Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
23.369 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.5) | 0.17% | — | Projectdiscovery NucleiAI | 22/9/2026 | 28/9/2026 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the workflow template loading path does not enforce the -file capability gate when resolving file: protocol templates referenced by a workflow. An untrusted unsigned workflow can therefore load a file-protocol template and… | |
| Pendiente de análisis | Media (5.3) | 0.40% | — | Projectdiscovery NucleiAI | 22/9/2026 | 25/9/2026 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the nuclei/mysql JavaScript library does not enforce the local-file sandbox when a JavaScript template supplies the allowAllFiles MySQL DSN option. An untrusted javascript: template scanning an attacker-controlled… | |
| Pendiente de análisis | Media (4.7) | 0.18% | — | Projectdiscovery NucleiAI | 22/9/2026 | 24/9/2026 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST template loading branch does not apply the unsigned code-template signature check before accepting a template that contains both a fuzzing: block and an unsigned code: block. When an operator enables -dast, an… | |
| Aplazada | Media (6.9) | 0.54% | — | Misp-project MispAI | 22/9/2026 | 22/9/2026 | In MISP's UsersController login() method, the pre-authentication database query used for the TOTP (two-factor authentication) verification branch did not include the User.disabled column in its SELECT fields list. The query selected only User.password, User.totp, and User.hotp_counter. When the TOTP branch… | |
| Aplazada | Media (5.1) | 0.44% | — | Misp-project MispAI | 22/9/2026 | 22/9/2026 | MISP contains a reflected cross-site scripting (XSS) vulnerability in the attribute histogram view. The $selectedTypes variable, which is derived from the URL path segment , was interpolated directly into a JavaScript array literal inside an onClick HTML attribute without any encoding or escaping. An attacker who can… | |
| Aplazada | Media (5.5) | 0.11% | — | Matter Project ChipAIMatter Standard SpecificationAI | 21/9/2026 | 24/9/2026 | An issue in Matter Standard Specification-Implementation gap v1.5.1 Matter Project Chip V1.5.1 allows a local attacker to obtain sensitive information via the PerformCommissioningStep function in the ChipDeviceController.cpp component | |
| Pendiente de análisis | Media (5.3) | 0.06% | — | Zephyrproject ZephyrAI | 21/9/2026 | 22/9/2026 | The default AEAD nonce provider for the PSA Internal Trusted Storage transform module, secure_storage_its_transform_aead_get_nonce() in subsys/secure_storage/src/its/transform/aead_get.c, stores its nonce counter in unsynchronized function-local static variables (s_nonce and s_nonce_initialized). Every ITS write… | |
| Aplazada | Media (5.3) | 0.37% | — | Jsherpproject JsherpAI | 21/9/2026 | 22/9/2026 | jshERP through 3.6 contains a tenant isolation bypass vulnerability that allows authenticated users to read other tenants' records via the GET /tenant/info endpoint. Attackers can iterate the primary key to enumerate and access sensitive tenant data including login names, validity dates, user quotas, and enabled state… | |
| Pendiente de análisis | Alta (7.8) | 0.12% | — | Zephyrproject ZephyrAI | 21/9/2026 | 22/9/2026 | The Time-aware GPIO syscall verification handler z_vrfy_tgpio_pin_read_ts_ec() in drivers/timeaware_gpio/timeaware_gpio_handlers.c validated only the port device object and passed the caller-supplied timestamp and event_count output pointers to the driver without a K_SYSCALL_MEMORY_WRITE() check. The other handlers in… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Internship Management SystemAI | 20/9/2026 | 21/9/2026 | A weakness has been identified in code-projects Internship Management System 1.0. This vulnerability affects unknown code of the file /admin/login.php of the component Admin Login Form. Executing a manipulation of the argument Password can lead to sql injection. The attack may be performed from remote. The exploit has… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Internship Management SystemAI | 20/9/2026 | 22/9/2026 | A security flaw has been discovered in code-projects Internship Management System 1.0. This affects an unknown part of the file /employer/login.php. Performing a manipulation of the argument Password results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Internship Management SystemAI | 20/9/2026 | 21/9/2026 | A vulnerability was identified in code-projects Internship Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Such manipulation of the argument Password leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. | |
| Aplazada | Baja (2) | 0.35% | — | Code-projects Assessment ManagementAI | 20/9/2026 | 24/9/2026 | A vulnerability was determined in code-projects Assessment Management 1.0. Affected by this vulnerability is an unknown functionality of the file lecturer/add-single-mark.php. This manipulation of the argument mark causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been… | |
