Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
272 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.32% | — | Codeastro Online ClassroomAI | 5/4/2026 | 24/7/2026 | A vulnerability was identified in CodeAstro Online Classroom 1.0. Impacted is an unknown function of the file /OnlineClassroom/addvideos.php of the component Parameter Handler. The manipulation of the argument videotitle leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly… | |
| Aplazada | Baja (2.1) | 0.32% | — | Codeastro Online ClassroomAI | 5/4/2026 | 24/7/2026 | A vulnerability was determined in CodeAstro Online Classroom 1.0. This issue affects some unknown processing of the file /OnlineClassroom/updatedetailsfromfaculty.php?myfid=108 of the component Parameter Handler. Executing a manipulation of the argument fname can lead to sql injection. The attack may be performed from… | |
| Aplazada | Baja (2.1) | 0.32% | — | Codeastro Online ClassroomAI | 5/4/2026 | 24/7/2026 | A vulnerability was found in CodeAstro Online Classroom 1.0. This vulnerability affects unknown code of the file /OnlineClassroom/addassessment.php of the component Parameter Handler. Performing a manipulation of the argument deleteid results in sql injection. The attack is possible to be carried out remotely. The… | |
| Analizada | Baja (2.9) | 0.36% | — | Astro | 24/3/2026 | 17/6/2026 | Astro is a web framework. From version 2.10.10 to before version 5.18.1, this issue concerns Astro's remotePatterns path enforcement for remote URLs used by server-side fetchers such as the image optimization endpoint. The path matching logic for /* wildcards is unanchored, so a pathname that contains the allowed… | |
| Analizada | Crítica (9.1) | 0.50% | — | @astrojs/vercel | 24/3/2026 | 17/6/2026 | Astro is a web framework. Prior to version 10.0.2, the @astrojs/vercel serverless entrypoint reads the x-astro-path header and x_astro_path query parameter to rewrite the internal request path, with no authentication whatsoever. On deployments without Edge Middleware, this lets anyone bypass Vercel's platform-level… | |
| Analizada | Alta (7.5) | 0.43% | — | @astrojs/node | 24/3/2026 | 17/6/2026 | Astro is a web framework. Prior to version 10.0.0, Astro's Server Islands POST handler buffers and parses the full request body as JSON without enforcing a size limit. Because JSON.parse() allocates a V8 heap object for every element in the input, a crafted payload of many small JSON objects achieves ~15x memory… | |
| Analizada | Alta (7.1) | 0.84% | — | Wanderingastronomer Vociferous | 11/3/2026 | 17/6/2026 | Vociferous provides cross-platform, offline speech-to-text with local AI refinement. Prior to 4.4.2, the vulnerability exists in src/api/system.py within the export_file route. The application accepts a JSON payload containing a filename and content. While the developer intended for a native UI dialog to handle the… | |
| Analizada | Crítica (10) | 0.48% | 💥 PoC | Templaza Astroid Framework | 5/3/2026 | 17/6/2026 | A improperly secured file management feature allows uploads of dangerous data types for unauthenticated users, leading to remote code execution. | |
| Analizada | Alta (7.2) | 0.41% | — | @astrojs/node | 26/2/2026 | 17/6/2026 | Astro is a web framework. In versions 9.0.0 through 9.5.3, a bug in Astro's image pipeline allows bypassing `image.domains` / `image.remotePatterns` restrictions, enabling the server to fetch content from unauthorized remote hosts. Astro provides an `inferSize` option that fetches remote images at render time to… | |
| Analizada | Baja (1.9) | 0.24% | — | Codeastro Food Ordering System | 25/2/2026 | 17/6/2026 | A security vulnerability has been detected in CodeAstro Food Ordering System 1.0. This affects an unknown function of the file food_ordering.exe. Such manipulation leads to stack-based buffer overflow. The attack can only be performed from a local environment. The exploit has been disclosed publicly and may be used. | |
| Analizada | Alta (7.5) | 0.78% | — | @astrojs/node | 24/2/2026 | 17/6/2026 | Astro is a web framework. In versions 9.0.0 through 9.5.3, Astro server actions have no default request body size limit, which can lead to memory exhaustion DoS. A single large POST to a valid action endpoint can crash the server process on memory-constrained deployments. On-demand rendered sites built with Astro can… | |
| Analizada | Media (6.9) | 1.9% | 💥 Exploit | @astrojs/node | 24/2/2026 | 17/6/2026 | Astro is a web framework. Prior to version 9.5.4, Server-Side Rendered pages that return an error with a prerendered custom error page (eg. `404.astro` or `500.astro`) are vulnerable to SSRF. If the `Host:` header is changed to an attacker's server, it will be fetched on `/500.html` and they can redirect this to any… | |
