Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2827▼ 257 respecto a la semana anterior
Críticas / altas1324▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

23.388 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.9)0.40%—Libexpat Project Libexpat16/4/202614/7/2026
libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
AnalizadaAlta (8.2)0.52%—Maddy Project Maddy16/4/202617/6/2026
maddy is a composable, all-in-one mail server. Versions prior to 0.9.3 contain an LDAP injection vulnerability in the auth.ldap module where user-supplied usernames are interpolated into LDAP search filters and DN strings via strings.ReplaceAll() without any LDAP filter escaping, despite the go-ldap/ldap/v3 library's…
AnalizadaMedia (5.5)0.15%—Fedoraproject SssdRedhat Openshift Container PlatformRedhat Enterprise Linux15/4/20261/9/2026
A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PAM passkey responder fails to properly handle raw bytes received from a pipe. Because the data is treated as a NUL-terminated C string without explicit termination, it results in an out-of-bounds read…
AnalizadaAlta (7.4)0.40%—Openproject15/4/202617/6/2026
OpenProject is an open-source project management application. In versions prior to 17.3.0, 2FA OTP verification in the confirm_otp action of the two_factor_authentication module has no rate limiting, lockout mechanism, or failed-attempt tracking. The existing brute_force_block_after_failed_logins setting only counts…
AplazadaAlta (8.3)0.22%—Xquic Project XquicAI15/4/202617/6/2026
Improper input validation, Improper verification of cryptographic signature vulnerability in XQUIC Project XQUIC xquic on Linux (QUIC protocol implementation, packet processing module, STREAM frame handler modules) allows Protocol Manipulation.This issue affects XQUIC: through 1.8.3.
AnalizadaAlta (7.1)0.39%—Lfprojects Zarf15/4/202617/6/2026
Zarf is an Airgap Native Packager Manager for Kubernetes. Versions 0.23.0 through 0.74.1 contain an arbitrary file write vulnerability in the zarf package inspect sbom and zarf package inspect documentation subcommands. These subcommands output file paths are constructed by joining a user-controlled output directory…
AnalizadaCrítica (9.1)0.66%—Oauth2 Proxy Project Oauth2 Proxy14/4/202624/7/2026
OAuth2 Proxy es un proxy inverso que proporciona autenticación utilizando proveedores OAuth2. Las versiones anteriores a la 7.15.2 contienen una omisión de autenticación dependiente de la configuración en implementaciones donde OAuth2 Proxy se utiliza con una integración de estilo auth_request (como nginx…
AnalizadaBaja (3.5)0.22%—Oauth2 Proxy Project Oauth2 Proxy14/4/202624/7/2026
OAuth2 Proxy es un proxy inverso que proporciona autenticación utilizando proveedores OAuth2. Una regresión introducida en 7.11.0 impide que OAuth2 Proxy borre la cookie de sesión al renderizar la página de inicio de sesión. En implementaciones que dependen de la página de inicio de sesión como parte de su flujo de…
ModificadaMedia (4)0.68%—Podman Project Podman14/4/202624/7/2026
Podman es una herramienta para gestionar contenedores OCI y pods. Las versiones 4.8.0 a la 5.8.1 contienen una vulnerabilidad de inyección de comandos en el backend de máquina HyperV en pkg/machine/hyperv/stubber.go, donde la ruta de la imagen de la VM se inserta en una cadena de PowerShell entre comillas dobles sin…
AplazadaBaja (2.1)0.32%—Code-projects Easy Blog SiteAI13/4/202617/6/2026
A security flaw has been discovered in code-projects Easy Blog Site 1.0. This affects an unknown function of the file post.php. Performing a manipulation of the argument tags results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
ModificadaAlta (8.1)0.93%—Simple-git Project Simple-git13/4/202615/7/2026
simple-git enables running native Git commands from JavaScript. Versions up to and including 3.31.1 allow execution of arbitrary commands through Git option manipulation, bypassing safety checks meant to block dangerous options like -u and --upload-pack. The flaw stems from an incomplete fix for CVE-2022-25860, as…
AplazadaBaja (1.9)0.35%💥 PoCCode-projects Simple Content Management SystemAI13/4/202617/6/2026
A weakness has been identified in code-projects Simple Content Management System 1.0. This affects an unknown part of the file /web/admin/welcome.php. Executing a manipulation of the argument News Title can lead to cross site scripting. The attack can be executed remotely. The exploit has been made available to the…
AplazadaMedia (5.5)0.41%💥 PoCCode-projects Simple Content Management SystemAI13/4/202617/6/2026
A security flaw has been discovered in code-projects Simple Content Management System 1.0. Affected by this issue is some unknown functionality of the file /web/index.php. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been released…
AplazadaMedia (5.5)0.41%💥 PoCCode-projects Simple Content Management SystemAI13/4/202617/6/2026
A vulnerability was identified in code-projects Simple Content Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /web/admin/login.php. Such manipulation of the argument User leads to sql injection. The attack may be launched remotely. The exploit is publicly available and…
AplazadaMedia (5.5)0.41%—Code-projects Faculty Management SystemAI13/4/202617/6/2026
A vulnerability was detected in code-projects Faculty Management System 1.0. Impacted is an unknown function of the file /subject-print.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.
