Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2713▼ 170 respecto a la semana anterior
Críticas / altas1244▼ 301 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 186 respecto a la semana anterior
–

2110 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)1.1%—Cdwanjiang Flash Flood Disaster Monitoring AND Warning System5/8/202317/6/2026
Se ha encontrado una vulnerabilidad clasificada como problemática en Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. Esta vulnerabilidad afecta a código desconocido del archivo "\Service\FileDownload.ashx". La manipulación del argumento "Files" conduce a un path traversal: "../filedir". El ataque puede…
ModificadaCrítica (9.8)1.4%—Phpgurukul Online Security Guards Hiring System4/8/202317/6/2026
Online Security Guards Hiring System v.1.0 de PHPGurukul es vulnerable a SQL Injection a través de osghs/admin/search.php.
ModificadaMedia (6.1)0.36%—Phpjabbers Catering System1/8/202317/6/2026
Se ha descubierto que Catering System v1.0 de PHPJabbers contiene una vulnerabilidad Cross-Site Scripting (XSS) a través del componente /index.php?controller=pjAdmin&action=pjActionForgot.
ModificadaMedia (4.3)0.61%—Backupbliss Backup MigrationBackupbliss CloneCopy-delete-posts Duplicate PostInisev Enhanced Text Widget+628/7/202317/6/2026
Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers…
ModificadaMedia (6.5)0.69%—Backupbliss Backup MigrationBackupbliss CloneCopy-delete-posts Duplicate PostInisev Enhanced Text Widget+728/7/202317/6/2026
Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permissions,…
ModificadaCrítica (9.8)0.90%—Cdwanjiang Flash Flood Disaster Monitoring AND Warning System21/7/202317/6/2026
A vulnerability classified as problematic was found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This vulnerability affects unknown code of the file /Service/FileHandler.ashx. The manipulation of the argument userFile leads to unrestricted upload. The exploit has been disclosed to the public and…
ModificadaBaja (3.7)0.67%—Cdwanjiang Flash Flood Disaster Monitoring AND Warning System21/7/202317/6/2026
A vulnerability classified as problematic has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This affects an unknown part of the file /Service/ImageStationDataService.asmx of the component File Name Handler. The manipulation leads to insufficiently random values. The complexity of an…
ModificadaCrítica (9.8)0.95%—Cdwanjiang Flash Flood Disaster Monitoring AND Warning System21/7/202317/6/2026
A vulnerability was found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /Controller/Ajaxfileupload.ashx. The manipulation of the argument file leads to unrestricted upload. The exploit has been…
ModificadaCrítica (9.8)0.89%—Cdwanjiang Flash Flood Disaster Monitoring AND Warning System20/7/202317/6/2026
A vulnerability has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0 and classified as critical. This vulnerability affects unknown code of the file /App_Resource/UEditor/server/upload.aspx. The manipulation of the argument file leads to unrestricted upload. The exploit has been disclosed…
ModificadaAlta (8.8)0.88%—Istrong Four Mountain Torrent Disaster Prevention, Control Monitoring AND Early Warning System20/7/202317/6/2026
A vulnerability, which was classified as critical, was found in Gen Technology Four Mountain Torrent Disaster Prevention and Control of Monitoring and Early Warning System up to 20230712. This affects an unknown part of the file /Duty/AjaxHandle/UploadFloodPlanFileUpdate.ashx. The manipulation of the argument Filedata…
ModificadaCrítica (9.8)4.0%💥 PoCVmware Spring Security19/7/202317/6/2026
Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlux, and the potential for a security bypass.
ModificadaMedia (5.3)0.66%💥 PoCVmware Spring Security18/7/202317/6/2026
Spring Security versions 5.8 prior to 5.8.5, 6.0 prior to 6.0.5, and 6.1 prior to 6.1.2 could be susceptible to authorization rule misconfiguration if the application uses requestMatchers(String) and multiple servlets, one of them being Spring MVC’s DispatcherServlet. (DispatcherServlet is a Spring MVC component that…
ModificadaMedia (5.3)0.47%—Vmware Spring Hateoas17/7/202317/6/2026
Reactive web applications that use Spring HATEOAS to produce hypermedia-based responses might be exposed to malicious forwarded headers if they are not behind a trusted proxy that ensures correctness of such headers, or if they don't have anything else in place to handle (and possibly discard) forwarded headers either…
ModificadaAlta (7.5)0.97%—Codecentric Spring Boot AdminThymeleaf14/7/202317/6/2026
Thymeleaf through 3.1.1.RELEASE, as used in spring-boot-admin (aka Spring Boot Admin) through 3.1.1 and other products, allows sandbox bypass via crafted HTML. This may be relevant for SSTI (Server Side Template Injection) and code execution in spring-boot-admin if MailNotifier is enabled and there is write access to…
ModificadaMedia (6.1)0.36%—Phpgurukul Maid Hiring Management System13/7/202317/6/2026
Una vulnerabilidad de tipo Cross-Site Scripting (XSS) en Maid Hiring Management System v1.0 permite a los atacantes ejecutar scripts web o HTML arbitrarios a través de un payload manipulado inyectado en el parámetro "Title" del componente "/admin/contactus.php".
ModificadaMedia (6.1)0.36%—Phpgurukul Maid Hiring Management System13/7/202317/6/2026
A cross-site scripting (XSS) vulnerability in Maid Hiring Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page Description of the /admin/aboutus.php component.
ModificadaMedia (6.1)0.36%—Phpgurukul Maid Hiring Management System13/7/202317/6/2026
Maid Hiring Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/search-booking-request.php.
ModificadaAlta (7.5)0.57%—Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station13/7/202317/6/2026
Server information leak of configuration data when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning.
ModificadaAlta (7.5)0.65%—Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station13/7/202317/6/2026
Server or Console Station DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation. See Honeywell Security Notification for recommendations on upgrading and versioning.
ModificadaAlta (7.5)0.66%—Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station13/7/202317/6/2026
Experion server may experience a DoS due to a heap overflow which could occur when handling a specially crafted message
ModificadaAlta (7.5)0.65%—Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station13/7/202317/6/2026
Experion server DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation. See Honeywell Security Notification for recommendations on upgrading and versioning.
ModificadaAlta (7.5)0.60%—Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station13/7/202317/6/2026
Experion server may experience a DoS due to a stack overflow when handling a specially crafted message.
ModificadaMedia (6)0.20%—Cisco Broadworks Application Delivery Platform FirmwareCisco Broadworks Application Server FirmwareCisco Broadworks Database Server FirmwareCisco Broadworks Database Troubleshooting Server Firmware+1212/7/202317/6/2026
A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device. The vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing a crafted command to the affected…
ModificadaCrítica (9.8)0.96%—Istrong Mountain Flood Disaster Prevention Monitoring AND Early Warning System11/7/202317/6/2026
A vulnerability, which was classified as critical, has been found in Suncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System up to 20230706. This issue affects some unknown processing of the file /Duty/AjaxHandle/UpLoadFloodPlanFile.ashx of the component UpLoadFloodPlanFile. The manipulation…
ModificadaCrítica (9.8)0.96%—Istrong Mountain Flood Disaster Prevention Monitoring AND Early Warning System11/7/202317/6/2026
A vulnerability classified as critical was found in Suncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System up to 20230706. This vulnerability affects unknown code of the file /Duty/AjaxHandle/Write/UploadFile.ashx of the component Duty Write-UploadFile. The manipulation of the argument…
Orbitaley — Vulnerabilidades