Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
4214 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.36% | — | Nsquared Simply Schedule AppointmentsAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Blind SQL Injection.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.9.27. | |
| Aplazada | Alta (7.2) | 0.82% | — | Gerador DE Certificados Devapps Gerador DE CertificadosAI | 8/4/2026 | 20/7/2026 | The Gerador de Certificados – DevApps plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the moveUploadedFile() function in all versions up to, and including, 1.3.6. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload… | |
| Aplazada | Media (5.5) | 0.51% | — | Code-projects Online Application System FOR AdmissionAI | 6/4/2026 | 17/6/2026 | A vulnerability was found in code-projects Online Application System for Admission 1.0. Impacted is an unknown function of the file /enrollment/database/oas.sql. Performing a manipulation results in insecure storage of sensitive information. The attack is possible to be carried out remotely. The exploit has been made… | |
| Aplazada | Baja (2.1) | 0.32% | — | Code-projects Online Application System FOR AdmissionAI | 6/4/2026 | 17/6/2026 | A vulnerability has been found in code-projects Online Application System for Admission 1.0. This issue affects some unknown processing of the file /enrollment/admsnform.php of the component Endpoint. Such manipulation leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the… | |
| Aplazada | Baja (1.9) | 0.15% | — | Investory TOY Planet Trouble APPAI | 3/4/2026 | 24/7/2026 | A vulnerability was detected in Investory Toy Planet Trouble App up to 1.5.5 on Android. Impacted is an unknown function of the file assets/google-services-desktop.json of the component app.investory.toyfactory. The manipulation of the argument current_key results in use of hard-coded cryptographic key . The attack… | |
| Aplazada | Baja (1.9) | 0.15% | — | Dialogue APPAI | 3/4/2026 | 24/7/2026 | A vulnerability was determined in Dialogue App up to 4.3.2 on Android. The affected element is an unknown function of the file file res/raw/config.json of the component ca.diagram.dialogue. Executing a manipulation of the argument SEGMENT_WRITE_KEY can lead to use of hard-coded cryptographic key . The attack is… | |
| Aplazada | Baja (1.1) | 0.13% | — | Shinrays Games Goods Triple APPAI | 2/4/2026 | 24/7/2026 | A security flaw has been discovered in Shinrays Games Goods Triple App up to 1.200. The affected element is an unknown function of the file jRwTX.java of the component cats.goods.sort.sorting.games. Performing a manipulation of the argument AES_IV/AES_PASSWORD results in use of hard-coded cryptographic key . Attacking… | |
| Aplazada | Media (5.5) | 0.52% | — | Sourcecodester Leave Application SystemAI | 2/4/2026 | 17/6/2026 | A vulnerability was identified in SourceCodester Leave Application System 1.0. Impacted is an unknown function of the file /index.php?page=manage_user of the component User Information Handler. Such manipulation of the argument ID leads to authorization bypass. The attack can be executed remotely. The exploit is… | |
| Aplazada | Media (5.5) | 0.48% | — | Sourcecodester Leave Application SystemAI | 31/3/2026 | 24/7/2026 | A vulnerability was detected in SourceCodester Leave Application System 1.0. This affects an unknown part. Performing a manipulation of the argument page results in file inclusion. Remote exploitation of the attack is possible. The exploit is now public and may be used. | |
| Aplazada | Baja (1.9) | 0.35% | — | Sourcecodester Leave Application SystemAI | 31/3/2026 | 24/7/2026 | A security vulnerability has been detected in SourceCodester Leave Application System 1.0. Affected by this issue is some unknown functionality of the component User Management Handler. Such manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed publicly and may… | |
| Modificada | Crítica (9.1) | 0.89% | — | Redhat Build OF Apache Camel - HawtioRedhat Build OF Apache Camel FOR Spring BootRedhat Data GridRedhat Fuse+6 | 27/3/2026 | 21/9/2026 | A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP standards, can be exploited by a remote attacker to perform request smuggling.… | |
| Modificada | Crítica (9.1) | 0.89% | — | Redhat Build OF Apache Camel - HawtioRedhat Build OF Apache Camel FOR Spring BootRedhat Data GridRedhat Fuse+6 | 27/3/2026 | 21/9/2026 | A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exploited to launch request smuggling attacks, potentially bypassing… | |
