Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3142▲ 563 respecto a la semana anterior
Críticas / altas1455▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
23.915 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.41% | — | Argusteknoloji BilgerAI | 16/9/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability with user privileges in ArgusTech BILGER allows Exploitation of Trusted Identifiers. This issue affects BILGER: before 2.4.6. | |
| Aplazada | Baja (3.2) | 0.13% | — | IP Project Node-ipAI | 16/9/2025 | 17/6/2026 | The ip (aka node-ip) package through 2.0.1 (in NPM) might allow SSRF because the IP address value 017700000001 is improperly categorized as globally routable via isPublic. NOTE: this issue exists because of an incomplete fix for CVE-2024-29415. | |
| Analizada | Media (5.5) | 0.49% | — | 1000projects Online Student Project Report Submission AND Evaluation System | 15/9/2025 | 17/6/2026 | A vulnerability was identified in 1000projects Online Student Project Report Submission and Evaluation System 1.0. The impacted element is an unknown function of the file /admin/controller/student_controller.php. Such manipulation of the argument new_image leads to unrestricted upload. The attack may be performed from… | |
| Analizada | Media (5.5) | 0.46% | — | 1000projects Online Student Project Report Submission AND Evaluation System | 15/9/2025 | 17/6/2026 | A vulnerability was determined in 1000projects Online Student Project Report Submission and Evaluation System 1.0. The affected element is an unknown function of the file /admin/controller/faculty_controller.php. This manipulation of the argument new_image causes unrestricted upload. The attack is possible to be… | |
| Analizada | Baja (2.9) | 0.45% | — | Newbee-mall Project Newbee-mall | 15/9/2025 | 17/6/2026 | A vulnerability was found in newbee-mall 1.0. Impacted is the function mallKaptcha of the file /common/mall/kaptcha. The manipulation results in guessable captcha. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has… | |
| Modificada | Alta (7.5) | 1.3% | — | Libexpat Project Libexpat | 15/9/2025 | 17/6/2026 | libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing. | |
| Analizada | Baja (2.1) | 0.30% | — | Newbee-mall Project Newbee-mall | 15/9/2025 | 17/6/2026 | A vulnerability has been found in newbee-mall up to 613a662adf1da7623ec34459bc83e3c1b12d8ce7. This issue affects the function paySuccess of the file /paySuccess of the component Order Status Handler. The manipulation of the argument orderNo leads to improper authorization. Remote exploitation of the attack is… | |
| Modificada | Crítica (9.8) | 0.88% | — | Sueamcms Project Sueamcms | 12/9/2025 | 5/7/2026 | File Upload vulnerability in SueamCMS v.0.1.2 allows a remote attacker to execute arbitrary code via the lack of filtering. | |
| Analizada | Alta (8.8) | 0.32% | — | Utcms Project Utcms | 10/9/2025 | 17/6/2026 | Se ha encontrado una vulnerabilidad en HuangDou UTCMS V9 y ha sido clasificada como crítica. Esta vulnerabilidad afecta a la función RunSql del archivo app/modules/ut-data/admin/mysql.php. La manipulación del argumento sql conduce a una inyección SQL. El ataque puede iniciarse remotamente. El exploit se ha divulgado… | |
| Aplazada | Media (5.4) | 0.22% | — | Nebojsa Target Video Easy PublishAI | 9/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Nebojsa Target Video Easy Publish brid-video-easy-publish.This issue affects Target Video Easy Publish: from n/a through <= 3.8.9. | |
| Analizada | Crítica (9.9) | 19% | 💥 Exploit | Fogproject | 6/9/2025 | 17/6/2026 | FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Versions 1.5.10.1673 and below contain an authentication bypass vulnerability. It is possible for an attacker to perform an unauthenticated DB dump where they could pull a full SQL DB without credentials. A fix is expected to be… | |
| Analizada | Media (6.5) | 0.83% | 💥 Exploit | @astrojs/cloudflare | 5/9/2025 | 17/6/2026 | Astro is a web framework for content-driven websites. Versions 11.0.3 through 12.6.5 are vulnerable to SSRF when using Astro's Cloudflare adapter. When configured with output: 'server' while using the default imageService: 'compile', the generated image optimization endpoint doesn't check the URLs it receives,… | |
