Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3142▲ 566 respecto a la semana anterior
Críticas / altas1456▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
23.914 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.23% | 💥 PoC | Fairsketch Rise Ultimate Project Manager | 29/9/2025 | 5/7/2026 | A cross-site scripting (XSS) vulnerability in FairSketch RISE Ultimate Project Manager & CRM 3.9.4 allows an administrator to store a JavaScript payload using the file explorer in the admin dashboard when creating new folders. | |
| Analizada | Media (5.1) | 0.18% | — | Apt-cacher-ng Project Apt-cacher-ng | 29/9/2025 | 17/6/2026 | Reflected cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vulnerability allows malicious scripts (XSS) to be executed in “/html/<filename>.html”. | |
| Analizada | Media (5.1) | 0.18% | — | Apt-cacher-ng Project Apt-cacher-ng | 29/9/2025 | 17/6/2026 | Reflected Cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vulnerability allows an attacker to execute malicious scripts (XSS) in the web management application. The vulnerability is caused by improper handling of GET inputs included in the URL in “/acng-report.html”. | |
| Analizada | Baja (2.1) | 4.2% | — | Wenkucms Project Wenkucms | 29/9/2025 | 9/10/2026 | Se encontró una vulnerabilidad en mirweiye wenkucms hasta la versión 3.4. Esto afecta a la función createPathOne del archivo app/common/common.PHP. La manipulación resulta en inyección de comandos. El ataque puede lanzarse de forma remota. El exploit se ha hecho público y podría utilizarse. | |
| Aplazada | Media (5.5) | 0.42% | — | Pmticket Project-management-softwareAI | 29/9/2025 | 9/10/2026 | Se detectó una vulnerabilidad en el software de gestión de proyectos pmTicket hasta 2ef379da2075f4761a2c9029cf91d073474e7486. El elemento afectado es la función loadLanguage del archivo classes/class.database.php del componente Manejador de Cookies. La manipulación del argumento user_id resulta en deserialización. El… | |
| Analizada | Baja (2) | 0.29% | — | Fabian Project Monitoring System | 28/9/2025 | 9/10/2026 | Se ha encontrado una vulnerabilidad en code-projects Project Monitoring System 1.0. Afectada es una función desconocida del archivo /onlineJobSearchEngine/postjob.php. Dicha manipulación del argumento txtapplyto conduce a cross site scripting. El ataque puede ser lanzado remotamente. El exploit ha sido revelado al… | |
| Analizada | Baja (2) | 0.38% | — | Projectworlds Online Tours AND Travels | 28/9/2025 | 9/10/2026 | Una vulnerabilidad de seguridad ha sido detectada en Projectworlds Online Tours and Travels 1.0. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /admin/change-image.PHP. La manipulación del argumento packageimage lleva a una carga sin restricciones. El ataque puede ser iniciado… | |
| Analizada | Media (5.5) | 0.48% | — | Fabian Project Monitoring System | 27/9/2025 | 9/10/2026 | Se ha encontrado una vulnerabilidad en code-projects Project Monitoring System 1.0. El elemento afectado es una función desconocida del archivo /login.php. Esta manipulación del argumento username/password causa inyección SQL. El ataque puede iniciarse de forma remota. El exploit ha sido publicado y puede ser… | |
| Analizada | Media (5.5) | 0.48% | — | Projectworlds Online Shopping System | 27/9/2025 | 9/10/2026 | Una vulnerabilidad fue identificada en Projectworlds Online Shopping System 1.0. Esto afecta una parte desconocida del archivo /store/cart_add.PHP. Dicha manipulación del argumento ID conduce a inyección SQL. El ataque puede ser realizado de forma remota. El exploit está disponible públicamente y podría ser utilizado. | |
| Analizada | Baja (1.9) | 0.30% | — | Projectworlds Visitor Management System | 27/9/2025 | 9/10/2026 | Una vulnerabilidad ha sido encontrada en Projectworlds Visitor Management System 1.0. Afectada es una función desconocida del archivo /myform.php del componente Add Visitor Page. La manipulación del argumento Name conduce a cross site scripting. La explotación remota del ataque es posible. El exploit ha sido divulgado… | |
| Aplazada | Media (4.4) | 0.20% | — | Zephyr Project ManagerAI | 26/9/2025 | 17/6/2026 | The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.3.202 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,… | |
