Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
272 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.63% | — | Scalar AstroAI | 19/5/2026 | 24/7/2026 | scalar/astro v0.1.13 was discovered to contain a Server-Side Request Forgery (SSRF) in the scalar_url query parameter of the Scalar Proxy endpoint. This vulnerability allows unauthenticated attackers to force the backend server to send HTTP requests to attacker-controlled URLs, leading to authentication cookies and… | |
| Aplazada | Crítica (9.8) | 0.69% | — | Scalar AstroAI | 19/5/2026 | 24/7/2026 | scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the scalar_url query parameter of the Scalar Proxy endpoint. This vulnerability allows attackers to execute arbitrary code via uploading a crafted SVG file. | |
| Analizada | Baja (2.9) | 0.20% | — | Astro | 13/5/2026 | 17/6/2026 | Astro is a web framework. Astro versions prior to 6.1.10 used AES-GCM encryption to protect the confidentiality and integrity of server island props and slots parameters, but did not bind the ciphertext to its intended component or parameter type. An attacker could replay one component's encrypted props (p) value as… | |
| Analizada | Alta (7.6) | 0.43% | — | Clerk/astroClerk/backendClerk/chrome-extensionClerk/clerk-expo+13 | 11/5/2026 | 17/6/2026 | Clerk JavaScript is the official JavaScript repository for Clerk authentication. has(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/nextjs, @clerk/backend, and other framework SDKs can return true for certain combined authorization checks when the result should be false, allowing a… | |
| Aplazada | Baja (2.1) | 0.32% | — | Codeastro Online Catering Ordering SystemAI | 10/5/2026 | 24/7/2026 | A vulnerability has been found in CodeAstro Online Catering Ordering System 1.0. This affects an unknown function of the file /deleteorder.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Media (5.5) | 0.41% | — | Codeastro Leave Management SystemAI | 8/5/2026 | 17/6/2026 | A weakness has been identified in CodeAstro Leave Management System 1.0. Affected is an unknown function of the file /login.php. This manipulation of the argument txt_username causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. | |
| Aplazada | Baja (2.1) | 0.32% | — | Codeastro Online ClassroomAI | 7/5/2026 | 17/6/2026 | A security flaw has been discovered in CodeAstro Online Classroom 1.0. This vulnerability affects unknown code of the file /askquery.php. The manipulation of the argument squeryx results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. | |
| Aplazada | Media (6.5) | 0.43% | — | Codeastro Membership Management SystemAI | 7/5/2026 | 5/7/2026 | A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This vulnerability affects the file upload functionality, where improper file sanitization allows attackers to inject malicious files which leads RCE. | |
| Aplazada | Baja (2.1) | 0.32% | — | Codeastro Online ClassroomAI | 4/5/2026 | 17/6/2026 | A vulnerability was determined in CodeAstro Online Classroom 1.0. This impacts an unknown function of the file /OnlineClassroom/facultydetails. This manipulation of the argument deleteid causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Baja (2.1) | 0.32% | — | Codeastro Online ClassroomAI | 4/5/2026 | 17/6/2026 | A vulnerability was found in CodeAstro Online Classroom 1.0. This affects an unknown function of the file /OnlineClassroom/addnewstudent. The manipulation of the argument fname results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. | |
| Aplazada | Baja (2.1) | 0.32% | — | Codeastro Online ClassroomAI | 4/5/2026 | 17/6/2026 | A vulnerability has been found in CodeAstro Online Classroom 1.0. The impacted element is an unknown function of the file /OnlineClassroom/studentdetails. The manipulation of the argument deleteid leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public… | |
| Aplazada | Baja (2.1) | 0.32% | — | Codeastro Online ClassroomAI | 4/5/2026 | 17/6/2026 | A flaw has been found in CodeAstro Online Classroom 1.0. The affected element is an unknown function of the file /OnlineClassroom/facultylogin. Executing a manipulation of the argument fid can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. | |
| Aplazada | Baja (2.1) | 0.32% | — | Codeastro Online ClassroomAI | 4/5/2026 | 17/6/2026 | A vulnerability was detected in CodeAstro Online Classroom 1.0. Impacted is an unknown function of the file /OnlineClassroom/studentlogin. Performing a manipulation of the argument sid results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. | |
