Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
23.398 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2) | 0.34% | — | Anirbandutta News-buzzCode-projects Content Management System | 29/12/2025 | 7/10/2026 | Una falla de seguridad ha sido descubierta en code-projects/anirbandutta9 Content Management System y News-Buzz 1.0. Esta vulnerabilidad afecta código desconocido del archivo /admin/editposts.php. Realizar la manipulación del argumento image resulta en una carga sin restricciones. El ataque puede ser iniciado… | |
| Analizada | Media (5.5) | 0.43% | — | Code-projects Assessment Management | 29/12/2025 | 7/10/2026 | Una vulnerabilidad fue identificada en code-projects Assessment Management 1.0. Esto afecta una parte desconocida del archivo login.PHP. Dicha manipulación del argumento userid conduce a inyección SQL. El ataque puede ser lanzado remotamente. El exploit está disponible públicamente y podría ser usado. | |
| Analizada | Media (5.5) | 0.43% | — | Code-projects Assessment Management | 29/12/2025 | 7/10/2026 | Una vulnerabilidad fue determinada en code-projects Assessment Management 1.0. Afectada por este problema es alguna funcionalidad desconocida del archivo /admin/add-module.PHP. Esta manipulación del argumento linked[] causa inyección SQL. El ataque puede iniciarse remotamente. El exploit ha sido divulgado públicamente… | |
| Aplazada | Baja (2.1) | 0.32% | — | Omec-project UPFAI | 28/12/2025 | 7/10/2026 | Se ha encontrado una vulnerabilidad en omec-project UPF hasta la versión 2.1.3-dev. Esto afecta a la función handleSessionEstablishmentRequest del archivo /pfcpiface/pfcpiface/messages_session.go del componente Manejador de Solicitudes de Establecimiento de Sesión PFCP. Esta manipulación provoca una desreferenciación… | |
| Analizada | Alta (7.5) | 0.42% | — | Libxmljs Project Libxmljs | 26/12/2025 | 17/6/2026 | A vulnerability exists in the libxmljs 1.0.11 when parsing a specially crafted XML document. Accessing the internal _ref property on entity_ref and entity_decl nodes causes a segmentation fault, potentially leading to a denial-of-service (DoS). | |
| Analizada | Media (6.2) | 0.23% | — | Unrtf Project Unrtf | 23/12/2025 | 17/6/2026 | A stack overflow in the src/main.c component of GNU Unrtf v0.21.10 allows attackers to cause a Denial of Service (DoS) via injecting a crafted input into the filename parameter. | |
| Analizada | Alta (8.7) | 0.95% | — | Projectsend | 22/12/2025 | 17/6/2026 | ProjectSend r1605 contains a remote code execution vulnerability that allows attackers to upload malicious files by manipulating file extensions. Attackers can upload shell scripts with disguised extensions through the upload.process.php endpoint to execute arbitrary commands on the server. | |
| Modificada | Crítica (9.3) | 0.43% | — | Webtareas Project Webtareas | 22/12/2025 | 17/6/2026 | WebTareas 2.4 contains a SQL injection vulnerability in the webTareasSID cookie parameter that allows unauthenticated attackers to manipulate database queries. Attackers can exploit error-based and time-based blind SQL injection techniques to extract database information and potentially access sensitive system data. | |
| Analizada | Alta (8.7) | 0.48% | — | Webtareas Project Webtareas | 22/12/2025 | 17/6/2026 | WebTareas 2.4 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the chat photo upload functionality. Attackers can upload a PHP file with arbitrary code to the /files/Messages/ directory and execute it directly through the generated file path. | |
| Aplazada | Crítica (9.5) | 0.30% | — | Sharp Display Solutions ProjectorAI | 22/12/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sharp Display Solutions projectors allows a attacker may improperly access the HTTP server and execute arbitrary actions. | |
| Aplazada | Crítica (9.5) | 0.30% | — | Sharp Display Solutions ProjectorsAI | 22/12/2025 | 17/6/2026 | Improper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may create and run unauthorized firmware. | |
| Analizada | Alta (8.8) | 0.26% | — | Fastapi-users Project Fastapi Users | 19/12/2025 | 17/6/2026 | FastAPI Users allows users to quickly add a registration and authentication system to their FastAPI project. Prior to version 15.0.2, the OAuth login state tokens are completely stateless and carry no per-request entropy or any data that could link them to the session that initiated the OAuth flow.… | |
| Analizada | Alta (8.5) | 0.85% | — | Filezilla-project Filezilla Client | 19/12/2025 | 17/6/2026 | FileZilla Client 3.63.1 contains a DLL hijacking vulnerability that allows attackers to execute malicious code by placing a crafted TextShaping.dll in the application directory. Attackers can generate a reverse shell payload using msfvenom and replace the missing DLL to achieve remote code execution when the… | |
