Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2871▲ 247 respecto a la semana anterior
Críticas / altas1338▼ 91 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
21.649 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.22% | — | Hitesh Chandwani Recaptcha FOR Asgaros ForumAIGoogle RecaptchaAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hitesh Chandwani reCAPTCHA (v2 & v3) for Asgaros Forum recaptcha-for-asgaros-forum allows DOM-Based XSS.This issue affects reCAPTCHA (v2 & v3) for Asgaros Forum: from n/a through <= 1.1.0. | |
| Pendiente de análisis | Crítica (9.6) | 0.84% | — | Centreon-open-ticketsAICentreon Infra MonitoringAI | 13/7/2026 | 13/7/2026 | This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets module that leads to Remote Code Execution. The message_confirm field is stored without sanitization and rendered via Smarty with no security policy enabled, allowing any authenticated user, to inject and execute… | |
| Aplazada | Media (5.5) | 0.67% | — | Soniccloudorg Sonic-agentAI | 12/7/2026 | 14/7/2026 | A vulnerability was determined in SonicCloudOrg sonic-agent up to 2.7.2. This affects an unknown function of the file sonic-server-controller/src/main/java/org/cloud/sonic/controller/controller/ExchangeController.java of the component JWT Authentication Filter. This manipulation causes code injection. The attack may… | |
| Aplazada | Baja (2.1) | 2.0% | — | Soniccloudorg Sonic-agentAI | 12/7/2026 | 13/7/2026 | A vulnerability was found in SonicCloudOrg sonic-agent up to 2.7.2. The impacted element is the function evalIsFailed of the file sonic-agent/src/main/java/org/cloud/sonic/agent/tests/script/GroovyScriptImpl.java of the component Groovy Script Handler. The manipulation results in os command injection. The attack can… | |
| Aplazada | Baja (2.1) | 2.7% | — | Soniccloudorg Sonic-agentAI | 12/7/2026 | 15/7/2026 | A vulnerability has been found in SonicCloudOrg sonic-agent up to 2.7.2. The affected element is an unknown function of the file AndroidWSServer.java of the component Android WebSocket Server. The manipulation of the argument path leads to os command injection. The attack can be initiated remotely. The exploit has… | |
| Aplazada | Alta (8.7) | 0.36% | — | Luci-app-upnpAIMiniupnpdAI | 12/7/2026 | 30/9/2026 | luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject JavaScript via UPnP IGD AddPortMapping SOAP requests. Attackers can send malicious HTML in the NewPortMappingDescription field, which miniupnpd stores and luci-app-upnp renders without output encoding,… | |
| Aplazada | Baja (2.1) | 0.33% | — | BahmnicoreAI | 12/7/2026 | 13/7/2026 | A vulnerability was detected in Bahmni bahmnicore up to 0.93. This affects the function additionalParams of the file /openmrs/ws/rest/v1/bahmnicore/sql of the component Search Endpoint. Performing a manipulation of the argument test results in sql injection. The attack can be initiated remotely. The exploit is now… | |
| Aplazada | Baja (1.9) | 0.15% | — | Minitool Partition WizardAI | 12/7/2026 | 13/7/2026 | A weakness has been identified in MiniTool Partition Wizard up to 13.6. The affected element is an unknown function in the library pwdrvio.sys of the component Signed Kernel Driver. This manipulation causes improper access controls. The attack can only be executed locally. The exploit has been made available to the… | |
| Aplazada | Media (6.5) | 0.41% | — | Iqonic KivicareAI | 11/7/2026 | 15/7/2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 4.5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… | |
| Aplazada | Media (6.5) | 0.47% | — | Iqonic KivicareAI | 11/7/2026 | 13/7/2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 4.5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… | |
| Aplazada | Media (6.9) | 0.48% | — | Nezha MonitoringAI | 10/7/2026 | 13/7/2026 | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to 2.2.5, the GET /api/v1/ddns and GET /api/v1/notification endpoints return full resource objects including plaintext third-party API credentials, including Cloudflare API tokens, TencentCloud SecretKeys, Slack,… | |
| Aplazada | Crítica (9.8) | 0.73% | — | Miniorange Oauth Single Sign ON - SSOAI | 10/7/2026 | 21/7/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Client) allows Password Recovery Exploitation. This issue affects OAuth Single Sign On - SSO (OAuth Client): from n/a through 38.5.8. | |
