Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

1742 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.4)0.48%💥 PoCPgadmin 431/7/20265/8/2026
The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION READ ONLY wrapper. sqlparse's string-literal lexing can disagree with…
AnalizadaMedia (5.3)0.38%—Pgadmin 431/7/20265/8/2026
The per-tool permission system (custom roles / role-based tool permissions, introduced in pgAdmin 4 9.3) did not enforce its permission check consistently. In SERVER mode, pgAdmin 4 gates each tool behind a per-tool Flask-Security permission, but the permission decorator (permissions_required) was applied only to a…
AnalizadaCrítica (9.3)0.40%—Pgadmin 431/7/20265/8/2026
/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including user_id, shared, shared_username, and the stored credential fields password,…
AnalizadaMedia (6.9)0.42%—Pgadmin 431/7/20265/8/2026
In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles desktop-mode auto-login and the Kerberos/Webserver-auth redirect, so any route shipped without the decorator is reachable without authentication (CWE-306). This is the…
AnalizadaAlta (7.7)0.72%—Pgadmin 431/7/20267/8/2026
The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. The previous implementation substituted the username directly into the command string and…
AnalizadaAlta (8.7)0.61%—Pgadmin 431/7/20265/8/2026
The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorrect assumption that schema, table, publication, and subscription names…
AplazadaAlta (8.8)0.45%—Dynamiapps Frontend AdminAI31/7/202626/8/2026
The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags that the sanitizer had neutralized. A double-encoded payload submitted by an unauthenticated visitor is therefore stored as a live tag and later output…
AplazadaMedia (6.5)0.30%—Dynamiapps Frontend AdminAI30/7/202630/7/2026
The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term creation, modification, and deletion operations, allowing authenticated users with low privileges (such as Subscribers) to create, rename, and delete arbitrary taxonomy terms.
AplazadaCrítica (9.8)1.1%—Wpase Admin AND Site EnhancementsAI30/7/202630/7/2026
The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive_html function. This is due to the frontend save handler enforces only a publicly emitted nonce with no authentication check, CAPTCHA validation is…
AplazadaMedia (6.1)0.40%💥 PoCMilk AdminAI27/7/202628/7/2026
Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController.php in Milk admin <=0.9.8 allows remote attackers to inject arbitrary web script or HTML via the action parameter in a crafted request
AplazadaMedia (4.9)0.66%💥 PoCMilk AdminAI27/7/202628/7/2026
An issue in the redirect parameter in Milk admin <=0.9.8 allows remote attackers to redirect users to arbitrary external URLs via a crafted request.
AplazadaBaja (2.1)0.35%—Zsadmin2025 Zs-adminAI21/7/202622/7/2026
A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This impacts an unknown function of the file /api/system/file/upload of the component com.zs.file.controller.SysFileController. Performing a manipulation of the argument File results in unrestricted upload. It…
AplazadaBaja (2.1)0.37%—Zsadmin2025 Zs-adminAIMybatis-plusAI21/7/202623/7/2026
A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This affects the function getTenantId of the file /api/system/sys/dept/page of the component MyBatis-Plus Tenant Plugin. Such manipulation of the argument X-Tenant-Id leads to authorization bypass. The attack may be…
AplazadaBaja (2.1)0.32%—Zsadmin2025 Zs-adminAI21/7/202622/7/2026
A vulnerability was determined in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. The impacted element is the function OrderItem.asc/OrderItem.desc of the file /api/system/sys/dept/page of the component com.zs.sys.dept.controller.SysDeptController. This manipulation of the argument orderField…
AplazadaMedia (6)0.43%—AdminerAI20/7/202623/7/2026
Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to manipulate cookie attributes by injecting arbitrary values through the unsanitized X-Forwarded-Prefix HTTP header used in Set-Cookie path attributes. Attackers can exploit a misconfigured reverse proxy to downgrade SameSite…
AplazadaBaja (2.1)0.38%—Guohongze AdminsetAI19/7/202620/7/2026
A security vulnerability has been detected in guohongze adminset up to 0.61. Affected by this vulnerability is an unknown functionality of the file delivery/deli.py of the component Delivery Deployment Endpoint. The manipulation of the argument project_id leads to authorization bypass. It is possible to initiate the…
AnalizadaAlta (7.5)0.66%—Microsoft Remote Desktop WEB ClientMicrosoft Windows Admin Center17/7/202622/7/2026
Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.
AplazadaCrítica (9.8)0.47%—Beian.miit Cool-admin-javaAI17/7/202623/7/2026
cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java.
AnalizadaMedia (6.1)0.41%—Microsoft Windows Admin Center16/7/202614/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.
Pendiente de análisisAlta (8.8)1.2%—Lenovo Xclarity Integrator FOR Windows Admin CenterAI16/7/202616/7/2026
The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vulnerable to Powershell Command Injection when establishing remote PowerShell commands.
AplazadaMedia (6.1)0.42%💥 PoCXXL Job-adminAI15/7/202616/7/2026
Cross Site Scripting vulnerability in xxl-job-admin v.3.0.0 allows a remote attacker to execute arbitrary code via a crafted HTTP GET request containing a malicious script
AplazadaCrítica (9.1)0.22%💥 PoCXxl-job-adminAI15/7/202616/7/2026
A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an attacker to perform unauthorized modifications to Glue IDE shell scripts. The affected endpoint lacks proper CSRF token validation and accepts arbitrary HTTP methods via a permissive request mapping
AnalizadaAlta (8.8)0.99%—Microsoft Windows Admin Center14/7/202624/7/2026
Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)1.0%—Microsoft Windows Admin Center14/7/202624/7/2026
Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.
AnalizadaAlta (7.8)0.30%—Microsoft Windows Admin Center14/7/202617/7/2026
Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.