Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2753▲ 26 respecto a la semana anterior
Críticas / altas1468▲ 333 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
77 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.24% | — | IO Socket SSL SelfcertificateAI | 24/9/2026 | 25/9/2026 | IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Python script saved as a certificate file. The pyhton script attempts to retrieve code from a hardcoded http URL that is obfuscated with base64 encoding and run… | |
| Aplazada | Alta (7.8) | 0.12% | — | Crypt SelfcertificateAI | 22/9/2026 | 23/9/2026 | Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Python script saved as a certificate file. The pyhton script attempts to retrieve code from a hardcoded http URL that is obfuscated with base64 encoding… | |
| Pendiente de análisis | Media (6.5) | 0.25% | — | Steeltoe.security.authorization.certificateAI | 17/9/2026 | 30/9/2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, Steeltoe.Security.Authorization.Certificate deployments using AddOrgAndSpacePolicies() and UseCertificateAuthorization() trust the public certificate supplied in the… | |
| Pendiente de análisis | Alta (7.5) | 0.18% | — | Amazon Linux 2AICa-certificatesAI | 14/9/2026 | 22/9/2026 | The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certificates from the root store. NOTE: this issue exists because of an incorrect fix for CVE-2022-23491. | |
| Pendiente de análisis | Media (6.5) | 0.32% | — | Apache HttpdAIDogtag Certificate AuthorityAIRedhat Identity ManagementAI | 1/9/2026 | 1/9/2026 | An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for unauthenticated malformed requests. The same unauthenticated error path emits large multi-line stack traces into the CA debug log, creating a log-amplification resource exhaustion… | |
| Analizada | Media (6.9) | 10% | — | Greatdevelopers Certificate | 8/2/2026 | 17/6/2026 | A vulnerability was detected in Great Developers Certificate Generation System up to 97171bb0e5e22e52eacf4e4fa81773e5f3cffb73. This vulnerability affects unknown code of the file /restructured/csv.php. The manipulation of the argument photo results in os command injection. The attack can be executed remotely. This… | |
| Analizada | Media (5.3) | 0.24% | — | Greatdevelopers Certificate | 8/2/2026 | 17/6/2026 | A security vulnerability has been detected in Great Developers Certificate Generation System up to 97171bb0e5e22e52eacf4e4fa81773e5f3cffb73. This affects an unknown part of the file /restructured/csv.php. The manipulation leads to unrestricted upload. Remote exploitation of the attack is possible. This product follows… | |
| Analizada | Media (6.1) | 0.21% | — | Tgies Client-certificate-auth | 6/2/2026 | 17/6/2026 | client-certificate-auth is middleware for Node.js implementing client SSL certificate authentication/authorization. Versions 0.2.1 and 0.3.0 of client-certificate-auth contain an open redirect vulnerability. The middleware unconditionally redirects HTTP requests to HTTPS using the unvalidated Host header, allowing an… | |
| Analizada | Baja (2.1) | 0.18% | — | Oretnom23 Medical Certificate Generator APP | 2/2/2026 | 17/6/2026 | A vulnerability was determined in SourceCodester Medical Certificate Generator App 1.0. This affects an unknown part. This manipulation causes cross-site request forgery. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Media (6.5) | 0.20% | — | Sertifier Certificates Open BadgesAI | 6/11/2025 | 17/6/2026 | Missing Authorization vulnerability in sertifier Sertifier Certificate & Badge Maker sertifier-certificates-open-badges allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sertifier Certificate & Badge Maker: from n/a through <= 1.21. | |
| Aplazada | Media (4.3) | 0.11% | — | Sertifier Certificate AND Badge Maker FOR Wordpress Tutor LMSAI | 23/8/2025 | 17/6/2026 | The Sertifier Certificate & Badge Maker for WordPress – Tutor LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.19. This is due to missing or incorrect nonce validation on the 'sertifier_settings' page. This makes it possible for unauthenticated attackers to… | |
| Analizada | Media (5.3) | 0.27% | — | Phpgurukul Online Birth Certificate System | 31/5/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul HPGurukul Online Birth Certificate System 2.0. It has been classified as critical. Affected is an unknown function of the file /admin/registered-users.php. The manipulation of the argument del leads to sql injection. It is possible to launch the attack remotely. The exploit has… | |
