Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2904▼ 176 respecto a la semana anterior
Críticas / altas1294▼ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.41% | — | Cerebrate-project CerebrateAI | 11/6/2026 | 17/6/2026 | Cerebrate before version 1.37 exposed credential material from self-registration requests. The self-registration workflow stored the registrant’s hashed password in the inbox message data payload. This payload was returned unredacted through inbox index and view responses, including HTML, JSON, and CSV outputs, and… | |
| Aplazada | Media (6.3) | 0.35% | — | Cerebrate-project CerebrateAI | 11/6/2026 | 17/6/2026 | Cerebrate before version 1.37 allowed the id primary key field to be supplied through request input during CRUD edit operations and certain custom entity patching flows. In affected entities that did not explicitly mark id as inaccessible, an authenticated attacker could submit a crafted edit request containing the id… | |
| Aplazada | Alta (8.7) | 0.43% | — | Cerebrate-project CerebrateAI | 11/6/2026 | 23/7/2026 | Cerebrate before version 1.37 contains a mass-assignment vulnerability in the generic CRUD add path. The add() handler attempted to remove an attacker-supplied id from $params before normalizing the request through __massageInput(). Because the normalized $input could still contain an id field, a user able to reach an… | |
| Aplazada | Crítica (9.4) | 0.42% | — | Cerebrate-project CerebrateAI | 28/11/2025 | 17/6/2026 | UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges (e.g., obtain a higher role such as admin) via the user-edit endpoint by supplying or modifying role_id or organisation_id fields in the edit request. | |
| Modificada | Media (5.3) | 0.43% | — | Cerebrate-project Cerebrate | 5/9/2023 | 17/6/2026 | Cerebrate before 1.15 lacks the Secure attribute for the session cookie. | |
| Modificada | Media (4.3) | 0.39% | — | Cerebrate-project Cerebrate | 29/8/2023 | 17/6/2026 | In Cerebrate 1.14, a vulnerability in UserSettingsController allows authenticated users to change user settings of other users. | |
| Modificada | Crítica (9.8) | 0.70% | — | Cerebrate-project Cerebrate | 27/3/2023 | 17/6/2026 | In Cerebrate 1.13, a blind SQL injection exists in the searchAll API endpoint. | |
| Modificada | Crítica (9.1) | 0.63% | — | Cerebrate-project Cerebrate | 24/2/2023 | 17/6/2026 | Cerebrate 1.12 does not properly consider organisation_id during creation of API keys. | |
| Modificada | Media (6.1) | 1.1% | — | Cerebrate-project Cerebrate | 18/2/2022 | 17/6/2026 | An issue was discovered in Cerebrate through 1.4. XSS could occur in the bookmarks component. | |
| Modificada | Media (5.3) | 0.93% | — | Cerebrate-project Cerebrate | 18/2/2022 | 17/6/2026 | An issue was discovered in Cerebrate through 1.4. Username enumeration could occur. | |
| Modificada | Media (5.3) | 1.3% | — | Cerebrate-project Cerebrate | 18/2/2022 | 17/6/2026 | An issue was discovered in Cerebrate through 1.4. Endpoints could be open even when not enabled. | |
| Modificada | Media (4.3) | 0.61% | — | Cerebrate-project Cerebrate | 18/2/2022 | 17/6/2026 | An issue was discovered in Cerebrate through 1.4. An incorrect sharing group ACL allowed an unprivileged user to edit and modify sharing groups. | |
| Modificada | Media (6.1) | 0.62% | — | Cerebrate-project Cerebrate | 18/2/2022 | 17/6/2026 | An issue was discovered in Cerebrate through 1.4. genericForm allows reflected XSS in form descriptions via a user-controlled description. |