Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
23.374 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.5) | 0.84% | — | 389 Project 389 Directory ServerAI | 7/9/2026 | 8/9/2026 | A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, 1, or 2) produces an encrypted_buffer_count below the already-consumed… | |
| Modificada | Alta (8.7) | 0.54% | — | Misp-project Misp | 7/9/2026 | 14/9/2026 | Affected versions of MISP permit unauthenticated or weakly constrained request paths to perform persistent work without adequate input bounds or rate limiting. The users/forgot password-reset endpoint accepted an attacker-controlled email value without first imposing a reasonable length bound or validating its format.… | |
| Pendiente de análisis | Alta (7.5) | 0.56% | — | 389 Project 389 Directory ServerAI | 7/9/2026 | 8/9/2026 | A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. This can allow an… | |
| Analizada | Media (5.3) | 0.27% | — | Misp-project Misp | 7/9/2026 | 9/9/2026 | Affected versions of MISP allow authenticated users to retrieve object-reference records by UUID through EventGraphTool::get_reference_data() without first checking whether the requester is authorized to view the object the reference belongs to. The vulnerable code queried ObjectReference.uuid directly and returned… | |
| Analizada | Baja (2.3) | 0.28% | — | Misp-project Misp | 7/9/2026 | 9/9/2026 | Affected versions of MISP contain inconsistent authorization checks across dashboard widgets that display organisation information. Several organisation-related widgets did not honor Security.hide_organisation_index_from_users. As a result, authenticated users without the perm_sharing_group permission could enumerate… | |
| Analizada | Media (5.1) | 0.24% | — | Misp-project Misp | 7/9/2026 | 9/9/2026 | Affected versions of MISP insufficiently validate URLs used by dashboard widgets, particularly the Button widget. The widget's URL is stored configuration controlled by a user. The previous renderer considered a URL safe if it appeared relative or if its parsed hostname matched the configured MISP hostname. That logic… | |
| Analizada | Alta (7) | 0.42% | — | Misp-project Misp | 7/9/2026 | 9/9/2026 | Affected versions of MISP contain insufficient validation of server-side outbound HTTP destinations in feed retrieval and TAXII discovery functionality. In feed processing, redirects were followed without validating the redirect scheme or destination. The original request headers were reused across redirect hops,… | |
| Modificada | Baja (2.3) | 0.27% | — | Misp-project Misp | 7/9/2026 | 14/9/2026 | Affected versions of MISP expose organisation metadata through the dashboard organisation picker without applying the same visibility restrictions enforced by the normal organisation index and per-organisation view. The affected endpoint returned fields including: - name. When… | |
| Analizada | Media (5.3) | 0.27% | — | Misp-project Misp | 7/9/2026 | 9/9/2026 | Affected versions of MISP inconsistently enforced email-address visibility in DashboardsController::listTemplates(). The query always fetched User.email, while redaction happened only inside the non-REST rendering branch. As a result, the same authenticated user who saw redacted data in the normal HTML interface could… | |
| Analizada | Alta (7.1) | 0.34% | — | Misp-project Misp | 7/9/2026 | 9/9/2026 | Affected versions of MISP do not enforce parent-event visibility when serving cryptographic keys through CryptographicKeysController::view(). The vulnerable handler queried CryptographicKey directly using the supplied key ID and selected sensitive fields such as: but did not fetch or authorize the associated parent… | |
| Aplazada | Media (5.5) | 0.53% | — | Code-projects Hospital Information SystemAI | 7/9/2026 | 9/9/2026 | A vulnerability was found in code-projects Hospital Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /HIS/his.sql of the component SQL Database Backup File Handler. Performing a manipulation results in information disclosure. Remote exploitation of the attack is possible.… | |
| Aplazada | Baja (2) | 0.35% | — | Code-projects Hospital Information SystemAI | 7/9/2026 | 8/9/2026 | A vulnerability has been found in code-projects Hospital Information System 1.0. Affected is an unknown function of the file /HIS/src/patients/editPatient.php of the component Patient Management. Such manipulation of the argument ID leads to cross site scripting. The attack may be launched remotely. The exploit has… | |
| Analizada | Media (5.1) | 0.26% | — | Misp-project Misp | 7/9/2026 | 9/9/2026 | Affected versions of MISP validate the user-configurable homepage by checking only whether the supplied path begins with /. That check is insufficient because protocol-relative URLs such as //attacker.example also begin with / but resolve to an external origin in browsers. The vulnerable homepage value can be stored… | |