| Analizada | Crítica (9.9) | 5.5% | 💥 Exploit | Argoproj Argo CD | 4/9/2025 | 17/6/2026 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. In versions 2.13.0 through 2.13.8, 2.14.0 through 2.14.15, 3.0.0 through 3.0.12 and 3.1.0-rc1 through 3.1.1, API tokens with project-level permissions are able to retrieve sensitive repository credentials (usernames, passwords) through the… | |
| Analizada | Media (5.5) | 0.44% | — | 1000projects Beauty Parlour Management System | 4/9/2025 | 17/6/2026 | A security vulnerability has been detected in 1000projects Beauty Parlour Management System 1.0. This impacts an unknown function of the file /admin/contact-us.php. The manipulation of the argument mobnumber leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may… | |
| Analizada | Media (5.5) | 0.44% | — | Projectworlds Travel Management System | 3/9/2025 | 17/6/2026 | A security flaw has been discovered in projectworlds Travel Management System 1.0. The impacted element is an unknown function of the file /viewcategory.php. Performing manipulation of the argument t1 results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public… | |
| Analizada | Media (5.5) | 0.44% | — | Projectworlds Travel Management System | 3/9/2025 | 17/6/2026 | A vulnerability was identified in projectworlds Travel Management System 1.0. The affected element is an unknown function of the file /viewpackage.php. Such manipulation of the argument t1 leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. | |
| Modificada | Alta (8.1) | 17% | 💥 PoC | Djangoproject Django | 3/9/2025 | 17/6/2026 | An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed QuerySet.annotate() or QuerySet.alias(). | |
| Analizada | Media (5.5) | 0.44% | — | Projectworlds Travel Management System | 3/9/2025 | 17/6/2026 | A vulnerability was determined in projectworlds Travel Management System 1.0. Impacted is an unknown function of the file /viewsubcategory.php. This manipulation of the argument t1 causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Media (5.5) | 0.44% | — | Projectworlds Travel Management System | 3/9/2025 | 17/6/2026 | A vulnerability has been found in projectworlds Travel Management System 1.0. This vulnerability affects unknown code of the file /enquiry.php. The manipulation of the argument t2 leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (5.5) | 0.44% | — | Projectworlds Travel Management System | 3/9/2025 | 1/10/2026 | Una vulnerabilidad fue encontrada en projectworlds Travel Management System 1.0. Este problema afecta algún procesamiento desconocido del archivo /detail.PHP. La manipulación del argumento pid resulta en inyección SQL. El ataque puede ser ejecutado remotamente. El exploit ha sido hecho público y podría ser usado. | |
| Analizada | Baja (1.9) | 0.29% | — | Code-projects POS Pharmacy System | 3/9/2025 | 17/6/2026 | A weakness has been identified in code-projects POS Pharmacy System 1.0. Affected is an unknown function of the file /main/products.php. This manipulation of the argument product_code/gen_name/product_name/supplier causes cross site scripting. The attack can be initiated remotely. The exploit has been made available… | |
| Analizada | Media (5.5) | 0.44% | — | 1000projects Beauty Parlour Management System | 3/9/2025 | 17/6/2026 | A vulnerability was identified in 1000projects Beauty Parlour Management System 1.0. This affects an unknown function of the file /admin/bwdates-reports-details.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly… | |
| Analizada | Media (6.5) | 0.25% | 💥 PoC | Doubo ERP Project Doubo ERP | 2/9/2025 | 17/6/2026 | Doubo ERP 1.0 has an SQL injection vulnerability due to a lack of filtering of user input, which can be remotely initiated by an attacker. | |
| Analizada | Baja (2.1) | 0.23% | — | Tianti Project Tianti | 1/9/2025 | 17/6/2026 | A vulnerability has been found in xujeff tianti 天梯 up to 2.3. The impacted element is the function ajaxUploadFile of the file src/main/java/com/jeff/tianti/controller/UploadController.java. The manipulation of the argument upfile leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit… | |
| Analizada | Media (5.5) | 0.47% | — | Code-projects Human Resource Integrated System | 31/8/2025 | 17/6/2026 | A security flaw has been discovered in code-projects Human Resource Integrated System 1.0. Impacted is an unknown function of the file login_attendance2.php. Performing manipulation of the argument employee_id/date results in sql injection. The attack can be initiated remotely. The exploit has been released to the… |