Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3072▲ 483 respecto a la semana anterior
Críticas / altas1456▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
23.914 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.35% | — | Projectworlds Advanced Library Management System | 17/11/2025 | 7/10/2026 | Una vulnerabilidad fue identificada en projectworlds Advanced Library Management System 1.0. Esta vulnerabilidad afecta código desconocido del archivo /add_member.php. Dicha manipulación del argumento roll_number conduce a inyección SQL. El ataque puede ser realizado de forma remota. El exploit está disponible… | |
| Analizada | Baja (2.1) | 0.35% | — | Projectworlds Advanced Library Management System | 16/11/2025 | 7/10/2026 | Se determinó una vulnerabilidad en projectworlds Advanced Library Management System 1.0. Esto afecta una parte desconocida del archivo /add_librarian.php. Esta manipulación del argumento Username causa inyección SQL. El ataque puede ser llevado a cabo de forma remota. El exploit ha sido divulgado públicamente y puede… | |
| Analizada | Baja (2.1) | 0.35% | — | Datax-web Project Datax-web | 16/11/2025 | 17/6/2026 | A flaw has been found in WeiYe-Jing datax-web up to 2.1.2. Affected is an unknown function. Executing manipulation can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used. | |
| Analizada | Baja (2.1) | 0.38% | — | Datax-web Project Datax-web | 16/11/2025 | 17/6/2026 | A vulnerability was detected in WeiYe-Jing datax-web up to 2.1.2. This impacts the function remove/update/pause/start/triggerJob of the component Job Handler. Performing manipulation results in improper access controls. The attack may be initiated remotely. The exploit is now public and may be used. | |
| Aplazada | Baja (2) | 0.25% | — | ProjectsendAI | 16/11/2025 | 17/6/2026 | A flaw has been found in projectsend up to r1720. Impacted is an unknown function of the component File Editor/Custom Download Aliases. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used. Upgrading to version r1945 is… | |
| Aplazada | Media (6.5) | 0.28% | — | Wedevs WP Project ManagerAI | 15/11/2025 | 7/10/2026 | La Gestión de Proyectos, Colaboración en Equipo, Tablero Kanban, Diagramas de Gantt, Gestor de Tareas y Más - el plugin WP Project Manager para WordPress es vulnerable a inyección SQL basada en tiempo a través del parámetro 'completed_at_operator' en todas las versiones hasta la 2.6.26, inclusive, debido a un escape… | |
| Aplazada | Media (4.3) | 0.19% | — | Edgarrojas Woo-pdf-invoice-builderAI | 13/11/2025 | 7/10/2026 | Vulnerabilidad de falta de autorización en EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a WooCommerce PDF Invoice Builder: desde n/a hasta menor o igual que 1.2.150. | |
| Analizada | Media (5.1) | 0.17% | — | Fairsketch Rise Ultimate Project Manager | 11/11/2025 | 17/6/2026 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'first_name' in '/clients/save_contact/'. | |
| Analizada | Media (5.1) | 0.16% | — | Fairsketch Rise Ultimate Project Manager | 11/11/2025 | 17/6/2026 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in '/tickets/save'. | |
| Analizada | Media (5.1) | 0.16% | — | Fairsketch Rise Ultimate Project Manager | 11/11/2025 | 17/6/2026 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'custom_field_1' in '/estimate_requests/save_estimate_request'. | |
| Analizada | Media (5.1) | 0.16% | — | Fairsketch Rise Ultimate Project Manager | 11/11/2025 | 17/6/2026 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'reply_message' in '/messages/reply'. | |
| Analizada | Media (5.1) | 0.16% | — | Fairsketch Rise Ultimate Project Manager | 11/11/2025 | 17/6/2026 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in '/events/save'. | |
| Analizada | Media (5.1) | 0.16% | — | Fairsketch Rise Ultimate Project Manager | 11/11/2025 | 17/6/2026 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in'/projects/save'. | |
