Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
23.887 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.33% | — | Adithyayelloju Restaurant-management-systemAI | 20/9/2026 | 21/9/2026 | A vulnerability has been found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Affected by this issue is some unknown functionality of the file admin/add_menu.php. The manipulation of the argument item/price/image/type leads to sql injection. It is possible to initiate… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Internship Management SystemAI | 20/9/2026 | 21/9/2026 | A weakness has been identified in code-projects Internship Management System 1.0. This vulnerability affects unknown code of the file /admin/login.php of the component Admin Login Form. Executing a manipulation of the argument Password can lead to sql injection. The attack may be performed from remote. The exploit has… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Internship Management SystemAI | 20/9/2026 | 22/9/2026 | A security flaw has been discovered in code-projects Internship Management System 1.0. This affects an unknown part of the file /employer/login.php. Performing a manipulation of the argument Password results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Internship Management SystemAI | 20/9/2026 | 21/9/2026 | A vulnerability was identified in code-projects Internship Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Such manipulation of the argument Password leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. | |
| Aplazada | Baja (2) | 0.35% | — | Code-projects Assessment ManagementAI | 20/9/2026 | 24/9/2026 | A vulnerability was determined in code-projects Assessment Management 1.0. Affected by this vulnerability is an unknown functionality of the file lecturer/add-single-mark.php. This manipulation of the argument mark causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been… | |
| Aplazada | Baja (1.9) | 0.37% | — | Code-projects Assessment ManagementAI | 20/9/2026 | 21/9/2026 | A vulnerability was found in code-projects Assessment Management 1.0. Affected is an unknown function of the file admin/add-user.php. The manipulation of the argument level results in cross site scripting. The attack may be launched remotely. The exploit has been made public and could be used. | |
| Aplazada | Baja (1.9) | 0.37% | — | Code-projects Assessment ManagementAI | 20/9/2026 | 21/9/2026 | A vulnerability has been found in code-projects Assessment Management 1.0. This impacts an unknown function of the file admin/edit-user.php of the component User Editing. The manipulation of the argument name/sname/email/username/password/id leads to cross site scripting. The attack may be initiated remotely. The… | |
| Pendiente de análisis | Media (5) | 0.10% | — | Cockpit-project Cockpit MachinesAI | 18/9/2026 | 22/9/2026 | A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process metadata to disclose a sensitive Red Hat Subscription Management (RHSM) offline token. The token is exposed when it is passed as a command-line argument to a helper script during the token validation… | |
| Pendiente de análisis | Media (4.7) | 0.20% | — | Zephyrproject ZephyrAI | 18/9/2026 | 18/9/2026 | net_icmpv6_send_error() in subsys/net/ip/icmpv6.c implemented only one of the three RFC 4443 section 2.4 suppression rules (do not answer an ICMPv6 error with an ICMPv6 error). It did not check whether the triggering packet's source address identifies a single node (rule e.6) or whether the packet was sent to a… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Matrimonial SystemAI | 17/9/2026 | 17/9/2026 | A vulnerability has been found in code-projects Matrimonial System 1.0. This vulnerability affects the function writepartnerprefs of the file /partner_preference.php. Such manipulation of the argument education leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public… | |
| Aplazada | Alta (8.7) | 0.65% | — | Pelican Project Pelican PanelAI | 16/9/2026 | 24/9/2026 | Pelican Panel versions before 1.0.0-beta35 enforce startup write permissions only through disabled form controls rather than server-side authorization checks. Attackers with startup.read permission can craft Livewire state updates to invoke afterStateUpdated callbacks and modify startup commands, docker images, and… | |
| Pendiente de análisis | Alta (7) | 0.12% | — | Projectdiscovery NucleiAI | 16/9/2026 | 24/9/2026 | Nuclei versions before 3.11.1 cache template signature verification based only on file modification time without content checksums. Attackers can replace verified templates with unsigned malicious content and restore the original modification time to bypass signature checks and execute arbitrary operating system… | |
