Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2844▲ 206 respecto a la semana anterior
Críticas / altas1323▼ 110 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
23.402 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 0.40% | — | Zephyrproject Zephyr | 19/9/2025 | 17/6/2026 | The function responsible for handling BLE connection responses does not verify whether a response is expected—that is, whether the device has initiated a connection request. Instead, it relies solely on identifier matching. | |
| Analizada | Media (6.5) | 0.21% | — | Zephyrproject Zephyr | 19/9/2025 | 17/6/2026 | A vulnerability was identified in the handling of Bluetooth Low Energy (BLE) fixed channels (such as SMP or ATT). Specifically, an attacker could exploit a flaw that causes the BLE target (i.e., the device under attack) to attempt to disconnect a fixed channel, which is not allowed per the Bluetooth specification.… | |
| Aplazada | Media (6.3) | 0.47% | — | Torproject TORAI | 18/9/2025 | 17/6/2026 | A security flaw has been discovered in Tor up to 0.4.7.16/0.4.8.17. Impacted is an unknown function of the component Onion Service Descriptor Handler. Performing manipulation results in resource consumption. The attack may be initiated remotely. The attack's complexity is rated as high. The exploitability is… | |
| Aplazada | Alta (8.8) | 0.20% | — | Sparkle-project SparkleAI | 16/9/2025 | 17/6/2026 | The Sparkle framework includes a helper tool Autoupdate. Due to lack of authentication of connecting clients a local unprivileged attacker can request installation of crafted malicious PKG file by racing to connect to the daemon when other app spawns it as root. This results in local privilege escalation to root… | |
| Aplazada | Media (4.8) | 0.17% | — | Sparkle-project SparkleAI | 16/9/2025 | 17/6/2026 | The Sparkle framework includes an XPC service Downloader.xpc, by default this service is private to the application its bundled with. A local unprivileged attacker can register this XPC service globally which will inherit TCC permissions of the application. Lack of validation of connecting client allows the attacker… | |
| Aplazada | Baja (3.2) | 0.13% | — | IP Project Node-ipAI | 16/9/2025 | 17/6/2026 | The ip (aka node-ip) package through 2.0.1 (in NPM) might allow SSRF because the IP address value 017700000001 is improperly categorized as globally routable via isPublic. NOTE: this issue exists because of an incomplete fix for CVE-2024-29415. | |
| Analizada | Media (5.5) | 0.49% | — | 1000projects Online Student Project Report Submission AND Evaluation System | 15/9/2025 | 17/6/2026 | A vulnerability was identified in 1000projects Online Student Project Report Submission and Evaluation System 1.0. The impacted element is an unknown function of the file /admin/controller/student_controller.php. Such manipulation of the argument new_image leads to unrestricted upload. The attack may be performed from… | |
| Analizada | Media (5.5) | 0.46% | — | 1000projects Online Student Project Report Submission AND Evaluation System | 15/9/2025 | 17/6/2026 | A vulnerability was determined in 1000projects Online Student Project Report Submission and Evaluation System 1.0. The affected element is an unknown function of the file /admin/controller/faculty_controller.php. This manipulation of the argument new_image causes unrestricted upload. The attack is possible to be… | |
| Analizada | Baja (2.9) | 0.45% | — | Newbee-mall Project Newbee-mall | 15/9/2025 | 17/6/2026 | A vulnerability was found in newbee-mall 1.0. Impacted is the function mallKaptcha of the file /common/mall/kaptcha. The manipulation results in guessable captcha. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has… | |
| Modificada | Alta (7.5) | 1.3% | — | Libexpat Project Libexpat | 15/9/2025 | 17/6/2026 | libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing. | |
| Analizada | Baja (2.1) | 0.30% | — | Newbee-mall Project Newbee-mall | 15/9/2025 | 17/6/2026 | A vulnerability has been found in newbee-mall up to 613a662adf1da7623ec34459bc83e3c1b12d8ce7. This issue affects the function paySuccess of the file /paySuccess of the component Order Status Handler. The manipulation of the argument orderNo leads to improper authorization. Remote exploitation of the attack is… | |
| Modificada | Crítica (9.8) | 0.88% | — | Sueamcms Project Sueamcms | 12/9/2025 | 5/7/2026 | File Upload vulnerability in SueamCMS v.0.1.2 allows a remote attacker to execute arbitrary code via the lack of filtering. | |