| Aplazada | Alta (8.6) | 0.41% | — | Ltb-project Self Service PasswordAI | 19/12/2025 | 17/6/2026 | LDAP Tool Box Self Service Password 1.5.2 contains a password reset vulnerability that allows attackers to manipulate HTTP Host headers during token generation. Attackers can craft malicious password reset requests that generate tokens sent to a controlled server, enabling potential account takeover by intercepting… | |
| Analizada | Media (6.9) | 0.27% | — | Proxychains-ng Project Proxychains-ng | 18/12/2025 | 17/6/2026 | rofl0r/proxychains-ng versions up to and including 4.17 and prior to commit cc005b7 contain a stack-based buffer overflow vulnerability in the function proxy_from_string() located in src/libproxychains.c. When parsing crafted proxy configuration entries containing overly long username or password fields, the… | |
| Analizada | Media (6.9) | 0.23% | — | RTL 433 Project RTL 433 | 18/12/2025 | 17/6/2026 | merbanan/rtl_433 versions up to and including 25.02 and prior to commit 25e47f8 contain a stack-based buffer overflow vulnerability in the function parse_rfraw() located in src/rfraw.c. When processing crafted or excessively large raw RF input data, the application may write beyond the bounds of a stack buffer,… | |
| Analizada | Media (6.9) | 0.35% | — | Glpi-project Glpi | 18/12/2025 | 17/6/2026 | GLPI 9.5.7 contains a username enumeration vulnerability in the lost password recovery mechanism that allows attackers to validate email addresses. Attackers can systematically test email addresses by submitting requests to the password reset endpoint and analyzing response differences to identify valid user accounts. | |
| Aplazada | Alta (7.5) | 0.46% | — | Code-projects Task ManagerAI | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Agence web Eoxia – Montpellier Task Manager task-manager allows PHP Local File Inclusion.This issue affects Task Manager: from n/a through <= 3.0.2. | |
| Analizada | Media (6.3) | 7.2% | — | Lfprojects Model Context Protocol Servers | 17/12/2025 | 17/6/2026 | In mcp-server-git versions prior to 2025.12.17, the git_diff and git_checkout functions passed user-controlled arguments directly to git CLI commands without sanitization. Flag-like values (e.g., `--output=/path/to/file` for `git_diff`) would be interpreted as command-line options rather than git refs, enabling… | |
| Modificada | Alta (7.1) | 0.38% | — | Projectsend | 17/12/2025 | 17/6/2026 | ProjectSend r1605 contains an insecure direct object reference vulnerability that allows unauthenticated attackers to download private files by manipulating the download ID parameter. Attackers can access any user's private files by changing the 'id' parameter in the download request to process.php. | |
| Modificada | Media (5.1) | 0.31% | — | Projectsend | 17/12/2025 | 17/6/2026 | projectSend r1605 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript through the custom assets configuration page. Attackers can craft a JavaScript payload in the custom assets section that will execute when other users load the affected page,… | |
| Modificada | Media (6.2) | 0.50% | — | Projectsend | 17/12/2025 | 17/6/2026 | ProjectSend r1605 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into user profile names. Attackers can craft payloads like =calc|a!z| in the name field to trigger code execution when administrators export action logs as CSV files. | |
| Analizada | Media (6.4) | 7.0% | — | Lfprojects Model Context Protocol Servers | 17/12/2025 | 30/9/2026 | En versiones de mcp-server-git anteriores a 2025.12.17, cuando el servidor se inicia con la bandera --repository para restringir las operaciones a una ruta de repositorio específica, no validaba que los argumentos repo_path en llamadas de herramientas posteriores estuvieran realmente dentro de esa ruta configurada.… | |
| Analizada | Media (6.5) | 8.1% | — | Lfprojects Model Context Protocol Servers | 17/12/2025 | 30/9/2026 | Servidores de Protocolo de Contexto de Modelo es una colección de implementaciones de referencia para el protocolo de contexto de modelo (MCP). En versiones de mcp-server-git anteriores a 2025.9.25, la herramienta git_init aceptaba rutas de sistema de archivos arbitrarias y creaba repositorios Git sin validar la… | |
| Analizada | Media (6.1) | 0.22% | — | Slims Project Slims | 17/12/2025 | 17/6/2026 | Reflected cross-site scripting (XSS) in SLiMS (slims9_bulian) before 9.6.0 via improper handling of $_SERVER['PHP_SELF' ] in index.php/sysconfig.inc.php, which allows remote attackers to execute arbitrary JavaScript in a victim's browser by supplying a crafted URL path. |