Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2851▼ 221 respecto a la semana anterior
Críticas / altas1331▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
9817 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.3) | 0.62% | — | Dulldusk Phpfilemanager | 16/12/2025 | 17/6/2026 | phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by exploiting loose type comparison in password hash validation. Attackers can craft specific password hashes beginning with 0e or 00e to bypass authentication and upload malicious PHP files to the server. | |
| Analizada | Alta (8.1) | 0.40% | — | HP Poly VideoosHP Poly Tcos | 16/12/2025 | 7/10/2026 | En escenarios limitados, los datos sensibles podrían escribirse en el archivo de registro si un administrador utiliza el Centro de administración de Microsoft Teams (TAC) para realizar cambios en la configuración del dispositivo. El archivo de registro afectado es visible solo para usuarios con credenciales de… | |
| Aplazada | Media (4.3) | 0.26% | — | Publishpress Schedule Post ChangesAI | 16/12/2025 | 17/6/2026 | The Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the getAuthors function in all versions up to, and including, 4.9.2. This makes it possible for… | |
| Aplazada | Media (5.3) | 0.38% | — | Stylishpricelist Stylish Price ListAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Design Stylish Price List stylish-price-list allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stylish Price List: from n/a through <= 7.2.2. | |
| Analizada | Crítica (9.3) | 0.45% | — | Phpjabbers BUS Reservation System | 15/12/2025 | 17/6/2026 | Bus Reservation System 1.1 contains a SQL injection vulnerability in the pickup_id parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, and time-based blind SQL injection techniques to steal information from the database. | |
| Analizada | Alta (8.1) | 0.34% | — | Filamentphp Filament | 10/12/2025 | 17/6/2026 | Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.3.0 contain a flaw in the handling of recovery codes for app-based multi-factor authentication, allowing the same recovery code to be reused indefinitely. This issue does not affect email-based MFA. It also… | |
| Analizada | Media (5.3) | 0.24% | — | Machphy Mad-proxy | 10/12/2025 | 17/6/2026 | mad-proxy is a Python-based HTTP/HTTPS proxy server for detection and blocking of malicious web activity using custom security policies. Versions 0.3 and below allow attackers to bypass HTTP/HTTPS traffic interception rules, potentially exposing sensitive traffic. This issue does not have a fix at the time of… | |
| Analizada | Media (4.8) | 0.40% | — | HP Omen Gaming HUBHP System Event Utility | 9/12/2025 | 17/6/2026 | HP System Event Utility and Omen Gaming Hub might allow execution of certain files outside of their restricted paths. This potential vulnerability was remediated with HP System Event Utility version 3.2.12 and Omen Gaming Hub version 1101.2511.101.0. | |
| Modificada | Media (6.1) | 0.27% | — | Phpipam | 9/12/2025 | 5/7/2026 | Cross-site scripting (XSS) vulnerability in Request IP form in phpIPAM v1.7.3 allows remote attackers to inject arbitrary web script or HTML via the instructions parameter for the /app/admin/instructions/edit-result.php endpoint. | |
| Aplazada | Alta (7.5) | 0.45% | — | Opal WP FashionAIPHPAI | 9/12/2025 | 7/10/2026 | Control inadecuado del nombre de fichero para la declaración Include/Require en un programa PHP, vulnerabilidad ('Inclusión remota de ficheros PHP') en Opal_WP Fashion fashion2, permite la Inclusión local de ficheros PHP. Este problema afecta a Fashion: desde n/a hasta < 5.3.0. | |
| Aplazada | Alta (7.5) | 0.46% | — | Dream-theme The7 ElementsAIPHPAI | 9/12/2025 | 7/10/2026 | La vulnerabilidad de control inadecuado del nombre de fichero para la declaración include/require en un programa PHP ('PHP inclusión remota de ficheros') en Dream-Theme The7 Elements dt-the7-core permite la inclusión local de ficheros de PHP. Este problema afecta a The7 Elements: desde n/a hasta menor o igual que… | |
| Analizada | Baja (3.3) | 0.20% | — | Phpipam | 8/12/2025 | 17/6/2026 | phpIPAM v1.7.3 contains a Cross-Site Request Forgery (CSRF) vulnerability in the database export functionality. The generate-mysql.php function, located in the /app/admin/import-export/ endpoint, allows remote attackers to trigger large database dump downloads via crafted HTTP GET requests if an administrator has an… | |
