Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3077▲ 492 respecto a la semana anterior
Críticas / altas1455▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
23.914 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.3) | 0.92% | — | Newforma Project Center | 9/10/2025 | 8/10/2026 | Newforma Info Exchange (NIX) acepta datos .NET serializados a través del endpoint '/remoteweb/remote.rem', permitiendo a un atacante remoto no autenticado ejecutar código arbitrario con privilegios de 'NT AUTHORITY\NetworkService'. El endpoint vulnerable es utilizado por Newforma Project Center Server (NPCS), por lo… | |
| Analizada | Media (5.5) | 0.43% | — | Projectworlds Gate Pass Management System | 9/10/2025 | 8/10/2026 | Una vulnerabilidad ha sido encontrada en projectworlds Gate Pass Management System 1.0. Este problema afecta a algún procesamiento desconocido del archivo /add-pass.php. Tal manipulación del argumento fullname lleva a inyección SQL. El ataque puede ser ejecutado remotamente. El exploit ha sido divulgado al público y… | |
| Analizada | Alta (8.8) | 0.45% | — | Projectworlds GYM Management System | 8/10/2025 | 17/6/2026 | ProjectWorlds Gym Management System1.0 is vulnerable to SQL Injection via the "id" parameter in the profile/edit.php page | |
| Modificada | Media (5.5) | 0.42% | — | Projectworlds Advanced Library Management System | 8/10/2025 | 8/10/2026 | Una vulnerabilidad fue determinada en projectworlds Advanced Library Management System 1.0. Afectada por este problema es alguna funcionalidad desconocida del archivo /view_member.php. Ejecutar una manipulación del argumento user_id puede llevar a inyección SQL. El ataque puede ser lanzado remotamente. El exploit ha… | |
| Modificada | Baja (2.1) | 0.33% | — | Projectworlds Advanced Library Management System | 8/10/2025 | 8/10/2026 | Una falla de seguridad ha sido descubierta en projectworlds Advanced Biblioteca Management System 1.0. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /edit_book.PHP. La manipulación del argumento image resulta en carga sin restricciones. Es posible lanzar el ataque remotamente. El… | |
| Analizada | Baja (1.9) | 0.26% | — | Projectworlds Advanced Library Management System | 8/10/2025 | 8/10/2026 | Una vulnerabilidad fue identificada en projectworlds Advanced Library Management System 1.0. Afectada es una función desconocida del archivo /edit_admin.php. La manipulación del argumento firstname conduce a cross site scripting. Es posible iniciar el ataque de forma remota. El exploit está disponible públicamente y… | |
| Aplazada | Media (5.3) | 0.46% | — | Openplcproject OpenplcAI | 7/10/2025 | 8/10/2026 | Una vulnerabilidad de denegación de servicio existe en la funcionalidad del servidor ModbusTCP de OpenPLC _v3 a931181e8b81e36fadf7b74d5cba99b73c3f6d58. Una serie de conexiones de red especialmente diseñadas puede llevar a que el servidor no procese solicitudes Modbus subsiguientes. Un atacante puede abrir una serie de… | |
| Analizada | Media (5.5) | 0.53% | — | Code-projects Crud Operation System | 7/10/2025 | 9/10/2026 | Una vulnerabilidad fue encontrada en code-projects Student Crud Operation hasta 3.3. Esta vulnerabilidad afecta la función move_uploaded_file del archivo add.php del componente Add Student Page/Edit Student Page. Realizar manipulación resulta en carga sin restricciones. El ataque puede ser iniciado remotamente. El… | |
| Aplazada | Crítica (9.3) | 0.65% | — | Pyvista Project PyvistaAI | 6/10/2025 | 17/6/2026 | PyVista provides 3D plotting and mesh analysis through an interface for the Visualization Toolkit (VTK). Version 0.46.3 of the PyVista Project is vulnerable to remote code execution via dependency confusion. Two pieces of code use`--extra-index-url`. But when `--extra-index-url` is used, pip always checks for the PyPI… | |
| Analizada | Media (5.5) | 0.41% | — | Code-projects Crud Operation System | 6/10/2025 | 9/10/2026 | Una vulnerabilidad de seguridad ha sido detectada en code-projects Student Crud Operation 3.3. Afectada es una función desconocida del archivo delete.PHP. La manipulación del argumento ID conduce a inyección SQL. El ataque es posible de llevar a cabo remotamente. El exploit ha sido divulgado públicamente y puede ser… | |
| Modificada | Crítica (9.9) | 82% | 💥 Exploit | RedisLfprojects Valkey | 3/10/2025 | 17/6/2026 | Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate the garbage collector, trigger a use-after-free and potentially lead to remote code execution. The problem exists in all versions of Redis with Lua… | |
| Modificada | Alta (7.2) | 18% | 💥 Exploit | Motioneye Project Motioneye | 3/10/2025 | 5/7/2026 | MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. Unsanitized user input is written to Motion configuration files, allowing remote authenticated attackers with admin access to achieve code execution when Motion is restarted. | |
