Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1742 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.4) | 0.48% | 💥 PoC | Pgadmin 4 | 31/7/2026 | 5/8/2026 | The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION READ ONLY wrapper. sqlparse's string-literal lexing can disagree with… | |
| Analizada | Media (5.3) | 0.38% | — | Pgadmin 4 | 31/7/2026 | 5/8/2026 | The per-tool permission system (custom roles / role-based tool permissions, introduced in pgAdmin 4 9.3) did not enforce its permission check consistently. In SERVER mode, pgAdmin 4 gates each tool behind a per-tool Flask-Security permission, but the permission decorator (permissions_required) was applied only to a… | |
| Analizada | Crítica (9.3) | 0.40% | — | Pgadmin 4 | 31/7/2026 | 5/8/2026 | /misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including user_id, shared, shared_username, and the stored credential fields password,… | |
| Analizada | Media (6.9) | 0.42% | — | Pgadmin 4 | 31/7/2026 | 5/8/2026 | In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles desktop-mode auto-login and the Kerberos/Webserver-auth redirect, so any route shipped without the decorator is reachable without authentication (CWE-306). This is the… | |
| Analizada | Alta (7.7) | 0.72% | — | Pgadmin 4 | 31/7/2026 | 7/8/2026 | The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. The previous implementation substituted the username directly into the command string and… | |
| Analizada | Alta (8.7) | 0.61% | — | Pgadmin 4 | 31/7/2026 | 5/8/2026 | The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorrect assumption that schema, table, publication, and subscription names… | |
| Aplazada | Alta (8.8) | 0.45% | — | Dynamiapps Frontend AdminAI | 31/7/2026 | 26/8/2026 | The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags that the sanitizer had neutralized. A double-encoded payload submitted by an unauthenticated visitor is therefore stored as a live tag and later output… | |
| Aplazada | Media (6.5) | 0.30% | — | Dynamiapps Frontend AdminAI | 30/7/2026 | 30/7/2026 | The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term creation, modification, and deletion operations, allowing authenticated users with low privileges (such as Subscribers) to create, rename, and delete arbitrary taxonomy terms. | |
| Aplazada | Crítica (9.8) | 1.1% | — | Wpase Admin AND Site EnhancementsAI | 30/7/2026 | 30/7/2026 | The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive_html function. This is due to the frontend save handler enforces only a publicly emitted nonce with no authentication check, CAPTCHA validation is… | |
| Aplazada | Media (6.1) | 0.40% | 💥 PoC | Milk AdminAI | 27/7/2026 | 28/7/2026 | Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController.php in Milk admin <=0.9.8 allows remote attackers to inject arbitrary web script or HTML via the action parameter in a crafted request | |
| Aplazada | Media (4.9) | 0.66% | 💥 PoC | Milk AdminAI | 27/7/2026 | 28/7/2026 | An issue in the redirect parameter in Milk admin <=0.9.8 allows remote attackers to redirect users to arbitrary external URLs via a crafted request. | |
| Aplazada | Baja (2.1) | 0.35% | — | Zsadmin2025 Zs-adminAI | 21/7/2026 | 22/7/2026 | A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This impacts an unknown function of the file /api/system/file/upload of the component com.zs.file.controller.SysFileController. Performing a manipulation of the argument File results in unrestricted upload. It… | |
| Aplazada | Baja (2.1) | 0.37% | — | Zsadmin2025 Zs-adminAIMybatis-plusAI | 21/7/2026 | 23/7/2026 | A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This affects the function getTenantId of the file /api/system/sys/dept/page of the component MyBatis-Plus Tenant Plugin. Such manipulation of the argument X-Tenant-Id leads to authorization bypass. The attack may be… | |
| Aplazada | Baja (2.1) | 0.32% | — | Zsadmin2025 Zs-adminAI | 21/7/2026 | 22/7/2026 | A vulnerability was determined in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. The impacted element is the function OrderItem.asc/OrderItem.desc of the file /api/system/sys/dept/page of the component com.zs.sys.dept.controller.SysDeptController. This manipulation of the argument orderField… | |
| Aplazada | Media (6) | 0.43% | — | AdminerAI | 20/7/2026 | 23/7/2026 | Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to manipulate cookie attributes by injecting arbitrary values through the unsanitized X-Forwarded-Prefix HTTP header used in Set-Cookie path attributes. Attackers can exploit a misconfigured reverse proxy to downgrade SameSite… | |
| Aplazada | Baja (2.1) | 0.38% | — | Guohongze AdminsetAI | 19/7/2026 | 20/7/2026 | A security vulnerability has been detected in guohongze adminset up to 0.61. Affected by this vulnerability is an unknown functionality of the file delivery/deli.py of the component Delivery Deployment Endpoint. The manipulation of the argument project_id leads to authorization bypass. It is possible to initiate the… | |
| Analizada | Alta (7.5) | 0.66% | — | Microsoft Remote Desktop WEB ClientMicrosoft Windows Admin Center | 17/7/2026 | 22/7/2026 | Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network. | |
| Aplazada | Crítica (9.8) | 0.47% | — | Beian.miit Cool-admin-javaAI | 17/7/2026 | 23/7/2026 | cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java. | |
| Analizada | Media (6.1) | 0.41% | — | Microsoft Windows Admin Center | 16/7/2026 | 14/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network. | |
| Pendiente de análisis | Alta (8.8) | 1.2% | — | Lenovo Xclarity Integrator FOR Windows Admin CenterAI | 16/7/2026 | 16/7/2026 | The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vulnerable to Powershell Command Injection when establishing remote PowerShell commands. | |
| Aplazada | Media (6.1) | 0.42% | 💥 PoC | XXL Job-adminAI | 15/7/2026 | 16/7/2026 | Cross Site Scripting vulnerability in xxl-job-admin v.3.0.0 allows a remote attacker to execute arbitrary code via a crafted HTTP GET request containing a malicious script | |
| Aplazada | Crítica (9.1) | 0.22% | 💥 PoC | Xxl-job-adminAI | 15/7/2026 | 16/7/2026 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an attacker to perform unauthorized modifications to Glue IDE shell scripts. The affected endpoint lacks proper CSRF token validation and accepts arbitrary HTTP methods via a permissive request mapping | |
| Analizada | Alta (8.8) | 0.99% | — | Microsoft Windows Admin Center | 14/7/2026 | 24/7/2026 | Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 1.0% | — | Microsoft Windows Admin Center | 14/7/2026 | 24/7/2026 | Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (7.8) | 0.30% | — | Microsoft Windows Admin Center | 14/7/2026 | 17/7/2026 | Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally. |