Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2851▼ 221 respecto a la semana anterior
Críticas / altas1331▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
–

9817 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.3)0.62%—Dulldusk Phpfilemanager16/12/202517/6/2026
phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by exploiting loose type comparison in password hash validation. Attackers can craft specific password hashes beginning with 0e or 00e to bypass authentication and upload malicious PHP files to the server.
AnalizadaAlta (8.1)0.40%—HP Poly VideoosHP Poly Tcos16/12/20257/10/2026
En escenarios limitados, los datos sensibles podrían escribirse en el archivo de registro si un administrador utiliza el Centro de administración de Microsoft Teams (TAC) para realizar cambios en la configuración del dispositivo. El archivo de registro afectado es visible solo para usuarios con credenciales de…
AplazadaMedia (4.3)0.26%—Publishpress Schedule Post ChangesAI16/12/202517/6/2026
The Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the getAuthors function in all versions up to, and including, 4.9.2. This makes it possible for…
AplazadaMedia (5.3)0.38%—Stylishpricelist Stylish Price ListAI16/12/202517/6/2026
Missing Authorization vulnerability in Design Stylish Price List stylish-price-list allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stylish Price List: from n/a through <= 7.2.2.
AnalizadaCrítica (9.3)0.45%—Phpjabbers BUS Reservation System15/12/202517/6/2026
Bus Reservation System 1.1 contains a SQL injection vulnerability in the pickup_id parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, and time-based blind SQL injection techniques to steal information from the database.
AnalizadaAlta (8.1)0.34%—Filamentphp Filament10/12/202517/6/2026
Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.3.0 contain a flaw in the handling of recovery codes for app-based multi-factor authentication, allowing the same recovery code to be reused indefinitely. This issue does not affect email-based MFA. It also…
AnalizadaMedia (5.3)0.24%—Machphy Mad-proxy10/12/202517/6/2026
mad-proxy is a Python-based HTTP/HTTPS proxy server for detection and blocking of malicious web activity using custom security policies. Versions 0.3 and below allow attackers to bypass HTTP/HTTPS traffic interception rules, potentially exposing sensitive traffic. This issue does not have a fix at the time of…
AnalizadaMedia (4.8)0.40%—HP Omen Gaming HUBHP System Event Utility9/12/202517/6/2026
HP System Event Utility and Omen Gaming Hub might allow execution of certain files outside of their restricted paths. This potential vulnerability was remediated with HP System Event Utility version 3.2.12 and Omen Gaming Hub version 1101.2511.101.0.
ModificadaMedia (6.1)0.27%—Phpipam9/12/20255/7/2026
Cross-site scripting (XSS) vulnerability in Request IP form in phpIPAM v1.7.3 allows remote attackers to inject arbitrary web script or HTML via the instructions parameter for the /app/admin/instructions/edit-result.php endpoint.
AplazadaAlta (7.5)0.45%—Opal WP FashionAIPHPAI9/12/20257/10/2026
Control inadecuado del nombre de fichero para la declaración Include/Require en un programa PHP, vulnerabilidad ('Inclusión remota de ficheros PHP') en Opal_WP Fashion fashion2, permite la Inclusión local de ficheros PHP. Este problema afecta a Fashion: desde n/a hasta < 5.3.0.