| Aplazada | Baja (1.9) | 0.37% | — | Code-projects Assessment ManagementAI | 20/9/2026 | 21/9/2026 | A vulnerability was found in code-projects Assessment Management 1.0. Affected is an unknown function of the file admin/add-user.php. The manipulation of the argument level results in cross site scripting. The attack may be launched remotely. The exploit has been made public and could be used. | |
| Aplazada | Baja (1.9) | 0.37% | — | Code-projects Assessment ManagementAI | 20/9/2026 | 21/9/2026 | A vulnerability has been found in code-projects Assessment Management 1.0. This impacts an unknown function of the file admin/edit-user.php of the component User Editing. The manipulation of the argument name/sname/email/username/password/id leads to cross site scripting. The attack may be initiated remotely. The… | |
| Pendiente de análisis | Media (5) | 0.10% | — | Cockpit-project Cockpit MachinesAI | 18/9/2026 | 22/9/2026 | A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process metadata to disclose a sensitive Red Hat Subscription Management (RHSM) offline token. The token is exposed when it is passed as a command-line argument to a helper script during the token validation… | |
| Pendiente de análisis | Media (4.7) | 0.20% | — | Zephyrproject ZephyrAI | 18/9/2026 | 18/9/2026 | net_icmpv6_send_error() in subsys/net/ip/icmpv6.c implemented only one of the three RFC 4443 section 2.4 suppression rules (do not answer an ICMPv6 error with an ICMPv6 error). It did not check whether the triggering packet's source address identifies a single node (rule e.6) or whether the packet was sent to a… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Matrimonial SystemAI | 17/9/2026 | 17/9/2026 | A vulnerability has been found in code-projects Matrimonial System 1.0. This vulnerability affects the function writepartnerprefs of the file /partner_preference.php. Such manipulation of the argument education leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public… | |
| Aplazada | Alta (8.7) | 0.65% | — | Pelican Project Pelican PanelAI | 16/9/2026 | 24/9/2026 | Pelican Panel versions before 1.0.0-beta35 enforce startup write permissions only through disabled form controls rather than server-side authorization checks. Attackers with startup.read permission can craft Livewire state updates to invoke afterStateUpdated callbacks and modify startup commands, docker images, and… | |
| Pendiente de análisis | Alta (7) | 0.12% | — | Projectdiscovery NucleiAI | 16/9/2026 | 24/9/2026 | Nuclei versions before 3.11.1 cache template signature verification based only on file modification time without content checksums. Attackers can replace verified templates with unsigned malicious content and restore the original modification time to bypass signature checks and execute arbitrary operating system… | |
| Aplazada | Media (5.5) | 0.56% | — | Code-projects Matrimonial SystemAI | 16/9/2026 | 16/9/2026 | A vulnerability was determined in code-projects Matrimonial System 1.0. This affects an unknown part of the file /search.php of the component Regular Search. This manipulation of the argument sex/mothertongue/maritialstatus/country/state/religion/agemin/agemax causes sql injection. The attack can be initiated… | |
| Aplazada | Media (5.3) | 0.52% | — | Vllm-project VllmAI | 16/9/2026 | 22/9/2026 | A vulnerability was found in vllm-project vllm up to 0.29.0. Affected by this issue is some unknown functionality of the file vllm/v1/sample/thinking_budget_state.py. The manipulation results in inefficient algorithmic complexity. It is possible to launch the attack remotely. The pull request to fix this issue awaits… | |
| Aplazada | Media (5.3) | 0.39% | — | A2ui-project A2uiAI | 16/9/2026 | 28/9/2026 | A vulnerability was identified in a2ui-project a2ui 0.8/0.9/1.0. Impacted is an unknown function of the file model-processor.ts of the component Model Processor. The manipulation of the argument current[segment] leads to information disclosure. The attack may be initiated remotely. The identifier of the patch is… | |
| Aplazada | Media (5.3) | 0.52% | — | A2ui-project A2uiAI | 16/9/2026 | 28/9/2026 | A vulnerability was determined in a2ui-project a2ui 0.9/0.9.1. This issue affects the function updateComponents of the file basic_functions.ts of the component Update Components. Executing a manipulation can lead to resource consumption. The attack can be launched remotely. The project was informed of the problem… | |
| Aplazada | Media (6.9) | 0.70% | — | Vllm-project VllmAI | 16/9/2026 | 16/9/2026 | A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0. Affected is the function MoRIIOConnectorScheduler.request_finished/MoRIIOConnectorWorker.get_finished/MoRIIOWrapper._handle_release_message of the file vllm/distributed/kv_transfer/kv_connector/v1/moriio/moriio_connector.py of the component MoRIIO… |