| Modificada | Crítica (9.1) | 0.89% | — | Redhat Build OF Apache Camel - HawtioRedhat Build OF Apache Camel FOR Spring BootRedhat Data GridRedhat Fuse+5 | 27/3/2026 | 21/9/2026 | A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions of Apache Traffic Server and Google Cloud Classic Application Load Balancer, potentially leading to… | |
| Modificada | Alta (7.2) | 0.53% | — | Redhat Build OF KeycloakRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 26/3/2026 | 17/6/2026 | A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where this permission is equivalent to `manage-permissions`. This allows the administrator to escalate privileges and gain control over roles, users, or other administrative functions within the realm. This… | |
| Modificada | Baja (3.1) | 0.33% | — | Redhat Build OF KeycloakRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 26/3/2026 | 26/6/2026 | A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSRF) by manipulating the `client_session_host` parameter during refresh token requests. This occurs when a Keycloak client is configured to use the `backchannel.logout.url` with the `application.session.host` placeholder.… | |
| Analizada | Media (5.4) | 0.29% | — | IBM Websphere Application Server | 25/3/2026 | 17/6/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is vulnerable to server-side request forgery (SSRF). This may allow remote attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Analizada | Crítica (9.8) | 0.40% | — | IBM Websphere Application Server | 25/3/2026 | 17/6/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could provide weaker than expected security when administering security settings. | |
| Analizada | Alta (7.2) | 0.56% | — | IBM Websphere Application Server | 25/3/2026 | 17/6/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is affected by privilege escalation. A privileged user could gain additional access to the application server. | |
| Aplazada | Crítica (9.1) | 0.50% | — | Syarif Mobile APP EditorAI | 19/3/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Syarif Mobile App Editor mobile-app-editor allows Upload a Web Shell to a Web Server.This issue affects Mobile App Editor: from n/a through <= 1.3.1. | |
| Modificada | Media (5.8) | 0.39% | — | Redhat Build OF KeycloakRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 18/3/2026 | 17/6/2026 | A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirects when processing certain client configuration requests. This behavior allows an attacker to trick the server into making unintended requests to internal or restricted resources. As a result,… | |
| Aplazada | Media (4.3) | 0.21% | — | Simply Schedule AppointmentsAI | 13/3/2026 | 17/6/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.9.29. This is due to the `get_item_permissions_check` method granting access to users with the `ssa_manage_appointments`… | |
| Aplazada | Baja (2) | 0.35% | — | Xierongwkhd Weimai-wetappAI | 11/3/2026 | 17/6/2026 | A flaw has been found in xierongwkhd weimai-wetapp up to 5fe9e8225be4f73f2c5087f134aff657bdf1c6f2. This vulnerability affects the function getLikeMovieList of the file source-code/src/main/java/com/moke/wp/wx_weimai/controller/HomeController.java of the component Endpoint. Executing a manipulation of the argument cat… | |
| Aplazada | Baja (2) | 0.33% | — | Xierongwkhd Weimai-wetappAI | 11/3/2026 | 17/6/2026 | A vulnerability was detected in xierongwkhd weimai-wetapp up to 5fe9e8225be4f73f2c5087f134aff657bdf1c6f2. This affects the function getAdmins of the file source-code/src/main/java/com/moke/wp/wx_weimai/controller/admin/Admin_AdminUserController.java. Performing a manipulation of the argument keyword results in sql… | |
| Modificada | Alta (8.1) | 0.49% | — | Redhat Build OF KeycloakRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 5/3/2026 | 14/9/2026 | A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even after it has been disabled by an administrator. An attacker who knows the IdP alias can reuse a previously generated login request to bypass the administrative… | |
| Analizada | Media (5.3) | 0.20% | — | Netapp Ontap | 5/3/2026 | 17/6/2026 | ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Successful exploit could allow an authenticated attacker to view a listing of the contents in a directory for which they lack permission. |