Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
208 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.23% | — | Primakon Project Contract Management | 25/11/2025 | 17/6/2026 | Primakon Pi Portal 1.0.18 API endpoints responsible for retrieving object-specific or filtered data (e.g., user profiles, project records) fail to implement sufficient server-side validation to confirm that the requesting user is authorized to access the requested object or dataset. This vulnerability can be exploited… | |
| Analizada | Alta (8.8) | 0.29% | — | Primakon Project Contract Management | 25/11/2025 | 17/6/2026 | The Primakon Pi Portal 1.0.18 API /api/V2/pp_udfv_admin endpoint, fails to perform necessary server-side validation. The administrative LoginAs or user impersonation feature is vulnerable to a access control failure. This flaw allows any authenticated low-privileged user to execute a direct PATCH request, enabling… | |
| Analizada | Alta (8.8) | 0.29% | — | Primakon Project Contract Management | 25/11/2025 | 17/6/2026 | Primakon Pi Portal 1.0.18 /api/v2/pp_users endpoint fails to adequately check user permissions before processing a PATCH request to modify the PP_SECURITY_PROFILE_ID. Because of weak access controls any low level user can use this API and change their permission to Administrator by using PP_SECURITY_PROFILE_ID=2… | |
| Analizada | Crítica (9.8) | 0.38% | — | Primakon Project Contract Management | 25/11/2025 | 17/6/2026 | Primakon Pi Portal 1.0.18 API endpoints fail to enforce sufficient authorization checks when processing requests. Specifically, a standard user can exploit this flaw by sending direct HTTP requests to administrative endpoints, bypassing the UI restrictions. This allows the attacker to manipulate data outside their… | |
| Analizada | Alta (8.6) | 0.28% | — | Primakon Project Contract Management | 25/11/2025 | 17/6/2026 | Primakon Pi Portal 1.0.18 REST /api/v2/user/register endpoint suffers from a Broken Access Control vulnerability. The endpoint fails to implement any authorization checks, allowing unauthenticated attackers to perform POST requests to register new user accounts in the application's local database. This bypasses the… | |
| Analizada | Alta (8.8) | 0.29% | — | Primakon Project Contract Management | 25/11/2025 | 17/6/2026 | The Primakon Pi Portal 1.0.18 /api/V2/pp_users?email endpoint is used for user data filtering but lacks proper server-side validation against the authenticated session. By manipulating the email parameter to an arbitrary value (e.g., otheruser@user.com), an attacker can assume the session and gain full access to the… | |
| Analizada | Media (4.3) | 0.22% | — | Primakon Project Contract Management | 25/11/2025 | 17/6/2026 | Primakon Pi Portal 1.0.18 /api/v2/users endpoint is vulnerable to unauthorized data exposure due to deficient access control mechanisms. Any authenticated user, regardless of their privilege level (including standard or low-privileged users), can make a GET request to this endpoint and retrieve a complete, unfiltered… | |
| Aplazada | Crítica (9.4) | 0.28% | — | Beims Contractor WEBAI | 17/11/2025 | 17/6/2026 | A SQL Injection vulnerability on an endpoint in BEIMS Contractor Web, a legacy product that is no longer maintained or patched by the vendor, allows an unauthorised user to retrieve sensitive database contents via unsanitized parameter input. This vulnerability occurs due to improper input validation on… | |
| Aplazada | Alta (7.5) | 0.46% | — | Kevonadonis WP AbstractsAI | 22/10/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Kevon Adonis WP Abstracts wp-abstracts-manuscripts-manager allows PHP Local File Inclusion.This issue affects WP Abstracts: from n/a through <= 2.7.4. | |
| Aplazada | Media (5.4) | 0.35% | — | Cobblestonesoftware Enterprise Contract Management PortalAI | 17/10/2025 | 5/7/2026 | CobbleStone Enterprise Contract Management Portal v.22.4.0 is vulnerable to Stored Cross-Site Scripting (XSS) in its chat box component. This allows a remote attacker to execute arbitrary code. NOTE: the Supplier reports that this is "Present only in an obsolete, unsupported version no longer in circulation." | |
| Aplazada | Media (6.9) | 0.36% | — | Piextract Soop-clmAI | 13/10/2025 | 17/6/2026 | SOOP-CLM developed by PiExtract has a Server-Side Request Forgery vulnerability, allowing privileged remote attackers to read server files or probe internal network information. | |
