Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2753▲ 26 respecto a la semana anterior
Críticas / altas1468▲ 333 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

77 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.24%—IO Socket SSL SelfcertificateAI24/9/202625/9/2026
IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Python script saved as a certificate file. The pyhton script attempts to retrieve code from a hardcoded http URL that is obfuscated with base64 encoding and run…
AplazadaAlta (7.8)0.12%—Crypt SelfcertificateAI22/9/202623/9/2026
Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Python script saved as a certificate file. The pyhton script attempts to retrieve code from a hardcoded http URL that is obfuscated with base64 encoding…
Pendiente de análisisMedia (6.5)0.25%—Steeltoe.security.authorization.certificateAI17/9/202630/9/2026
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, Steeltoe.Security.Authorization.Certificate deployments using AddOrgAndSpacePolicies() and UseCertificateAuthorization() trust the public certificate supplied in the…
Pendiente de análisisAlta (7.5)0.18%—Amazon Linux 2AICa-certificatesAI14/9/202622/9/2026
The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certificates from the root store. NOTE: this issue exists because of an incorrect fix for CVE-2022-23491.
Pendiente de análisisMedia (6.5)0.32%—Apache HttpdAIDogtag Certificate AuthorityAIRedhat Identity ManagementAI1/9/20261/9/2026
An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for unauthenticated malformed requests. The same unauthenticated error path emits large multi-line stack traces into the CA debug log, creating a log-amplification resource exhaustion…
AnalizadaMedia (6.9)10%—Greatdevelopers Certificate8/2/202617/6/2026
A vulnerability was detected in Great Developers Certificate Generation System up to 97171bb0e5e22e52eacf4e4fa81773e5f3cffb73. This vulnerability affects unknown code of the file /restructured/csv.php. The manipulation of the argument photo results in os command injection. The attack can be executed remotely. This…
AnalizadaMedia (5.3)0.24%—Greatdevelopers Certificate8/2/202617/6/2026
A security vulnerability has been detected in Great Developers Certificate Generation System up to 97171bb0e5e22e52eacf4e4fa81773e5f3cffb73. This affects an unknown part of the file /restructured/csv.php. The manipulation leads to unrestricted upload. Remote exploitation of the attack is possible. This product follows…
AnalizadaMedia (6.1)0.21%—Tgies Client-certificate-auth6/2/202617/6/2026
client-certificate-auth is middleware for Node.js implementing client SSL certificate authentication/authorization. Versions 0.2.1 and 0.3.0 of client-certificate-auth contain an open redirect vulnerability. The middleware unconditionally redirects HTTP requests to HTTPS using the unvalidated Host header, allowing an…
AnalizadaBaja (2.1)0.18%—Oretnom23 Medical Certificate Generator APP2/2/202617/6/2026
A vulnerability was determined in SourceCodester Medical Certificate Generator App 1.0. This affects an unknown part. This manipulation causes cross-site request forgery. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
AplazadaMedia (6.5)0.20%—Sertifier Certificates Open BadgesAI6/11/202517/6/2026
Missing Authorization vulnerability in sertifier Sertifier Certificate & Badge Maker sertifier-certificates-open-badges allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sertifier Certificate & Badge Maker: from n/a through <= 1.21.
