Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▲ 15 respecto a la semana anterior
Críticas / altas1274▼ 248 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
23.398 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.9) | 0.47% | — | Mogublog Project Mogublog | 1/12/2025 | 25/9/2026 | Una vulnerabilidad fue identificada en moxi159753 Mogu Blog v2 hasta la versión 5.2. Este problema afecta a un procesamiento desconocido del archivo /storage/ del componente Storage Management Endpoint Storage Management. La manipulación conduce a la falta de autorización. El ataque puede ser iniciado remotamente. La… | |
| Analizada | Media (5.5) | 0.56% | — | Wtcms Project Wtcms | 30/11/2025 | 3/9/2026 | A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Impacted is the function fetch of the file /index.php. Performing manipulation of the argument content results in code injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. This… | |
| Analizada | Baja (2.1) | 0.32% | — | Wtcms Project Wtcms | 30/11/2025 | 17/6/2026 | A security flaw has been discovered in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. This affects the function check/uncheck/delete of the file application/Comment/Controller/CommentadminController.class.php of the component CommentadminController. The manipulation of the argument ids results in sql… | |
| Analizada | Media (5.5) | 0.38% | — | Wtcms Project Wtcms | 30/11/2025 | 7/10/2026 | Una vulnerabilidad fue identificada en taosir WTCMS hasta 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Afectada por este problema es la función delete del archivo application/Admin/Controller/SlideController.class.php del componente SlideController. La manipulación del argumento ids conduce a inyección SQL. La… | |
| Analizada | Media (6.3) | 0.51% | — | Palletsprojects Werkzeug | 29/11/2025 | 7/10/2026 | Werkzeug es una completa biblioteca de aplicaciones web WSGI. Antes de la versión 3.1.4, la función safe_join de Werkzeug permite segmentos de ruta con nombres de dispositivos de Windows. En Windows, existen nombres de dispositivos especiales como CON, AUX, etc. que están implícitamente presentes y son legibles en… | |
| Aplazada | Crítica (9.4) | 0.42% | — | Cerebrate-project CerebrateAI | 28/11/2025 | 17/6/2026 | UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges (e.g., obtain a higher role such as admin) via the user-edit endpoint by supplying or modifying role_id or organisation_id fields in the edit request. | |
| Modificada | Media (5.5) | 0.20% | — | Libexpat Project Libexpat | 28/11/2025 | 17/6/2026 | In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time. | |
| Modificada | Alta (7.7) | 0.52% | 💥 PoC | Validator Project Validator | 27/11/2025 | 14/7/2026 | Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take into account Unicode variation selectors (\uFE0F, \uFE0E) appearing in a sequence which lead to improper string length calculation. This… | |
| Analizada | Media (6.5) | 0.26% | — | Tinyproxy Project Tinyproxy | 26/11/2025 | 17/6/2026 | Tinyproxy through 1.11.2 contains an integer overflow vulnerability in the strip_return_port() function within src/reqs.c. | |
| Modificada | Alta (7) | 0.33% | — | Webform Multiple File Upload Project Webform Multiple File Upload | 26/11/2025 | 17/6/2026 | Webform Multiple File Upload module for Drupal 7.x contains a cross-site scripting (XSS) vulnerability in the file name renderer. An unauthenticated attacker can exploit this vulnerability by uploading a file with a malicious filename containing JavaScript code (e.g., "<img src=1 onerror=alert(document.domain)>") to a… | |
| Analizada | Media (5.4) | 0.20% | — | Formwork Project Formwork | 26/11/2025 | 17/6/2026 | Formwork is a flat file-based Content Management System (CMS). Prior to version 2.2.0, inserting unsanitized data into the blog tag field results in stored cross‑site scripting (XSS). Any user with credentials to the Formwork CMS who accesses or edits an affected blog post will have attacker‑controlled script executed… | |
| Analizada | Alta (8.8) | 0.73% | — | Fugue-project Fugue | 25/11/2025 | 17/6/2026 | Fugue is a unified interface for distributed computing that lets users execute Python, Pandas, and SQL code on Spark, Dask, and Ray with minimal rewrites. In version 0.9.2 and prior, there is a remote code execution vulnerability by pickle deserialization via FlaskRPCServer. The Fugue framework implements an RPC… | |
| Analizada | Media (5.3) | 0.23% | — | Primakon Project Contract Management | 25/11/2025 | 17/6/2026 | Primakon Pi Portal 1.0.18 API endpoints responsible for retrieving object-specific or filtered data (e.g., user profiles, project records) fail to implement sufficient server-side validation to confirm that the requesting user is authorized to access the requested object or dataset. This vulnerability can be exploited… | |