AplazadaAlta (7.5)0.46%—Dream-theme The7 ElementsAIPHPAI9/12/20257/10/2026
La vulnerabilidad de control inadecuado del nombre de fichero para la declaración include/require en un programa PHP ('PHP inclusión remota de ficheros') en Dream-Theme The7 Elements dt-the7-core permite la inclusión local de ficheros de PHP. Este problema afecta a The7 Elements: desde n/a hasta menor o igual que…
AnalizadaBaja (3.3)0.20%—Phpipam8/12/202517/6/2026
phpIPAM v1.7.3 contains a Cross-Site Request Forgery (CSRF) vulnerability in the database export functionality. The generate-mysql.php function, located in the /app/admin/import-export/ endpoint, allows remote attackers to trigger large database dump downloads via crafted HTTP GET requests if an administrator has an…
AnalizadaBaja (2.1)0.34%—Philipinho Simple-php-blog8/12/20257/10/2026
Una vulnerabilidad de seguridad ha sido descubierta en Philipinho Simple-PHP-Blog hasta 94b5d3e57308bce5dfbc44c3edafa9811893d958. Este problema afecta a algún procesamiento desconocido del archivo /edit.php. La manipulación conduce a una inyección SQL. El ataque puede realizarse de forma remota. El exploit ha sido…
AnalizadaBaja (1.9)0.28%—Alokjaiswal Hotel-management-services-using-mysql-and-php7/12/202517/6/2026
A vulnerability was found in alokjaiswal Hotel-Management-services-using-MYSQL-and-php up to 5f8b60a7aa6c06a5632de569d4e3f6a8cd82f76f. Affected by this vulnerability is an unknown functionality of the file /dishsub.php. The manipulation of the argument item.name results in cross site scripting. It is possible to…
AnalizadaBaja (2)0.23%—Alokjaiswal Hotel-management-services-using-mysql-and-php7/12/202517/6/2026
A vulnerability has been found in alokjaiswal Hotel-Management-services-using-MYSQL-and-php up to 5f8b60a7aa6c06a5632de569d4e3f6a8cd82f76f. Affected is an unknown function of the file /usersub.php of the component Request Pending Page. The manipulation leads to cross site scripting. It is possible to initiate the…
AplazadaMedia (5.5)0.30%—Trippwastaken PHP Guitar ShopAI5/12/202525/9/2026
Se ha identificado una vulnerabilidad en TrippWasTaken PHP-Guitar-Shop hasta 6ce0868889617c1975982aae6df8e49555d0d555. Esta vulnerabilidad afecta código desconocido del archivo /product.php del componente Página de Detalles del Producto. La ejecución de la manipulación del argumento ID puede conducir a inyección SQL.…
AnalizadaMedia (5.4)0.08%—HP Image Assistant3/12/202517/6/2026
—
AnalizadaMedia (6.5)0.20%—Phpgurukul Billing System2/12/202517/6/2026
PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the admin/index.php endpoint. Specifically, the username parameter accepts unvalidated user input, which is then concatenated directly into a backend SQL query.
AnalizadaMedia (6.5)0.20%—Phpgurukul Billing System2/12/202517/6/2026
PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the /admin/password-recovery.php endpoint. Specifically, the username and mobileno parameters accepts unvalidated user input, which is then concatenated directly into a backend SQL query.
AnalizadaMedia (4.3)0.24%—Phpgurukul Online Shopping Portal25/11/202517/6/2026
Insecure Direct Object Reference (IDOR) in the Track order function in PHPGURUKUL Online Shopping Portal 2.1 allows information disclosure via the oid parameter.
ModificadaBaja (2)0.22%—Phpgurukul Hostel Management System24/11/20258/10/2026
Se ha encontrado una vulnerabilidad en PHPGurukul Hostel Management System 2.1. El elemento afectado es una función desconocida del archivo /register-complaint.PHP. La ejecución de una manipulación del argumento cdetails puede conducir a cross-site scripting. Es posible lanzar el ataque de forma remota. El exploit ha…
AplazadaCrítica (9.1)0.21%—Hpke-jsAI21/11/202517/6/2026
hpke-js is a Hybrid Public Key Encryption (HPKE) module built on top of Web Cryptography API. Prior to version 1.7.5, the public SenderContext Seal() API has a race condition which allows for the same AEAD nonce to be re-used for multiple Seal() calls. This can lead to complete loss of Confidentiality and Integrity of…
AplazadaMedia (6.6)0.41%—Matrixaddons Easy InvoiceAIPHPAI21/11/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in MatrixAddons Easy Invoice easy-invoice allows PHP Local File Inclusion.This issue affects Easy Invoice: from n/a through <= 2.1.4.
AplazadaMedia (4.3)0.19%—Schedule Post Changes With Publishpress FutureAI21/11/20258/10/2026
El plugin Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories para WordPress es vulnerable a la modificación no autorizada de datos debido a una falta de verificación de autorización en la función saveFutureActionData en todas las versiones hasta la 4.9.1,…
AnalizadaAlta (7.5)0.30%—Thinkphp20/11/202517/6/2026
The fetch function in file thinkphp\library\think\Template.php in ThinkPHP 5.0.24 allows attackers to read arbitrary files via crafted file path in a template value.