| Aplazada | Alta (8.6) | 0.58% | — | Piextract Soop-clmAI | 13/10/2025 | 17/6/2026 | SOOP-CLM developed by PiExtract has a Hidden Functionality vulnerability, allowing privileged remote attackers to exploit a hidden functionality to execute arbitrary code on the server. | |
| Aplazada | Alta (7.1) | 0.13% | — | Loopus WP Attractive Donations SystemAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in loopus WP Attractive Donations System wp-attractive-donations-system-easy-stripe-paypal-donations allows Stored XSS.This issue affects WP Attractive Donations System: from n/a through < 1.29. | |
| Aplazada | Media (6.9) | 0.35% | — | Openzeppelin ContractsAI | 17/7/2025 | 17/6/2026 | OpenZeppelin Contracts is a library for secure smart contract development. Starting in version 5.2.0 and prior to version 5.4.0, the `lastIndexOf(bytes,byte,uint256)` function of the `Bytes.sol` library may access uninitialized memory when the following two conditions hold: 1) the provided buffer length is empty (i.e.… | |
| Aplazada | Crítica (9.8) | 0.51% | — | Coresmartcontracts UniswapAI | 29/4/2025 | 17/6/2026 | An issue in Coresmartcontracts Uniswap v.3.0 and fixed in v.4.0 allows a remote attacker to escalate privileges via the _modifyPosition function | |
| Aplazada | Crítica (9.3) | 0.65% | — | Lisandro Martinez Wp-smart-contractsAI | 11/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lisandro Martinez WPSmartContracts wp-smart-contracts allows Blind SQL Injection.This issue affects WPSmartContracts: from n/a through <= 2.0.12. | |
| Aplazada | Alta (7.1) | 0.19% | — | Kevonadonis WP AbstractsAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Kevon Adonis WP Abstracts wp-abstracts-manuscripts-manager allows Cross Site Request Forgery.This issue affects WP Abstracts: from n/a through <= 2.7.5. | |
| Aplazada | Media (4.7) | 0.10% | — | Microsoft Identity WEBAIMicrosoft Identity AbstractionsAIMicrosoft Asp.net CoreAI | 9/4/2025 | 17/6/2026 | Microsoft Identity Web is a library which contains a set of reusable classes used in conjunction with ASP.NET Core for integrating with the Microsoft identity platform (formerly Azure AD v2.0 endpoint) and AAD B2C. This vulnerability affects confidential client applications, including daemons, web apps, and web APIs.… | |
| Aplazada | Crítica (9.8) | 0.52% | — | Piextract Soop-clmAI | 31/3/2025 | 17/6/2026 | SOOP-CLM from PiExtract has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Aplazada | Media (6.5) | 0.26% | — | WP Online ContractAI | 5/3/2025 | 17/6/2026 | The WP Online Contract plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the json_import() and json_export() functions in all versions up to, and including, 5.1.4. This makes it possible for unauthenticated attackers to import and export the plugin's settings. | |
| Analizada | Media (5.4) | 0.22% | — | Kevonadonis WP Abstracts | 12/2/2025 | 17/6/2026 | The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.3. This is due to missing nonce validation on multiple functions. This makes it possible for unauthenticated attackers to delete arbitrary accounts via a forged request granted they can trick a… | |
| Aplazada | Media (5.5) | 0.56% | 💥 PoC | Rarlab RAR Extractor - UnarchiverAIRarlab RAR Extractor - Unarchiver PROAI | 21/1/2025 | 17/6/2026 | An issue in RAR Extractor - Unarchiver Free and Pro v.6.4.0 allows local attackers to inject arbitrary code potentially leading to remote control and unauthorized access to sensitive user data via the exploit_combined.dylib component on MacOS. | |
| Analizada | Media (6.1) | 0.20% | — | Kevonadonis WP Abstracts | 18/1/2025 | 17/6/2026 | The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.2. This is due to missing nonce validation on the wpabstracts_load_status() and wpabstracts_delete_abstracts() functions. This makes it possible for unauthenticated attackers to inject malicious… | |
| Aplazada | Crítica (9.8) | 0.65% | — | Pepegxng Smart ContractAI | 30/10/2024 | 17/6/2026 | An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the mint function. NOTE: this is disputed by third parties because the impact is limited to function calls. | |
| Aplazada | Alta (8.8) | 0.49% | — | Pepegxng Smart ContractAI | 30/10/2024 | 17/6/2026 | An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the _transfer function. NOTE: this is disputed by third parties because the impact is limited to function calls. |