Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.90% | — | Craterapp CraterAI | 25/8/2026 | 24/9/2026 | Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self-update API that allows authenticated company owners to write arbitrary files outside the intended extraction directory by supplying crafted ZIP archives with ../ sequences to the unzip endpoint. Attackers can exploit unsanitized ZIP entry… | |
| Aplazada | Alta (8.3) | 0.37% | — | Craterapp CraterAI | 5/8/2026 | 26/8/2026 | Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePolicy and other sibling policies which additionally verify ->hasCompany(->company_id). Any authenticated user of one company can read, edit, or delete another company's… | |
| Aplazada | Alta (8.3) | 0.37% | — | Craterapp CraterAI | 5/8/2026 | 28/8/2026 | Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce both a Bouncer ability check and ->hasCompany(->company_id). CustomerPolicy's view/update/delete methods omit the company-ownership check entirely, checking only the blanket ability. Route-model-bound customer lookups and… | |
| Aplazada | Baja (2) | 0.35% | — | Craterapp CraterAI | 6/7/2026 | 6/7/2026 | A weakness has been identified in crater-invoice-inc crater up to 6.0.6. This affects the function getFormattedString of the file app/Http/Requests/InvoicesRequest.php of the component Invoice Note Handler. Executing a manipulation of the argument notes can lead to cross site scripting. The attack may be launched… | |
| Aplazada | Crítica (9.8) | 44% | — | Crater InvoiceAILaravelAI | 7/1/2025 | 17/6/2026 | A vulnerability in Crater Invoice allows an unauthenticated attacker with knowledge of the APP_KEY to achieve remote command execution on the server by manipulating the laravel_session cookie, exploiting arbitrary deserialization through the encrypted session data. The exploitation vector of this vulnerability relies… | |
| Modificada | Alta (8.8) | 1.7% | — | Annke Crater 2 Firmware | 12/8/2024 | 17/6/2026 | An OS command injection vulnerability in the ccm_debug component of MIPC Camera firmware prior to v5.4.1.240424171021 allows attackers within the same network to execute arbitrary code via a crafted HTML request. | |
| Modificada | Alta (7.2) | 20% | — | Craterapp Crater | 30/10/2023 | 17/6/2026 | /api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PHP code by placing this code into an image/png IDAT chunk of a Company Logo image. | |
| Modificada | Alta (7.2) | 1.6% | — | Craterapp Crater | 29/3/2022 | 17/6/2026 | Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6. | |
| Modificada | Alta (7.8) | 0.92% | — | Craterapp Crater | 23/3/2022 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.6. | |
| Modificada | Media (4.3) | 0.43% | — | Craterapp Crater | 21/3/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in GitHub repository crater-invoice/crater prior to 6.0.4. | |
| Modificada | Media (6.5) | 0.96% | — | Craterapp Crater | 21/3/2022 | 17/6/2026 | Business Logic Errors in GitHub repository crater-invoice/crater prior to 6.0.5. | |
| Modificada | Media (5.4) | 0.61% | — | Craterapp Crater | 27/1/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in Packagist bytefury/crater prior to 6.0.2. | |
| Modificada | Media (5.3) | 1.2% | — | Craterapp Crater | 26/1/2022 | 17/6/2026 | Improper Access Control in GitHub repository crater-invoice/crater prior to 6.0.2. | |
| Modificada | Alta (7.2) | 1.4% | — | Craterapp Crater | 17/1/2022 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0. | |
| Modificada | Alta (8.8) | 1.5% | — | Craterapp Crater | 12/1/2022 | 17/6/2026 | crater is vulnerable to Unrestricted Upload of File with Dangerous Type |