Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2834▲ 81 respecto a la semana anterior
Críticas / altas1316▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
21.078 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.54% | — | FrappeAI | 10/7/2026 | 13/7/2026 | Frappe is a full-stack web application framework. Prior to 16.19.0, authorization bypass was possible via the update_page endpoint in Workspace because public workspaces did not receive the required Workspace Manager edit check. This issue is fixed in version 16.19.0. | |
| Aplazada | Media (5.3) | 0.61% | — | FrappeAI | 10/7/2026 | 14/7/2026 | Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.110.0, users without write access could attach files to any doctype through file-handling API endpoints such as add_attachments. This issue is fixed in versions 16.20.0 and 15.110.0. | |
| Aplazada | Media (5.3) | 0.38% | — | FrappeAI | 10/7/2026 | 14/7/2026 | Frappe is a full-stack web application framework. Prior to 15.107.5 and 16.18.2, an endpoint in reportview lacked appropriate permission checks and that has since been fixed. This vulnerability is fixed in 15.107.5 and 16.18.2. | |
| Aplazada | Baja (2.3) | 0.55% | — | FrappeAI | 10/7/2026 | 13/7/2026 | Frappe is a full-stack web application framework. Prior to 16.18.3 and 15.108.0, check_safe_sql_query permitted SELECT INTO OUTFILE queries, which could potentially work on self-hosted sites if database permissions are not well aligned and MySQL FILE privileges are available. This issue is fixed in versions 16.18.3… | |
| Aplazada | Media (6.9) | 0.68% | — | FrappeAI | 10/7/2026 | 13/7/2026 | Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, path traversal via download_backups was possible due to lack of hardening. This issue is fixed in versions 16.19.0 and 15.109.0. | |
| Aplazada | Alta (7.1) | 0.50% | — | FrappeAIGoogle ChromeAI | 10/7/2026 | 13/7/2026 | Frappe is a full-stack web application framework. Prior to 16.18.3, possible path traversal and local file inclusion were possible through secure local resource access in the Chrome PDF Generator. This issue is fixed in version 16.18.3. | |
| Analizada | Media (5) | 0.34% | — | Snipeitapp Snipe-it | 10/7/2026 | 14/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report delete endpoint authorizes only reports.view and deletes CheckoutAcceptance::pending()->find($acceptanceId) by global ID without checking access to the related checkoutable asset, allowing a reports user in one company to… | |
| Analizada | Media (6.2) | 0.32% | — | Snipeitapp Snipe-it | 10/7/2026 | 14/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, default.blade.php renders header_color and related branding color settings inside a CSS style block with HTML escaping that is insufficient for the CSS context, allowing a superadmin to inject arbitrary CSS that affects authenticated users on… | |
| Analizada | Media (5.3) | 0.33% | — | Snipeitapp Snipe-it | 10/7/2026 | 14/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the legacy single-seat license checkin flow authorizes the action with the checkout permission instead of the checkin permission, allowing a user who can assign licenses but not unassign them to directly access the old checkin endpoint and reclaim a… | |
| Analizada | Media (5.7) | 0.34% | — | Snipeitapp Snipe-it | 10/7/2026 | 14/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV import capabilities and a valid API key to overwrite the created_by value of an import file, allowing unauthorized modification of import ownership metadata. This issue is fixed in version 8.6.1. | |
| Analizada | Media (6.5) | 0.59% | — | Snipeitapp Snipe-it | 10/7/2026 | 14/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated user with import and assets.update permissions can place a path traversal string in an asset image field through CSV import and then trigger image deletion, allowing deletion of arbitrary files accessible to the server process. This… | |
| Analizada | Media (6.2) | 0.44% | — | Snipeitapp Snipe-it | 10/7/2026 | 14/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UploadFileRequest sanitizes SVG content only when PHP finfo reports image/svg+xml and UploadedFilesController serves attachments inline without using StorageHelper::allowSafeInline(), allowing a low-privilege user to upload active XHTML or XML content… | |
| Analizada | Media (4.3) | 0.34% | — | Snipeitapp Snipe-it | 10/7/2026 | 14/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UsersController::show() and printInventory() authorize only user viewing before loading and rendering assigned license, accessory, and consumable relationships, allowing an authenticated user with only users.view to see inventory and cost/order… | |
