Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2904▼ 176 respecto a la semana anterior
Críticas / altas1294▼ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

13 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.1)0.41%—Cerebrate-project CerebrateAI11/6/202617/6/2026
Cerebrate before version 1.37 exposed credential material from self-registration requests. The self-registration workflow stored the registrant’s hashed password in the inbox message data payload. This payload was returned unredacted through inbox index and view responses, including HTML, JSON, and CSV outputs, and…
AplazadaMedia (6.3)0.35%—Cerebrate-project CerebrateAI11/6/202617/6/2026
Cerebrate before version 1.37 allowed the id primary key field to be supplied through request input during CRUD edit operations and certain custom entity patching flows. In affected entities that did not explicitly mark id as inaccessible, an authenticated attacker could submit a crafted edit request containing the id…
AplazadaAlta (8.7)0.43%—Cerebrate-project CerebrateAI11/6/202623/7/2026
Cerebrate before version 1.37 contains a mass-assignment vulnerability in the generic CRUD add path. The add() handler attempted to remove an attacker-supplied id from $params before normalizing the request through __massageInput(). Because the normalized $input could still contain an id field, a user able to reach an…
AplazadaCrítica (9.4)0.42%—Cerebrate-project CerebrateAI28/11/202517/6/2026
UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges (e.g., obtain a higher role such as admin) via the user-edit endpoint by supplying or modifying role_id or organisation_id fields in the edit request.
ModificadaMedia (5.3)0.43%—Cerebrate-project Cerebrate5/9/202317/6/2026
Cerebrate before 1.15 lacks the Secure attribute for the session cookie.
ModificadaMedia (4.3)0.39%—Cerebrate-project Cerebrate29/8/202317/6/2026
In Cerebrate 1.14, a vulnerability in UserSettingsController allows authenticated users to change user settings of other users.
ModificadaCrítica (9.8)0.70%—Cerebrate-project Cerebrate27/3/202317/6/2026
In Cerebrate 1.13, a blind SQL injection exists in the searchAll API endpoint.
ModificadaCrítica (9.1)0.63%—Cerebrate-project Cerebrate24/2/202317/6/2026
Cerebrate 1.12 does not properly consider organisation_id during creation of API keys.
ModificadaMedia (6.1)1.1%—Cerebrate-project Cerebrate18/2/202217/6/2026
An issue was discovered in Cerebrate through 1.4. XSS could occur in the bookmarks component.
ModificadaMedia (5.3)0.93%—Cerebrate-project Cerebrate18/2/202217/6/2026
An issue was discovered in Cerebrate through 1.4. Username enumeration could occur.
ModificadaMedia (5.3)1.3%—Cerebrate-project Cerebrate18/2/202217/6/2026
An issue was discovered in Cerebrate through 1.4. Endpoints could be open even when not enabled.
ModificadaMedia (4.3)0.61%—Cerebrate-project Cerebrate18/2/202217/6/2026
An issue was discovered in Cerebrate through 1.4. An incorrect sharing group ACL allowed an unprivileged user to edit and modify sharing groups.
ModificadaMedia (6.1)0.62%—Cerebrate-project Cerebrate18/2/202217/6/2026
An issue was discovered in Cerebrate through 1.4. genericForm allows reflected XSS in form descriptions via a user-controlled description.