Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

822 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.1)0.41%—Withstars Books-management-system27/4/202517/6/2026
A vulnerability classified as problematic was found in withstars Books-Management-System 1.0. This vulnerability affects unknown code of the file /api/comment/add of the component Comment Handler. The manipulation of the argument content leads to cross site scripting. The attack can be initiated remotely. The exploit…
AnalizadaMedia (5.1)0.41%—Withstars Books-management-system27/4/202517/6/2026
A vulnerability classified as problematic has been found in withstars Books-Management-System 1.0. This affects an unknown part of the file /admin/article/add/do. The manipulation of the argument Title leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the…
AnalizadaMedia (6.9)0.66%—Withstars Books-management-system27/4/202517/6/2026
A vulnerability was found in withstars Books-Management-System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /allreaders.html of the component Background Interface. The manipulation leads to missing authorization. The attack may be launched remotely. The exploit…
AnalizadaMedia (5.3)0.30%—Withstars Books-management-system27/4/202517/6/2026
A vulnerability was found in withstars Books-Management-System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /reader_delete.html. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed…
AnalizadaMedia (5.1)0.41%—Withstars Books-management-system27/4/202517/6/2026
A vulnerability was found in withstars Books-Management-System 1.0. It has been classified as problematic. Affected is an unknown function of the file /book_edit_do.html of the component Book Edit Page. The manipulation of the argument Name leads to cross site scripting. It is possible to launch the attack remotely.…
AplazadaCrítica (9.3)0.57%—Istar Configuration UtilityAI24/4/202517/6/2026
Under certain circumstances the iSTAR Configuration Utility (ICU) tool could have a buffer overflow issue
AplazadaMedia (6.1)0.30%💥 PoCLaravel StarterAI22/4/202517/6/2026
Laravel Starter 11.11.0 is vulnerable to Cross Site Scripting (XSS) in the tags feature. Any user with the ability of create or modify tags can inject malicious JavaScript code in the name field.
AplazadaAlta (8.8)0.37%—Starfish Review Generation AND MarketingAI17/4/202517/6/2026
Missing Authorization vulnerability in Starfish Reviews Starfish Review Generation & Marketing starfish-reviews allows Privilege Escalation.This issue affects Starfish Review Generation & Marketing: from n/a through <= 3.1.19.
AnalizadaCrítica (10)99%⚠ Explotación activa💥 ExploitErlang/otpCisco Confd BasicCisco Network Services OrchestratorCisco Cloud Native Broadband Network Gateway+1916/4/202517/6/2026
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain…
AplazadaAlta (8.5)0.34%—Magnigenie Review-stars-count-for-woocommerceAI10/4/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Magnigenie Review Stars Count For WooCommerce review-stars-count-for-woocommerce allows SQL Injection.This issue affects Review Stars Count For WooCommerce: from n/a through <= 2.0.
AplazadaMedia (5.9)0.35%—Hackathon-starterAI1/4/202517/6/2026
An issue in hackathon-starter v.8.1.0 allows a remote attacker to escalate privileges via the user.js component.
AplazadaMedia (5.1)0.97%—Novastar Cx40AI31/3/202517/6/2026
A vulnerability classified as critical has been found in Novastar CX40 up to 2.44.0. Affected is the function system/popen of the file /usr/nova/bin/netconfig of the component NetFilter Utility. The manipulation leads to command injection. The exploit has been disclosed to the public and may be used. The vendor was…
AplazadaMedia (5.1)0.29%—Novastar Cx40AI31/3/202517/6/2026
A vulnerability was found in Novastar CX40 up to 2.44.0. It has been rated as critical. This issue affects the function getopt of the file /usr/nova/bin/netconfig of the component NetFilter Utility. The manipulation of the argument cmd/netmask/pipeout/nettask leads to stack-based buffer overflow. The exploit has been…
AnalizadaMedia (5.3)0.45%—Bluestar Micro Mall30/3/202517/6/2026
A vulnerability classified as critical was found in Bluestar Micro Mall 1.0. Affected by this vulnerability is an unknown functionality of the file /api/api.php?mod=upload&type=1. The manipulation of the argument File leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to…
AnalizadaMedia (5.3)0.50%—Bluestar Micro Mall30/3/202517/6/2026
A vulnerability classified as critical has been found in Bluestar Micro Mall 1.0. Affected is an unknown function of the file /api/data.php. The manipulation of the argument Search leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
AnalizadaMedia (4.3)0.17%—Vollstart Event Tickets With Ticket Scanner28/3/202517/6/2026
The Event Tickets with Ticket Scanner WordPress plugin before 2.5.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
AplazadaMedia (4.9)0.62%—Rustaurius Five Star Restaurant ReservationsAI27/3/202517/6/2026
Missing Authorization vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Five Star Restaurant Reservations: from n/a through <= 2.6.29.
AplazadaMedia (4.3)0.17%—Vollstart Serial Codes Generator AND ValidatorAI27/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Vollstart Serial Codes Generator and Validator with WooCommerce Support serial-codes-generator-and-validator allows Cross Site Request Forgery.This issue affects Serial Codes Generator and Validator with WooCommerce Support: from n/a through <= 2.7.7.
AplazadaAlta (7.1)0.31%—Starblank Custom Product Stickers FOR WoocommerceAI26/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in starblank Custom Product Stickers for Woocommerce custom-product-stickers-for-woocommerce allows Reflected XSS.This issue affects Custom Product Stickers for Woocommerce: from n/a through <= 1.9.0.
AplazadaMedia (6.4)0.30%—Ayyash Studio THE Kick Start KITAI26/3/202517/6/2026
The Ayyash Studio — The kick-start kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above,…
AplazadaAlta (7.5)0.70%—Danswer-ai DanswerAITiangolo FastapiAIEncode StarletteAI20/3/202517/6/2026
A vulnerability in danswer-ai/danswer version 0.9.0 allows for denial of service through memory exhaustion. The issue arises from the use of a vulnerable version of the starlette package (<=0.49) via fastapi, which was patched in fastapi version 0.115.3. The vulnerability can be exploited by sending multiple requests…
AnalizadaMedia (4.8)0.30%—Starsea99 Starsea-mall16/3/202517/6/2026
A vulnerability, which was classified as problematic, has been found in StarSea99 starsea-mall 1.0. This issue affects some unknown processing of the file /admin/indexConfigs/save of the component Backend. The manipulation of the argument categoryName leads to cross site scripting. The attack may be initiated…
AnalizadaCrítica (9.1)0.43%—Fancywp Starter Templates8/3/202517/6/2026
The Starter Templates by FancyWP plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.0.0 via the 'http_request_host_is_external' filter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web…
AnalizadaMedia (5.3)0.50%—Starsea99 Starsea-mall7/3/202517/6/2026
A vulnerability has been found in StarSea99 starsea-mall 1.0/2.X and classified as critical. Affected by this vulnerability is the function updateUserInfo of the file /personal/updateInfo of the component com.siro.mall.controller.mall.UserController. The manipulation of the argument userId leads to improper access…
AnalizadaMedia (5.1)0.40%—Starsea99 Starsea-mall7/3/202517/6/2026
A vulnerability, which was classified as problematic, has been found in StarSea99 starsea-mall 1.0. This issue affects some unknown processing of the file /admin/goods/update. The manipulation of the argument goodsName leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed…
Orbitaley — Vulnerabilidades