AplazadaMedia (5.5)0.41%—Code-projects Vehicle Showroom Management SystemAI13/4/202617/6/2026
A security vulnerability has been detected in code-projects Vehicle Showroom Management System 1.0. This issue affects some unknown processing of the file /util/UpdateVehicleFunction.php. The manipulation of the argument VEHICLE_ID leads to sql injection. The attack may be initiated remotely. The exploit has been…
AplazadaMedia (5.5)0.41%—Code-projects Vehicle Showroom Management SystemAI13/4/202617/6/2026
A weakness has been identified in code-projects Vehicle Showroom Management System 1.0. This vulnerability affects unknown code of the file /util/Login_check.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the…
AplazadaMedia (5.5)0.41%—Code-projects Lost AND Found Thing ManagementAI13/4/202617/6/2026
A security flaw has been discovered in code-projects Lost and Found Thing Management 1.0. This affects an unknown part of the file /addcat.php. Performing a manipulation of the argument cata results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for…
AplazadaMedia (5.5)0.41%—Code-projects Lost AND Found Thing ManagementAI13/4/202617/6/2026
A vulnerability was identified in code-projects Lost and Found Thing Management 1.0. Affected by this issue is some unknown functionality of the file /catageory.php. Such manipulation of the argument cat leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might…
AplazadaMedia (5.5)0.41%—Code-projects Simple ChatboxAI13/4/202617/6/2026
A vulnerability was determined in code-projects Simple ChatBox up to 1.0. This affects an unknown part of the file /chatbox/insert.php of the component Endpoint. Executing a manipulation of the argument msg can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed…
AplazadaMedia (5.5)0.51%—Code-projects Simple ChatboxAI13/4/202617/6/2026
A vulnerability was found in code-projects Simple ChatBox 1.0. Affected by this issue is the function SimpleChatbox_PHP of the file chatbox.sql of the component Endpoint. Performing a manipulation results in file and directory information exposure. It is possible to initiate the attack remotely. The exploit has been…
AplazadaBaja (2.1)0.45%—Code-projects Simple ChatboxAI13/4/202617/6/2026
A vulnerability has been found in code-projects Simple ChatBox up to 1.0. Affected by this vulnerability is an unknown functionality of the file /chatbox/insert.php of the component Endpoint. Such manipulation of the argument msg leads to cross site scripting. The attack may be performed from remote. The exploit has…
AplazadaMedia (5.5)0.41%—Code-projects Vehicle Showroom Management SystemAI13/4/202617/6/2026
A vulnerability was identified in code-projects Vehicle Showroom Management System 1.0. Impacted is an unknown function of the file /util/StaffDetailsFunction.php. Such manipulation of the argument STAFF_ID leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.
AplazadaMedia (5.5)0.41%—Code-projects Vehicle Showroom Management SystemAI13/4/202617/6/2026
A vulnerability was determined in code-projects Vehicle Showroom Management System 1.0. This issue affects some unknown processing of the file /util/StaffAddingFunction.php. This manipulation of the argument STAFF_ID causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed…
AplazadaMedia (5.5)0.41%—Code-projects Vehicle Showroom Management SystemAI13/4/202617/6/2026
A vulnerability was found in code-projects Vehicle Showroom Management System 1.0. This vulnerability affects unknown code of the file /util/PaymentStatusFunction.php. The manipulation of the argument CUSTOMER_ID results in sql injection. It is possible to launch the attack remotely. The exploit has been made public…