| Aplazada | Alta (8.2) | 0.34% | — | Teknolojik Center Telecommunication Industry Trade CO LTD B2B Netsis PanelAI | 3/10/2025 | 8/10/2026 | Vulnerabilidad de Neutralización Inadecuada de Elementos Especiales utilizados en un Comando SQL (inyección SQL) en Teknolojik Center Telecommunication Industry Trade Co. Ltd. B2B - Netsis Panel permite la inyección SQL. Este problema afecta a B2B - Netsis Panel: hasta el 20251003. | |
| Analizada | Media (6.5) | 0.26% | — | Phpgurukul Online Shopping Portal Project | 2/10/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal Project v2.1 is vulnerable to SQL Injection in /shopping/login.php via the fullname parameter. | |
| Analizada | Media (5.1) | 0.21% | — | Creativeitem Ekushey Project Manager CRM | 2/10/2025 | 17/6/2026 | Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user inputs via the "/ekushey/index.php/client/project_file/upload/xxxx", affecting to "description" parameter via POST. This vulnerability could allow a remote attacker to send a specially crafted query… | |
| Analizada | Media (5.1) | 0.21% | — | Creativeitem Ekushey Project Manager CRM | 2/10/2025 | 17/6/2026 | Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user inputs via the "/ekushey/index.php/client/project_message/add/xxx", affecting to "message" parameter via POST. This vulnerability could allow a remote attacker to send a specially crafted query to an… | |
| Analizada | Media (5.1) | 0.21% | — | Creativeitem Ekushey Project Manager CRM | 2/10/2025 | 30/9/2026 | Vulnerabilidad de Cross Site Scripting Almacenado en Ekushey CRM v5.0 de Creativeitem, debido a la falta de validación adecuada de las entradas de usuario a través de la ruta '/ekushey/index.php/client/project_bug/create/xxx', afectando a los parámetros 'title' y 'description' vía POST. Esta vulnerabilidad podría… | |
| Analizada | Alta (7.5) | 8.9% | — | Argoproj Argo CD | 1/10/2025 | 17/6/2026 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. For versions 2.9.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.6 and 3.0.17, when the webhook.azuredevops.username and webhook.azuredevops.password are not set in the default configuration, the /api/webhook endpoint crashes the entire… | |
| Analizada | Alta (7.5) | 0.60% | — | Argoproj Argo CD | 1/10/2025 | 17/6/2026 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions 1.2.0 through 1.8.7, 2.0.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.7 and 3.0.18 are vulnerable to malicious API requests which can crash the API server and cause denial of service to legitimate clients. With the default… | |
| Analizada | Alta (7.5) | 0.59% | — | Argoproj Argo CD | 1/10/2025 | 17/6/2026 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions 1.2.0 through 1.8.7, 2.0.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.7 and 3.0.18 are vulnerable to malicious API requests which can crash the API server and cause denial of service to legitimate clients. Without a… | |
| Modificada | Media (6.5) | 0.91% | — | Djangoproject Django | 1/10/2025 | 17/6/2026 | An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. The django.utils.archive.extract() function, used by the "startapp --template" and "startproject --template" commands, allows partial directory traversal via an archive with file paths sharing a common prefix with the target… | |
| Modificada | Crítica (9.8) | 0.63% | — | Djangoproject Django | 1/10/2025 | 17/6/2026 | An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), QuerySet.alias(), QuerySet.aggregate(), and QuerySet.extra() are subject to SQL injection in column aliases, when using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed to… | |
| Modificada | Alta (8.1) | 0.40% | — | Podofo Project Podofo | 1/10/2025 | 17/6/2026 | A heap-use-after free in the PdfTokenizer::ReadDictionary function of podofo v0.10.0 to v0.10.5 allows attackers to cause a Denial of Service (DoS) by supplying a crafted PDF file. NOTE: this is disputed by the Supplier because there is no available file to reproduce the issue. | |
| Analizada | Media (5.3) | 0.47% | — | Argoproj Argo CD | 30/9/2025 | 17/6/2026 | Argo CD es una herramienta de entrega continua declarativa, GitOps para Kubernetes. Las versiones entre 2.1.0 y 2.14.19, 3.2.0-rc1, 3.1.0-rc1 hasta 3.1.7, y 3.0.0-rc1 hasta 3.0.18 contienen una condición de carrera en el manejador de credenciales del repositorio que puede causar que el servidor Argo CD entre en pánico… | |
| Modificada | Media (6.1) | 0.32% | — | Validator Project Validator | 30/9/2025 | 5/7/2026 | Una vulnerabilidad de omisión de validación de URL existe en validator.js hasta la versión 13.15.15. La función isURL() utiliza '://' como delimitador para analizar protocolos, mientras que los navegadores utilizan ':' como delimitador. Esta diferencia de análisis permite a los atacantes omitir la validación de… |