| Aplazada | Media (5.4) | 0.20% | — | Total Book ProjectAI | 11/11/2025 | 7/10/2026 | El plugin The Total Book Project para WordPress es vulnerable a Referencia Directa Insegura a Objeto en todas las versiones hasta la 1.0, inclusive, a través de varias funciones debido a la falta de validación en una clave controlada por el usuario. Esto hace posible que atacantes autenticados, con acceso de nivel… | |
| Analizada | Media (5.5) | 0.43% | — | Projectworlds Online Admission System | 10/11/2025 | 7/10/2026 | Una vulnerabilidad fue identificada en projectworlds Online Admission System 1.0. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /process_login.php. La manipulación del argumento keywords conduce a inyección SQL. El ataque puede ser iniciado remotamente. El exploit está disponible… | |
| Modificada | Baja (2.1) | 0.40% | — | Projectworlds Online Notes Sharing Platform | 7/11/2025 | 7/10/2026 | Una vulnerabilidad fue identificada en projectworlds Online Notes Sharing Platform 1.0. Afectada por este problema es alguna funcionalidad desconocida del archivo /dashboard/userprofile.php. Tal manipulación del argumento image conduce a carga sin restricciones. El ataque puede ser realizado desde remoto. El exploit… | |
| Aplazada | Crítica (9.8) | 0.50% | — | S2member Project S2memberAI | 6/11/2025 | 7/10/2026 | La vulnerabilidad de Deserialización de Datos No Confiables en Cristián Lávaque s2Member s2member permite la Inyección de Objetos. Este problema afecta a s2Member: desde n/a hasta menor o igual que 250701. | |
| Analizada | Media (6.8) | 0.13% | — | Cdprojekt GOG Galaxy | 5/11/2025 | 17/6/2026 | GOG Galaxy 2.0.0.2 suffers from Missing SSL Certificate Validation. An attacker who controls the local network, DNS, or a proxy can perform a man-in-the-middle (MitM) attack to intercept update requests and replace installer or update packages with malicious files. | |
| Analizada | Crítica (9.1) | 19% | 💥 Exploit | Djangoproject Django | 5/11/2025 | 17/6/2026 | Se descubrió un problema en 5.1 anterior a 5.1.14, 4.2 anterior a 4.2.26 y 5.2 anterior a 5.2.8. Los métodos 'QuerySet.filter()', 'QuerySet.exclude()' y 'QuerySet.get()', y la clase 'Q()', están sujetos a inyección SQL cuando se utiliza un diccionario adecuadamente diseñado, con expansión de diccionario, como… | |
| Analizada | Alta (7.5) | 1.9% | 💥 PoC | Djangoproject Django | 5/11/2025 | 17/6/2026 | Se descubrió un problema en 5.1 anterior a 5.1.14, 4.2 anterior a 4.2.26 y 5.2 anterior a 5.2.8. La normalización NFKC en Python es lenta en Windows. Como consecuencia, 'django.http.HttpResponseRedirect', 'django.http.HttpResponsePermanentRedirect' y el atajo 'django.shortcuts.redirect' estuvieron sujetos a un… | |
| Analizada | Media (6.7) | 0.09% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt+1 | 4/11/2025 | 17/6/2026 | In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10010443; Issue ID: MSV-3966. | |
| Analizada | Media (6.7) | 0.09% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt+1 | 4/11/2025 | 17/6/2026 | In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10010441; Issue ID: MSV-3967. | |
| Modificada | Media (6.5) | 0.38% | — | Fairsketch Rise Ultimate Project Manager | 3/11/2025 | 5/7/2026 | FairSketch Rise Ultimate Project Manager & CRM 3.9.4 is vulnerable to Insecure Permissions. A remote authenticated user can append comments or upload attachments to tickets for which they lack view or edit authorization, due to missing authorization checks in the ticketing/commenting API. | |
| Analizada | Crítica (9.8) | 0.55% | — | Car-booking-system-php Project Car-booking-system-php | 3/11/2025 | 17/6/2026 | Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/contact.php. | |
| Analizada | Crítica (9.4) | 0.47% | — | Car-booking-system-php Project Car-booking-system-php | 3/11/2025 | 17/6/2026 | Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/forgot-pass.php. |