Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
9809 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.37% | — | Phpgurukul Bank Locker Management SystemAI | 13/9/2026 | 15/9/2026 | A weakness has been identified in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the file /blms/banker/add-locker-form.php. This manipulation of the argument addressproof causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to… | |
| Aplazada | Baja (2.1) | 0.37% | — | Phpgurukul Bank Locker Management SystemAI | 13/9/2026 | 14/9/2026 | A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown function of the file sidebar.php. The manipulation of the argument UserType results in improper access controls. The attack may be launched remotely. The exploit has been released to the public and may be used… | |
| Aplazada | Media (5.5) | 0.57% | — | Phpgurukul Bank Locker Management SystemAI | 13/9/2026 | 16/9/2026 | A vulnerability was identified in PHPGurukul Bank Locker Management System 1.0. This affects an unknown function of the file /blms/view-assign-locker.php. The manipulation of the argument ltid leads to authorization bypass. The attack may be initiated remotely. The exploit is publicly available and might be used. | |
| Pendiente de análisis | Alta (7.5) | 0.57% | — | HPE Icewall Federation AgentAIHPE Icewall ProxyAI | 11/9/2026 | 11/9/2026 | A potential security vulnerability in HPE IceWall Federation Agent and Proxy could allow a remote unauthenticated attacker to cause a denial of service (DoS). | |
| Pendiente de análisis | Alta (8.8) | 0.30% | — | HPE IcewallAI | 11/9/2026 | 11/9/2026 | A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker to impersonate another user. | |
| Analizada | Media (6.1) | 0.33% | — | Mongodb PHP Library | 10/9/2026 | 29/9/2026 | Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB PHP Library can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an… | |
| Aplazada | Alta (8.7) | 0.28% | — | Thephpleague CommonmarkAI | 9/9/2026 | 9/9/2026 | league/commonmark versions before 2.6.0 contain polynomial time complexity vulnerabilities in Markdown parsing that allow attackers to cause denial of service. Attackers can submit carefully crafted Markdown inputs designed to trigger worst-case performance, and sending multiple requests in parallel exhausts CPU… | |
| Aplazada | Alta (7.2) | 0.64% | — | Publishpress CapabilitiesAI | 9/9/2026 | 11/9/2026 | The PublishPress Capabilities – User Role Editor, Access Permissions, User Capabilities, Admin Menus plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.50.0. This is due to the `addPluginCapabilities()` function unconditionally granting the Editor role all 15… | |
| Pendiente de análisis | Media (6.5) | 0.09% | — | Snowflake Python DriverAISnowflake GO DriverAISnowflake Jdbc DriverAISnowflake Node.js DriverAI+2 | 8/9/2026 | 10/9/2026 | Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encryption keys, pre-signed cloud-storage URLs, and SAML assertions to be written to diagnostic logs in circumstances where the available log redaction did… | |
| Pendiente de análisis | Alta (8.7) | 0.49% | — | Thephpleague CommonmarkAI | 7/9/2026 | 9/9/2026 | commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate footnote definitions. Attackers can craft documents with duplicate footnote definitions and references to create quadratic output expansion, consuming excessive memory and CPU to… | |
| Pendiente de análisis | Alta (8.7) | 0.51% | — | Thephpleague CommonmarkAI | 7/9/2026 | 8/9/2026 | commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Attributes extension where AttributesListener::findTargetAndDirection() performs quadratic-time sibling list scanning. Unauthenticated attackers can submit approximately 32 KB of repeated attribute blocks to cause parsing to… | |
| Pendiente de análisis | Media (6.9) | 0.42% | — | Thephpleague CommonmarkAI | 7/9/2026 | 10/9/2026 | commonmark versions from 2.0.0 before 2.8.4 contain a denial of service vulnerability in XmlRenderer that emits depth-proportional indentation for every XML tag. Attackers can provide deeply nested Markdown or AST structures to cause quadratic memory consumption and output amplification, exhausting server resources. | |
| Analizada | Media (6.9) | 0.39% | — | Thephpleague Commonmark | 7/9/2026 | 9/9/2026 | league/commonmark (thephpleague/commonmark) versions >= 2.7.0 and < 2.9.1 contain a cross-site scripting vulnerability in the AttributesExtension. Prefixing an attribute name with a single U+000C form feed byte (e.g. {\x0Conclick="alert(1)"}) bypasses the AttributesHelper::filterAttributes() 'on*' event-handler filter… | |