| Analizada | Alta (8.8) | 0.32% | — | Utcms Project Utcms | 10/9/2025 | 17/6/2026 | Se ha encontrado una vulnerabilidad en HuangDou UTCMS V9 y ha sido clasificada como crítica. Esta vulnerabilidad afecta a la función RunSql del archivo app/modules/ut-data/admin/mysql.php. La manipulación del argumento sql conduce a una inyección SQL. El ataque puede iniciarse remotamente. El exploit se ha divulgado… | |
| Analizada | Crítica (9.9) | 19% | 💥 Exploit | Fogproject | 6/9/2025 | 17/6/2026 | FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Versions 1.5.10.1673 and below contain an authentication bypass vulnerability. It is possible for an attacker to perform an unauthenticated DB dump where they could pull a full SQL DB without credentials. A fix is expected to be… | |
| Analizada | Media (5.5) | 0.44% | — | 1000projects Beauty Parlour Management System | 4/9/2025 | 17/6/2026 | A security vulnerability has been detected in 1000projects Beauty Parlour Management System 1.0. This impacts an unknown function of the file /admin/contact-us.php. The manipulation of the argument mobnumber leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may… | |
| Analizada | Media (5.5) | 0.44% | — | Projectworlds Travel Management System | 3/9/2025 | 17/6/2026 | A security flaw has been discovered in projectworlds Travel Management System 1.0. The impacted element is an unknown function of the file /viewcategory.php. Performing manipulation of the argument t1 results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public… | |
| Analizada | Media (5.5) | 0.44% | — | Projectworlds Travel Management System | 3/9/2025 | 17/6/2026 | A vulnerability was identified in projectworlds Travel Management System 1.0. The affected element is an unknown function of the file /viewpackage.php. Such manipulation of the argument t1 leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. | |
| Modificada | Alta (8.1) | 17% | 💥 PoC | Djangoproject Django | 3/9/2025 | 17/6/2026 | An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed QuerySet.annotate() or QuerySet.alias(). | |
| Analizada | Media (5.5) | 0.44% | — | Projectworlds Travel Management System | 3/9/2025 | 17/6/2026 | A vulnerability was determined in projectworlds Travel Management System 1.0. Impacted is an unknown function of the file /viewsubcategory.php. This manipulation of the argument t1 causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Media (5.5) | 0.44% | — | Projectworlds Travel Management System | 3/9/2025 | 17/6/2026 | A vulnerability has been found in projectworlds Travel Management System 1.0. This vulnerability affects unknown code of the file /enquiry.php. The manipulation of the argument t2 leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (5.5) | 0.44% | — | Projectworlds Travel Management System | 3/9/2025 | 1/10/2026 | Una vulnerabilidad fue encontrada en projectworlds Travel Management System 1.0. Este problema afecta algún procesamiento desconocido del archivo /detail.PHP. La manipulación del argumento pid resulta en inyección SQL. El ataque puede ser ejecutado remotamente. El exploit ha sido hecho público y podría ser usado. | |
| Analizada | Baja (1.9) | 0.29% | — | Code-projects POS Pharmacy System | 3/9/2025 | 17/6/2026 | A weakness has been identified in code-projects POS Pharmacy System 1.0. Affected is an unknown function of the file /main/products.php. This manipulation of the argument product_code/gen_name/product_name/supplier causes cross site scripting. The attack can be initiated remotely. The exploit has been made available… | |
| Analizada | Media (5.5) | 0.44% | — | 1000projects Beauty Parlour Management System | 3/9/2025 | 17/6/2026 | A vulnerability was identified in 1000projects Beauty Parlour Management System 1.0. This affects an unknown function of the file /admin/bwdates-reports-details.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly… | |
| Analizada | Media (6.5) | 0.25% | 💥 PoC | Doubo ERP Project Doubo ERP | 2/9/2025 | 17/6/2026 | Doubo ERP 1.0 has an SQL injection vulnerability due to a lack of filtering of user input, which can be remotely initiated by an attacker. | |
| Analizada | Baja (2.1) | 0.23% | — | Tianti Project Tianti | 1/9/2025 | 17/6/2026 | A vulnerability has been found in xujeff tianti 天梯 up to 2.3. The impacted element is the function ajaxUploadFile of the file src/main/java/com/jeff/tianti/controller/UploadController.java. The manipulation of the argument upfile leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit… |