| Analizada | Alta (8.8) | 0.29% | — | Primakon Project Contract Management | 25/11/2025 | 17/6/2026 | The Primakon Pi Portal 1.0.18 API /api/V2/pp_udfv_admin endpoint, fails to perform necessary server-side validation. The administrative LoginAs or user impersonation feature is vulnerable to a access control failure. This flaw allows any authenticated low-privileged user to execute a direct PATCH request, enabling… | |
| Analizada | Alta (8.8) | 0.29% | — | Primakon Project Contract Management | 25/11/2025 | 17/6/2026 | Primakon Pi Portal 1.0.18 /api/v2/pp_users endpoint fails to adequately check user permissions before processing a PATCH request to modify the PP_SECURITY_PROFILE_ID. Because of weak access controls any low level user can use this API and change their permission to Administrator by using PP_SECURITY_PROFILE_ID=2… | |
| Analizada | Crítica (9.8) | 0.38% | — | Primakon Project Contract Management | 25/11/2025 | 17/6/2026 | Primakon Pi Portal 1.0.18 API endpoints fail to enforce sufficient authorization checks when processing requests. Specifically, a standard user can exploit this flaw by sending direct HTTP requests to administrative endpoints, bypassing the UI restrictions. This allows the attacker to manipulate data outside their… | |
| Analizada | Alta (8.6) | 0.28% | — | Primakon Project Contract Management | 25/11/2025 | 17/6/2026 | Primakon Pi Portal 1.0.18 REST /api/v2/user/register endpoint suffers from a Broken Access Control vulnerability. The endpoint fails to implement any authorization checks, allowing unauthenticated attackers to perform POST requests to register new user accounts in the application's local database. This bypasses the… | |
| Analizada | Alta (8.8) | 0.29% | — | Primakon Project Contract Management | 25/11/2025 | 17/6/2026 | The Primakon Pi Portal 1.0.18 /api/V2/pp_users?email endpoint is used for user data filtering but lacks proper server-side validation against the authenticated session. By manipulating the email parameter to an arbitrary value (e.g., otheruser@user.com), an attacker can assume the session and gain full access to the… | |
| Analizada | Media (4.3) | 0.22% | — | Primakon Project Contract Management | 25/11/2025 | 17/6/2026 | Primakon Pi Portal 1.0.18 /api/v2/users endpoint is vulnerable to unauthorized data exposure due to deficient access control mechanisms. Any authenticated user, regardless of their privilege level (including standard or low-privileged users), can make a GET request to this endpoint and retrieve a complete, unfiltered… | |
| Aplazada | Alta (7.2) | 0.61% | — | ProjectlistAI | 25/11/2025 | 17/6/2026 | The ProjectList plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 0.3.0. This makes it possible for authenticated attackers, with Editor-level access and above, to upload arbitrary files on the affected site's server which may make… | |
| Aplazada | Media (4.9) | 0.31% | — | ProjectlistAI | 25/11/2025 | 17/6/2026 | The ProjectList plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions up to, and including, 0.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers,… | |
| Analizada | Baja (2.1) | 0.31% | — | Code-projects Library System | 24/11/2025 | 8/10/2026 | Se determinó una vulnerabilidad en code-projects Library System 1.0. Se ve afectada una función desconocida del archivo /mail.php. Esta manipulación del argumento ID causa inyección SQL. El ataque puede iniciarse remotamente. El exploit ha sido divulgado públicamente y puede ser utilizado. | |
| Analizada | Baja (2.1) | 0.31% | — | Code-projects Library System | 24/11/2025 | 8/10/2026 | Una vulnerabilidad fue encontrada en code-projects Library System 1.0. Esto impacta una función desconocida del archivo /return.php. La manipulación del argumento ID resulta en inyección SQL. El ataque puede ser lanzado remotamente. El exploit ha sido hecho público y podría ser usado. | |
| Analizada | Media (5.5) | 0.39% | — | Code-projects Library System | 24/11/2025 | 8/10/2026 | Una vulnerabilidad ha sido encontrada en code-projects Library System 1.0. Esto afecta una función desconocida del archivo /index.php del componente Login. La manipulación del argumento Username conduce a inyección SQL. El ataque puede ser iniciado remotamente. El exploit ha sido divulgado al público y puede ser… | |
| Analizada | Baja (2.1) | 0.35% | — | Projectworlds Advanced Library Management System | 23/11/2025 | 8/10/2026 | Una falla de seguridad ha sido descubierta en projectworlds puede pasar cargas útiles maliciosas hasta 1.0. Esta vulnerabilidad afecta código desconocido del archivo /add_book.php. La manipulación del argumento image resulta en subida irrestricta. El ataque puede ser ejecutado remotamente. El exploit ha sido publicado… |