_questionnaire. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been…
ModificadaCrítica (9.8)0.72%—Faculty Evaluation System Project Faculty Evaluation System28/4/202317/6/2026
A vulnerability was found in SourceCodester Faculty Evaluation System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/manage_academic.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed…
ModificadaCrítica (9.8)0.79%—Faculty Evaluation System Project Faculty Evaluation System28/4/202317/6/2026
A vulnerability was found in SourceCodester Faculty Evaluation System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file ajax.php?action=delete_class. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been…
ModificadaCrítica (9.8)0.74%—Faculty Evaluation System Project Faculty Evaluation System28/4/202317/6/2026
A vulnerability has been found in SourceCodester Faculty Evaluation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file ajax.php?action=delete_subject. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit…
ModificadaAlta (8.8)0.95%—Employee Performance Evaluation System Project Employee Performance Evaluation System14/4/202317/6/2026
Employee Performance Evaluation System v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file uploaded to the server.
AnalizadaAlta (7.5)1.4%—LUA10/4/202317/6/2026
In Lua 5.4.3, an erroneous finalizer called during a tail call leads to a heap-based buffer over-read.
ModificadaMedia (4.8)0.45%—Employee Performance Evaluation System Project Employee Performance Evaluation System19/12/20229/7/2026
Employee Performance Evaluation System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via adding new entries under the Departments and Designations module.
ModificadaMedia (4.6)0.25%—Samsung T-oscpakuc FirmwareSamsung T-oscpdeuc FirmwareSamsung T-oscpuabc FirmwareSamsung T-nkm2akuc Firmware+1113/12/202217/6/2026
The Samsung TV (2021 and 2022 model) smart remote control allows attackers to enable microphone access via Bluetooth spoofing when a user is activating remote control by pressing a button. This is fixed in xxx72510, E9172511 for 2021 models, xxxA1000, 4x2A0200 for 2022 models.
ModificadaMedia (4.8)0.53%—Evaluate Project Evaluate21/11/202217/6/2026
The Evaluate WordPress plugin through 1.0 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).
ModificadaAlta (8.8)0.13%—Qualcomm Kailua FirmwareQualcomm Sg8275 FirmwareQualcomm Sg8275p FirmwareQualcomm Sm8550 Firmware+1119/10/202217/6/2026
Memory corruption in BTHOST due to double free while music playback and calls over bluetooth headset in Snapdragon Mobile
ModificadaAlta (7.8)0.33%—Luadec Project Luadec3/8/202217/6/2026
Luadec v0.9.9 was discovered to contain a heap-buffer overflow via the function UnsetPending.
ModificadaAlta (7.5)2.8%—LUAFedoraproject Fedora1/7/202217/6/2026
An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.
ModificadaCrítica (9.1)3.0%—LUAFedoraproject Fedora8/4/202217/6/2026
singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.
ModificadaCrítica (9.8)1.3%—Employee Performance Evaluation Project Employee Performance Evaluation5/4/202217/6/2026
Employee Performance Evaluation v1.0 was discovered to contain a SQL injection vulnerability via the email parameter.
ModificadaMedia (6.3)0.98%—LUA14/3/202217/6/2026
Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file.
ModificadaMedia (5.5)0.42%—LUAFedoraproject Fedora11/1/202217/6/2026
Lua v5.4.3 and above are affected by SEGV by type confusion in funcnamefromcode function in ldebug.c which can cause a local denial of service.
ModificadaMedia (5.5)1.2%—LUAFedoraproject Fedora9/11/202117/6/2026
Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.
ModificadaAlta (8.7)1.9%—Siemens DK Standard Ethernet Controller Evaluation KIT FirmwareSiemens Ek-ertec 200 Evaulation KIT FirmwareSiemens Ek-ertec 200p Evaluation KIT FirmwareSiemens Ruggedcom Rm1224 Firmware+7513/7/202117/6/2026
Affected devices contain a vulnerability that allows an unauthenticated attacker to trigger a denial of service condition. The vulnerability can be triggered if a large amount of DCP reset packets are sent to the device.