Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3076▲ 446 respecto a la semana anterior
Críticas / altas1457▲ 26 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

23.914 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.3)0.92%—Djangoproject Django2/12/202517/6/2026
An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4.2.27. `FilteredRelation` is subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the `**kwargs` passed to `QuerySet.annotate()` or `QuerySet.alias()` on PostgreSQL. Earlier,…
ModificadaAlta (7.5)0.31%—Argusteknoloji Bilger2/12/202517/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Argus Technology Inc. BILGER allows Choosing Message Identifier. This issue affects BILGER: before 2.4.9.
AnalizadaAlta (8.7)0.58%—Gin-vue-admin Project Gin-vue-admin1/12/202517/6/2026
Gin-vue-admin is a backstage management system based on vue and gin. In 2.8.6 and earlier, attackers can delete any file on the server at will, causing damage or unavailability of server resources. Attackers can control the 'FileMd5' parameter to delete any file and folder.
AnalizadaBaja (2.1)0.63%—Mogublog Project Mogublog1/12/202525/9/2026
Se ha detectado una vulnerabilidad de seguridad en moxi159753 Mogu Blog v2 hasta la versión 5.2. El elemento afectado es la función FileOperation.unzip del archivo /networkDisk/unzipFile del componente ZIP File Handler. Dicha manipulación del argumento fileUrl conduce a salto de ruta. El ataque puede lanzarse de forma…
AnalizadaBaja (2.1)0.38%—Mogublog Project Mogublog1/12/202525/9/2026
Se ha identificado una vulnerabilidad en moxi159753 Mogu Blog v2 hasta la versión 5.2. El elemento afectado es una función desconocida del archivo /file/pictures. Esta manipulación del argumento filedatas provoca una carga sin restricciones. El ataque puede iniciarse de forma remota. El exploit ha sido puesto a…
AnalizadaMedia (5.5)0.53%—Mogublog Project Mogublog1/12/202525/9/2026
Se ha descubierto una vulnerabilidad de seguridad en moxi159753 Mogu Blog v2 hasta la versión 5.2. La función afectada es LocalFileServiceImpl.uploadPictureByUrl del archivo /file/uploadPicsByUrl. La manipulación da como resultado una Server-Side Request Forgery. El ataque puede lanzarse de forma remota. El exploit ha…
AnalizadaBaja (2.9)0.47%—Mogublog Project Mogublog1/12/202525/9/2026
Una vulnerabilidad fue identificada en moxi159753 Mogu Blog v2 hasta la versión 5.2. Este problema afecta a un procesamiento desconocido del archivo /storage/ del componente Storage Management Endpoint Storage Management. La manipulación conduce a la falta de autorización. El ataque puede ser iniciado remotamente. La…
AnalizadaMedia (5.5)0.56%—Wtcms Project Wtcms30/11/20253/9/2026
A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Impacted is the function fetch of the file /index.php. Performing manipulation of the argument content results in code injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. This…
AnalizadaBaja (2.1)0.32%—Wtcms Project Wtcms30/11/202517/6/2026
A security flaw has been discovered in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. This affects the function check/uncheck/delete of the file application/Comment/Controller/CommentadminController.class.php of the component CommentadminController. The manipulation of the argument ids results in sql…
AnalizadaMedia (5.5)0.38%—Wtcms Project Wtcms30/11/20257/10/2026
Una vulnerabilidad fue identificada en taosir WTCMS hasta 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Afectada por este problema es la función delete del archivo application/Admin/Controller/SlideController.class.php del componente SlideController. La manipulación del argumento ids conduce a inyección SQL. La…
AnalizadaMedia (6.3)0.51%—Palletsprojects Werkzeug29/11/20257/10/2026
Werkzeug es una completa biblioteca de aplicaciones web WSGI. Antes de la versión 3.1.4, la función safe_join de Werkzeug permite segmentos de ruta con nombres de dispositivos de Windows. En Windows, existen nombres de dispositivos especiales como CON, AUX, etc. que están implícitamente presentes y son legibles en…
AplazadaCrítica (9.4)0.42%—Cerebrate-project CerebrateAI28/11/202517/6/2026
UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges (e.g., obtain a higher role such as admin) via the user-edit endpoint by supplying or modifying role_id or organisation_id fields in the edit request.
ModificadaMedia (5.5)0.20%—Libexpat Project Libexpat28/11/202517/6/2026
In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.
