Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

822 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.9)0.38%—LitestarAI3/8/202610/9/2026
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypass the allowed hosts validation by omitting the Host header and supplying an X-Forwarded-Host header set to a whitelisted domain. The AllowedHostsMiddleware trusts the X-Forwarded-Host header as a…
AplazadaAlta (7.5)0.39%—Fivestarplugins Five Star Restaurant ReservationsAI2/8/202626/8/2026
The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users with the lowest booking-management role (which by default cannot access the Five Star Restaurant Reservations WordPress plugin before 2.7.23's settings) to reset the…
AplazadaAlta (8.1)0.40%💥 PoCLitestarAI28/7/202630/7/2026
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Litestar instances which use a template engine in conjunction with CSRF protection are vulnerable to HTML Injection which can be escalated to Cross Site Scripting due to the contents of the CSRF cookie being excluded from…
AplazadaCrítica (9.8)0.56%—Wgstart WgcloudAI21/7/202622/7/2026
SQL injection vulnerability in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the PortInfoMapper.xml file
AplazadaAlta (8.5)0.16%—Siemens ComosAISiemens Designcenter NXAISiemens Simcenter 3DAISiemens Simcenter FemapAI+614/7/20265/10/2026
A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1), Designcenter NX (All versions < V2512.7000), Simcenter 3D (All versions < V2512.7000), Simcenter Femap V2506 (All versions < V2506.0003), Simcenter Femap V2512 (All versions < V2512.0002), Simcenter…
AplazadaMedia (6.4)0.35%—Starboard Suite Reservation CalendarsAI11/7/202629/9/2026
The Starboard Suite Reservation Calendars plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in the [starboard-suite-lightbox] shortcode in all versions up to, and including, 3.1.4 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaCrítica (9.1)0.66%—Five Star Business ProfileAISchemaAI2/7/20262/7/2026
Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions.
AplazadaAlta (7.5)0.35%—Fivestarplugins Five Star Restaurant MenuAI26/6/202629/6/2026
Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2.5.2 versions.
AplazadaAlta (7.5)0.35%—Fivestarplugins Five Star Restaurant ReservationsAI25/6/202629/6/2026
Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions.
AnalizadaAlta (7.5)0.48%—Encode Starlette22/6/202626/6/2026
Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource consumption while parsing form data. These limits are enforced for multipart/form-data, but silently ignored for application/x-www-form-urlencoded. An unauthenticated…
AnalizadaMedia (5.3)0.27%—Encode Starlette22/6/202626/6/2026
Starlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being used to reconstruct request.url. Because request.url is rebuilt by concatenating {scheme}://{host}{path} and re-parsing the result, a path that does not begin with / (for example @google.com) moves…
AnalizadaMedia (5.3)0.35%—Encode Starlette17/6/202626/6/2026
Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing the HTTP method and looking it up as an attribute with getattr, without restricting the lookup to a known set of HTTP verbs. When an HTTPEndpoint subclass is…
ModificadaAlta (7.5)0.65%—Encode Starlette17/6/20264/8/2026
Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\attacker.com\share can cause os.path.realpath to initiate an outbound SMB connection before the path is rejected, exposing the service account’s NTLMv2 credentials for…
AplazadaMedia (4.3)0.15%—Jegstudio StartupzyAI17/6/20261/10/2026
Missing Authorization vulnerability in Jegstudio Startupzy startupzy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Startupzy: from n/a through 1.1.1.
AplazadaMedia (5.3)0.60%—Zauberzeug NiceguiAITiangolo FastapiAIEncode StarletteAIEncode UvicornAI2/6/202622/7/2026
NiceGUI is a Python-based UI framework. Prior to version 3.12.0, two FastAPI routes that serve per-component static assets in NiceGUI accept a sub-path parameter that may resolve to a directory rather than a file. Requests that resolve to a directory raise an unhandled RuntimeError inside Starlette's FileResponse,…
AplazadaAlta (7.5)0.43%—Fivestarplugins Five Star Restaurant ReservationsAI2/6/202622/7/2026
Missing Authorization vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Five Star Restaurant Reservations: from n/a through 2.7.14.
AplazadaBaja (2)0.20%—Sourcecodestar Pharmacy Sales AND Inventory SystemAI1/6/202622/7/2026
A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function create_medicine_name of the file /ShowForm/create_medicine_name/main. Performing a manipulation of the argument medicine_name results in cross site scripting. The attack can be…
AplazadaAlta (8.7)0.54%—Supremainc Biostar 2AI29/5/202621/7/2026
An unhandled exception in Suprema BioStar 2 (Server), versions 2.9.8, 2.9.10, and 2.9.11, that allows an unauthenticated remote attacker to cause a denial of service (DoS) by sending HTTP POST requests to the ‘/api/migration’ endpoint. This request triggers a failure that halts critical processes, leaving the system…
AplazadaCrítica (10)0.55%—Supremainc Biostar 2AI29/5/202621/7/2026
Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) that allow backup files to be publicly exposed when the administrator configures their path within the NGINX webroot. This vulnerability allows an attacker with network access to directly download backup ZIP files…
AnalizadaMedia (6.5)7.1%⚠ Explotación activa💥 ExploitEncode StarletteRedhat AI Inference ServerRedhat Ansible Automation PlatformRedhat Migration Toolkit FOR Applications+426/5/20261/10/2026
Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make…
AplazadaMedia (6.1)0.37%—CBX 5 Star Rating ReviewAI22/5/202623/7/2026
The CBX 5 Star Rating & Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
AplazadaMedia (4.3)0.36%—Rate Star Review VoteAI12/5/202617/6/2026
The Rate Star Review Vote - AJAX Reviews, Votes, Star Ratings plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.6.4. The vwrsr_review() AJAX handler lacks both capability checks and nonce verification. The only access control is an is_user_logged_in() check. When the…
AnalizadaCrítica (9.6)1.1%⚠ Explotación activa💥 PoCTanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+16712/5/202617/6/2026
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The…
AnalizadaAlta (7.6)0.43%—Clerk/astroClerk/backendClerk/chrome-extensionClerk/clerk-expo+1311/5/202617/6/2026
Clerk JavaScript is the official JavaScript repository for Clerk authentication. has(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/nextjs, @clerk/backend, and other framework SDKs can return true for certain combined authorization checks when the result should be false, allowing a…
ModificadaMedia (5.3)0.43%—Kazuho Starlet3/5/202617/6/2026
Starlet versions through 0.31 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starlet incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit…
Orbitaley — Vulnerabilidades