| Analizada | Media (5.3) | 0.27% | — | Phpgurukul Online Birth Certificate System | 31/5/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Online Birth Certificate System 2.0 and classified as critical. This issue affects some unknown processing of the file /admin/all-applications.php. The manipulation of the argument del leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed… | |
| Analizada | Media (5.3) | 0.25% | — | Phpgurukul Online Birth Certificate System | 31/5/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Online Birth Certificate System 2.0 and classified as critical. This vulnerability affects unknown code of the file /admin/users-applications.php. The manipulation of the argument userid leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.40% | — | Phpgurukul Online Birth Certificate System | 3/5/2025 | 17/6/2026 | A vulnerability classified as critical was found in PHPGurukul Online Birth Certificate System 2.0. Affected by this vulnerability is an unknown functionality of the file /admin/between-dates-report.php. The manipulation of the argument fromdate leads to sql injection. The attack can be launched remotely. The exploit… | |
| Analizada | Media (6.9) | 0.36% | — | Phpgurukul Online Birth Certificate System | 2/5/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Online Birth Certificate System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/search.php. The manipulation of the argument searchdata leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Analizada | Media (6.9) | 0.36% | — | Phpgurukul Online Birth Certificate System | 1/5/2025 | 17/6/2026 | A vulnerability classified as critical has been found in PHPGurukul Online Birth Certificate System 1.0. Affected is an unknown function of the file /admin/bwdates-reports-details.php. The manipulation of the argument fromdate leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Aplazada | Media (4.9) | 0.27% | — | Accredible Certificates Open BadgesAI | 10/4/2025 | 17/6/2026 | The Accredible Certificates & Open Badges plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Aplazada | Media (6.1) | 0.21% | — | Gift Certificate CreatorAI | 2/4/2025 | 17/6/2026 | The Gift Certificate Creator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘receip_address’ parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Analizada | Media (5.4) | 0.28% | — | Phpgurukul Online Birth Certificate System | 3/2/2025 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability was identified in the PHPGURUKUL Online Birth Certificate System v1.0 via the profile name to /user/certificate-form.php. | |
| Analizada | Media (6.1) | 0.20% | — | Phpgurukul Online Birth Certificate System | 17/12/2024 | 17/6/2026 | A stored HTML Injection vulnerability was identified in PHPGurukul Online Birth Certificate System v1.0 in /user/certificate-form.php. | |
| Analizada | Media (4.3) | 0.24% | — | Phpgurukul Online Birth Certificate System | 17/12/2024 | 17/6/2026 | An insecure direct object reference (IDOR) vulnerability was discovered in PHPGurukul Online Birth Certificate System v1.0. This vulnerability resides in the viewid parameter of /user/view-application-detail.php. Authenticated users can exploit this flaw by manipulating the viewid parameter in the URL to access… | |
| Analizada | Media (5.4) | 0.14% | — | Phpgurukul Online Birth Certificate System | 17/12/2024 | 17/6/2026 | Phpgurukul Online Birth Certificate System 1.0 suffers from insufficient password requirements which can lead to unauthorized access to user accounts. | |
| Analizada | Media (5.4) | 0.19% | — | Phpgurukul Online Birth Certificate System | 17/12/2024 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability was identified in Phpgurukul Online Birth Certificate System 1.0 in /user/certificate-form.php via the full name field. | |
| Aplazada | Media (6.1) | 0.11% | — | Easy Paypal Gift CertificateAI | 12/10/2024 | 17/6/2026 | The Easy PayPal Gift Certificate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. This is due to missing or incorrect nonce validation on the 'wpppgc_plugin_options' function. This makes it possible for unauthenticated attackers to update the plugin's settings… |