Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3008▲ 385 respecto a la semana anterior
Críticas / altas1453▲ 24 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
23.914 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.22% | — | Slims Project Slims | 17/12/2025 | 17/6/2026 | Reflected cross-site scripting (XSS) in SLiMS (slims9_bulian) before 9.6.0 via improper handling of $_SERVER['PHP_SELF' ] in index.php/sysconfig.inc.php, which allows remote attackers to execute arbitrary JavaScript in a victim's browser by supplying a crafted URL path. | |
| Modificada | Alta (7.5) | 0.26% | — | Jose4j Project Jose4j | 17/12/2025 | 17/6/2026 | In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression. | |
| Analizada | Media (5.3) | 0.19% | — | Python-jose Project Python-jose | 17/12/2025 | 17/6/2026 | In python-jose 3.3.0 (specifically jwe.decrypt), a vulnerability allows an attacker to cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation… | |
| Aplazada | Media (4.9) | 0.69% | — | Zephyr Project ManagerAI | 17/12/2025 | 28/9/2026 | El plugin Zephyr Project Manager para WordPress es vulnerable a salto de directorio en todas las versiones hasta la 3.3.203, inclusive, a través del parámetro 'file'. Esto permite a atacantes autenticados, con acceso de nivel Custom o superior, leer el contenido de archivos arbitrarios en el servidor, que pueden… | |
| Analizada | Media (4.3) | 0.22% | — | Glpi-project Glpi | 16/12/2025 | 17/6/2026 | GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.21, an unauthorized user with an API access can read all knowledge base entries. Users should upgrade to 10.0.21 to receive a patch. | |
| Analizada | Media (6.5) | 0.29% | — | Glpi-project Glpi | 16/12/2025 | 17/6/2026 | GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.21, an unauthenticated user can store an XSS payload through the inventory endpoint. Users should upgrade to 10.0.21 to receive a patch. | |
| Analizada | Baja (2.1) | 0.45% | — | Ctcms Project Ctcms | 15/12/2025 | 7/10/2026 | Se ha identificado una debilidad en el sistema de gestión de contenidos CTCMS hasta la versión 2.1.2. Esto afecta a una función desconocida en la biblioteca /ctcms/apps/libraries/CT_Parser.php del componente Frontend/Módulo de Gestión de Plantillas. Esta manipulación causa una neutralización incorrecta de elementos… | |
| Analizada | Baja (2) | 0.46% | — | Ctcms Project Ctcms | 15/12/2025 | 7/10/2026 | Una falla de seguridad ha sido descubierta en el Sistema de Gestión de Contenidos CTCMS hasta la versión 2.1.2. El elemento afectado es una función desconocida en la biblioteca /ctcms/libs/Ct_Config.php del componente Módulo de Configuración del Sistema de Backend. La manipulación del argumento Cj_Add/Cj_Edit resulta… | |
| Analizada | Baja (2) | 0.46% | — | Ctcms Project Ctcms | 15/12/2025 | 7/10/2026 | Se identificó una vulnerabilidad en el sistema de gestión de contenido CTCMS hasta 2.1.2. El elemento afectado es la función Save del archivo /ctcms/libs/Ct_App.php del componente Backend App Configuration Module. La manipulación del argumento CT_App_Paytype conduce a la inyección de código. La explotación remota del… | |
| Analizada | Media (5.3) | 0.35% | — | Inventory Management System Project Inventory Management System | 15/12/2025 | 17/6/2026 | Inventory Management System 1 was discovered to contain a SQL injection vulnerability. | |
| Analizada | Media (6.1) | 0.22% | — | Inventory Management System Project Inventory Management System | 15/12/2025 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in the component /index.php/cuzh4 of PHP Inventory Management System 1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |
| Aplazada | Crítica (9.1) | 0.69% | — | Redhat Openshift GitopsAIArgoproj ArgocdAI | 15/12/2025 | 7/10/2026 | Se encontró una vulnerabilidad en OpenShift GitOps. Los administradores de espacios de nombres pueden crear Recursos Personalizados (CRs) de ArgoCD que engañan al sistema para otorgarles permisos elevados en otros espacios de nombres, incluyendo espacios de nombres privilegiados. Un atacante autenticado puede luego… | |
| Analizada | Media (6.5) | 0.26% | — | Wekan Project Wekan | 15/12/2025 | 17/6/2026 | An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authorization flaw in card update handling allows board members (and potentially other authenticated users) to add/remove arbitrary user IDs in vote.positive / vote.negative arrays, enabling vote forgery and… | |