| Analizada | Baja (2.1) | 0.34% | — | Philipinho Simple-php-blog | 8/12/2025 | 7/10/2026 | Una vulnerabilidad de seguridad ha sido descubierta en Philipinho Simple-PHP-Blog hasta 94b5d3e57308bce5dfbc44c3edafa9811893d958. Este problema afecta a algún procesamiento desconocido del archivo /edit.php. La manipulación conduce a una inyección SQL. El ataque puede realizarse de forma remota. El exploit ha sido… | |
| Analizada | Baja (1.9) | 0.28% | — | Alokjaiswal Hotel-management-services-using-mysql-and-php | 7/12/2025 | 17/6/2026 | A vulnerability was found in alokjaiswal Hotel-Management-services-using-MYSQL-and-php up to 5f8b60a7aa6c06a5632de569d4e3f6a8cd82f76f. Affected by this vulnerability is an unknown functionality of the file /dishsub.php. The manipulation of the argument item.name results in cross site scripting. It is possible to… | |
| Analizada | Baja (2) | 0.23% | — | Alokjaiswal Hotel-management-services-using-mysql-and-php | 7/12/2025 | 17/6/2026 | A vulnerability has been found in alokjaiswal Hotel-Management-services-using-MYSQL-and-php up to 5f8b60a7aa6c06a5632de569d4e3f6a8cd82f76f. Affected is an unknown function of the file /usersub.php of the component Request Pending Page. The manipulation leads to cross site scripting. It is possible to initiate the… | |
| Aplazada | Media (5.5) | 0.30% | — | Trippwastaken PHP Guitar ShopAI | 5/12/2025 | 25/9/2026 | Se ha identificado una vulnerabilidad en TrippWasTaken PHP-Guitar-Shop hasta 6ce0868889617c1975982aae6df8e49555d0d555. Esta vulnerabilidad afecta código desconocido del archivo /product.php del componente Página de Detalles del Producto. La ejecución de la manipulación del argumento ID puede conducir a inyección SQL.… | |
| Analizada | Media (5.4) | 0.08% | — | HP Image Assistant | 3/12/2025 | 17/6/2026 | — | |
| Analizada | Media (6.5) | 0.20% | — | Phpgurukul Billing System | 2/12/2025 | 17/6/2026 | PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the admin/index.php endpoint. Specifically, the username parameter accepts unvalidated user input, which is then concatenated directly into a backend SQL query. | |
| Analizada | Media (6.5) | 0.20% | — | Phpgurukul Billing System | 2/12/2025 | 17/6/2026 | PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the /admin/password-recovery.php endpoint. Specifically, the username and mobileno parameters accepts unvalidated user input, which is then concatenated directly into a backend SQL query. | |
| Analizada | Media (4.3) | 0.24% | — | Phpgurukul Online Shopping Portal | 25/11/2025 | 17/6/2026 | Insecure Direct Object Reference (IDOR) in the Track order function in PHPGURUKUL Online Shopping Portal 2.1 allows information disclosure via the oid parameter. | |
| Modificada | Baja (2) | 0.22% | — | Phpgurukul Hostel Management System | 24/11/2025 | 8/10/2026 | Se ha encontrado una vulnerabilidad en PHPGurukul Hostel Management System 2.1. El elemento afectado es una función desconocida del archivo /register-complaint.PHP. La ejecución de una manipulación del argumento cdetails puede conducir a cross-site scripting. Es posible lanzar el ataque de forma remota. El exploit ha… | |
| Aplazada | Crítica (9.1) | 0.21% | — | Hpke-jsAI | 21/11/2025 | 17/6/2026 | hpke-js is a Hybrid Public Key Encryption (HPKE) module built on top of Web Cryptography API. Prior to version 1.7.5, the public SenderContext Seal() API has a race condition which allows for the same AEAD nonce to be re-used for multiple Seal() calls. This can lead to complete loss of Confidentiality and Integrity of… | |
| Aplazada | Media (6.6) | 0.41% | — | Matrixaddons Easy InvoiceAIPHPAI | 21/11/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in MatrixAddons Easy Invoice easy-invoice allows PHP Local File Inclusion.This issue affects Easy Invoice: from n/a through <= 2.1.4. | |
| Aplazada | Media (4.3) | 0.19% | — | Schedule Post Changes With Publishpress FutureAI | 21/11/2025 | 8/10/2026 | El plugin Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories para WordPress es vulnerable a la modificación no autorizada de datos debido a una falta de verificación de autorización en la función saveFutureActionData en todas las versiones hasta la 4.9.1,… | |
| Analizada | Alta (7.5) | 0.30% | — | Thinkphp | 20/11/2025 | 17/6/2026 | The fetch function in file thinkphp\library\think\Template.php in ThinkPHP 5.0.24 allows attackers to read arbitrary files via crafted file path in a template value. |