Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3081▲ 625 respecto a la semana anterior
Críticas / altas1483▲ 317 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
1737 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 1.3% | — | MineadminAI | 30/9/2026 | 30/9/2026 | MineAdmin is a ready-to-use backend management system suitable for quickly building website backends, operation platforms, permission centers, internal management systems, CMS, CRM, OA, ERP and other business applications. Prior to version 3.2.0-alpha.2, the app-store plugin service concatenates unsanitized… | |
| Aplazada | Alta (7.6) | 0.38% | — | Admin Notices ManagerAI | 30/9/2026 | 30/9/2026 | Administrator SQL Injection in Admin Notices Manager <= 1.6.0 versions. | |
| Pendiente de análisis | Alta (8.7) | 0.26% | — | Tibco AdministratorAI | 29/9/2026 | 30/9/2026 | Injection Vulnerability in Tibco Administrator version 5.13.0 & prior allows an authenticated user to submit specially crafted input through the web-based administration console. | |
| Aplazada | Alta (7.1) | 0.39% | — | FastadminAI | 29/9/2026 | 29/9/2026 | A vulnerability was detected in FastAdmin 1.6.1.20250430/1.6.5.20260602. This affects an unknown function of the file application/database.php of the component Database Management. The manipulation results in execution with unnecessary privileges. The attack may be launched remotely. The exploit is now public and may… | |
| Pendiente de análisis | Media (6.9) | 0.28% | — | AdminerAI | 26/9/2026 | 30/9/2026 | Adminer 5.5.1 through 6.0.1 improperly parses the login 'server' string in the host_port() function in adminer/include/functions.inc.php. The port capture group requires pure digits anchored to the end of the string, so any server value with a non-digit tail fails the regex and falls back to returning the whole string… | |
| Pendiente de análisis | Media (5.3) | 0.31% | — | AdminerAI | 26/9/2026 | 30/9/2026 | Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins/drivers/clickhouse.php, rewritten in 6.0.0) is loaded, is vulnerable to pre-authentication server-side request forgery. An unauthenticated attacker can submit auth[driver]=clickhouse with auth[server] set to an arbitrary URL (for example… | |
| Pendiente de análisis | Media (6.9) | 0.31% | — | AdminerAI | 26/9/2026 | 28/9/2026 | Adminer 4.16.0 through 6.0.1 contain a pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the optional Elasticsearch driver (plugins/drivers/elastic.php), fixed in 6.0.2. Because adminer/include/auth.inc.php invokes Driver::connect() before the login result is validated, an unauthenticated attacker… | |
| Pendiente de análisis | Media (5.3) | 0.28% | — | AdminerAI | 26/9/2026 | 28/9/2026 | Adminer before 6.0.2 contains a cross-site scripting vulnerability where the CONNECTION_ID() database result is interpolated into JavaScript without proper escaping, allowing a malicious database server to execute arbitrary JavaScript in the authenticated Adminer origin. In co-located deployments where the database… | |
| Aplazada | Baja (2) | 0.19% | — | Huanzi-qch Base-adminAI | 24/9/2026 | 24/9/2026 | A vulnerability was identified in huanzi-qch base-admin up to 52816b760cd53244989fd664bbb2b3d4edbfdbf1. This issue affects the function Save of the file base-admin-master\src\main\java\cn\huanzi\qch\baseadmin\common\controller\CommonController.java of the component Add User Handler. The manipulation of the argument… | |
| Aplazada | Media (6) | 0.41% | — | Sysadminsmedia HomeboxAI | 21/9/2026 | 29/9/2026 | HomeBox is a home inventory and organization system. Prior to 0.26.0, the default-on BlockBogonNets and BlockCloudMetadata notifier SSRF protections in backend/internal/sys/validate/notifier_url.go do not inspect IPv4 destinations embedded in the NAT64 prefixes 64:ff9b::/96 and 64:ff9b:1::/48. An authenticated user… | |