| Analizada | Media (6.1) | 0.31% | — | Snipeitapp Snipe-it | 10/7/2026 | 14/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the user edit flow stores url()->previous() from the attacker-controlled Referer header into Laravel’s intended URL session value and later uses redirect()->intended(...) when redirect_option=back is submitted, allowing Snipe-IT to be used as a trusted… | |
| Analizada | Media (4.8) | 0.43% | — | Snipeitapp Snipe-it | 10/7/2026 | 14/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Actionlog::logaction() stores the request User-Agent header and ReportsController::postActivityReport() writes that value to the Activity Report CSV without formula escaping, allowing a low-privileged authenticated user to store a formula-like… | |
| Analizada | Alta (7) | 0.54% | — | Snipeitapp Snipe-it | 10/7/2026 | 13/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.0, UsersController::update() passes a missing permission request field through NormalizePermissionsPayloadAction and PreserveUnauthorizedPrivilegedPermissionsAction in a way that can overwrite a target user’s permissions with a sparse result, allowing an… | |
| Analizada | Alta (7.7) | 0.38% | — | Snipeitapp Snipe-it | 10/7/2026 | 14/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, PATCH or PUT /api/v1/maintenances/{maintenance_id} checks access to the current maintenance record and asset but then fills attacker-controlled fields including asset_id without re-authorizing the newly supplied asset, allowing an authorized user to… | |
| Analizada | Media (5.3) | 0.29% | — | Snipeitapp Snipe-it | 10/7/2026 | 10/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, POST /api/v1/kits/{kit_id}/licenses checks whether the caller can edit kits but does not authorize access to the referenced license object, allowing a low-privilege user with predefined-kit permissions to bind a license they should not be able to… | |
| Analizada | Media (5.3) | 0.34% | — | Snipeitapp Snipe-it | 10/7/2026 | 13/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.0, POST /account/request/{itemType}/{itemId}/{cancel_by_admin?}/{requestingUser?} accepts cancel_by_admin as a URL path segment without sufficient authorization, allowing an authenticated user to supply a victim user ID and silently cancel that user’s… | |
| Analizada | Alta (7.1) | 0.48% | — | Snipeitapp Snipe-it | 10/7/2026 | 10/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the route filename parameter into a private upload-directory path without sanitization, allowing an authenticated attacker to traverse outside the intended directory and read arbitrary files accessible to… | |
| Analizada | Media (4.3) | 0.33% | — | Snipeitapp Snipe-it | 10/7/2026 | 13/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, when Full Multiple Companies Support and scope_locations_fmcs are enabled, the API location creation endpoint detects an invalid parent-child company mismatch but does not return immediately, allowing creation of a child location under a parent… | |
| Analizada | Media (4.8) | 0.29% | — | Snipeitapp Snipe-it | 10/7/2026 | 13/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, CommonMark escapes raw HTML but does not sanitize javascript: URIs in Markdown hyperlinks, allowing a user with assets.edit permission to place a malicious link in a markdown-textarea custom field that executes arbitrary JavaScript when another user… | |
| Modificada | Alta (7.1) | 0.44% | — | Snipeitapp Snipe-it | 10/7/2026 | 14/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated non-admin user with users.view and users.edit but without users.delete can directly POST to /users/bulksave with delete_user=1 because BulkUsersController::destroy() authorizes only update, allowing the user to soft-delete another… | |
| Analizada | Alta (7.7) | 0.39% | — | Snipeitapp Snipe-it | 10/7/2026 | 10/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request parameters to the Accessory model while company_id is mass assignable, allowing a low-privileged authenticated user in one company to create accessory records under another company when Full Multiple… | |
| Aplazada | Baja (3.1) | 0.32% | — | Nuxref AppriseAI | 10/7/2026 | 10/7/2026 | Apprise is an open source library which allows you to send a notification to almost all of the most popular notification services available. Prior to 1.11.0, Apprise HTTP-based notification plugins and HTTP attachment and config loaders in apprise/attachment/http.py and apprise/config/http.py follow HTTP redirects by… |