| Analizada | Alta (7.1) | 0.43% | — | Misp-project Misp | 7/9/2026 | 9/9/2026 | Affected versions of MISP allow any authenticated user to access TemplatesController::uploadFile() because the ACL entry for templates/uploadFile used the wildcard *. This bypasses the intended role restrictions applied to neighboring template-management operations. The upload handler accepts arbitrary content with… | |
| Analizada | Media (5.3) | 0.34% | — | Misp-project Misp | 7/9/2026 | 9/9/2026 | Affected versions of MISP contain improper authorization checks in the freetext feed preview functionality. The preview performed correlation lookups against attributes from events without applying the requesting user's ACL, allowing restricted event correlations and associated event information to be exposed to users… | |
| Aplazada | Baja (2.1) | 0.45% | — | Projectworlds Online Examination SystemAI | 7/9/2026 | 8/9/2026 | A vulnerability was determined in projectworlds Online Examination System 1.0. The affected element is an unknown function of the file feedback.php of the component Feedback Form. Executing a manipulation of the argument Name/Subject can lead to cross site scripting. The attack may be launched remotely. The exploit… | |
| Aplazada | Baja (1.3) | 0.52% | — | Lfprojects ValkeyAI | 6/9/2026 | 9/9/2026 | A weakness has been identified in valkey-io valkey up to 9.0.5/9.1.1. This affects the function kvstoreGetHashtable of the file src/kvstore.c. This manipulation of the argument didx causes out-of-bounds read. It is possible to initiate the attack remotely. The attack is considered to have high complexity. It is… | |
| Aplazada | Baja (2) | 0.33% | — | Projectwolds Online Attendance SystemAI | 6/9/2026 | 8/9/2026 | A security flaw has been discovered in Projectwolds Online Attendance System 1.0. Affected by this issue is some unknown functionality of the file profile.php. The manipulation of the argument email results in cross site scripting. The attack may be performed from remote. The exploit has been released to the public… | |
| Aplazada | Media (5.5) | 0.53% | — | Code-projects Hotel AND Tourism ReservationAI | 6/9/2026 | 11/9/2026 | A vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0. Affected is an unknown function of the file /ht/hotel_db%20(1).sql of the component Database Backup Handler. The manipulation results in information disclosure. The attack may be launched remotely. The exploit is now public and may… | |
| Aplazada | Baja (2.1) | 0.47% | — | Code-projects Hotel AND Tourism ReservationAIPHPAI | 6/9/2026 | 8/9/2026 | A security vulnerability has been detected in code-projects Hotel and Tourism Reservation in PHP 1.0. This impacts an unknown function of the file /ht/details.php. The manipulation of the argument room leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may… | |
| Aplazada | Media (5.5) | 0.57% | — | Diem-project DiemAI | 6/9/2026 | 11/9/2026 | A vulnerability was identified in diem-project diem up to 5.1.3. This vulnerability affects unknown code of the file dmFrontPlugin/modules/dmWidget/lib/BasedmWidgetActions.class.php of the component dmWidget. Such manipulation of the argument widget_id leads to authorization bypass. The attack may be launched… | |
| Aplazada | Baja (2.1) | 0.23% | — | Diem-project DiemAI | 6/9/2026 | 8/9/2026 | A vulnerability was determined in diem-project diem up to 5.1.3. This affects the function executeCommand of the file dmAdminPlugin/modules/dmConsole/actions/actions.class.php of the component dmConsole. This manipulation of the argument dm_command causes cross-site request forgery. The attack may be initiated… | |
| Aplazada | Baja (2) | 0.36% | — | Code-projects Task Management SystemAI | 6/9/2026 | 9/9/2026 | A vulnerability was found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/UpdateUserProfile.php of the component User Profile Update. The manipulation of the argument lname results in cross site scripting. The attack can be launched remotely. The… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Task Management System IN PHPAI | 6/9/2026 | 8/9/2026 | A vulnerability has been found in code-projects Task Management System In PHP 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Login. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.53% | — | Code-projects Daily Expense ManagerAI | 6/9/2026 | 8/9/2026 | A flaw has been found in code-projects Daily Expense Manager 1.0. Affected is an unknown function of the file /Daily-Expense-Manager/exp_ak.sql of the component Database Backup Handler. Executing a manipulation can lead to information disclosure. It is possible to launch the attack remotely. The exploit has been… |