Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2751▼ 38 respecto a la semana anterior
Críticas / altas1262▼ 270 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 209 respecto a la semana anterior
–

23.906 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.1)0.66%—Oauth2 Proxy Project Oauth2 Proxy14/4/202624/7/2026
OAuth2 Proxy es un proxy inverso que proporciona autenticación utilizando proveedores OAuth2. Las versiones anteriores a la 7.15.2 contienen una omisión de autenticación dependiente de la configuración en implementaciones donde OAuth2 Proxy se utiliza con una integración de estilo auth_request (como nginx…
AnalizadaBaja (3.5)0.22%—Oauth2 Proxy Project Oauth2 Proxy14/4/202624/7/2026
OAuth2 Proxy es un proxy inverso que proporciona autenticación utilizando proveedores OAuth2. Una regresión introducida en 7.11.0 impide que OAuth2 Proxy borre la cookie de sesión al renderizar la página de inicio de sesión. En implementaciones que dependen de la página de inicio de sesión como parte de su flujo de…
ModificadaMedia (4)0.68%—Podman Project Podman14/4/202624/7/2026
Podman es una herramienta para gestionar contenedores OCI y pods. Las versiones 4.8.0 a la 5.8.1 contienen una vulnerabilidad de inyección de comandos en el backend de máquina HyperV en pkg/machine/hyperv/stubber.go, donde la ruta de la imagen de la VM se inserta en una cadena de PowerShell entre comillas dobles sin…
AplazadaBaja (2.1)0.32%—Code-projects Easy Blog SiteAI13/4/202617/6/2026
A security flaw has been discovered in code-projects Easy Blog Site 1.0. This affects an unknown function of the file post.php. Performing a manipulation of the argument tags results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
ModificadaAlta (8.1)0.93%—Simple-git Project Simple-git13/4/202615/7/2026
simple-git enables running native Git commands from JavaScript. Versions up to and including 3.31.1 allow execution of arbitrary commands through Git option manipulation, bypassing safety checks meant to block dangerous options like -u and --upload-pack. The flaw stems from an incomplete fix for CVE-2022-25860, as…
AplazadaBaja (1.9)0.35%💥 PoCCode-projects Simple Content Management SystemAI13/4/202617/6/2026
A weakness has been identified in code-projects Simple Content Management System 1.0. This affects an unknown part of the file /web/admin/welcome.php. Executing a manipulation of the argument News Title can lead to cross site scripting. The attack can be executed remotely. The exploit has been made available to the…
AplazadaMedia (5.5)0.41%💥 PoCCode-projects Simple Content Management SystemAI13/4/202617/6/2026
A security flaw has been discovered in code-projects Simple Content Management System 1.0. Affected by this issue is some unknown functionality of the file /web/index.php. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been released…
AplazadaMedia (5.5)0.41%💥 PoCCode-projects Simple Content Management SystemAI13/4/202617/6/2026
A vulnerability was identified in code-projects Simple Content Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /web/admin/login.php. Such manipulation of the argument User leads to sql injection. The attack may be launched remotely. The exploit is publicly available and…
AplazadaMedia (5.5)0.41%—Code-projects Faculty Management SystemAI13/4/202617/6/2026
A vulnerability was detected in code-projects Faculty Management System 1.0. Impacted is an unknown function of the file /subject-print.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.
