Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
808 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.30% | — | Live555 Streaming Media | 1/12/2025 | 17/6/2026 | A use-after-free in the ADTSAudioFileSource::samplingFrequency() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted ADTS/AAC file. | |
| Analizada | Media (6.5) | 0.33% | — | Live555 Streaming Media | 1/12/2025 | 17/6/2026 | A buffer overflow in the getSideInfo2() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via a crafted MP3 stream. | |
| Analizada | Crítica (9.2) | 0.41% | — | Hsiaoming Joserfc | 18/11/2025 | 17/6/2026 | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In versions from 1.3.3 to before 1.3.5 and from 1.4.0 to before 1.4.2, the ExceededSizeError exception messages are embedded with non-decoded JWT token parts and may cause Python logging to… | |
| Analizada | Media (6.5) | 0.15% | — | Mayurik PET Grooming Management Software | 7/11/2025 | 17/6/2026 | The change password functionality at /pet_grooming/admin/change_pass.php in SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks. The application does not implement adequate anti-CSRF tokens or same-site cookie restrictions, allowing attackers to trick… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Anheng Mingyu Operation AND Maintenance Audit AND Risk Control SystemAI | 30/10/2025 | 17/6/2026 | Anheng Mingyu Operation and Maintenance Audit and Risk Control System up to 2023-08-10 contains a server-side request forgery (SSRF) vulnerability in the xmlrpc.sock handler. The product accepts specially crafted XML-RPC requests that can be used to instruct the server to connect to internal unix socket RPC endpoints… | |
| Analizada | Alta (8.2) | 0.52% | 💥 PoC | Mayurik PET Grooming Management Software | 30/10/2025 | 17/6/2026 | A path traversal vulnerability was identified in SourceCodester Pet Grooming Management System 1.0, affecting the admin/manage_website.php component. An authenticated user with administrative privileges can leverage this flaw by submitting a specially crafted POST request, enabling the deletion of arbitrary files on… | |
| Modificada | Media (6.1) | 0.20% | — | Mingsoft Mcms | 23/10/2025 | 5/7/2026 | A reflected cross-site scripting (XSS) vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload. | |
| Analizada | Crítica (9.8) | 0.64% | — | Mingsoft Mcms | 17/10/2025 | 17/6/2026 | A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remote attackers to execute arbitrary SQL queries via unsanitized input in the FreeMarker template rendering. | |
| Analizada | Alta (7.8) | 0.39% | — | Microsoft Xbox Gaming Services | 14/10/2025 | 17/6/2026 | Improper link resolution before file access ('link following') in XBox Gaming Services allows an authorized attacker to elevate privileges locally. | |
| Modificada | Media (6.5) | 0.26% | — | Mingsoft Mcms | 10/10/2025 | 5/7/2026 | An arbitrary file upload vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary code via uploading a crafted file. | |
| Analizada | Crítica (9.4) | 0.38% | — | Mayurik PET Grooming Management Software | 9/10/2025 | 17/6/2026 | SourceCodester Pet Grooming Management Software 1.0 is vulnerable to SQL Injection in admin/view_customer.php via the ID parameter. | |
| Analizada | Media (6.1) | 0.24% | — | Mayurik PET Grooming Management Software | 8/10/2025 | 17/6/2026 | SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via the fname (First Name) and lname (Last Name) fields. | |
| Analizada | Media (6.1) | 0.24% | — | Mayurik PET Grooming Management Software | 2/10/2025 | 17/6/2026 | SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross Site Scripting (XSS) via the Customer Name field under Customer Management Section. | |
| Analizada | Media (5.5) | 0.48% | — | Mayurik PET Grooming Management Software | 27/9/2025 | 17/6/2026 | A vulnerability has been found in SourceCodester Pet Grooming Management Software 1.0. Affected by this issue is some unknown functionality of the file /admin/print_inv.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.3) | 0.25% | — | Mayurik PET Grooming Management Software | 27/9/2025 | 17/6/2026 | A vulnerability has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack is possible to be carried out remotely. | |
| Aplazada | Alta (8.2) | 0.35% | — | Click Plus C2-03cpu-2AIClick Programming SoftwareAI | 23/9/2025 | 17/6/2026 | An improper resource shutdown or release vulnerability has been identified in the Click Plus C2-03CPU-2 device running firmware version 3.60. The vulnerability allows an unauthenticated attacker to perform a denial-of-service attack by exhausting all available device sessions of the Click Programming Software. | |
| Aplazada | Media (4.1) | 0.10% | — | Click Programming SoftwareAI | 23/9/2025 | 17/6/2026 | Cleartext storage of sensitive information was discovered in Click Programming Software version v3.60. The vulnerability can be exploited by a local user with access to the file system, while an administrator session is active, to steal credentials stored in clear text. | |
| Analizada | Media (5.5) | 0.48% | — | Mayurik PET Grooming Management Software | 23/9/2025 | 17/6/2026 | A weakness has been identified in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknown function of the file /admin/print1.php. Executing manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be… | |
| Analizada | Baja (2.1) | 0.38% | — | Mayurik PET Grooming Management Software | 23/9/2025 | 17/6/2026 | A security flaw has been discovered in SourceCodester Pet Grooming Management Software 1.0. This impacts an unknown function of the file /admin/view_payorder.php. Performing manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and… | |
| Analizada | Baja (2.1) | 0.47% | — | Mayurik PET Grooming Management Software | 23/9/2025 | 30/9/2026 | A weakness has been identified in SourceCodester Pet Grooming Management Software 1.0. This affects an unknown function of the file /admin/print-payment.php. This manipulation of the argument sql111 causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could… | |
| Analizada | Baja (2.1) | 0.47% | — | Mayurik PET Grooming Management Software | 23/9/2025 | 30/9/2026 | A security flaw has been discovered in SourceCodester Pet Grooming Management Software 1.0. The impacted element is an unknown function of the file /admin/inv-print.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the… | |
| Analizada | Media (5.5) | 0.48% | — | Mayurik PET Grooming Management Software | 23/9/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Pet Grooming Management Software 1.0. The affected element is an unknown function of the file /admin/fetch_product_details.php. The manipulation of the argument barcode results in sql injection. The attack may be performed from remote. The exploit has been made public and… | |
| Analizada | Baja (2.1) | 0.38% | — | Mayurik PET Grooming Management Software | 23/9/2025 | 17/6/2026 | A security vulnerability has been detected in SourceCodester Pet Grooming Management Software 1.0. This affects an unknown part of the file /admin/edit.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. | |
| Aplazada | Media (5.4) | 0.30% | — | Sayful Islam Upcoming Events ListsAI | 22/9/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Sayful Islam Upcoming Events Lists upcoming-events-lists allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Upcoming Events Lists: from n/a through <= 1.4.0. | |
| Analizada | Media (5.5) | 0.60% | — | Mayurik PET Grooming Management Software | 22/9/2025 | 17/6/2026 | A security vulnerability has been detected in SourceCodester Pet Grooming Management Software 1.0. This affects an unknown function of the file /admin/edit_tax.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and… |