| Modificada | Crítica (9.8) | 0.67% | — | Codeastro Membership Management System | 18/2/2026 | 8/9/2026 | CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter. | |
| Modificada | Alta (7.5) | 0.45% | — | Codeastro Membership Management System | 18/2/2026 | 8/9/2026 | Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users via direct requests with a manipulated id parameter, resulting in insecure direct object reference (IDOR). | |
| Modificada | Crítica (9.8) | 0.40% | 💥 PoC | Codeastro Membership Management System | 18/2/2026 | 8/9/2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter. | |
| Analizada | Baja (2) | 0.40% | — | Codeastro Real Estate Management System | 19/12/2025 | 17/6/2026 | A security vulnerability has been detected in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /admin/userdelete.php of the component Administrator Endpoint. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Modificada | Baja (2) | 0.36% | — | Codeastro Real Estate Management System | 19/12/2025 | 17/6/2026 | A weakness has been identified in CodeAstro Real Estate Management System 1.0. This impacts an unknown function of the file /admin/stateadd.php of the component Administrator Endpoint. This manipulation causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and… | |
| Modificada | Baja (2) | 0.36% | — | Codeastro Real Estate Management System | 19/12/2025 | 17/6/2026 | A security flaw has been discovered in CodeAstro Real Estate Management System 1.0. This affects an unknown function of the file /admin/userbuilderdelete.php of the component Administrator Endpoint. The manipulation results in sql injection. The attack can be launched remotely. The exploit has been released to the… | |
| Analizada | Baja (2) | 0.36% | — | Codeastro Real Estate Management System | 19/12/2025 | 17/6/2026 | A vulnerability was identified in CodeAstro Real Estate Management System 1.0. The impacted element is an unknown function of the file /admin/useragentdelete.php of the component Administrator Endpoint. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and… | |
| Analizada | Media (6.5) | 0.31% | — | Astro | 9/12/2025 | 17/6/2026 | Astro is a web framework. Versions 5.15.7 and below have a double URL encoding bypass which allows any unauthenticated attacker to bypass path-based authentication checks in Astro middleware, granting unauthorized access to protected routes. While the original CVE-2025-64765 was fixed in v5.15.8, the fix is… | |
| Analizada | Media (6.1) | 0.26% | — | Astro | 19/11/2025 | 17/6/2026 | Astro is a web framework. Prior to version 5.15.9, when using Astro's Cloudflare adapter (@astrojs/cloudflare) with output: 'server', the image optimization endpoint (/_image) contains a critical vulnerability in the isRemoteAllowed() function that unconditionally allows data: protocol URLs. This enables Cross-Site… | |
| Analizada | Media (6.9) | 0.50% | — | Astro | 19/11/2025 | 17/6/2026 | Astro is a web framework. Prior to version 5.15.8, a mismatch exists between how Astro normalizes request paths for routing/rendering and how the application’s middleware reads the path for validation checks. Astro internally applies decodeURI() to determine which route to render, while the middleware uses… | |
| Analizada | Media (5.4) | 0.49% | 💥 Exploit | Astro | 19/11/2025 | 17/6/2026 | Astro is a web framework. Prior to version 5.15.8, a reflected XSS vulnerability is present when the server islands feature is used in the targeted application, regardless of what was intended by the component template(s). This issue has been patched in version 5.15.8. | |
| Analizada | Baja (3.5) | 0.40% | — | Astro | 19/11/2025 | 17/6/2026 | Astro is a web framework. Prior to version 5.14.3, a vulnerability has been identified in the Astro framework's development server that allows arbitrary local file read access through the image optimization endpoint. The vulnerability affects Astro development environments and allows remote attackers to read any image… | |
| Modificada | Media (5.5) | 0.38% | — | Codeastro Simple Inventory System | 17/11/2025 | 17/6/2026 | A vulnerability was determined in CodeAstro Simple Inventory System 1.0. The impacted element is an unknown function of the file /index.php of the component Login. Executing a manipulation of the argument Username can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed… |