Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
40.015 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.28% | — | FineadminAI | 5/10/2026 | 6/10/2026 | FineAdmin v1.0 was discovered to contain a SQL injection vulnerability via the field/order parameter at ButtonService.GetListByFilter(). This vulnerability allows attackers to access sensitive database information via crafted SQL statements. | |
| Aplazada | Crítica (9.8) | 0.46% | — | PlaneAI | 5/10/2026 | 5/10/2026 | Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and deployments/cli/community/ manifests provide fixed, publicly known SECRET_KEY and LIVE_SERVER_SECRET_KEY defaults that remain active when operators do not override them. The top-level setup.sh randomizes secrets only… | |
| Aplazada | Crítica (9.1) | 0.38% | — | PlaneAI | 5/10/2026 | 5/10/2026 | Plane is an open-source project management tool. Prior to 1.4.0, Plane trusts email addresses returned by Gitea OAuth and by self-managed GitLab OAuth deployments where email confirmation is disabled, without verifying that the provider authenticated ownership of the address. An attacker can set an OAuth identity's… | |
| Aplazada | Crítica (9.8) | 0.39% | — | PlaneAI | 5/10/2026 | 6/10/2026 | Plane is an open-source project management tool. Prior to 1.4.0, Plane's signup flow creates a logged-in User row for any submitted email without an out-of-band ownership check, while User.email is unique=True. The authenticated user can call GET /api/users/me/workspaces/invitations/, which returns each… | |
| Aplazada | Crítica (9.1) | 0.38% | — | PlaneAI | 5/10/2026 | 5/10/2026 | Plane is an open-source project management tool. Prior to 1.4.0, Plane's magic-code email login uses a six-digit numeric OTP with approximately 20 bits of entropy. The verifier has no per-code failed-attempt counter, and an incorrect code does not increment a counter, invalidate the Redis entry, or lock the email… | |
| Aplazada | Crítica (9.6) | 0.32% | — | PlaneAI | 5/10/2026 | 5/10/2026 | Plane is an open-source project management tool. Prior to 1.4.0, ProjectBulkAssetEndpoint.post in apps/api/plane/app/views/asset/v2.py retrieves assets using id__in=asset_ids and workspace__slug=slug but does not constrain the query with project_id from the URL. A workspace Guest can provide asset UUIDs from another… | |
| Aplazada | Crítica (9.9) | 0.35% | — | PlaneAI | 5/10/2026 | 5/10/2026 | Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook_task.py calls requests.post() without allow_redirects=False and does not validate redirect targets. validate_url() blocks private, loopback, link-local, and reserved addresses in the original… | |
| Pendiente de análisis | Crítica (9.8) | 0.86% | — | Apache StrutsAI | 5/10/2026 | 6/10/2026 | Improper neutralization of special elements used in an expression language statement ('Expression Language Injection') vulnerability in Apache Struts. If the application is configured to use the legacy RESTful action mapper, a crafted request can inject an OGNL expression that may lead to remote code execution. Struts… | |
| Aplazada | Crítica (9.3) | 0.25% | — | Wp-base WP Base BookingAI | 5/10/2026 | 6/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n/a through 6.4.0. | |
| Aplazada | Crítica (9.8) | 0.39% | — | GouguoaAI | 5/10/2026 | 6/10/2026 | GouGuOA v6.0.5 and before is vulnerable to SQL Injection in /home/message/rubbish via the keywords parameter. | |
| Aplazada | Crítica (9.8) | 0.39% | — | WookteamAI | 5/10/2026 | 6/10/2026 | WookTeam v1.6.6 and before is vulnerable to RCE in the project task export interface /api/project/task/export. The data parameter is base64-decoded and passed directly into the string2array() function in app/Module/Base.php, which executes eval("\$array = $data;") whenever the decoded string starts with array. An… | |
| Aplazada | Crítica (9.8) | 0.74% | — | Dormakaba Evolo ServiceAI | 5/10/2026 | 6/10/2026 | An issue in dormakaba evolo Service (all versions) allows a remote attacker to execute arbitrary code as SYSTEM via a .NET component. | |
| Pendiente de análisis | Crítica (9.3) | 0.28% | — | Ordasoft Joomla CCKAI | 5/10/2026 | 6/10/2026 | Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Joomla CCK < 8.3.16 - The order column for records was user provided and not properly validated, leading to a SQL injection vector. | |