| Analizada | Crítica (9.8) | 0.43% | — | Magix-combine-ex Project Magix-combine-ex | 24/9/2025 | 17/6/2026 | Una vulnerabilidad de Contaminación de Prototipos en la función util-deps.addFileDepend de las versiones de magix-combine-ex hasta la 1.2.10 permite a los atacantes inyectar propiedades en Object.prototype mediante el suministro de una carga útil manipulada, causando denegación de servicio (DoS) como consecuencia… | |
| Analizada | Alta (8.6) | 0.31% | — | Keyangxiang Csvtojson | 24/9/2025 | 17/6/2026 | El paquete csvtojson, una herramienta para convertir datos CSV a JSON con capacidades de análisis personalizables, contiene una vulnerabilidad de contaminación de prototipos en versiones anteriores a la 2.0.10. Este problema surge debido a una sanitización insuficiente de nombres de encabezado anidados durante el… | |
| Analizada | Media (5.5) | 0.42% | — | 1000projects Bookstore Management System | 23/9/2025 | 17/6/2026 | A vulnerability was determined in 1000projects Bookstore Management System 1.0. The impacted element is an unknown function of the file /login.php. This manipulation of the argument unm causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Media (5.3) | 0.29% | — | Wedevs WP Project ManagerAI | 22/9/2025 | 30/9/2026 | Vulnerabilidad de credenciales codificadas de forma rígida en weDevs WP Project Manager permite recuperar datos sensibles incrustados. Este problema afecta a WP Project Manager: desde n/d hasta 2.6.25. | |
| Analizada | Baja (2.1) | 0.45% | — | Phpgurukul CAR Rental Project | 22/9/2025 | 17/6/2026 | A flaw has been found in PHPGurukul Car Rental Project 3.0. Affected by this issue is some unknown functionality of the file /carrental/search.php. Executing manipulation of the argument autofocus can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be… | |
| Analizada | Media (6.5) | 0.21% | — | Zephyrproject Zephyr | 19/9/2025 | 17/6/2026 | Unsafe handling in bt_conn_tx_processor causes a use-after-free, resulting in a write-before-zero. The written 4 bytes are attacker-controlled, enabling precise memory corruption. | |
| Analizada | Alta (7.6) | 0.21% | — | Zephyrproject Zephyr | 19/9/2025 | 17/6/2026 | Parameters are not validated or sanitized, and are later used in various internal operations. | |
| Analizada | Alta (8.1) | 0.40% | — | Zephyrproject Zephyr | 19/9/2025 | 17/6/2026 | The function responsible for handling BLE connection responses does not verify whether a response is expected—that is, whether the device has initiated a connection request. Instead, it relies solely on identifier matching. | |
| Analizada | Media (6.5) | 0.21% | — | Zephyrproject Zephyr | 19/9/2025 | 17/6/2026 | A vulnerability was identified in the handling of Bluetooth Low Energy (BLE) fixed channels (such as SMP or ATT). Specifically, an attacker could exploit a flaw that causes the BLE target (i.e., the device under attack) to attempt to disconnect a fixed channel, which is not allowed per the Bluetooth specification.… | |
| Aplazada | Media (6.3) | 0.47% | — | Torproject TORAI | 18/9/2025 | 17/6/2026 | A security flaw has been discovered in Tor up to 0.4.7.16/0.4.8.17. Impacted is an unknown function of the component Onion Service Descriptor Handler. Performing manipulation results in resource consumption. The attack may be initiated remotely. The attack's complexity is rated as high. The exploitability is… | |
| Aplazada | Alta (8.8) | 0.20% | — | Sparkle-project SparkleAI | 16/9/2025 | 17/6/2026 | The Sparkle framework includes a helper tool Autoupdate. Due to lack of authentication of connecting clients a local unprivileged attacker can request installation of crafted malicious PKG file by racing to connect to the daemon when other app spawns it as root. This results in local privilege escalation to root… | |
| Aplazada | Media (4.8) | 0.17% | — | Sparkle-project SparkleAI | 16/9/2025 | 17/6/2026 | The Sparkle framework includes an XPC service Downloader.xpc, by default this service is private to the application its bundled with. A local unprivileged attacker can register this XPC service globally which will inherit TCC permissions of the application. Lack of validation of connecting client allows the attacker… | |
| Aplazada | Media (6.5) | 0.36% | — | Argusteknoloji BilgerAI | 16/9/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in ArgusTech BILGER allows Choosing Message Identifier. This issue affects BILGER: before 2.4.6. | |
| Aplazada | Media (6.5) | 0.41% | — | Argusteknoloji BilgerAI | 16/9/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability with user privileges in ArgusTech BILGER allows Exploitation of Trusted Identifiers. This issue affects BILGER: before 2.4.6. |