| Analizada | Alta (8.2) | 0.34% | — | Wekan Project Wekan | 15/12/2025 | 17/6/2026 | An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upload API treats the Authorization bearer value as a userId and enters a non-terminating body-handling branch for any non-empty bearer token, enabling trivial application-layer DoS and latent… | |
| Analizada | Alta (8.8) | 0.34% | — | Wekan Project Wekan | 15/12/2025 | 17/6/2026 | An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authenticated users can update their entire user document (beyond profile fields), including orgs/teams and loginDisabled, due to missing server-side authorization checks; this enables privilege escalation and… | |
| Analizada | Alta (7.5) | 0.31% | — | Wekan Project Wekan | 15/12/2025 | 17/6/2026 | An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Unauthenticated attackers can update a board's "sort" value (Boards.allow returns true without verifying userId), allowing arbitrary reordering of boards. | |
| Analizada | Alta (8.1) | 0.38% | — | Wekan Project Wekan | 15/12/2025 | 17/6/2026 | An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Uploaded attachments can be served with attacker-controlled Content-Type (text/html), allowing execution of attacker-supplied HTML/JS in the application's origin and enabling session/token theft and CSRF actions. | |
| Modificada | Crítica (9) | 0.33% | 💥 PoC | Misp-project Misp | 15/12/2025 | 22/6/2026 | In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path. | |
| Analizada | Media (5.5) | 0.43% | — | Projectworlds Advanced Library Management System | 12/12/2025 | 7/10/2026 | Se ha encontrado una vulnerabilidad en projectworlds Advanced Library Management System 1.0. Afectada por este problema es alguna funcionalidad desconocida del archivo /borrow_book.php. Dicha manipulación del argumento roll_number conduce a inyección SQL. El ataque puede lanzarse remotamente. El exploit ha sido… | |
| Analizada | Media (5.5) | 0.43% | — | Projectworlds Advanced Library Management System | 12/12/2025 | 7/10/2026 | Se ha encontrado una falla en projectworlds Advanced Library Management System 1.0. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /view_admin.php. Esta manipulación del argumento admin_id causa inyección SQL. El ataque puede ser iniciado remotamente. El exploit ha sido publicado y puede… | |
| Analizada | Alta (8.7) | 3.4% | — | Yogeshojha Rengine | 11/12/2025 | 17/6/2026 | reNgine 2.2.0 contains a command injection vulnerability in the nmap_cmd parameter of scan engine configuration that allows authenticated attackers to execute arbitrary commands. Attackers can modify the nmap_cmd parameter with malicious base64-encoded payloads to achieve remote code execution during scan engine… | |
| Analizada | Media (5.3) | 0.36% | — | Quic-go Project Quic-go | 11/12/2025 | 17/6/2026 | quic-go is an implementation of the QUIC protocol in Go. Versions 0.56.0 and below are vulnerable to excessive memory allocation through quic-go's HTTP/3 client and server implementations by sending a QPACK-encoded HEADERS frame that decodes into a large header field section (many unique header names and/or large… | |
| Analizada | Crítica (9.8) | 0.54% | — | Easyimages2.0 Project Easyimages2.0 | 11/12/2025 | 17/6/2026 | An arbitrary file rename vulnerability in the /admin/manager.php component of EasyImages 2.0 v2.8.6 and below allows attackers to execute arbitrary code via renaming a PHP file to a SVG format. | |
| Analizada | Crítica (9.1) | 0.57% | — | Easyimages2.0 Project Easyimages2.0 | 11/12/2025 | 17/6/2026 | An arbitrary file rename vulnerability in the /admin/filer.php component of EasyImages 2.0 v2.8.6 and below allows attackers with Administrator privileges to execute arbitrary code via injecting a crafted payload into an uploaded file name. | |
| Analizada | Alta (8.8) | 0.21% | — | Easyimages2.0 Project Easyimages2.0 | 11/12/2025 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the /admin/admin.inc.php component of EasyImages 2.0 v2.8.6 and below allows attackers to escalate privileges to Administrator via user interaction with a malicious web page. |