Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3075▲ 488 respecto a la semana anterior
Críticas / altas1457▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
21.656 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.37% | — | Sourcecodester Online Examination AND Learning Management SystemAI | 5/7/2026 | 6/7/2026 | A security flaw has been discovered in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vulnerability is the function pathinfo of the file /upload_files.php of the component Filename Extension. Performing a manipulation results in unrestricted upload. Remote exploitation of the… | |
| Aplazada | Baja (2.1) | 0.37% | — | Sourcecodester Online Examination AND Learning Management SystemAI | 5/7/2026 | 7/7/2026 | A vulnerability was identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected is an unknown function of the file /process_lesson.php. Such manipulation of the argument user_id leads to unrestricted upload. The attack may be launched remotely. The exploit is publicly available and might… | |
| Aplazada | Media (5.5) | 0.50% | — | Sourcecodester Online Examination Learning Management SystemAI | 5/7/2026 | 6/7/2026 | A flaw has been found in SourceCodester Onlne Examination & Learning Management System 1.0. The impacted element is an unknown function of the file register.php of the component Registration Endpoint. Executing a manipulation of the argument role can lead to improper privilege management. The attack can be executed… | |
| Aplazada | Baja (1.1) | 0.14% | — | Zcaceres Markdownify-mcpAI | 5/7/2026 | 6/7/2026 | A flaw has been found in zcaceres markdownify-mcp up to 1.1.0. This impacts the function saveToTempFile of the file src/Markdownify.ts of the component webpage-to-markdown/youtube-to-markdown/bing-search-to-markdown. This manipulation causes insufficiently random values. The attack is restricted to local execution. A… | |
| Aplazada | Media (4.8) | 0.17% | — | Zcaceres Markdownify-mcpAI | 5/7/2026 | 6/7/2026 | A weakness has been identified in zcaceres markdownify-mcp up to 1.1.0. The affected element is the function assertPathAllowed of the file src/Markdownify.ts. Executing a manipulation can lead to symlink following. The attack can only be executed locally. The pull request to fix this issue awaits acceptance. | |
| Aplazada | Baja (2.1) | 0.37% | — | Sourcecodester Syllabus-aligned Learning Management AND Examination SystemAI | 5/7/2026 | 6/7/2026 | A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management and Examination System 1.0. Impacted is an unknown function of the file upload_files.php. Performing a manipulation results in unrestricted upload. The attack may be initiated remotely. The exploit has been released to the… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple AND Nice Shopping Cart ScriptAI | 4/7/2026 | 6/7/2026 | A vulnerability was identified in SourceCodester Simple and Nice Shopping Cart Script 1.0. Affected is an unknown function of the file /admin/girlsproductdeletequery.php. Such manipulation of the argument user_id leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple AND Nice Shopping Cart ScriptAI | 4/7/2026 | 6/7/2026 | A vulnerability was determined in SourceCodester Simple and Nice Shopping Cart Script 1.0. This impacts an unknown function of the file /admin/mensproductdeletequery.php. This manipulation of the argument user_id causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple AND Nice Shopping Cart ScriptAI | 4/7/2026 | 6/7/2026 | A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown function of the file /admin/login.php of the component Admin Login. The manipulation of the argument Username results in sql injection. The attack may be launched remotely. The exploit has been made public and… | |
| Aplazada | Alta (7.8) | 0.83% | — | Kirilkirkov Ecommerce-codeigniter-bootstrapAI | 4/7/2026 | 6/7/2026 | A security vulnerability has been detected in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 13fd582aaf49aeab7438acc0fc3eb973a1f5e6a7. The affected element is the function getCartItems in the library application/libraries/ShoppingCart.php. The manipulation of the argument shopping_cart leads to deserialization. The… | |
| Aplazada | Media (5.3) | 0.48% | — | Kirilkirkov Ecommerce-codeigniter-bootstrapAI | 4/7/2026 | 6/7/2026 | A weakness has been identified in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 23105f25dadf57b4314fc015a63a7c6e910c89df. Impacted is the function do_upload_others_images of the file application/modules/vendor/controllers/AddProduct.php of the component Vendor Image Manager. Executing a manipulation of the… | |
