Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

197 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (10)0.48%—Chef AutomateAI11/9/202618/9/2026
A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.
AnalizadaAlta (7)0.28%—Microsoft Power Automate FOR Desktop8/9/202629/9/2026
Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally.
AplazadaMedia (5.3)0.35%—Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI20/8/202624/8/2026
A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects the function add_grade of the file /index.php. Performing a manipulation of the argument student_id results in improper authorization. The attack can be initiated remotely.
AplazadaMedia (6.1)0.36%—Beta Systems Software AG Anow AutomateAI18/8/20269/9/2026
Cross-site scripting vulnerability in the user documentation field in Beta Systems Software AG ANOW! Automate v.3.3.1.90 allows a remote attacker to execute arbitrary code
AnalizadaMedia (5.4)0.16%—Intel Hardware-aware-automated-machine-learning11/8/20262/10/2026
Uncontrolled search path for some Hardware-Aware-Automated-MachineLearning NA before version 45cd723 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may…
AplazadaBaja (1.9)0.17%—Automateyournetwork McpyatsAI9/8/202612/8/2026
A vulnerability was identified in automateyournetwork MCPyATS up to 0.1.4. The affected element is the function processGenerateRequest of the file mcp_servers/mermaid/index.ts of the component generate_mermaid_markdown. The manipulation of the argument folder/name leads to path traversal. The attack must be carried…
AplazadaAlta (7.3)0.20%—Sourcecodester Casap Automated Enrollment SystemAI29/7/20261/10/2026
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter status.
AplazadaAlta (7.3)0.20%—Sourcecodester Casap Automated Enrollment SystemAI29/7/20261/10/2026
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters fname and student_class.
AplazadaAlta (7.3)0.20%—Sourcecodester Casap Automated Enrollment SystemAI29/7/20261/10/2026
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the parameter new_password.
AplazadaCrítica (9.8)0.32%—Sourcecodester Casap Automated Enrollment SystemAI29/7/20261/10/2026
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters fname, lname, and student_class.
AplazadaCrítica (9.8)0.32%—Sourcecodester Casap Automated Enrollment SystemAI29/7/20261/10/2026
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the parameter class_name.
AplazadaBaja (2.9)0.40%—Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI3/7/20266/7/2026
A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This issue affects some unknown processing. The manipulation results in session fixiation. The attack can be executed remotely. The attack requires a high level of complexity. The exploitability is assessed as…
AplazadaBaja (2.1)0.37%—Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI3/7/20267/7/2026
A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This vulnerability affects unknown code of the file /index.php?action=view_student of the component POST Handler. The manipulation of the argument ID leads to authorization bypass. Remote…
AplazadaAlta (7.5)0.35%—Checkview Automated TestingAI25/6/202629/6/2026
Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions.
AplazadaMedia (6.9)0.28%—Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI17/6/202618/6/2026
A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. Affected is an unknown function of the file /index.php of the component Student Self-Registration Endpoint. The manipulation leads to improper access controls. Remote exploitation of the attack…
AplazadaBaja (2.1)0.27%—Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI14/6/202623/7/2026
A vulnerability has been found in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. The impacted element is an unknown function of the file /index.php. The manipulation of the argument action leads to cross site scripting. The attack is possible to be carried out remotely. The exploit has…
AplazadaBaja (2.1)0.42%—Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI26/5/202624/7/2026
A weakness has been identified in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This impacts an unknown function of the file /index.php of the component SQL Handler. Executing a manipulation can lead to information exposure through error message. The attack may be performed from remote.…
AplazadaBaja (2.1)0.23%—Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI26/5/202624/7/2026
A security flaw has been discovered in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects an unknown function. Performing a manipulation results in cross-site request forgery. The attack is possible to be carried out remotely. The exploit has been released to the public and may…
AnalizadaAlta (8.8)0.21%—Connectwise Automate21/5/202623/7/2026
The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations. This issue is addressed in Automate 2026.5.
AnalizadaMedia (6.5)1.00%—Microsoft Power Automate FOR Desktop12/5/202617/6/2026
Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose information over a network.
AplazadaMedia (5.5)0.79%—Crocodilestick Calibre-web-automatedAI4/5/202617/6/2026
A flaw has been found in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this issue is some unknown functionality of the file cps/cwa_functions.py of the component Admin Endpoint. This manipulation causes missing authentication. It is possible to initiate the attack remotely. The exploit has been…
AplazadaBaja (2.1)0.46%—Crocodilestick Calibre-web-automatedAI4/5/202617/6/2026
A vulnerability was detected in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this vulnerability is the function generate_auth_token of the file cps/kobo_auth.py of the component Kobo auth-token Route. The manipulation results in improper authorization. The attack may be performed from remote. The…
AplazadaBaja (2.1)0.45%—Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI29/4/202617/6/2026
A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This vulnerability affects unknown code of the file /index.php?action=register of the component Registration. The manipulation of the argument student_id/full_name/section/username results in cross site…
AnalizadaAlta (7.1)0.13%—Connectwise Automate20/4/202617/6/2026
ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automate Solution Center where certain client-to-server communications could occur without transport-layer encryption. This could allow network‑based interception of Solution Center traffic in Automate…
AplazadaMedia (5.3)0.26%—Nfusionsolutions Precious Metals Automated Product Pricing PROAI8/4/202624/7/2026
Missing Authorization vulnerability in nfusionsolutions Precious Metals Automated Product Pricing – Pro precious-metals-automated-product-pricing-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Precious Metals Automated Product Pricing – Pro: from n/a through <= 4.0.5.