Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
5178 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.65% | — | Canonical Juju | 8/7/2025 | 17/6/2026 | In Juju versions prior to 3.6.8 and 2.9.52, any authenticated controller user was allowed to upload arbitrary agent binaries to any model or to the controller itself, without verifying model membership or requiring explicit permissions. This enabled the distribution of poisoned binaries to new or upgraded machines,… | |
| Analizada | Media (6.5) | 0.72% | — | Canonical Juju | 8/7/2025 | 17/6/2026 | The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on the controller to upload a charm. Uploading a malicious charm that exploits a Zip Slip vulnerability could allow an attacker to gain access to a machine running a unit through the affected charm. | |
| Analizada | Media (6.5) | 0.35% | — | Canonical Juju | 8/7/2025 | 17/6/2026 | The /log endpoint on a Juju controller lacked sufficient authorization checks, allowing unauthorized users to access debug messages that could contain sensitive information. | |
| Aplazada | Alta (7.1) | 0.26% | — | Quanticalabs PressroomAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs Pressroom pressroom allows Reflected XSS.This issue affects Pressroom: from n/a through <= 7.0. | |
| Analizada | Media (6.5) | 0.16% | — | Canonical Juju/utils | 1/7/2025 | 17/6/2026 | Certificate generation in juju/utils using the cert.NewLeaf function could include private information. If this certificate were then transferred over the network in plaintext, an attacker listening on that network could sniff the certificate and trivially extract the private key from it. | |
| Analizada | Alta (7.8) | 55% | ⚠ Explotación activa💥 Exploit | Sudo Project SudoCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+4 | 30/6/2025 | 17/6/2026 | Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option. | |
| Analizada | Media (6.5) | 0.15% | — | Anujk305 Medical Card Generation System | 27/6/2025 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the Inquiry Management functionality /mcgs/admin/readenq.php of the Phpgurukul Medical Card Generation System 1.0. The vulnerable endpoint allows an authenticated admin to delete inquiry records via a simple GET request, without requiring a CSRF token or… | |
| Analizada | Media (6.5) | 0.15% | — | Anujk305 Medical Card Generation System | 27/6/2025 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the Manage Card functionality (/mcgs/admin/manage-card.php) of PHPGurukul Medical Card Generation System 1.0. The vulnerable endpoint allows an authorized admin to delete medical card records by sending a simple GET request without verifying the origin of the… | |
| Analizada | Media (6.1) | 0.24% | — | Anujk305 Medical Card Generation System | 27/6/2025 | 17/6/2026 | A stored blind XSS vulnerability exists in the Contact Page of the Phpgurukul Medical Card Generation System 1.0 mcgs/contact.php. The name field fails to properly sanitize user input, allowing an attacker to inject malicious JavaScript. | |
| Aplazada | Alta (7.1) | 0.21% | — | Quanticalabs Css3 Vertical WEB Pricing TablesAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs CSS3 Vertical Web Pricing Tables css3_vertical_web_pricing_tables allows Reflected XSS.This issue affects CSS3 Vertical Web Pricing Tables: from n/a through <= 1.9. | |
| Analizada | Alta (8.8) | 0.27% | — | Canonical Cloud-init | 26/6/2025 | 17/6/2026 | When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration. | |
| Analizada | Media (5.3) | 0.14% | — | Canonical Cloud-init | 26/6/2025 | 17/6/2026 | cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This is used for the "/run/cloud-init/hook-hotplug-cmd" FIFO. An unprivileged user could trigger hotplug-hook commands. | |
| Aplazada | Media (6.5) | 0.23% | — | Atakanau Automatically Hierarchic Categories IN MenuAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atakan Au Automatically Hierarchic Categories in Menu automatically-hierarchic-categories-in-menu allows Stored XSS.This issue affects Automatically Hierarchic Categories in Menu: from n/a through <= 2.0.9. | |
| Analizada | Alta (8.5) | 0.30% | — | Canonical Authd | 16/6/2025 | 17/6/2026 | A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the first time will be considered to be part of the root group in the context of that SSH session. | |
| Analizada | Media (5.3) | 0.45% | — | Phpgurukul Medical Card Generation System | 5/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in PHPGurukul Medical Card Generation System 1.0. This issue affects some unknown processing of the file /admin/manage-card.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.45% | — | Phpgurukul Medical Card Generation System | 5/6/2025 | 17/6/2026 | A vulnerability classified as critical was found in PHPGurukul Medical Card Generation System 1.0. This vulnerability affects unknown code of the file /admin/unreadenq.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (5.3) | 0.45% | — | Phpgurukul Medical Card Generation System | 5/6/2025 | 17/6/2026 | A vulnerability classified as critical has been found in PHPGurukul Medical Card Generation System 1.0. This affects an unknown part of the file /admin/readenq.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (6.5) | 0.34% | — | Philips Clinical Collaboration Platform | 2/6/2025 | 17/6/2026 | Clinical Collaboration Platform 12.2.1.5 has a weak logout system where the session token remains valid after logout and allows a remote attacker to obtain sensitive information and execute arbitrary code. | |
| Analizada | Media (6.5) | 0.36% | — | Philips Clinical Collaboration Platform | 2/6/2025 | 17/6/2026 | An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the usertoken function of default.aspx. | |
| Analizada | Media (6.5) | 0.36% | — | Philips Clinical Collaboration Platform | 2/6/2025 | 17/6/2026 | An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the session management component. | |
| Modificada | Media (4.7) | 0.76% | 💥 PoC | Canonical ApportCanonical Ubuntu Linux | 30/5/2025 | 17/6/2026 | Race condition in Canonical apport up to and including 2.32.0 allows a local attacker to leak sensitive information via PID-reuse by leveraging namespaces. When handling a crash, the function `_check_global_pid_and_forward`, which detects if the crashing process resided in a container, was being called before… | |
| Analizada | Media (6.1) | 0.24% | — | Bestpractical Request Tracker | 28/5/2025 | 17/6/2026 | Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an RT permalink. | |
| Analizada | Media (6.1) | 0.24% | — | Bestpractical Request Tracker | 28/5/2025 | 17/6/2026 | Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an Asset name. | |
| Modificada | Media (6.1) | 0.31% | — | Bestpractical Request Tracker | 28/5/2025 | 17/6/2026 | Best Practical RT (Request Tracker) 4.4 through 4.4.7 and 5.0 through 5.0.7 allows XSS via injection of crafted parameters in a search URL. | |
| Analizada | Media (6.1) | 0.33% | — | Phpgurukul Medical Card Generation System | 23/5/2025 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in the component mcgs/download-medical-cards.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the searchdata parameter. |