| Aplazada | Media (5.5) | 0.56% | — | Code-projects Matrimonial SystemAI | 16/9/2026 | 16/9/2026 | A vulnerability was determined in code-projects Matrimonial System 1.0. This affects an unknown part of the file /search.php of the component Regular Search. This manipulation of the argument sex/mothertongue/maritialstatus/country/state/religion/agemin/agemax causes sql injection. The attack can be initiated… | |
| Aplazada | Media (5.3) | 0.52% | — | Vllm-project VllmAI | 16/9/2026 | 22/9/2026 | A vulnerability was found in vllm-project vllm up to 0.29.0. Affected by this issue is some unknown functionality of the file vllm/v1/sample/thinking_budget_state.py. The manipulation results in inefficient algorithmic complexity. It is possible to launch the attack remotely. The pull request to fix this issue awaits… | |
| Aplazada | Media (5.3) | 0.39% | — | A2ui-project A2uiAI | 16/9/2026 | 28/9/2026 | A vulnerability was identified in a2ui-project a2ui 0.8/0.9/1.0. Impacted is an unknown function of the file model-processor.ts of the component Model Processor. The manipulation of the argument current[segment] leads to information disclosure. The attack may be initiated remotely. The identifier of the patch is… | |
| Aplazada | Media (5.3) | 0.52% | — | A2ui-project A2uiAI | 16/9/2026 | 28/9/2026 | A vulnerability was determined in a2ui-project a2ui 0.9/0.9.1. This issue affects the function updateComponents of the file basic_functions.ts of the component Update Components. Executing a manipulation can lead to resource consumption. The attack can be launched remotely. The project was informed of the problem… | |
| Aplazada | Media (6.9) | 0.70% | — | Vllm-project VllmAI | 16/9/2026 | 16/9/2026 | A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0. Affected is the function MoRIIOConnectorScheduler.request_finished/MoRIIOConnectorWorker.get_finished/MoRIIOWrapper._handle_release_message of the file vllm/distributed/kv_transfer/kv_connector/v1/moriio/moriio_connector.py of the component MoRIIO… | |
| Aplazada | Media (5.3) | 0.43% | — | A2ui-project A2uiAI | 16/9/2026 | 17/9/2026 | A vulnerability was determined in a2ui-project a2ui up to 0.10.6. This affects the function processMessages of the file renderers/web_core/src/v0_9/processing/message-processor.ts of the component Message Parsing. This manipulation causes dynamically-determined object attributes. The attack can be initiated remotely.… | |
| Aplazada | Media (5.3) | 0.48% | — | A2ui-project A2uiAI | 16/9/2026 | 16/9/2026 | A vulnerability was found in a2ui-project a2ui up to 0.10.7. Affected by this issue is the function openUrl of the file renderers/web_core/src/v0_9/rendering/generic-binder.ts of the component Binder. The manipulation results in open redirect. It is possible to launch the attack remotely. The project was informed of… | |
| Aplazada | Media (6.9) | 0.51% | — | A2ui-project A2uiAI | 16/9/2026 | 16/9/2026 | A vulnerability has been found in a2ui-project a2ui up to 0.10.7. Affected by this vulnerability is the function httpx.get of the file agent_sdks/python/a2ui_agent/src/a2ui/extensions/file_resolve/file_resolver.py of the component FileResolver. The manipulation leads to server-side request forgery. It is possible to… | |
| Aplazada | Media (5.1) | 0.32% | — | A2ui-project A2uiAI | 16/9/2026 | 16/9/2026 | A vulnerability was detected in a2ui-project a2ui up to 0.10.6. This impacts the function z.any of the file renderers/web_core/src/v0_9/schema/server-to-client.ts of the component Angular Renderer. Performing a manipulation of the argument primaryColor results in injection. The attack is possible to be carried out… | |
| Aplazada | Media (5.1) | 0.35% | — | A2ui-project A2uiAI | 16/9/2026 | 22/9/2026 | A flaw has been found in a2ui-project a2ui up to 0.10.7. Affected is an unknown function of the file samples/community/client/angular/projects/a2a-chat-canvas/src/lib/services/sanitizer-markdown-renderer-service.ts of the component a2a-chat-canvas. Executing a manipulation can lead to cross site scripting. The attack… | |
| Aplazada | Media (6.9) | 0.72% | — | A2ui-project A2uiAI | 15/9/2026 | 16/9/2026 | A vulnerability was identified in a2ui-project a2ui up to 0.10.6. Affected is an unknown function of the file renderers/web_core/src/v0_9/basic_catalog/functions/safe_regex.ts of the component Basic Catalog. Such manipulation leads to inefficient regular expression complexity. The attack can be launched remotely. | |
| Aplazada | Alta (7.1) | 0.28% | — | Oracle Project IntelligenceAIOracle E-business SuiteAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Project Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Intelligence.… | |
| Aplazada | Alta (8.1) | 0.35% | — | Oracle Project IntelligenceAIOracle E-business SuiteAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Oracle Project Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Intelligence.… |