Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2833▲ 79 respecto a la semana anterior
Críticas / altas1316▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
–

23.399 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.28%—Wedevs WP Project ManagerAI15/11/20257/10/2026
La Gestión de Proyectos, Colaboración en Equipo, Tablero Kanban, Diagramas de Gantt, Gestor de Tareas y Más - el plugin WP Project Manager para WordPress es vulnerable a inyección SQL basada en tiempo a través del parámetro 'completed_at_operator' en todas las versiones hasta la 2.6.26, inclusive, debido a un escape…
AnalizadaMedia (5.1)0.17%—Fairsketch Rise Ultimate Project Manager11/11/202517/6/2026
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'first_name' in '/clients/save_contact/'.
AnalizadaMedia (5.1)0.16%—Fairsketch Rise Ultimate Project Manager11/11/202517/6/2026
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in '/tickets/save'.
AnalizadaMedia (5.1)0.16%—Fairsketch Rise Ultimate Project Manager11/11/202517/6/2026
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'custom_field_1' in '/estimate_requests/save_estimate_request'.
AnalizadaMedia (5.1)0.16%—Fairsketch Rise Ultimate Project Manager11/11/202517/6/2026
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'reply_message' in '/messages/reply'.
AnalizadaMedia (5.1)0.16%—Fairsketch Rise Ultimate Project Manager11/11/202517/6/2026
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in '/events/save'.
AnalizadaMedia (5.1)0.16%—Fairsketch Rise Ultimate Project Manager11/11/202517/6/2026
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in'/projects/save'.
AplazadaMedia (5.4)0.20%—Total Book ProjectAI11/11/20257/10/2026
El plugin The Total Book Project para WordPress es vulnerable a Referencia Directa Insegura a Objeto en todas las versiones hasta la 1.0, inclusive, a través de varias funciones debido a la falta de validación en una clave controlada por el usuario. Esto hace posible que atacantes autenticados, con acceso de nivel…
AnalizadaMedia (5.5)0.43%—Projectworlds Online Admission System10/11/20257/10/2026
Una vulnerabilidad fue identificada en projectworlds Online Admission System 1.0. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /process_login.php. La manipulación del argumento keywords conduce a inyección SQL. El ataque puede ser iniciado remotamente. El exploit está disponible…
ModificadaBaja (2.1)0.40%—Projectworlds Online Notes Sharing Platform7/11/20257/10/2026
Una vulnerabilidad fue identificada en projectworlds Online Notes Sharing Platform 1.0. Afectada por este problema es alguna funcionalidad desconocida del archivo /dashboard/userprofile.php. Tal manipulación del argumento image conduce a carga sin restricciones. El ataque puede ser realizado desde remoto. El exploit…
AplazadaCrítica (9.8)0.50%—S2member Project S2memberAI6/11/20257/10/2026
La vulnerabilidad de Deserialización de Datos No Confiables en Cristián Lávaque s2Member s2member permite la Inyección de Objetos. Este problema afecta a s2Member: desde n/a hasta menor o igual que 250701.
AnalizadaCrítica (9.1)19%💥 ExploitDjangoproject Django5/11/202517/6/2026
Se descubrió un problema en 5.1 anterior a 5.1.14, 4.2 anterior a 4.2.26 y 5.2 anterior a 5.2.8. Los métodos 'QuerySet.filter()', 'QuerySet.exclude()' y 'QuerySet.get()', y la clase 'Q()', están sujetos a inyección SQL cuando se utiliza un diccionario adecuadamente diseñado, con expansión de diccionario, como…
AnalizadaAlta (7.5)1.9%💥 PoCDjangoproject Django5/11/202517/6/2026
Se descubrió un problema en 5.1 anterior a 5.1.14, 4.2 anterior a 4.2.26 y 5.2 anterior a 5.2.8. La normalización NFKC en Python es lenta en Windows. Como consecuencia, 'django.http.HttpResponseRedirect', 'django.http.HttpResponsePermanentRedirect' y el atajo 'django.shortcuts.redirect' estuvieron sujetos a un…
AnalizadaMedia (6.7)0.09%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt+14/11/202517/6/2026
In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10010443; Issue ID: MSV-3966.
AnalizadaMedia (6.7)0.09%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt+14/11/202517/6/2026
In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10010441; Issue ID: MSV-3967.
ModificadaMedia (6.5)0.38%—Fairsketch Rise Ultimate Project Manager3/11/20255/7/2026
FairSketch Rise Ultimate Project Manager & CRM 3.9.4 is vulnerable to Insecure Permissions. A remote authenticated user can append comments or upload attachments to tickets for which they lack view or edit authorization, due to missing authorization checks in the ticketing/commenting API.
AnalizadaCrítica (9.8)0.55%—Car-booking-system-php Project Car-booking-system-php3/11/202517/6/2026
Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/contact.php.
AnalizadaCrítica (9.4)0.47%—Car-booking-system-php Project Car-booking-system-php3/11/202517/6/2026
Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/forgot-pass.php.
AnalizadaCrítica (9.8)0.55%—Car-booking-system-php Project Car-booking-system-php3/11/202517/6/2026
Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/sign-in.php.
AnalizadaMedia (5.4)0.29%—Car-booking-system-php Project Car-booking-system-php3/11/202517/6/2026
Car-Booking-System-PHP v.1.0 is vulnerable to Cross Site Scripting (XSS) in /carlux/booking.php.
AnalizadaMedia (5.4)0.30%—Water Management System Project Water Management System3/11/202517/6/2026
Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /orders.php.
AnalizadaMedia (6.1)0.30%—Water Management System Project Water Management System3/11/202517/6/2026
Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /edit_product.php?id=1.
AnalizadaMedia (6.1)0.30%—Water Management System Project Water Management System3/11/202517/6/2026
Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /add_customer.php.
AnalizadaMedia (6.1)0.30%—Water Management System Project Water Management System3/11/202517/6/2026
Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /add_vendor.php.
AnalizadaMedia (5.4)0.24%—School Management System PHP Project School Management System PHP3/11/202517/6/2026
School Management System PHP v1.0 is vulnerable to Cross Site Scripting (XSS) in /login.php via the password parameter.