| Aplazada | Media (5.5) | 0.62% | — | Kirilkirkov Ecommerce Codeigniter BootstrapAI | 4/7/2026 | 6/7/2026 | A security flaw has been discovered in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 222ff31c06687b1c6d0e1ab63953f82c3674c52b. This issue affects some unknown processing of the file application/modules/vendor/controllers/AddProduct.php of the component Vendor Multi-Image Endpoint. Performing a manipulation of the… | |
| Aplazada | Baja (2.1) | 0.49% | — | Kirilkirkov Ecommerce Codeigniter BootstrapAI | 4/7/2026 | 6/7/2026 | A vulnerability was identified in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 213babdbaa949e94557246414db0130e01394517. This vulnerability affects the function checkForPostRequests of the file application/core/MY_Controller.php of the component Subscribed Emails Admin Page. Such manipulation of the argument… | |
| Aplazada | Baja (2.1) | 0.49% | — | Kirilkirkov Ecommerce-codeigniter-bootstrapAI | 4/7/2026 | 7/7/2026 | A vulnerability was determined in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 49b20f53de2b7ec34e920b11c863f1491d911a04. This affects an unknown part of the file /index.php/api/product/set of the component Hidden REST API Endpoint. This manipulation of the argument title/description causes cross site scripting.… | |
| Aplazada | Baja (2.1) | 0.46% | — | Kirilkirkov Ecommerce-codeigniter-bootstrapAI | 4/7/2026 | 6/7/2026 | A vulnerability was found in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 95dfa8cebbb87ab46ae450643a07241274a74dce. Affected by this issue is the function setReferrer of the file application/core/MY_Controller.php of the component Trusted Backend Interface. The manipulation of the argument href results in open… | |
| Pendiente de análisis | Alta (8.4) | 0.18% | 💥 PoC | Unity ParsecAI | 4/7/2026 | 6/7/2026 | An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. This issue affects Parsec through v2026-05-04.0. The patched version is Parsec for Windows version 150-104a. A user can generate a situation where there is an instance of parsecd.exe running… | |
| Aplazada | Media (5.3) | 0.35% | — | Ninjaforms Ninja Forms File UploadsAI | 3/7/2026 | 6/7/2026 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.29. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to read all plugin debug log… | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Entra Provisioning Service | 2/7/2026 | 8/7/2026 | Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Media (5.1) | 0.30% | — | Infiniflow RagflowAI | 2/7/2026 | 14/7/2026 | RAGFlow before 0.26.3 stores an agent pipeline (DSL) node name without sanitization: the agent update endpoint normalizes the submitted DSL via normalize_dsl, which only performs JSON serialization validation and preserves the node name verbatim. The dataflow-result web UI then renders that name into the "Rerun from… | |
| Analizada | Alta (7.5) | 0.36% | — | UI Unifi Network Application | 2/7/2026 | 6/7/2026 | A malicious actor with access to the network and under certain conditions could exploit an Incorrect Authorization vulnerability found in UniFi Network Application to persist privileges within UniFi Network Application after such access had been removed. | |
| Analizada | Alta (8.8) | 0.49% | — | UI Unifi Protect | 2/7/2026 | 6/7/2026 | A malicious actor with access to the network and low privileges could exploit an authenticated SQL Injection vulnerability found in UniFi Protect Application to escalate privileges on the host device. | |
| Analizada | Alta (8.1) | 0.39% | — | UI Unifi Talk Application | 2/7/2026 | 9/7/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Talk Application to escalate privileges within the UniFi Talk Application. | |
| Analizada | Alta (8.3) | 0.37% | — | UI Unifi Network Application | 2/7/2026 | 6/7/2026 | A malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application. | |
| Analizada | Alta (8.6) | 0.56% | — | UI Unifi Access | 2/7/2026 | 17/8/2026 | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Access Application to access files on the host device. | |
| En análisis | Crítica (9.8) | 0.41% | — | UI Unifi Connect | 2/7/2026 | 9/7/2026 | A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices. |