Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3232▲ 666 respecto a la semana anterior
Críticas / altas1516▲ 123 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

21.084 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.1)0.53%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+114/4/202617/6/2026
Una lectura fuera de límites en Microsoft Office Excel permite a un atacante no autorizado divulgar información localmente.
AnalizadaAlta (8.8)0.78%—Microsoft Azure Logic Apps14/4/202617/6/2026
Insufficiently protected credentials in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.6)1.9%—Adobe ConnectAdobe Connect Desktop Application14/4/202628/8/2026
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact…
AnalizadaCrítica (9.3)0.74%—Adobe ConnectAdobe Connect Desktop Application14/4/202628/8/2026
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this…
AnalizadaCrítica (9.3)0.74%—Adobe ConnectAdobe Connect Desktop Application14/4/202628/8/2026
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this…
AnalizadaCrítica (9.3)0.74%—Adobe ConnectAdobe Connect Desktop Application14/4/202628/8/2026
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this…
AnalizadaCrítica (9)0.77%—Microsoft Power Apps14/4/202617/6/2026
Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (7.8)0.41%—Microsoft 365 AppsMicrosoft Office Long Term Servicing Channel14/4/202617/6/2026
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaMedia (6.1)0.28%—Adobe ConnectAdobe Connect Desktop Application14/4/202628/8/2026
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Scope is changed.
AnalizadaMedia (6.5)0.50%—Snipeitapp Snipe-it14/4/202617/6/2026
An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attackers with the users.edit permission to modify sensitive authentication and account-state fields of other non-admin users via supplying a crafted PUT request.
AplazadaBaja (2.7)0.31%—Sourcecodester Patient Appointment Scheduler SystemAI14/4/202617/6/2026
SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/user/manage_user.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Patient Appointment Scheduler SystemAI14/4/202617/6/2026
SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/appointments/manage_appointment.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Patient Appointment SchedulerAI14/4/202617/6/2026
SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/appointments/view_details.php.
AplazadaBaja (2.7)0.39%—Sourcecodester Patient Appointment Scheduler SystemAI14/4/202617/6/2026
SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to arbitrary code execution (RCE) via /scheduler/classes/SystemSettings.php?f=update_settings.
AplazadaCrítica (9.8)1.2%—Hostbillapp HostbillAI14/4/202617/6/2026
An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code and escalate privileges via the CSV registration field
AnalizadaMedia (6.1)0.26%—SAP Netweaver Application Server Abap14/4/202617/6/2026
Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft malicious URL that, if accessed by a victim, they could be redirected to the page controlled by the attacker. This causes low impact on confidentiality and integrity of the application with no impact…
AnalizadaMedia (6.1)0.29%—SAP Netweaver Application Server Java14/4/202617/6/2026
Due to a Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java), an unauthenticated attacker could supply crafted input that is interpreted by the application and causes it to reference attacker-controlled content. If a victim accesses the affected functionality, that…
AplazadaMedia (5.4)0.23%—Snipeitapp Snipe-itAI13/4/20265/7/2026
Cross-Site Scripting vulnerability in the Snipe-IT web-based asset management system v8.3.0 to up and including v8.3.1 allows authenticated attacker with lowest privileges sufficient only to log in, to inject arbitrary JavaScript code via "Name" and "Surname" fields. The JavaScript code is executed whenever "Activity…
Pendiente de análisisAlta (8.4)0.20%—AleappAI8/4/202624/7/2026
ALEAPP (Analizador de Eventos y Registros de Android y Protobuf) hasta la versión 3.4.0 contiene una vulnerabilidad de salto de ruta en el analizador de artefactos NQ_Vault.py que utiliza valores file_name_from controlados por el atacante de una base de datos directamente como nombre de archivo de salida, permitiendo…
AnalizadaMedia (5.3)0.28%—Frappe Learning8/4/202624/7/2026
Frappe Learning Management System (LMS) es un sistema de aprendizaje que ayuda a los usuarios a estructurar su contenido. Antes de la versión 2.46.0, se ha identificado una vulnerabilidad en Frappe Learning donde las puntuaciones de los cuestionarios pueden ser modificadas por los estudiantes antes de la entrega. La…
ModificadaCrítica (9.1)0.42%—Frappe ErpnextFrappe8/4/202625/7/2026
Una vulnerabilidad de falsificación de petición del lado del servidor (SSRF) existe en la funcionalidad de Formato de Impresión de ERPNext v16.0.1 y Frappe Framework v16.1.1, donde el HTML proporcionado por el usuario no se sanea suficientemente antes de ser renderizado a PDF. Al generar PDFs a partir de contenido…
AplazadaMedia (6.5)0.22%—Elfsight Whatsapp Chat CCAI8/4/202624/7/2026
Vulnerabilidad de Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') en Elfsight Elfsight WhatsApp Chat CC elfsight-whatsapp-chat permite XSS basado en DOM. Este problema afecta a Elfsight WhatsApp Chat CC: desde n/a hasta <= 1.2.0.
AplazadaMedia (5.3)0.26%—Nsquared Simply Schedule AppointmentsAI8/4/202624/7/2026
Vulnerabilidad por falta de autorización en NSquared Simply Schedule Appointments simply-schedule-appointments permite explotar niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a Simply Schedule Appointments: desde n/a hasta <= 1.6.10.2.
AplazadaMedia (6)0.21%—Bootstrapped Visual Link PreviewAI8/4/202624/7/2026
Vulnerabilidad de falsificación de petición del lado del servidor (SSRF) en Brecht Visual Link Preview visual-link-preview permite la falsificación de petición del lado del servidor. Este problema afecta a Visual Link Preview: desde n/a hasta <= 2.3.0.
AplazadaCrítica (9.6)0.20%—Priyanshumittal AppointmentAI8/4/202624/7/2026
Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en priyanshumittal Appointment appointment permite subir un shell web a un servidor web. Este problema afecta a Appointment: desde n/a hasta <= 3.5.5.