Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
–

1742 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.3)0.52%—Ash-project ASH AdminAI31/8/20261/9/2026
Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin's client JavaScript read its state cookies (tenant, actor_resource,…
AplazadaAlta (7.9)1.9%—Qubes Core-admin-linuxAI30/8/20268/9/2026
Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom0 to an attacker-controlled qube, because the "system" library function is used to process an error message that may have shell metacharacters. This occurs in core-admin-linux/file-copy-vm/qfile-dom0-agent.c.
AplazadaMedia (4.3)0.25%—Dynamiapps Frontend AdminAI29/8/202631/8/2026
The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to delete arbitrary membership plans.
Pendiente de análisisCrítica (9.9)0.29%—IBM Administration Runtime Expert FOR IAIIBM Application Runtime Expert FOR IAI28/8/202631/8/2026
IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability to execute actions under another user's authenticated profile gaining…
Pendiente de análisisAlta (7.5)0.43%—IBM Administration Runtime Expert FOR IAI28/8/20261/9/2026
IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.
AplazadaAlta (8.8)0.56%—Piccolo AdminAIPiccolo APIAI28/8/20269/9/2026
Piccolo Admin is an admin interface and content management system for Python, built on top of Piccolo. Prior to 1.14.0, piccolo_admin/endpoints.py uses superuser_validators to block PUT, PATCH, DELETE, and POST requests by non-superusers but permits GET requests to configured user and session tables, while…
AplazadaAlta (8.8)0.42%—Cjbi Admin3AI28/8/20269/9/2026
The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are missing permission checks. /Any logged-in user can upload arbitrary files, and any anonymous attacker can download them.
AplazadaMedia (5.4)0.45%—Starlette AdminAITiangolo FastapiAIEncode StarletteAI26/8/20269/9/2026
Starlette-Admin is a fast, beautiful and extensible administrative interface framework for FastAPI and Starlette applications. Prior to 0.16.1, the list API does not validate user-supplied order_by and structured where field names against the configured sortable_fields and searchable_fields allowlists. An…
AplazadaAlta (7.1)0.30%—Continew AdminAI25/8/202624/9/2026
ContiNew Admin fails to apply file-upload permission checks or file-type allowlist validation to multipart upload endpoints, allowing authenticated users to store files with arbitrary extensions. Attackers can initialize chunked uploads, send file parts, and complete uploads to leave arbitrary files in the storage…
AplazadaMedia (6.1)0.41%—AdminerAI25/8/20268/9/2026
Adminer before 5.4.3 uses a CSRF token scheme that transmits both the XOR mask and the masked value in every token (format (rand XOR secret):rand), allowing anyone who observes a single CSRF token (e.g., via network sniffing, log files, Referrer header, or XSS) to recover the session secret with a single XOR operation…
AplazadaCrítica (9.3)0.90%—AdminerAI25/8/20268/9/2026
Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP code to the web root, achieving remote code execution when the trace file is…
AplazadaMedia (5.3)0.34%—AdminerAIMysqlAI25/8/20268/9/2026
Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid CSP nonces without proper validation. Attackers controlling a rogue MySQL server can return crafted version strings that break out of the JavaScript context and execute arbitrary code, bypassing Content Security Policy…
AplazadaAlta (8.6)1.2%—AdminerAI25/8/20268/9/2026
Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is not blocked despite ATTACH restrictions. Authenticated attackers can execute VACUUM INTO to write PHP code to arbitrary file paths and execute commands on the server.
AplazadaAlta (7.1)0.62%—AdminerAI25/8/20268/9/2026
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that allows authenticated users to upload PHP files by exploiting a permissive default extension allowlist. Attackers can upload PHP webshells to columns ending in _path and execute arbitrary code as the…
AplazadaAlta (7.2)0.53%—AdminerAI25/8/20268/9/2026
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the database-list drop action fails to validate file extensions before deletion. An authenticated attacker can submit arbitrary relative file paths in the db[] parameter to delete any files writable by the PHP process.
AplazadaMedia (6.9)0.43%—AdminerAI25/8/20268/9/2026
Adminer before 5.5.0 contains a server-side request forgery vulnerability in the login form's server field validator, which only inspects leading integers for privileged ports and fails to reject non-numeric port values. Attackers can inject PDO DSN keys like host= and port= into the server parameter to bypass the…
AplazadaMedia (5.3)0.29%—AdminerAI25/8/20268/9/2026
Adminer 4.6.0 before 5.5.0 prepends the client-supplied X-Forwarded-Prefix header to $_SERVER["REQUEST_URI"] with no trusted-proxy check and no validation of the prefix value. An attacker can supply an absolute URL (e.g. X-Forwarded-Prefix: https://evil.example) that flows into Location redirect headers, the…
AplazadaBaja (2.3)0.39%—AdminerAI25/8/20268/9/2026
Adminer 4.6.0 through 5.5.0 (fixed in 5.5.1) contains an incomplete fix for a prior X-Forwarded-Prefix vulnerability (GHSA-8478-xrj3-h9c2). The validation guard (bootstrap.inc.php) only rejects prefixes matching ^/[^/], blocking //evil.com but allowing values such as /\evil.com whose second character is a backslash.…
AplazadaMedia (5.3)0.33%—AdminerAI25/8/202630/9/2026
Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled contain an arbitrary file write vulnerability in the ns parameter of plugins/sql-log.php. An authenticated user can supply path traversal sequences in the ns parameter to write arbitrary .sql files with attacker-controlled content to any writable…
Pendiente de análisisMedia (6.9)0.08%—Johnsoncontrols Simplex Incident ManagerAIJohnsoncontrols Autocall Fire AdministratorAI21/8/20263/9/2026
Cleartext Storage of Sensitive Information in Memory vulnerability in Johnson Controls Simplex Incident Manager / Autocall Fire Administrator may allow an attcker to Retrieve Embedded Sensitive Data. This issue affects Simplex Incident Manager / Autocall Fire Administrator: before 2.01.05.
Pendiente de análisisAlta (8.5)0.42%—JET AdminAI21/8/202626/8/2026
Jet Admin allows an authenticated attacker to inject JavaScript via the sign-in page's scripts and styles option. Injected script is executed in the context of any visiting user's domain.
Pendiente de análisisCrítica (9.2)0.57%—JET AdminAI21/8/202626/8/2026
Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute traffic to the attacker-controlled app. Once connected to the target domain, the attacker's workspace is populated with the victim's OAuth Client ID and Client…
AplazadaAlta (7.5)0.63%—Fuyaweb Internet AND Informatics Services Architectpanel WEB Admin PanelAI21/8/202626/8/2026
Execution after redirect (EAR) vulnerability in FuyaWeb Internet and Informatics Services ArchitectPanel Web Admin Panel allows Authentication Bypass. This issue affects ArchitectPanel Web Admin Panel: through 28072026.
AplazadaAlta (7.5)0.35%—THE Library Corporation LS2 AdminAI20/8/202629/9/2026
The Library Corporation LS2 Admin v5.7 to v5.8.0 was discovered to contain an information disclosure vulnerability.
AplazadaBaja (2.1)0.37%—EladminAI20/8/202625/8/2026
A vulnerability was found in elunez eladmin up to 2.7. The impacted element is the function EmailController/AliPayController/GeneratorController/GenConfigController. The manipulation results in improper authorization. The attack can be launched remotely. The exploit has been made public and could be used. The project…