| Aplazada | Crítica (9.8) | 0.89% | — | Miniorange Social Login AND RegisterAI | 10/7/2026 | 13/7/2026 | The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass leading to account takeover in versions up to and including 7.7.0. This is due to the Profile Completion flow accepting an arbitrary email address via the 'email_field' POST… | |
| Analizada | Media (5) | 0.34% | — | Snipeitapp Snipe-it | 10/7/2026 | 14/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report delete endpoint authorizes only reports.view and deletes CheckoutAcceptance::pending()->find($acceptanceId) by global ID without checking access to the related checkoutable asset, allowing a reports user in one company to… | |
| Analizada | Media (6.2) | 0.32% | — | Snipeitapp Snipe-it | 10/7/2026 | 14/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, default.blade.php renders header_color and related branding color settings inside a CSS style block with HTML escaping that is insufficient for the CSS context, allowing a superadmin to inject arbitrary CSS that affects authenticated users on… | |
| Analizada | Media (5.3) | 0.33% | — | Snipeitapp Snipe-it | 10/7/2026 | 14/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the legacy single-seat license checkin flow authorizes the action with the checkout permission instead of the checkin permission, allowing a user who can assign licenses but not unassign them to directly access the old checkin endpoint and reclaim a… | |
| Analizada | Media (5.7) | 0.34% | — | Snipeitapp Snipe-it | 10/7/2026 | 14/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV import capabilities and a valid API key to overwrite the created_by value of an import file, allowing unauthorized modification of import ownership metadata. This issue is fixed in version 8.6.1. | |
| Analizada | Media (6.5) | 0.59% | — | Snipeitapp Snipe-it | 10/7/2026 | 14/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated user with import and assets.update permissions can place a path traversal string in an asset image field through CSV import and then trigger image deletion, allowing deletion of arbitrary files accessible to the server process. This… | |
| Analizada | Media (6.2) | 0.44% | — | Snipeitapp Snipe-it | 10/7/2026 | 14/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UploadFileRequest sanitizes SVG content only when PHP finfo reports image/svg+xml and UploadedFilesController serves attachments inline without using StorageHelper::allowSafeInline(), allowing a low-privilege user to upload active XHTML or XML content… | |
| Analizada | Media (4.3) | 0.34% | — | Snipeitapp Snipe-it | 10/7/2026 | 14/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UsersController::show() and printInventory() authorize only user viewing before loading and rendering assigned license, accessory, and consumable relationships, allowing an authenticated user with only users.view to see inventory and cost/order… | |
| Analizada | Media (6.1) | 0.31% | — | Snipeitapp Snipe-it | 10/7/2026 | 14/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the user edit flow stores url()->previous() from the attacker-controlled Referer header into Laravel’s intended URL session value and later uses redirect()->intended(...) when redirect_option=back is submitted, allowing Snipe-IT to be used as a trusted… | |
| Analizada | Media (4.8) | 0.43% | — | Snipeitapp Snipe-it | 10/7/2026 | 14/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Actionlog::logaction() stores the request User-Agent header and ReportsController::postActivityReport() writes that value to the Activity Report CSV without formula escaping, allowing a low-privileged authenticated user to store a formula-like… | |
| Aplazada | Media (4.4) | 0.24% | — | WP Ultimate CSV Importer Infinite Scroll Ajax Load MoreAI | 10/7/2026 | 14/7/2026 | The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Analizada | Alta (7) | 0.54% | — | Snipeitapp Snipe-it | 10/7/2026 | 13/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.0, UsersController::update() passes a missing permission request field through NormalizePermissionsPayloadAction and PreserveUnauthorizedPrivilegedPermissionsAction in a way that can overwrite a target user’s permissions with a sparse result, allowing an… | |
| Analizada | Alta (7.7) | 0.38% | — | Snipeitapp Snipe-it | 10/7/2026 | 14/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, PATCH or PUT /api/v1/maintenances/{maintenance_id} checks access to the current maintenance record and asset but then fills attacker-controlled fields including asset_id without re-authorizing the newly supplied asset, allowing an authorized user to… |