Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2759▼ 357 respecto a la semana anterior
Críticas / altas1278▼ 254 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
23.388 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Online FIR SystemAI | 6/4/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects Online FIR System 1.0. Affected by this vulnerability is an unknown functionality of the file /Login/checklogin.php of the component Login. The manipulation of the argument email/password leads to sql injection. The attack is possible to be carried out… | |
| Modificada | Alta (7.5) | 0.65% | — | Go-jose Project Go-jose | 6/4/2026 | 18/9/2026 | Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field… | |
| Analizada | Alta (7.5) | 0.39% | — | Distribution Project Distribution | 6/4/2026 | 17/6/2026 | Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, in pull-through cache mode, distribution discovers token auth endpoints by parsing WWW-Authenticate challenges returned by the configured upstream registry. The realm URL from a bearer challenge is used without validating… | |
| Analizada | Alta (8.8) | 0.45% | — | Glpi-project Glpi | 6/4/2026 | 17/6/2026 | GLPI is a free asset and IT management software package. From 10.0.0 to before 10.0.24 and 11.0.6, an authenticated user can perform a SQL injection via the logs export feature. This vulnerability is fixed in 10.0.24 and 11.0.6. | |
| Analizada | Crítica (9.8) | 0.40% | — | Glpi-project Glpi | 6/4/2026 | 17/6/2026 | GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GLPI's Search engine. This vulnerability is fixed in 11.0.6. | |
| Analizada | Media (6.1) | 0.28% | — | Glpi-project Glpi | 6/4/2026 | 17/6/2026 | GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated user can store an XSS payload through the inventory endpoint. This vulnerability is fixed in 11.0.6. | |
| Analizada | Alta (7.2) | 0.54% | 💥 PoC | Glpi-project Glpi | 6/4/2026 | 17/6/2026 | GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, template injection by an administrator lead to RCE. This vulnerability is fixed in 11.0.6. | |
| Analizada | Media (4.8) | 0.32% | — | Glpi-project Glpi | 6/4/2026 | 17/6/2026 | GLPI is a Free Asset and IT Management Software package. From 0.60 to before 10.0.24, an authenticated technician user can store an XSS payload in a supplier fields. This vulnerability is fixed in 10.0.24. | |
| Aplazada | Media (5.5) | 0.51% | — | Code-projects Online Application System FOR AdmissionAI | 6/4/2026 | 17/6/2026 | A vulnerability was found in code-projects Online Application System for Admission 1.0. Impacted is an unknown function of the file /enrollment/database/oas.sql. Performing a manipulation results in insecure storage of sensitive information. The attack is possible to be carried out remotely. The exploit has been made… | |
| Aplazada | Baja (2.1) | 0.32% | — | Code-projects Online Application System FOR AdmissionAI | 6/4/2026 | 17/6/2026 | A vulnerability has been found in code-projects Online Application System for Admission 1.0. This issue affects some unknown processing of the file /enrollment/admsnform.php of the component Endpoint. Such manipulation leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the… | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Simple Laundry SystemAI | 6/4/2026 | 17/6/2026 | A flaw has been found in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /userfinishregister.php of the component Parameter Handler. This manipulation of the argument firstName causes sql injection. Remote exploitation of the attack is possible. The exploit has been… | |
| Aplazada | Baja (1.9) | 0.35% | — | Code-projects Online Shoe StoreAI | 6/4/2026 | 17/6/2026 | A vulnerability was detected in code-projects Online Shoe Store 1.0. This affects an unknown part of the file /admin/admin_feature.php of the component Add Product Page. The manipulation of the argument product_name results in cross site scripting. The attack may be launched remotely. The exploit is now public and may… | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Easy Blog SiteAI | 6/4/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects Easy Blog Site 1.0. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be… | |
