Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3001▼ 62 respecto a la semana anterior
Críticas / altas1373▲ 34 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)459▼ 50 respecto a la semana anterior
29 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 1.3% | — | Heimdall Data Database ProxyAI | 20/8/2026 | 1/9/2026 | Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required to exploit this vulnerability. The specific flaw exists within the… | |
| Pendiente de análisis | Alta (7.2) | 1.1% | — | Heimdall Data Database ProxyAI | 29/7/2026 | 30/7/2026 | Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required to exploit this vulnerability. The specific flaw exists within… | |
| Aplazada | Alta (8.8) | 0.45% | — | Heimdall Data Database ProxyAI | 6/11/2025 | 17/6/2026 | Heimdall Data Database Proxy Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Minimal user interaction is required to exploit this vulnerability. The specific flaw exists within the… | |
| Aplazada | Alta (7.5) | 0.61% | — | Radiustheme Testimonial Slider AND Showcase PROAI | 22/10/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Testimonial Slider And Showcase Pro testimonial-slider-showcase-pro allows PHP Local File Inclusion.This issue affects Testimonial Slider And Showcase Pro: from n/a through <= 2.1.7. | |
| Aplazada | Alta (8.1) | 0.93% | — | Radiustheme Testimonial Slider AND Showcase PROAI | 11/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Testimonial Slider And Showcase Pro testimonial-slider-showcase-pro allows PHP Local File Inclusion.This issue affects Testimonial Slider And Showcase Pro: from n/a through <= 2.3.15. | |
| Aplazada | Media (4.3) | 0.24% | — | Admin AND Site Enhancements ASE PROAI | 27/1/2025 | 17/6/2026 | Missing Authorization vulnerability in NotFound Admin and Site Enhancements (ASE) Pro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Admin and Site Enhancements (ASE) Pro: from n/a through 7.6.1.1. | |
| Modificada | Media (6.1) | 0.85% | — | Membership Database Project Membership Database | 8/5/2023 | 17/6/2026 | The Membership Database WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Alta (7.5) | 0.25% | — | WP CSV TO Database Project WP CSV TO Database | 14/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tips and Tricks HQ, josh401 WP CSV to Database – Insert CSV file content into WordPress plugin <= 2.6 versions. | |
| Modificada | Crítica (9.8) | 0.68% | — | Mnbikeways Database Project Mnbikeways Database | 17/1/2023 | 17/6/2026 | A vulnerability was found in MNBikeways database and classified as critical. This issue affects some unknown processing of the file Data/views.py. The manipulation of the argument id1/id2 leads to sql injection. The identifier of the patch is 829a027aca7c17f5a7ec1addca8dd5d5542f86ac. It is recommended to apply a patch… | |
| Modificada | Baja (3.7) | 0.35% | — | Gobase Project Gobase | 27/12/2022 | 17/6/2026 | A race condition can cause incorrect HTTP request routing. | |
| Modificada | Media (5.4) | 0.30% | — | Student Result OR Employee Database Project Student Result OR Employee Database | 22/8/2022 | 17/6/2026 | The Student Result or Employee Database WordPress plugin before 1.7.5 does not have CSRF in its AJAX actions, allowing attackers to make logged in user with a role as low as contributor to add/edit and delete students via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping, it could also lead to… | |
| Modificada | Crítica (9.8) | 0.63% | — | Update BY Case Project Update BY Case | 12/8/2022 | 17/6/2026 | This Rails gem adds two methods to the ActiveRecord::Base class that allow you to update many records on a single database hit, using a case sql statement for it. Before version 0.1.3 `update_by_case` gem used custom sql strings, and it was not sanitized, making it vulnerable to sql injection. Upgrade to version >=… | |
| Modificada | Crítica (9.3) | 1.3% | — | Python-recipe-database Project Python-recipe-database | 11/7/2022 | 17/6/2026 | The JustAnotherSoftwareDeveloper/Python-Recipe-Database repository through 2021-03-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Alta (7.5) | 1.7% | — | Semantic-release Project Semantic-release | 9/6/2022 | 17/6/2026 | semantic-release is an open source npm package for automated version management and package publishing. In affected versions secrets that would normally be masked by semantic-release can be accidentally disclosed if they contain characters that are excluded from uri encoding by `encodeURI`. Occurrence is further… | |
| Modificada | Media (4.3) | 0.38% | — | Contact Form Advanced Database Project Contact Form Advanced Database | 13/12/2021 | 17/6/2026 | The Contact Form Advanced Database WordPress plugin through 1.0.8 does not have any authorisation as well as CSRF checks in its delete_cf7_data and export_cf7_data AJAX actions, available to any authenticated users, which could allow users with a role as low as subscriber to call them. The delete_cf7_data would lead… | |
| Modificada | Baja (3.3) | 0.43% | — | Please Project Please | 27/5/2021 | 17/6/2026 | please before 0.4 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option. | |
| Modificada | Alta (8.1) | 1.4% | — | Semantic-release Project Semantic-release | 18/11/2020 | 17/6/2026 | In the npm package semantic-release before version 17.2.3, secrets that would normally be masked by `semantic-release` can be accidentally disclosed if they contain characters that become encoded when included in a URL. Secrets that do not contain characters that become encoded when included in a URL are already… | |
| Modificada | Crítica (9.8) | 1.0% | — | Online TV Database Project Online TV Database | 10/1/2020 | 16/6/2026 | An SQL Injection vulnerability exists in the ID parameter in Online TV Database 2011. | |
| Modificada | Media (5.3) | 1.4% | — | 9base Project 9baseDebian Linux | 21/11/2019 | 17/6/2026 | 9base 1:6-6 and 1:6-7 insecurely creates temporary files which results in predictable filenames. | |
| Modificada | Crítica (9.8) | 1.7% | — | Gigasetpro Maxwell Basic Firmware | 20/12/2018 | 17/6/2026 | Missing password verification in the web interface on Gigaset Maxwell Basic VoIP phones with firmware 2.22.7 would allow a remote attacker (in the same network as the device) to change the admin password without authentication (and without knowing the original password). | |
| Modificada | Alta (7.5) | 1.6% | — | No-case Project No-case | 7/6/2018 | 17/6/2026 | The no-case module is vulnerable to regular expression denial of service. When malicious untrusted user input is passed into no-case it can block the event loop causing a denial of service condition. | |
| Modificada | Crítica (9.8) | 2.2% | — | Advanced World Database Project Advanced World Database | 13/12/2017 | 17/6/2026 | Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country parameter. | |
| Modificada | Media (5.5) | 3.4% | — | Hibara Software Attachecase FOR JavaHibara Software Attachecase LiteHibara Software Attachecase PRO | 28/4/2017 | 17/6/2026 | Directory traversal vulnerability in AttacheCase for Java 0.60 and earlier, AttacheCase Lite 1.4.6 and earlier, and AttacheCase Pro 1.5.7 and earlier allows remote attackers to read arbitrary files via specially crafted ATC file. | |
| Modificada | Baja (3.5) | 0.95% | — | Linear Case Project Linear Case | 15/6/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Linear Case module 6.x-1.x before 6.x-1.3 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.3% | — | Content Rating Extbase Project Content Rating Extbase | 3/2/2015 | 17/6/2026 | SQL injection vulnerability in the Content Rating Extbase extension 2.0.3 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. |