Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

349 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.56%—Clickhouse3/9/202417/6/2026
ClickHouse v24.3.3.102 was discovered to contain a buffer overflow via the component DB::evaluateConstantExpressionImpl.
AnalizadaAlta (8.8)0.30%—Siamonhasan Warehouse Inventory System20/8/202417/6/2026
A Cross-Site Request Forgery (CSRF) in the component categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.
AnalizadaAlta (8.8)0.31%—Siamonhasan Warehouse Inventory System20/8/202417/6/2026
A Cross-Site Request Forgery (CSRF) in the component delete_media.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.
ModificadaAlta (8.8)0.31%—Siamonhasan Warehouse Inventory System20/8/202417/6/2026
A Cross-Site Request Forgery (CSRF) in the component delete_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.
AnalizadaAlta (8.8)0.31%—Siamonhasan Warehouse Inventory System20/8/202417/6/2026
A Cross-Site Request Forgery (CSRF) in the component delete_user.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.
AnalizadaAlta (8.8)0.31%—Siamonhasan Warehouse Inventory System20/8/202417/6/2026
A Cross-Site Request Forgery (CSRF) in the component delete_categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.
AnalizadaAlta (8.8)0.31%—Siamonhasan Warehouse Inventory System20/8/202417/6/2026
A Cross-Site Request Forgery (CSRF) in the component delete_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.
AnalizadaAlta (8.8)0.22%—Siamonhasan Warehouse Inventory System20/8/202417/6/2026
A Cross-Site Request Forgery (CSRF) in the component edit_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.
ModificadaAlta (8.8)0.31%—Siamonhasan Warehouse Inventory System20/8/202417/6/2026
A Cross-Site Request Forgery (CSRF) in the component add_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.
AnalizadaAlta (8)0.30%—Siamonhasan Warehouse Inventory System20/8/202417/6/2026
A Cross-Site Request Forgery (CSRF) in the component edit_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.
ModificadaAlta (8.8)0.31%—Siamonhasan Warehouse Inventory System20/8/202417/6/2026
A Cross-Site Request Forgery (CSRF) in the component add_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.
AnalizadaAlta (8.8)0.31%—Siamonhasan Warehouse Inventory System20/8/202417/6/2026
A Cross-Site Request Forgery (CSRF) in the component edit_categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.
AnalizadaMedia (5.3)0.44%—Mayurik Best House Rental Management System15/8/202417/6/2026
A vulnerability classified as problematic was found in SourceCodester Best House Rental Management System 1.0. This vulnerability affects unknown code of the file /rental_0/rental/ajax.php?action=save_tenant of the component POST Parameter Handler. The manipulation of the argument lastname leads to cross site…
AnalizadaAlta (8)0.30%—Mayurik Best House Rental Management12/8/202417/6/2026
A Cross-Site Request Forgery (CSRF) vulnerability was found in SourceCodester Best House Rental Management System v1.0. This could lead to an attacker tricking the administrator into adding/modifying/deleting valid tenant data via a crafted HTML page, as demonstrated by a Delete Tenant action at the…
AnalizadaAlta (8.8)0.53%—Mayurik Best House Rental Management System12/8/202417/6/2026
SourceCodester Best House Rental Management System v1.0 is vulnerable to Incorrect Access Control via /rental/payment_report.php, /rental/balance_report.php, /rental/invoices.php, /rental/tenants.php, and /rental/users.php.
AnalizadaMedia (5.4)0.52%—Mayurik Best House Rental Management System12/8/202417/6/2026
A Reflected Cross Site Scripting (XSS) vulnerability was found in "edit-cate.php" in SourceCodester House Rental Management System v1.0.
ModificadaMedia (5.4)0.64%—Mayurik Best House Rental Management System12/8/202417/6/2026
A Stored Cross Site Scripting (XSS) vulnerability was found in "manage_houses.php" in SourceCodester Best House Rental Management System v1.0. It allows remote attackers to execute arbitrary code via "House_no" and "Description" parameter fields.
AnalizadaMedia (4.8)0.33%—Shawon786 House Manager7/8/202417/6/2026
The House Manager WordPress plugin through 1.0.8.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
AnalizadaMedia (6.9)0.37%—Siamonhasan Warehouse Inventory System4/8/202417/6/2026
A vulnerability was found in OSWAPP Warehouse Inventory System 1.0/2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /change_password.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been…
AnalizadaMedia (6.9)0.37%—Siamonhasan Warehouse Inventory System4/8/202417/6/2026
A vulnerability was found in OSWAPP Warehouse Inventory System 1.0/2.0. It has been classified as problematic. Affected is an unknown function of the file /edit_account.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public…
AplazadaAlta (8.1)0.72%—ClickhouseAI1/8/202417/6/2026
It is possible to crash or redirect the execution flow of the ClickHouse server process from an unauthenticated vector by sending a specially crafted request to the ClickHouse server native interface. This redirection is limited to what is available within a 256-byte range of memory at the time of execution, and no…
AnalizadaMedia (4.7)0.83%—Mayurik Best House Rental Management System29/7/202417/6/2026
Cross Site Scripting vulnerability in Best House Rental Management System 1.0 allows a remote attacker to execute arbitrary code via the "House No" and "Description" parameters in the houses page at the index.php component.
AnalizadaMedia (5.7)0.10%—Dell Data Lakehouse18/7/202417/6/2026
Dell Data Lakehouse, version(s) 1.0.0.0, contain(s) a Missing Encryption of Sensitive Data vulnerability in the DDAE (Starburst). A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure.
AplazadaAlta (7.8)0.15%—Software House C Cure 9000AI16/7/202417/6/2026
Under certain circumstances the impacted Software House C•CURE 9000 installer will utilize unnecessarily wide permissions.
AplazadaAlta (7.7)0.42%—Software House C Cure 9000AI10/7/202417/6/2026
Under certain circumstances the Software House C●CURE 9000 installer will utilize weak credentials.
Orbitaley — Vulnerabilidades