AplazadaMedia (5.5)0.41%—Code-projects Vehicle Showroom Management SystemAI13/4/202617/6/2026
A security vulnerability has been detected in code-projects Vehicle Showroom Management System 1.0. This issue affects some unknown processing of the file /util/UpdateVehicleFunction.php. The manipulation of the argument VEHICLE_ID leads to sql injection. The attack may be initiated remotely. The exploit has been…
AplazadaMedia (5.5)0.41%—Code-projects Vehicle Showroom Management SystemAI13/4/202617/6/2026
A weakness has been identified in code-projects Vehicle Showroom Management System 1.0. This vulnerability affects unknown code of the file /util/Login_check.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the…
AplazadaMedia (5.5)0.41%—Code-projects Lost AND Found Thing ManagementAI13/4/202617/6/2026
A security flaw has been discovered in code-projects Lost and Found Thing Management 1.0. This affects an unknown part of the file /addcat.php. Performing a manipulation of the argument cata results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for…
AplazadaMedia (5.5)0.41%—Code-projects Lost AND Found Thing ManagementAI13/4/202617/6/2026
A vulnerability was identified in code-projects Lost and Found Thing Management 1.0. Affected by this issue is some unknown functionality of the file /catageory.php. Such manipulation of the argument cat leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might…
AplazadaMedia (5.5)0.41%—Code-projects Simple ChatboxAI13/4/202617/6/2026
A vulnerability was determined in code-projects Simple ChatBox up to 1.0. This affects an unknown part of the file /chatbox/insert.php of the component Endpoint. Executing a manipulation of the argument msg can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed…
AplazadaMedia (5.5)0.51%—Code-projects Simple ChatboxAI13/4/202617/6/2026
A vulnerability was found in code-projects Simple ChatBox 1.0. Affected by this issue is the function SimpleChatbox_PHP of the file chatbox.sql of the component Endpoint. Performing a manipulation results in file and directory information exposure. It is possible to initiate the attack remotely. The exploit has been…
AplazadaBaja (2.1)0.45%—Code-projects Simple ChatboxAI13/4/202617/6/2026
A vulnerability has been found in code-projects Simple ChatBox up to 1.0. Affected by this vulnerability is an unknown functionality of the file /chatbox/insert.php of the component Endpoint. Such manipulation of the argument msg leads to cross site scripting. The attack may be performed from remote. The exploit has…
AplazadaMedia (5.5)0.41%—Code-projects Vehicle Showroom Management SystemAI13/4/202617/6/2026
A vulnerability was identified in code-projects Vehicle Showroom Management System 1.0. Impacted is an unknown function of the file /util/StaffDetailsFunction.php. Such manipulation of the argument STAFF_ID leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.
AplazadaMedia (5.5)0.41%—Code-projects Vehicle Showroom Management SystemAI13/4/202617/6/2026
A vulnerability was determined in code-projects Vehicle Showroom Management System 1.0. This issue affects some unknown processing of the file /util/StaffAddingFunction.php. This manipulation of the argument STAFF_ID causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed…
AplazadaMedia (5.5)0.41%—Code-projects Vehicle Showroom Management SystemAI13/4/202617/6/2026
A vulnerability was found in code-projects Vehicle Showroom Management System 1.0. This vulnerability affects unknown code of the file /util/PaymentStatusFunction.php. The manipulation of the argument CUSTOMER_ID results in sql injection. It is possible to launch the attack remotely. The exploit has been made public…
AplazadaBaja (2.1)0.45%—Code-projects Simple Laundry SystemAI13/4/202617/6/2026
A vulnerability has been found in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /checkupdatestatus.php. The manipulation of the argument serviceId leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be…
AplazadaMedia (5.5)0.41%—Code-projects Vehicle Showroom Management SystemAI13/4/202617/6/2026
A flaw has been found in code-projects Vehicle Showroom Management System 1.0. Affected by this issue is some unknown functionality of the file /util/BookVehicleFunction.php. Executing a manipulation of the argument BRANCH_ID can lead to sql injection. The attack may be performed from remote. The exploit has been…
AplazadaMedia (5.5)0.41%—Code-projects Vehicle Showroom Management SystemAI13/4/202617/6/2026
A vulnerability was detected in code-projects Vehicle Showroom Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /util/MonthTotalReportUpdateFunction.php. Performing a manipulation of the argument BRANCH_ID results in sql injection. The attack is possible to be carried out…
AnalizadaAlta (7.1)0.13%—Libexif Project Libexif12/4/202617/6/2026
In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.
AnalizadaAlta (7.1)0.13%—Libexif Project Libexif12/4/202617/6/2026
In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.
AnalizadaAlta (7.1)0.28%—MYT Project MYT12/4/202617/6/2026
MyT-PM 1.5.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the Charge[group_total] parameter. Attackers can submit crafted POST requests to the /charge/admin endpoint with error-based, time-based blind, or stacked query…