Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

1742 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.30%—Microsoft Windows Admin Center14/7/202621/7/2026
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.
AnalizadaMedia (6.5)0.84%—Microsoft Windows Admin Center14/7/202621/7/2026
Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.
AnalizadaAlta (8.8)0.75%—Microsoft Windows Admin Center14/7/202621/7/2026
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
AplazadaAlta (7.7)0.48%—Vmware Boot Admin ServerAI13/7/202615/7/2026
Spring Boot Admin Server before 4.1.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers to register instances with attacker-controlled healthUrl and managementUrl parameters without validation against private IP ranges or metadata endpoints. Attackers can force the server to…
AplazadaMedia (5.3)0.29%—Andy Moyle Church AdminAI13/7/202613/7/2026
Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Church Admin: from n/a through <= 5.0.30.
AplazadaMedia (5.5)0.50%—Hcr707305003 ShiroiadminAI12/7/202613/7/2026
A vulnerability was determined in hcr707305003 shiroiAdmin 1.1/1.3. Affected is the function FileController::upload of the file app/common/controller/FileController.php. Executing a manipulation of the argument File can lead to unrestricted upload. The attack may be launched remotely. The exploit has been publicly…
AplazadaAlta (8.7)0.36%—Getgrav Grav-plugin-admin2AIGetgrav GravAI11/7/202613/7/2026
The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable window.__GRAV_CONFIG__ in the Admin2 SPA bootstrap page at /grav/admin (and its subroutes). This object is returned in every unauthenticated response and discloses the server URL, API prefix, admin base path, runtime…
AplazadaAlta (8.7)0.36%—Getgrav Grav-plugin-adminAI10/7/202610/7/2026
grav-plugin-admin is an HTML user interface that provides a way to configure Grav and create and modify pages. In 1.10.52 and earlier, an authenticated attacker with admin.users permission can change the password of any user account, including the super administrator, by sending a direct POST request to…
AplazadaAlta (8.1)0.47%—Admin AND Site Enhancements PROAIWpase Admin AND Site EnhancementsAI6/7/20266/7/2026
The Admin and Site Enhancements (ASE) WordPress plugin before 8.8.4, admin-site-enhancements-pro WordPress plugin before 8.8.4 does not perform authentication, authorization, or nonce checks on a role-restoration request handler, allowing unauthenticated attackers to restore a previously demoted administrator account…
AplazadaCrítica (9.6)0.45%—Admin AND Site Enhancements PROAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro <= 8.8.5 versions.
AplazadaBaja (2.7)0.32%—AdminifyAI2/7/20262/7/2026
The Adminify WordPress plugin before 4.2.10 does not perform per-user read-capability checks on the results returned by one of its administration search features, allowing users with a low-privilege role (Contributor) to disclose non-public content that WordPress would not otherwise expose to them, such as other…
AplazadaMedia (6.5)0.44%—Goadmingroup GoadminAI1/7/20262/7/2026
SQL Injection vulnerability in GoAdminGroup GoAdmin (last release v1.2.26) allows a remote attacker to execute arbitrary code and obtain sensitive information via the the __sort_type URL parameter on all /admin/info/{table} endpoints
AplazadaAlta (7.6)0.38%—AdministratorAI26/6/202626/6/2026
Administrator SQL Injection in Popup box <= 6.0.1 versions.
AplazadaAlta (7.7)0.22%💥 PoCGrocery Store Management System Using PHP AND Mysql PhpmyadminAI25/6/202626/6/2026
GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0 was discovered to contain a SQL injection vulnerability in the scost parameter in /grocery/search_products.php. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.
AplazadaCrítica (9.6)0.54%—PoweradminAIPowerdnsAI23/6/202625/6/2026
Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 use the attacker-controlled `HTTP_HOST` request header as the authoritative source for building callback URLs in its OIDC, SAML, and logout authentication flows without any validation. An unauthenticated attacker…
AplazadaMedia (6.9)0.38%—PoweradminAIPowerdnsAI23/6/202625/6/2026
Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 are vulnerable to CSV Injection (Formula Injection) in its log export functionality. User-controlled data — specifically the username field — is written to exported CSV files without sanitizing formula trigger…
AplazadaAlta (7.4)0.69%—Gin-vue-adminAI19/6/202623/6/2026
gin-vue-admin is an AI-assisted basic development platform. In version 2.9.1, an authenticated attacker with access to the code-generation feature and MCP management interface can exploit this vulnerability by injecting attacker-controlled Go source code through POST /autoCode/addFunc, and then invoking POST…
AplazadaMedia (4.3)0.19%—User Admin SimplifierAI19/6/202622/6/2026
The User Admin Simplifier plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.0. This is due to missing or incorrect nonce validation on the useradminsimplifier_options_page function. This makes it possible for unauthenticated attackers to reset and permanently…
AnalizadaMedia (5.3)0.43%—Pgadmin 419/6/202629/6/2026
SQL injection in pgAdmin 4's named restore point endpoint (POST /browser/server/restore_point/{gid}/{sid}). The user-supplied 'value' field was interpolated directly into the SQL string with str.format() instead of being passed as a bound parameter, allowing an authenticated pgAdmin user with a connected PostgreSQL…
AnalizadaMedia (5.3)0.38%—Pgadmin 419/6/202629/6/2026
Open redirect in pgAdmin 4's multi-factor authentication flow. The MFA validate and register endpoints honoured the user-supplied 'next' query/form parameter without confirming the target pointed back inside pgAdmin, so an authenticated victim who clicked /mfa/validate?next=<external> -- a link typically delivered by…
AnalizadaCrítica (9.3)0.27%—Pgadmin 419/6/202629/6/2026
Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text returned by a PostgreSQL server (ErrorResponse messages, including object names quoted back inside relation-does-not-exist errors and inside EXPLAIN Recheck Cond / Exact Heap Blocks fields) was passed verbatim through…
AnalizadaMedia (4.8)0.22%—Pgadmin 419/6/202629/6/2026
HTML injection in pgAdmin 4's cloud deployment module. The verify_credentials, deploy, regions, and update-server endpoints under /rds/, /azure/, /google/, and the top-level /cloud/ blueprint propagated AWS / Azure / Google SDK exception text — and the related file-resolution and database-commit exception text — into…
AnalizadaCrítica (9.5)1.0%—Pgadmin 419/6/20261/7/2026
Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqleditor/initialize/sqleditor/update_connection/<sgid>/<sid>/<did> -- were the only routes in the module missing the @pga_login_required decorator. Both reach a pickle.loads sink on…
AnalizadaCrítica (9.4)0.66%—Pgadmin 419/6/20261/7/2026
Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that the assistant reads to execute arbitrary SQL with the privileges of the pgAdmin user's database role. The AI Assistant's execute_sql_query tool runs LLM-generated SQL inside a BEGIN TRANSACTION READ…
AnalizadaAlta (8.7)0.71%—Pgadmin 419/6/20261/7/2026
SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... IS '<description>'`` for a user-supplied description field. The Jinja templates for Domains (and their constraints), Foreign Tables, Languages, and Event Triggers, plus the Views OID-lookup query, interpolated the description…
Orbitaley — Vulnerabilidades