AplazadaMedia (4.3)0.11%—Sertifier Certificate AND Badge Maker FOR Wordpress Tutor LMSAI23/8/202517/6/2026
The Sertifier Certificate & Badge Maker for WordPress – Tutor LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.19. This is due to missing or incorrect nonce validation on the 'sertifier_settings' page. This makes it possible for unauthenticated attackers to…
AnalizadaMedia (5.3)0.27%—Phpgurukul Online Birth Certificate System31/5/202517/6/2026
A vulnerability was found in PHPGurukul HPGurukul Online Birth Certificate System 2.0. It has been classified as critical. Affected is an unknown function of the file /admin/registered-users.php. The manipulation of the argument del leads to sql injection. It is possible to launch the attack remotely. The exploit has…
AnalizadaMedia (5.3)0.27%—Phpgurukul Online Birth Certificate System31/5/202517/6/2026
A vulnerability was found in PHPGurukul Online Birth Certificate System 2.0 and classified as critical. This issue affects some unknown processing of the file /admin/all-applications.php. The manipulation of the argument del leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed…
AnalizadaMedia (5.3)0.25%—Phpgurukul Online Birth Certificate System31/5/202517/6/2026
A vulnerability has been found in PHPGurukul Online Birth Certificate System 2.0 and classified as critical. This vulnerability affects unknown code of the file /admin/users-applications.php. The manipulation of the argument userid leads to sql injection. The attack can be initiated remotely. The exploit has been…
AnalizadaMedia (6.9)0.40%—Phpgurukul Online Birth Certificate System3/5/202517/6/2026
A vulnerability classified as critical was found in PHPGurukul Online Birth Certificate System 2.0. Affected by this vulnerability is an unknown functionality of the file /admin/between-dates-report.php. The manipulation of the argument fromdate leads to sql injection. The attack can be launched remotely. The exploit…
AnalizadaMedia (6.9)0.36%—Phpgurukul Online Birth Certificate System2/5/202517/6/2026
A vulnerability has been found in PHPGurukul Online Birth Certificate System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/search.php. The manipulation of the argument searchdata leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to…
AnalizadaMedia (6.9)0.36%—Phpgurukul Online Birth Certificate System1/5/202517/6/2026
A vulnerability classified as critical has been found in PHPGurukul Online Birth Certificate System 1.0. Affected is an unknown function of the file /admin/bwdates-reports-details.php. The manipulation of the argument fromdate leads to sql injection. It is possible to launch the attack remotely. The exploit has been…
AplazadaMedia (4.9)0.27%—Accredible Certificates Open BadgesAI10/4/202517/6/2026
The Accredible Certificates & Open Badges plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…
AplazadaMedia (6.1)0.21%—Gift Certificate CreatorAI2/4/202517/6/2026
The Gift Certificate Creator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘receip_address’ parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AnalizadaMedia (5.4)0.28%—Phpgurukul Online Birth Certificate System3/2/202517/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability was identified in the PHPGURUKUL Online Birth Certificate System v1.0 via the profile name to /user/certificate-form.php.
AnalizadaMedia (6.1)0.20%—Phpgurukul Online Birth Certificate System17/12/202417/6/2026
A stored HTML Injection vulnerability was identified in PHPGurukul Online Birth Certificate System v1.0 in /user/certificate-form.php.
AnalizadaMedia (4.3)0.24%—Phpgurukul Online Birth Certificate System17/12/202417/6/2026
An insecure direct object reference (IDOR) vulnerability was discovered in PHPGurukul Online Birth Certificate System v1.0. This vulnerability resides in the viewid parameter of /user/view-application-detail.php. Authenticated users can exploit this flaw by manipulating the viewid parameter in the URL to access…
AnalizadaMedia (5.4)0.14%—Phpgurukul Online Birth Certificate System17/12/202417/6/2026
Phpgurukul Online Birth Certificate System 1.0 suffers from insufficient password requirements which can lead to unauthorized access to user accounts.
AnalizadaMedia (5.4)0.19%—Phpgurukul Online Birth Certificate System17/12/202417/6/2026
A stored cross-site scripting (XSS) vulnerability was identified in Phpgurukul Online Birth Certificate System 1.0 in /user/certificate-form.php via the full name field.
AplazadaMedia (6.1)0.11%—Easy Paypal Gift CertificateAI12/10/202417/6/2026
The Easy PayPal Gift Certificate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. This is due to missing or incorrect nonce validation on the 'wpppgc_plugin_options' function. This makes it possible for unauthenticated attackers to update the plugin's settings…