| Aplazada | Alta (8.1) | 0.45% | — | Sysadminsmedia HomeboxAI | 21/9/2026 | 23/9/2026 | HomeBox is a home inventory and organization system. Prior to 0.26.0, NotifierRepository.Update in backend/internal/data/repo/repo_notifier.go updates a notifier through UpdateOneID(id) without requiring the record's user ID to match the authenticated user. An authenticated user who supplies another tenant's notifier… | |
| Aplazada | Alta (8.1) | 0.49% | — | Sysadminsmedia HomeboxAI | 21/9/2026 | 23/9/2026 | HomeBox is a home inventory and organization system. Prior to 0.26.0, MaintenanceEntryRepository.Update and MaintenanceEntryRepository.Delete in backend/internal/data/repo/repo_maintenance_entry.go use UpdateOneID(id) and DeleteOneID(id) without verifying that the maintenance entry belongs to the authenticated user's… | |
| Aplazada | Media (5.4) | 0.29% | — | Sysadminsmedia HomeboxAI | 21/9/2026 | 29/9/2026 | HomeBox is a home inventory and organization system. Prior to 0.26.0, POST /v1/groups/members invokes HandleGroupMemberAdd and GroupService.AddMember using a caller-supplied userID without requiring an owner role, an invitation token, target-user consent, or target-user notification. Any authenticated user can force… | |
| Aplazada | Alta (8.1) | 0.49% | — | Sysadminsmedia HomeboxAI | 21/9/2026 | 23/9/2026 | HomeBox is a home inventory and organization system. Prior to 0.26.0, HandleWipeInventory in backend/app/api/handlers/v1/v1_ctrl_actions.go authorizes POST /v1/actions/wipe-inventory through the global ctx.User.IsOwner value instead of the caller's role in the active group, while the active group is selected through… | |
| Analizada | Alta (8.7) | 0.58% | — | Pgadmin 4 | 17/9/2026 | 21/9/2026 | pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/object request to the pg_dump argument vector as a bare trailing positional argument, without validation. Because pg_dump parses its options with getopt_long, which permutes arguments, a value beginning with a dash was… | |
| Analizada | Crítica (9.3) | 0.58% | — | Pgadmin 4 | 17/9/2026 | 21/9/2026 | pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of pgAdmin, delivered through the WSGI/CGI environment. WebserverAuthentication.get_user() read config.WEBSERVER_REMOTE_USER from request.environ and, when that returned nothing, fell back… | |
| Analizada | Alta (7.1) | 0.35% | — | Pgadmin 4 | 17/9/2026 | 21/9/2026 | pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of the --dbname option given to pg_restore and psql. libpq expands a database name containing an equals sign into a full connection string, and connection keywords embedded in that value take precedence over the… | |
| Analizada | Media (6) | 0.32% | — | Pgadmin 4 | 17/9/2026 | 21/9/2026 | pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested path with Filemanager.check_access_permission() and then opened the file for writing with a plain open() call. CVE-2026-7819 had previously hardened the separate file upload path by opening its target… | |
| Aplazada | Crítica (9.8) | 0.61% | — | Eduadmin BookingAI | 17/9/2026 | 17/9/2026 | Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions. | |
| En análisis | Media (6.8) | 0.13% | — | Dell Openmanage Server AdministratorAI | 17/9/2026 | 18/9/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering. | |
| En análisis | Alta (7.4) | 0.37% | — | Dell Openmanage Server AdministratorAI | 17/9/2026 | 19/9/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery. | |
| En análisis | Alta (7.2) | 0.46% | — | Dell Openmanage Server AdministratorAI | 17/9/2026 | 18/9/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| En análisis | Alta (7.3) | 0.14% | — | Dell Openmanage Server AdministratorAI | 17/9/2026 | 18/9/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. | |
| En análisis | Media (6.5) | 0.44% | — | Dell Openmanage Server AdministratorAI | 17/9/2026 | 18/9/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. | |
| En análisis | Media (6.4) | 0.23% | — | Dell Openmanage Server AdministratorAI | 17/9/2026 | 19/9/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery. |