| Analizada | Alta (8.7) | 0.49% | — | Thephpleague Commonmark | 7/9/2026 | 10/9/2026 | league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code block detection, reference link label lookup, and emphasis delimiter processing that perform super-linear work on crafted input. Attackers can submit specially crafted Markdown with long backtick runs, nested… | |
| Analizada | Alta (8.7) | 0.49% | — | Thephpleague Commonmark | 7/9/2026 | 9/9/2026 | commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when processing distinctly-named attributes. Attackers can submit Markdown with numerous distinct attribute names to cause quadratic-time attribute merging and filtering, consuming disproportionate CPU… | |
| Aplazada | Media (5.5) | 0.50% | — | ThinkphpAILight0011 CMSAI | 7/9/2026 | 11/9/2026 | A security flaw has been discovered in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Affected by this issue is the function Upload::upload of the file ThinkPHP/Library/Think/Upload.class.php. Performing a manipulation results in unrestricted upload. The attack is… | |
| Pendiente de análisis | Alta (8.7) | 0.51% | — | Thephpleague CommonmarkAI | 7/9/2026 | 19/9/2026 | league/commonmark versions >= 2.0.0 and < 2.8.4 (patched in 2.9.0) contain a denial of service vulnerability in UniqueSlugNormalizer::normalize(), which restarts its numeric-suffix search from 1 on every slug collision, resulting in O(K^2) time complexity for K headings that collapse to the same base slug. The… | |
| Analizada | Alta (8.7) | 0.52% | — | Thephpleague Commonmark | 7/9/2026 | 19/9/2026 | The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. When either extension is explicitly registered on the Environment (they are not enabled by default and are excluded from the standard… | |
| Aplazada | Baja (2.1) | 0.47% | — | Code-projects Hotel AND Tourism ReservationAIPHPAI | 6/9/2026 | 8/9/2026 | A security vulnerability has been detected in code-projects Hotel and Tourism Reservation in PHP 1.0. This impacts an unknown function of the file /ht/details.php. The manipulation of the argument room leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Task Management System IN PHPAI | 6/9/2026 | 8/9/2026 | A vulnerability has been found in code-projects Task Management System In PHP 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Login. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Media (5.1) | 0.24% | — | PhpmyfaqAI | 4/9/2026 | 14/9/2026 | phpMyFAQ versions before 4.1.8 contain a stored cross-site scripting vulnerability in FaqHelper::convertOldInternalLinks() that calls html_entity_decode() on sanitized FAQ content, reversing entity-encoding protection. Authenticated users with FAQ editing privileges can inject JavaScript payloads that execute in the… | |
| Aplazada | Media (6.3) | 0.31% | — | PhpmyfaqAI | 4/9/2026 | 8/9/2026 | phpMyFAQ before 4.1.8 contains an authorization bypass vulnerability in the question creation endpoint where the isAddingQuestionsAllowed() method grants access to all callers when main.enableAskQuestions is enabled, ignoring the records.allowQuestionsForGuests setting. Unauthenticated attackers can submit questions… | |
| Aplazada | Alta (7.1) | 0.52% | — | PhpmyfaqAI | 4/9/2026 | 10/9/2026 | phpMyFAQ versions before 4.1.8 contain an authentication bypass vulnerability in the user control panel API endpoint that allows authenticated attackers to change account passwords without verifying the current password. Attackers with session access can submit a PUT request to the user data update endpoint with only… | |
| Aplazada | Alta (7.1) | 0.52% | — | PhpmyfaqAI | 4/9/2026 | 8/9/2026 | phpMyFAQ before 4.1.8 contains an authentication bypass vulnerability in its two-factor authentication (TOTP) disable functionality. The removeTwofactorConfig() handler (reachable via POST /api/user/remove-twofactor) verifies only that the user is logged in and that a valid CSRF token is supplied, then disables TOTP… | |
| Aplazada | Media (5.3) | 0.49% | — | PhpmyfaqAI | 4/9/2026 | 8/9/2026 | phpMyFAQ before 4.2.0-alpha.2 contains a missing authorization vulnerability in the admin dashboard API endpoints searches and content-health that enforce only authentication without permission checks. Any authenticated user can access these endpoints to read site-wide search statistics and content-health counters… |