Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3001▼ 62 respecto a la semana anterior
Críticas / altas1373▲ 34 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)459▼ 50 respecto a la semana anterior
–

29 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)1.3%—Heimdall Data Database ProxyAI20/8/20261/9/2026
Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required to exploit this vulnerability. The specific flaw exists within the…
Pendiente de análisisAlta (7.2)1.1%—Heimdall Data Database ProxyAI29/7/202630/7/2026
Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required to exploit this vulnerability. The specific flaw exists within…
AplazadaAlta (8.8)0.45%—Heimdall Data Database ProxyAI6/11/202517/6/2026
Heimdall Data Database Proxy Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Minimal user interaction is required to exploit this vulnerability. The specific flaw exists within the…
AplazadaAlta (7.5)0.61%—Radiustheme Testimonial Slider AND Showcase PROAI22/10/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Testimonial Slider And Showcase Pro testimonial-slider-showcase-pro allows PHP Local File Inclusion.This issue affects Testimonial Slider And Showcase Pro: from n/a through <= 2.1.7.
AplazadaAlta (8.1)0.93%—Radiustheme Testimonial Slider AND Showcase PROAI11/4/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Testimonial Slider And Showcase Pro testimonial-slider-showcase-pro allows PHP Local File Inclusion.This issue affects Testimonial Slider And Showcase Pro: from n/a through <= 2.3.15.
AplazadaMedia (4.3)0.24%—Admin AND Site Enhancements ASE PROAI27/1/202517/6/2026
Missing Authorization vulnerability in NotFound Admin and Site Enhancements (ASE) Pro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Admin and Site Enhancements (ASE) Pro: from n/a through 7.6.1.1.
ModificadaMedia (6.1)0.85%—Membership Database Project Membership Database8/5/202317/6/2026
The Membership Database WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaAlta (7.5)0.25%—WP CSV TO Database Project WP CSV TO Database14/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Tips and Tricks HQ, josh401 WP CSV to Database – Insert CSV file content into WordPress plugin <= 2.6 versions.
ModificadaCrítica (9.8)0.68%—Mnbikeways Database Project Mnbikeways Database17/1/202317/6/2026
A vulnerability was found in MNBikeways database and classified as critical. This issue affects some unknown processing of the file Data/views.py. The manipulation of the argument id1/id2 leads to sql injection. The identifier of the patch is 829a027aca7c17f5a7ec1addca8dd5d5542f86ac. It is recommended to apply a patch…
ModificadaBaja (3.7)0.35%—Gobase Project Gobase27/12/202217/6/2026
A race condition can cause incorrect HTTP request routing.
ModificadaMedia (5.4)0.30%—Student Result OR Employee Database Project Student Result OR Employee Database22/8/202217/6/2026
The Student Result or Employee Database WordPress plugin before 1.7.5 does not have CSRF in its AJAX actions, allowing attackers to make logged in user with a role as low as contributor to add/edit and delete students via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping, it could also lead to…
ModificadaCrítica (9.8)0.63%—Update BY Case Project Update BY Case12/8/202217/6/2026
This Rails gem adds two methods to the ActiveRecord::Base class that allow you to update many records on a single database hit, using a case sql statement for it. Before version 0.1.3 `update_by_case` gem used custom sql strings, and it was not sanitized, making it vulnerable to sql injection. Upgrade to version >=…
ModificadaCrítica (9.3)1.3%—Python-recipe-database Project Python-recipe-database11/7/202217/6/2026
The JustAnotherSoftwareDeveloper/Python-Recipe-Database repository through 2021-03-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaAlta (7.5)1.7%—Semantic-release Project Semantic-release9/6/202217/6/2026
semantic-release is an open source npm package for automated version management and package publishing. In affected versions secrets that would normally be masked by semantic-release can be accidentally disclosed if they contain characters that are excluded from uri encoding by `encodeURI`. Occurrence is further…
ModificadaMedia (4.3)0.38%—Contact Form Advanced Database Project Contact Form Advanced Database13/12/202117/6/2026
The Contact Form Advanced Database WordPress plugin through 1.0.8 does not have any authorisation as well as CSRF checks in its delete_cf7_data and export_cf7_data AJAX actions, available to any authenticated users, which could allow users with a role as low as subscriber to call them. The delete_cf7_data would lead…
ModificadaBaja (3.3)0.43%—Please Project Please27/5/202117/6/2026
please before 0.4 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option.
ModificadaAlta (8.1)1.4%—Semantic-release Project Semantic-release18/11/202017/6/2026
In the npm package semantic-release before version 17.2.3, secrets that would normally be masked by `semantic-release` can be accidentally disclosed if they contain characters that become encoded when included in a URL. Secrets that do not contain characters that become encoded when included in a URL are already…
ModificadaCrítica (9.8)1.0%—Online TV Database Project Online TV Database10/1/202016/6/2026
An SQL Injection vulnerability exists in the ID parameter in Online TV Database 2011.
ModificadaMedia (5.3)1.4%—9base Project 9baseDebian Linux21/11/201917/6/2026
9base 1:6-6 and 1:6-7 insecurely creates temporary files which results in predictable filenames.
ModificadaCrítica (9.8)1.7%—Gigasetpro Maxwell Basic Firmware20/12/201817/6/2026
Missing password verification in the web interface on Gigaset Maxwell Basic VoIP phones with firmware 2.22.7 would allow a remote attacker (in the same network as the device) to change the admin password without authentication (and without knowing the original password).
ModificadaAlta (7.5)1.6%—No-case Project No-case7/6/201817/6/2026
The no-case module is vulnerable to regular expression denial of service. When malicious untrusted user input is passed into no-case it can block the event loop causing a denial of service condition.
ModificadaCrítica (9.8)2.2%—Advanced World Database Project Advanced World Database13/12/201717/6/2026
Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country parameter.
ModificadaMedia (5.5)3.4%—Hibara Software Attachecase FOR JavaHibara Software Attachecase LiteHibara Software Attachecase PRO28/4/201717/6/2026
Directory traversal vulnerability in AttacheCase for Java 0.60 and earlier, AttacheCase Lite 1.4.6 and earlier, and AttacheCase Pro 1.5.7 and earlier allows remote attackers to read arbitrary files via specially crafted ATC file.
ModificadaBaja (3.5)0.95%—Linear Case Project Linear Case15/6/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Linear Case module 6.x-1.x before 6.x-1.3 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)1.3%—Content Rating Extbase Project Content Rating Extbase3/2/201517/6/2026
SQL injection vulnerability in the Content Rating Extbase extension 2.0.3 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.