| Aplazada | Media (5.5) | 0.41% | — | Projectworlds CAR Rental SystemAI | 6/4/2026 | 17/6/2026 | A weakness has been identified in projectworlds Car Rental System 1.0. Affected by this vulnerability is an unknown functionality of the file /pay.php of the component Parameter Handler. Executing a manipulation of the argument mpesa can lead to sql injection. The attack can be launched remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.41% | — | Projectworlds CAR Rental SystemAI | 6/4/2026 | 17/6/2026 | A security vulnerability has been detected in projectworlds Car Rental System 1.0. This vulnerability affects unknown code of the file /message_admin.php of the component Parameter Handler. Such manipulation of the argument Message leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.41% | — | Projectworlds CAR Rental ProjectAI | 6/4/2026 | 24/7/2026 | Una vulnerabilidad fue identificada en projectworlds Car Rental Project 1.0. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /book_car.PHP del componente Gestor de Parámetros. La manipulación del argumento fname lleva a inyección SQL. El ataque puede ser iniciado remotamente. El exploit… | |
| Aplazada | Baja (2.1) | 0.23% | — | ProjectsendAI | 6/4/2026 | 24/7/2026 | Una falla de seguridad ha sido descubierta en ProjectSend r2002. Esta vulnerabilidad afecta código desconocido del archivo upload.php. Realizar una manipulación resulta en falsificación de petición en sitios cruzados. El ataque puede ser iniciado remotamente. El exploit ha sido liberado al público y puede ser usado… | |
| Analizada | Media (6.9) | 0.17% | — | Filezilla-project Filezilla Client | 5/4/2026 | 24/7/2026 | FileZilla 3.40.0 contiene una vulnerabilidad de denegación de servicio en la funcionalidad de búsqueda local que permite a atacantes locales colapsar la aplicación al proporcionar una cadena de ruta malformada. Los atacantes pueden desencadenar el colapso al introducir una ruta manipulada que contiene 384 caracteres… | |
| Analizada | Alta (8.6) | 0.20% | — | River Past Video Cleaner Project River Past Video Cleaner | 5/4/2026 | 24/7/2026 | River Past Video Cleaner 7.6.3 contiene una vulnerabilidad de desbordamiento de búfer en el gestor de excepciones estructuradas que permite a atacantes locales ejecutar código arbitrario al proporcionar una cadena maliciosa en el campo Lame_enc.dll. Los atacantes pueden crear una carga útil con 280 bytes de relleno,… | |
| Analizada | Media (6.9) | 0.19% | — | River Past Ringtone Converter Project River Past Ringtone Converter | 5/4/2026 | 24/7/2026 | River Past Ringtone Converter 2.7.6.1601 contiene una vulnerabilidad de desbordamiento de búfer local que permite a los atacantes bloquear la aplicación al proporcionar entrada sobredimensionada a los campos de activación. Los atacantes pueden pegar 300 bytes de datos en el cuadro de texto de correo electrónico y el… | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Simple Laundry SystemAI | 5/4/2026 | 24/7/2026 | Una vulnerabilidad de seguridad ha sido detectada en code-projects Simple Laundry System 1.0. Afectada por este problema es alguna funcionalidad desconocida del archivo /delmemberinfo.PHP del componente Gestor de Parámetros. Tal manipulación del argumento userid conduce a inyección SQL. El ataque puede ser lanzado… | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Simple Laundry SystemAI | 5/4/2026 | 24/7/2026 | Se ha identificado una vulnerabilidad en code-projects Simple Laundry System 1.0. Esta vulnerabilidad afecta a una funcionalidad desconocida del archivo /searchguest.php del componente Gestor de Parámetros. Esta manipulación del argumento searchServiceId provoca inyección SQL. El ataque puede iniciarse remotamente. El… | |
| Aplazada | Media (5.5) | 0.41% | 💥 PoC | Code-projects Concert Ticket Reservation SystemAI | 5/4/2026 | 24/7/2026 | Se ha identificado una debilidad en el sistema de reserva de entradas para conciertos 1.0 de code-projects. Esto afecta una parte desconocida del archivo /ConcertTicketReservationSystem-master/login.php del componente Gestor de Parámetros. La ejecución de una manipulación del argumento Email puede llevar a una… | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Concert Ticket Reservation SystemAI | 5/4/2026 | 24/7/2026 | Se ha descubierto un fallo de seguridad en el sistema de reserva de entradas para conciertos 1.0 de code-projects. Afectada por este problema es alguna funcionalidad desconocida del archivo /ConcertTicketReservationSystem-master/process_search.php del componente Gestor de Parámetros. Realizar una manipulación del… | |
| Aplazada | Baja (2.1) | 0.45% | — | Code-projects Simple Laundry SystemAI | 5/4/2026 | 24/7/2026 | Una vulnerabilidad fue determinada en code-projects Simple Laundry System 1.0. Afectada es una función desconocida del archivo /modstaffinfo.php del componente Gestor de Parámetros. Ejecutando una manipulación del argumento userid puede llevar a cross site scripting. El ataque puede ser lanzado remotamente. El exploit… |