| Aplazada | Baja (2.1) | 0.32% | — | Timbroddin Astro-mcp-serverAI | 1/5/2026 | 17/6/2026 | A security flaw has been discovered in TimBroddin astro-mcp-server up to 1.1.1. The impacted element is an unknown function of the file src/index.ts of the component MCP Tool Query Construction. Performing a manipulation of the argument request.params.arguments results in sql injection. The attack may be initiated… | |
| Aplazada | Baja (2.1) | 0.32% | — | Codeastro Online ClassroomAI | 28/4/2026 | 24/7/2026 | A security vulnerability has been detected in CodeAstro Online Classroom 1.0. Affected is an unknown function of the file /guestdetails. Such manipulation of the argument deleteid leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. | |
| Aplazada | Baja (2.1) | 0.32% | — | Codeastro Online ClassroomAI | 27/4/2026 | 17/6/2026 | A flaw has been found in CodeAstro Online Classroom 1.0. This affects an unknown part of the file /addnewfaculty. Executing a manipulation of the argument fname can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. | |
| Aplazada | Media (5.5) | 0.47% | — | Joecastrom Mcp-chat-studioAI | 27/4/2026 | 17/6/2026 | A vulnerability was detected in JoeCastrom mcp-chat-studio up to 1.5.0. Affected by this issue is some unknown functionality of the file server/routes/llm.js of the component LLM Models API. Performing a manipulation of the argument req.query.base_url results in server-side request forgery. Remote exploitation of the… | |
| Aplazada | Media (5.5) | 0.51% | 💥 PoC | Codeastro Online JOB PortalAI | 27/4/2026 | 17/6/2026 | A security vulnerability has been detected in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /users/user-cvs/. The manipulation leads to file and directory information exposure. Remote exploitation of the attack is possible. The exploit has been disclosed… | |
| Aplazada | Baja (2) | 0.33% | 💥 PoC | Codeastro Online JOB PortalAI | 26/4/2026 | 17/6/2026 | A security flaw has been discovered in CodeAstro Online Job Portal 1.0. The affected element is an unknown function of the file /admin/jobs-admins/delete-jobs.php of the component All Jobs Page. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely.… | |
| Aplazada | Crítica (9.1) | 0.53% | — | Clerk NextjsAIClerk NuxtAIClerk AstroAIClerk SharedAI | 24/4/2026 | 17/6/2026 | Clerk JavaScript is the official JavaScript repository for Clerk authentication. createRouteMatcher in @clerk/nextjs, @clerk/nuxt, and @clerk/astro can be bypassed by certain crafted requests, allowing them to skip middleware gating and reach downstream handlers. This vulnerability is fixed in @clerk/astro 1.5.7,… | |
| Analizada | Media (6.1) | 0.27% | — | Astro | 24/4/2026 | 17/6/2026 | Astro is a web framework. Prior to 6.1.6, the defineScriptVars function in Astro's server-side rendering pipeline uses a case-sensitive regex /<\/script>/g to sanitize values injected into inline <script> tags via the define:vars directive. HTML parsers close <script> elements case-insensitively and also accept… | |
| Aplazada | Crítica (9.8) | 0.80% | 💥 PoC | Codeastro Simple Attendance Management SystemAI | 17/4/2026 | 17/6/2026 | A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attackers to bypass authentication via the username parameter in index.php. | |
| Aplazada | Baja (2.1) | 0.38% | 💥 PoC | Codeastro Online JOB PortalAI | 13/4/2026 | 17/6/2026 | A vulnerability was identified in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the file /jobs/job-delete.php of the component Delete Job Posting Handler. Such manipulation of the argument ID leads to improper access controls. The attack can be launched remotely. The exploit is… | |
| Aplazada | Baja (2.1) | 0.32% | — | Codeastro Online ClassroomAI | 10/4/2026 | 17/6/2026 | A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected is an unknown function of the file /updatedetailsfromstudent.php?eno=146891650. Executing a manipulation of the argument fname can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may… | |
| Aplazada | Baja (2.1) | 0.32% | — | Codeastro Online ClassroomAI | 10/4/2026 | 17/6/2026 | A security flaw has been discovered in CodeAstro Online Classroom 1.0/2.php. Affected by this vulnerability is an unknown functionality of the file /OnlineClassroom/takeassessment2.php?exid=14. Performing a manipulation of the argument Q1 results in sql injection. Remote exploitation of the attack is possible. The… |