ModificadaAlta (7.7)0.52%💥 PoCValidator Project Validator27/11/202514/7/2026
Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take into account Unicode variation selectors (\uFE0F, \uFE0E) appearing in a sequence which lead to improper string length calculation. This…
AnalizadaMedia (6.5)0.26%—Tinyproxy Project Tinyproxy26/11/202517/6/2026
Tinyproxy through 1.11.2 contains an integer overflow vulnerability in the strip_return_port() function within src/reqs.c.
ModificadaAlta (7)0.33%—Webform Multiple File Upload Project Webform Multiple File Upload26/11/202517/6/2026
Webform Multiple File Upload module for Drupal 7.x contains a cross-site scripting (XSS) vulnerability in the file name renderer. An unauthenticated attacker can exploit this vulnerability by uploading a file with a malicious filename containing JavaScript code (e.g., "<img src=1 onerror=alert(document.domain)>") to a…
AnalizadaMedia (5.4)0.20%—Formwork Project Formwork26/11/202517/6/2026
Formwork is a flat file-based Content Management System (CMS). Prior to version 2.2.0, inserting unsanitized data into the blog tag field results in stored cross‑site scripting (XSS). Any user with credentials to the Formwork CMS who accesses or edits an affected blog post will have attacker‑controlled script executed…
AnalizadaAlta (8.8)0.73%—Fugue-project Fugue25/11/202517/6/2026
Fugue is a unified interface for distributed computing that lets users execute Python, Pandas, and SQL code on Spark, Dask, and Ray with minimal rewrites. In version 0.9.2 and prior, there is a remote code execution vulnerability by pickle deserialization via FlaskRPCServer. The Fugue framework implements an RPC…
AnalizadaMedia (5.3)0.23%—Primakon Project Contract Management25/11/202517/6/2026
Primakon Pi Portal 1.0.18 API endpoints responsible for retrieving object-specific or filtered data (e.g., user profiles, project records) fail to implement sufficient server-side validation to confirm that the requesting user is authorized to access the requested object or dataset. This vulnerability can be exploited…
AnalizadaAlta (8.8)0.29%—Primakon Project Contract Management25/11/202517/6/2026
The Primakon Pi Portal 1.0.18 API /api/V2/pp_udfv_admin endpoint, fails to perform necessary server-side validation. The administrative LoginAs or user impersonation feature is vulnerable to a access control failure. This flaw allows any authenticated low-privileged user to execute a direct PATCH request, enabling…
AnalizadaAlta (8.8)0.29%—Primakon Project Contract Management25/11/202517/6/2026
Primakon Pi Portal 1.0.18 /api/v2/pp_users endpoint fails to adequately check user permissions before processing a PATCH request to modify the PP_SECURITY_PROFILE_ID. Because of weak access controls any low level user can use this API and change their permission to Administrator by using PP_SECURITY_PROFILE_ID=2…
AnalizadaCrítica (9.8)0.38%—Primakon Project Contract Management25/11/202517/6/2026
Primakon Pi Portal 1.0.18 API endpoints fail to enforce sufficient authorization checks when processing requests. Specifically, a standard user can exploit this flaw by sending direct HTTP requests to administrative endpoints, bypassing the UI restrictions. This allows the attacker to manipulate data outside their…
AnalizadaAlta (8.6)0.28%—Primakon Project Contract Management25/11/202517/6/2026
Primakon Pi Portal 1.0.18 REST /api/v2/user/register endpoint suffers from a Broken Access Control vulnerability. The endpoint fails to implement any authorization checks, allowing unauthenticated attackers to perform POST requests to register new user accounts in the application's local database. This bypasses the…
AnalizadaAlta (8.8)0.29%—Primakon Project Contract Management25/11/202517/6/2026
The Primakon Pi Portal 1.0.18 /api/V2/pp_users?email endpoint is used for user data filtering but lacks proper server-side validation against the authenticated session. By manipulating the email parameter to an arbitrary value (e.g., otheruser@user.com), an attacker can assume the session and gain full access to the…
AnalizadaMedia (4.3)0.22%—Primakon Project Contract Management25/11/202517/6/2026
Primakon Pi Portal 1.0.18 /api/v2/users endpoint is vulnerable to unauthorized data exposure due to deficient access control mechanisms. Any authenticated user, regardless of their privilege level (including standard or low-privileged users), can make a GET request to this endpoint and retrieve a complete, unfiltered…