Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

6578 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.6)0.47%—Aaluoxiang OA System10/9/202517/6/2026
oasys v1.1 es vulnerable a salto de directorio en ProcedureController.
AplazadaAlta (7)0.23%—Broadcom SOCAICalix Gigacenter ONTAI9/9/202530/9/2026
Vulnerabilidad de Privilegios Excesivos en Calix GigaCenter ONT (módulos Broadcom SoC) permite el Abuso de Privilegios. Este problema afecta a los GigaCenter ONT: 844E, 844G, 844GE, 854GE, 812G, 813G, 818G.
AplazadaCrítica (9.8)0.34%—Hossein Material DashboardAI9/9/202517/6/2026
Weak Password Recovery Mechanism for Forgotten Password vulnerability in Hossein Material Dashboard material-dashboard.This issue affects Material Dashboard: from n/a through <= 1.4.6.
AnalizadaBaja (3.8)0.29%💥 PoCEliehanna Compress & Upload9/9/202510/7/2026
The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
AnalizadaMedia (5.5)0.42%—Campcodes Online Loan Management System8/9/202517/6/2026
A vulnerability was determined in Campcodes Online Loan Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=delete_payment. Executing manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and…
AnalizadaMedia (5.5)0.48%—Campcodes Online Loan Management System8/9/202517/6/2026
A vulnerability was found in Campcodes Online Loan Management System 1.0. This vulnerability affects unknown code of the file /ajax.php?action=delete_loan. Performing manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used.
AnalizadaMedia (5.5)0.55%—Jinher OA8/9/202517/6/2026
A vulnerability was found in Jinher OA up to 1.2. This impacts an unknown function of the file /c6/Jhsoft.Web.projectmanage/TaskManage/AddTask.aspx/?Type=add of the component XML Handler. The manipulation results in xml external entity reference. The attack can be executed remotely. The exploit has been made public…
AnalizadaMedia (5.5)1.8%💥 ExploitJinher OA8/9/202517/6/2026
A flaw has been found in Jinher OA up to 1.2. The impacted element is an unknown function of the file /C6/Jhsoft.Web.departments/GetTreeDate.aspx. Executing manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used.
AnalizadaMedia (5.5)0.55%—Jinher OA8/9/202530/9/2026
Una vulnerabilidad ha sido encontrada en Jinher OA hasta 1.2. Esto afecta a una función desconocida del archivo /c6/Jhsoft.Web.projectmanage/ProjectManage/XmlHttp.aspx/?Type=add del componente Gestor XML. La manipulación conduce a una referencia de entidad externa XML. La explotación remota del ataque es posible. El…
AplazadaMedia (4.3)0.31%—KeycloakAI5/9/202517/6/2026
A flaw was found in Keycloak. Keycloak’s account console and other pages accept arbitrary text in the error_description query parameter. This text is directly rendered in error pages without validation or sanitization. While HTML encoding prevents XSS, an attacker can craft URLs with misleading messages (e.g., fake…
ModificadaCrítica (9.8)0.42%—Thememove Maxcoach5/9/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove MaxCoach maxcoach allows PHP Local File Inclusion.This issue affects MaxCoach: from n/a through <= 3.2.5.
AplazadaAlta (7.1)0.12%—Ericzane Floating Window Music PlayerAI5/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ericzane Floating Window Music Player floating-window-music-player allows Stored XSS.This issue affects Floating Window Music Player: from n/a through <= 3.4.2.
AplazadaMedia (5.9)0.18%—Gourl Bitcoin Payment Gateway Paid Downloads MembershipAI5/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gourl GoUrl Bitcoin Payment Gateway & Paid Downloads & Membership gourl-bitcoin-payment-gateway-paid-downloads-membership allows Stored XSS.This issue affects GoUrl Bitcoin Payment Gateway & Paid Downloads &…
AplazadaMedia (6.5)0.17%—Easy Download Media CounterAI5/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Remi Corson Easy Download Media Counter easy-download-media-counter allows Stored XSS.This issue affects Easy Download Media Counter: from n/a through <= 1.2.
AplazadaAlta (7.1)0.13%—Deepak S Hide Real Download PathAI5/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Deepak S Hide Real Download Path hide-real-download-path allows Stored XSS.This issue affects Hide Real Download Path: from n/a through <= 1.6.
AplazadaBaja (3.8)0.25%—Pickplugins JOB Board ManagerAI5/9/202517/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in PickPlugins Job Board Manager job-board-manager allows Code Injection.This issue affects Job Board Manager: from n/a through <= 2.1.61.
AnalizadaBaja (2.1)0.36%—Jinher OA4/9/202517/6/2026
A vulnerability was detected in Jinher OA 1.0. Affected is an unknown function of the file /jc6/platform/sys/login!changePassWord.action of the component POST Request Handler. The manipulation of the argument Account results in cross site scripting. The attack can be launched remotely. The exploit is now public and…
AplazadaMedia (5.3)0.39%—VaadinAIVaadin-serverAIVaadin-upload-flowAI4/9/202514/9/2026
When the Vaadin Upload's start listener is used to validate metadata about an incoming upload, it is possible to bypass the upload validation. Users of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include: Product version Vaadin 7.0.0 - 7.7.47 Vaadin 8.0.0 -…
AplazadaBaja (2.3)0.42%—Ckeditor5AICkeditor5-clipboardAI4/9/202517/6/2026
CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. ckeditor5 and ckeditor5-clipboard versions 46.0.0 through 46.0.2 and 44.2.0 through 45.2.1 contain a Cross-Site Scripting (XSS) vulnerability. Ability to exploit could be triggered by a specific user action (leading to unauthorized JavaScript…
AplazadaAlta (8.4)0.19%—Fujielectric Frenic-loaderAI3/9/202517/6/2026
Fuji Electric FRENIC-Loader 4 is vulnerable to a deserialization of untrusted data when importing a file through a specified window, which may allow an attacker to execute arbitrary code.
AnalizadaCrítica (9.8)0.65%—Cockroachlabs Cockroach-k8s-request-cert2/9/202517/6/2026
Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability. This vulnerability could allow remote attackers to bypass authentication on systems that use the affected version of the Cockroach Labs cockroach-k8s-request-cert container image. The specific flaw exists within the…
AplazadaCrítica (9.8)14%—H2oai H2o-3AI1/9/202517/6/2026
A vulnerability in the h2oai/h2o-3 repository allows attackers to exploit deserialization of untrusted data, potentially leading to arbitrary code execution and reading of system files. This issue affects the latest master branch version 3.47.0.99999. The vulnerability arises from the ability to bypass regular…
AnalizadaMedia (5.5)1.8%💥 ExploitCampcodes Online Loan Management System31/8/202517/6/2026
A weakness has been identified in Campcodes Online Loan Management System 1.0. The affected element is an unknown function of the file /ajax.php?action=login. Executing manipulation of the argument Username can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the…
AnalizadaBaja (2)0.34%—Zoneland O2oa31/8/202517/6/2026
A vulnerability was detected in O2OA up to 10.0-410. Affected is an unknown function of the file /x_query_assemble_designer/jaxrs/importmodel of the component Personal Profile Page. Performing manipulation of the argument description/applicationName/queryName results in cross site scripting. Remote exploitation of the…
AnalizadaBaja (2)0.34%—Zoneland O2oa31/8/202517/6/2026
A security vulnerability has been detected in O2OA up to 10.0-410. This impacts an unknown function of the file /x_query_assemble_designer/jaxrs/statement of the component Personal Profile Page. Such manipulation of the argument description/queryName leads to cross site scripting. The attack may be launched remotely.…