Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

2298 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.1)0.47%—Sourcecodester Class AND Exam Timetabling SystemAI23/8/202626/8/2026
A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /BSIS1.php. Executing a manipulation of the argument course can lead to cross site scripting. The attack may be launched remotely. The exploit has been made available to the public and…
AplazadaAlta (8.8)0.51%—LeantimeAI19/8/20268/9/2026
Leantime JSON-RPC API through version 3.9.0 contains a missing authorization vulnerability in the JSON-RPC dispatcher in app/Domain/Api/Controllers/Jsonrpc.php. The dispatcher does not enforce authorization before invoking service-layer methods, allowing an authenticated user to call methods or act on resources…
Pendiente de análisisAlta (8.8)0.15%—Dell Watchdog Timer DriverAI18/8/202620/8/2026
Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.
AplazadaMedia (5.5)0.43%—Sourcecodester Class AND Exam Timetabling SystemAI18/8/202620/8/2026
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This issue affects some unknown processing of the file /edit_subject1.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed…
AplazadaMedia (5.5)0.43%—Sourcecodester Class AND Exam Timetabling SystemAI18/8/202620/8/2026
A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /edit_subject2.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public…
AplazadaBaja (2.1)0.47%—Sourcecodester Class AND Exam Timetabling SystemAI17/8/202620/8/2026
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSHRM1.php. Performing a manipulation of the argument course results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public…
AplazadaBaja (2.1)0.47%—Sourcecodester Class AND Exam Timetabling SystemAI17/8/202620/8/2026
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /BSCE2.php. Such manipulation of the argument course leads to cross site scripting. The attack may be launched remotely. The exploit is publicly available and might…
AplazadaCrítica (9.3)1.3%—Iptime A3004tAI17/8/202620/8/2026
A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component Session Validation. Performing a manipulation results in improper authentication. Remote exploitation of the attack is possible. The exploit is now public and may be used. The…
AplazadaBaja (2.1)0.40%—Codecanyon Timecamp Integration FOR CRMAI17/8/202620/8/2026
A vulnerability was identified in CodeCanyon TimeCamp Integration for CRM up to 2.8. This issue affects some unknown processing of the file /clients/save_contact of the component Contact Information Update. Such manipulation of the argument contact_id leads to authorization bypass. The attack can be launched remotely.…
AplazadaMedia (5.5)0.43%—Sourcecodester Class AND Exam Timetabling SystemAI15/8/202620/8/2026
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /edit_teacher.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and…
AplazadaAlta (8.5)0.36%—Visitor Traffic Real Time Statistics PROAI13/8/202614/8/2026
Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
AplazadaAlta (7.1)0.25%—Visitor Traffic Real Time Statistics PROAI13/8/202614/8/2026
Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
AplazadaAlta (7.1)0.25%—Visitors Traffic Real Time StatisticsAI13/8/202614/8/2026
Unauthenticated Cross Site Scripting (XSS) in Visitors Traffic Real Time Statistics <= 8.11 versions.
AnalizadaMedia (5.4)0.16%—Intel Gaudi Container Runtime11/8/20261/10/2026
Path traversal for some gaudi-container-runtime before version 1.24.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local…
AplazadaMedia (5.5)2.7%—EFM Iptime Ax8004mAI10/8/202612/8/2026
A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of the component CGI Endpoint. This manipulation of the argument fname causes os command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The…
AplazadaCrítica (9.6)0.61%—Katacontainers Kata RuntimeAI7/8/20269/9/2026
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, kata-runtime is vulnerable to host code execution via an unvalidated configuration path annotation. The runtime accepts an arbitrary…
AnalizadaAlta (7.1)0.44%—Timescaledb6/8/20261/9/2026
TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability that allows authenticated attackers to cause query-result integrity failures or backend crashes by supplying a crafted Simple8b selector-11 value, which is stored in the signed int16 Arrow dictionary-index type and…
AnalizadaAlta (7.2)0.53%—Timescaledb6/8/20261/9/2026
TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression reverse row iterator (tsl/src/compression/algorithms/dictionary.c). The forward path validates the decoded index; the reverse path uses an assertion compiled out of release builds, leaving the 64-bit…
AnalizadaAlta (7.1)0.51%—Timescaledb6/8/20261/9/2026
TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability in the Gorilla compression reverse row iterator that allows authenticated attackers to cause a denial of service by storing a crafted compressed datum with an internally inconsistent BitArray. Attackers with DML access to…
AplazadaAlta (8.1)0.38%—Uptimekuma Uptime KumaAIMatomoAI5/8/202626/8/2026
Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo value as a bare, unquoted JavaScript expression inside a <script> block rendered on every public status page. A siteId value such as , once saved by an editor/admin, executes arbitrary JavaScript for…
AplazadaAlta (7.1)0.32%—MagistralaAIPostgresqlAITimescaledbAI5/8/202626/8/2026
Magistrala (formerly Mainflux)'s message-readers API reads a value from the HTTP query string (readers/api/http/transport.go) with no validation and interpolates it directly into raw SQL queries via fmt.Sprintf in both the PostgreSQL reader (readers/postgres/messages.go: ) and the TimescaleDB reader…
AplazadaCrítica (9.9)0.58%—Openplc RuntimeAI5/8/202626/8/2026
OpenPLC Runtime v3's compile_program function (webserver/openplc.py) parses directives from uploaded Structured Text (.st) program files and writes the referenced content to with no validation that file_path stays within the ./core directory. A path-validation function, validate_file_path, exists elsewhere in the…
AplazadaAlta (8.1)0.35%—LeantimeAI5/8/202628/8/2026
Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable, and disable2FA, which act on a caller-supplied userId parameter with no ownership check, session pinning, or permission-attribute gate (unlike other RPC-exposed methods in the same dispatcher).
AplazadaAlta (8.6)0.26%—LeantimeAI30/7/202631/7/2026
Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perform state-changing actions on behalf of authenticated users by excluding the Laravel VerifyCsrfToken middleware from the global middleware stack in app/Http/Kernel.php. Attackers can craft malicious pages…
AplazadaAlta (8.4)0.35%—LeantimeAI30/7/202631/7/2026
Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attackers to read internal resources by passing unsanitized user-supplied filenames to file_get_contents() in the Blueprints::import() method without path validation. Attackers can submit crafted…