| Pendiente de análisis | Crítica (9.8) | 0.36% | — | Dromara NorthstarAI | 5/10/2026 | 6/10/2026 | Northstar (dromara/northstar, quantitative trading platform) <= 9.1.1 enables the H2 Console but its auth interceptor only covers /northstar/**, so /h2-console is exposed with no authentication and the embedded H2 DB uses default sa / empty password. Any network-reachable attacker can run arbitrary system commands via… | |
| Pendiente de análisis | Crítica (9) | 0.27% | — | HPE Integrated Lights OUT 7AI | 5/10/2026 | 6/10/2026 | A remote user validation failure vulnerability exists in HPE Integrated Lights-Out (iLO) 7 firmware. | |
| Aplazada | Crítica (9.3) | 0.64% | — | Totolink A3002muAI | 5/10/2026 | 6/10/2026 | A security vulnerability has been detected in Totolink A3002MU 1.0.0-B20230403.1455. This affects an unknown function of the file /boafrm/formIpQoS of the component QoS Rule Handler. The manipulation of the argument addQos/comment/entry_name leads to stack-based buffer overflow. Remote exploitation of the attack is… | |
| Aplazada | Crítica (9.3) | 0.78% | — | Totolink A3002muAI | 5/10/2026 | 6/10/2026 | A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The impacted element is the function sub_40FCFC of the file /bin/boa of the component Authentication Check. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been made available to… | |
| Pendiente de análisis | Crítica (9.5) | 0.35% | — | Perforce P4 SearchAI | 5/10/2026 | 6/10/2026 | P4 Search prior to 2026.4.2 does not fail securely when its service authentication token is blank. In affected configurations, an unauthenticated attacker with network access can obtain the highest application privilege, potentially leading to compromise of P4 Search and the connected P4 Server. | |
| Pendiente de análisis | Crítica (10) | 0.42% | — | Perforce P4 SearchAI | 5/10/2026 | 6/10/2026 | Perforce P4 Search container images prior to 2026.4.2 reset the service authentication token to a publicly documented default value. An unauthenticated attacker with network access can obtain the highest application privilege, potentially leading to arbitrary code execution and compromise of the connected P4 Server. | |
| Pendiente de análisis | Crítica (9.5) | 0.36% | — | Perforce P4 SearchAI | 5/10/2026 | 6/10/2026 | Perforce P4 Search container images prior to 2026.4.2 enable an unauthenticated Java debug interface. An attacker with network access to this interface can execute arbitrary code as the P4 Search service account, potentially leading to compromise of the connected P4 Server. | |
| Aplazada | Crítica (9.1) | 0.32% | — | Yaml Project Yaml FOR PerlAI | 5/10/2026 | 6/10/2026 | YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes. A perl/hash:Class tag blesses a hash into the class it names. The document supplies the object's fields, and Perl calls DESTROY when it goes out of scope. What DESTROY does depends on the classes the process… | |
| Aplazada | Crítica (9.1) | 0.19% | — | LegcordAI | 4/10/2026 | 6/10/2026 | Legcord 1.1.0 through 1.3.0 contains a configuration injection vulnerability that allows script in the Discord page to write any config key via the window.legcord settings.setConfig bridge. Attackers exploiting a Discord XSS can set additionalArguments to persistently add --proxy-server and --ignore-certificate-errors… | |
| Aplazada | Crítica (9.2) | 0.38% | — | LegcordAI | 4/10/2026 | 6/10/2026 | Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the Discord page to escape the themes directory via unvalidated theme ids. Attackers running script in the Discord origin, such as through XSS, can abuse themes.folder, themes.uninstall, and themes.install… | |
| Aplazada | Crítica (9.1) | 0.20% | — | Maclof Kubernetes ClientAI | 4/10/2026 | 6/10/2026 | maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in parseKubeconfig() and parseKubeconfigFile() when a kubeconfig lacks certificate-authority-data, ignoring insecure-skip-tls-verify. On-path attackers can impersonate the Kubernetes API server to capture Bearer tokens or Basic… | |
| Aplazada | Crítica (9.1) | 0.19% | — | Bestwebsoft Google MapsAI | 4/10/2026 | 6/10/2026 | The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_VERIFYPEER. On-path attackers can present any certificate to intercept Google Maps web-service requests, steal the API… |