Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
349 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.56% | — | Clickhouse | 3/9/2024 | 17/6/2026 | ClickHouse v24.3.3.102 was discovered to contain a buffer overflow via the component DB::evaluateConstantExpressionImpl. | |
| Analizada | Alta (8.8) | 0.30% | — | Siamonhasan Warehouse Inventory System | 20/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the component categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | |
| Analizada | Alta (8.8) | 0.31% | — | Siamonhasan Warehouse Inventory System | 20/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the component delete_media.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | |
| Modificada | Alta (8.8) | 0.31% | — | Siamonhasan Warehouse Inventory System | 20/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the component delete_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | |
| Analizada | Alta (8.8) | 0.31% | — | Siamonhasan Warehouse Inventory System | 20/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the component delete_user.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | |
| Analizada | Alta (8.8) | 0.31% | — | Siamonhasan Warehouse Inventory System | 20/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the component delete_categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | |
| Analizada | Alta (8.8) | 0.31% | — | Siamonhasan Warehouse Inventory System | 20/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the component delete_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | |
| Analizada | Alta (8.8) | 0.22% | — | Siamonhasan Warehouse Inventory System | 20/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the component edit_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | |
| Modificada | Alta (8.8) | 0.31% | — | Siamonhasan Warehouse Inventory System | 20/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the component add_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | |
| Analizada | Alta (8) | 0.30% | — | Siamonhasan Warehouse Inventory System | 20/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the component edit_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | |
| Modificada | Alta (8.8) | 0.31% | — | Siamonhasan Warehouse Inventory System | 20/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the component add_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | |
| Analizada | Alta (8.8) | 0.31% | — | Siamonhasan Warehouse Inventory System | 20/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the component edit_categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | |
| Analizada | Media (5.3) | 0.44% | — | Mayurik Best House Rental Management System | 15/8/2024 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Best House Rental Management System 1.0. This vulnerability affects unknown code of the file /rental_0/rental/ajax.php?action=save_tenant of the component POST Parameter Handler. The manipulation of the argument lastname leads to cross site… | |
| Analizada | Alta (8) | 0.30% | — | Mayurik Best House Rental Management | 12/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability was found in SourceCodester Best House Rental Management System v1.0. This could lead to an attacker tricking the administrator into adding/modifying/deleting valid tenant data via a crafted HTML page, as demonstrated by a Delete Tenant action at the… | |
| Analizada | Alta (8.8) | 0.53% | — | Mayurik Best House Rental Management System | 12/8/2024 | 17/6/2026 | SourceCodester Best House Rental Management System v1.0 is vulnerable to Incorrect Access Control via /rental/payment_report.php, /rental/balance_report.php, /rental/invoices.php, /rental/tenants.php, and /rental/users.php. | |
| Analizada | Media (5.4) | 0.52% | — | Mayurik Best House Rental Management System | 12/8/2024 | 17/6/2026 | A Reflected Cross Site Scripting (XSS) vulnerability was found in "edit-cate.php" in SourceCodester House Rental Management System v1.0. | |
| Modificada | Media (5.4) | 0.64% | — | Mayurik Best House Rental Management System | 12/8/2024 | 17/6/2026 | A Stored Cross Site Scripting (XSS) vulnerability was found in "manage_houses.php" in SourceCodester Best House Rental Management System v1.0. It allows remote attackers to execute arbitrary code via "House_no" and "Description" parameter fields. | |
| Analizada | Media (4.8) | 0.33% | — | Shawon786 House Manager | 7/8/2024 | 17/6/2026 | The House Manager WordPress plugin through 1.0.8.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Analizada | Media (6.9) | 0.37% | — | Siamonhasan Warehouse Inventory System | 4/8/2024 | 17/6/2026 | A vulnerability was found in OSWAPP Warehouse Inventory System 1.0/2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /change_password.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.37% | — | Siamonhasan Warehouse Inventory System | 4/8/2024 | 17/6/2026 | A vulnerability was found in OSWAPP Warehouse Inventory System 1.0/2.0. It has been classified as problematic. Affected is an unknown function of the file /edit_account.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Aplazada | Alta (8.1) | 0.72% | — | ClickhouseAI | 1/8/2024 | 17/6/2026 | It is possible to crash or redirect the execution flow of the ClickHouse server process from an unauthenticated vector by sending a specially crafted request to the ClickHouse server native interface. This redirection is limited to what is available within a 256-byte range of memory at the time of execution, and no… | |
| Analizada | Media (4.7) | 0.83% | — | Mayurik Best House Rental Management System | 29/7/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Best House Rental Management System 1.0 allows a remote attacker to execute arbitrary code via the "House No" and "Description" parameters in the houses page at the index.php component. | |
| Analizada | Media (5.7) | 0.10% | — | Dell Data Lakehouse | 18/7/2024 | 17/6/2026 | Dell Data Lakehouse, version(s) 1.0.0.0, contain(s) a Missing Encryption of Sensitive Data vulnerability in the DDAE (Starburst). A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Aplazada | Alta (7.8) | 0.15% | — | Software House C Cure 9000AI | 16/7/2024 | 17/6/2026 | Under certain circumstances the impacted Software House C•CURE 9000 installer will utilize unnecessarily wide permissions. | |
| Aplazada | Alta (7.7) | 0.42% | — | Software House C Cure 9000AI | 10/7/2024 | 17/6/2026 | Under certain circumstances the Software House C●CURE 9000 installer will utilize weak credentials. |