Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▲ 10 respecto a la semana anterior
Críticas / altas1458▲ 322 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

262 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.1)0.28%—Gedelumbung HospitalmanagementAISunhater KcfinderAI29/9/202630/9/2026
A vulnerability was identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affected by this issue is the function app_user_login_model.php::cekUserLogin of the file application/models/app_user_login_model.php of the component KCFinder File Manager. Such manipulation of the…
AplazadaAlta (8.6)0.45%—Album Cover FinderAI12/9/202614/9/2026
The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.
AplazadaAlta (8.1)0.90%—ElfinderAI31/8/20269/9/2026
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, checkExtractItems() in php/elFinderVolumeDriver.class.php calls mimetypeInternalDetect() without passing the result through mimeTypeNormalize(). Because the .phtml, .phar, .php5, and .php3 extensions are absent…
AplazadaMedia (5.4)0.18%—ElfinderAI31/8/20269/9/2026
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, the netmount command is omitted from elFinderConnector::$csrfProtectedCmds in php/elFinderConnector.class.php, so validateCsrfToken() is not called for this state-changing operation. In the shipped…
AplazadaAlta (8.6)0.55%—ElfinderAI31/8/20269/9/2026
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, elFinder URL uploads in php/elFinder.class.php can bypass server-side request forgery protections when PHP cURL is unavailable because validate_address() validates $info['ip'], but get_remote_contents() selects…
AplazadaAlta (7.1)0.25%—Superstorefinder Super Store FinderAI31/8/20261/9/2026
Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions.
En análisisBaja (3.1)0.29%—Tanium FindingsAI19/8/20261/9/2026
Tanium addressed a compression bomb vulnerability in Findings.
AplazadaAlta (8.8)0.42%—Service Finder BookingAI13/8/202614/8/2026
Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions.
AplazadaMedia (6.5)0.37%—Service Finder BookingAI13/8/202614/8/2026
Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions.
AplazadaAlta (8.7)0.44%—FlawfinderAI11/8/20269/9/2026
Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code. Versions prior to 2.0.20 have an improper input neutralization issue leading to output manipulation, specifically, Terminal/ANSI Escape Sequence Injection and XML Injection. A malicious file whose name contains ANSI escape…
AplazadaCrítica (9.8)0.48%—Openlibraryfoundation VufindAI6/8/20269/9/2026
Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to stop processing an incoming request in VuFind\Controller\AbstractBase::validateAccessPermission after it has found that controller level access permissions do not allow access to the requested function.…
AplazadaCrítica (9.1)0.46%—Superstorefinder Super Store FinderAI3/8/202631/8/2026
The Super Store Finder WordPress plugin before 7.11 does not sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection and extract data from the database.
AplazadaAlta (7.5)0.46%—Find-my-wayAI28/7/202630/7/2026
find-my-way is a framework-independent HTTP router that internally uses a Radix Tree and supports route parameters and wildcards. Versions prior to 9.7.0 are vulnerable to remotely triggerable DoS in find-my-way when it is used with Node's HTTP/2 server. The lookup() function passes req.method into find(), and find()…
AplazadaBaja (1.9)1.1%—Bahmutov Find-cypress-specsAI23/7/202623/7/2026
A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element is the function shell.exec of the file src/index.js of the component Branch Handler. This manipulation of the argument --branch causes os command injection. The attack is restricted to local execution. The exploit has…
Pendiente de análisisMedia (5.3)0.40%—Apple Find MYAI21/7/202623/7/2026
The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint Token) to enumerate devices and remove offline devices from an Apple ID account without triggering two-factor authentication or ownership verification. This may result in unauthorized removal of…
AplazadaAlta (8.8)0.44%—ElfinderAI27/5/202617/6/2026
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.68, an authenticated SQL injection vulnerability in the elFinder MySQL volume driver (elFinderVolumeMySQL) allows any logged-in user, including users with read-only access to the affected volume, to inject SQL through…
AnalizadaAlta (8.9)2.7%—Std42 Elfinder23/4/202617/6/2026
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contains a command injection vulnerability in the resize command. The bg (background color) parameter is accepted from user input and passed through image resize/rotate processing. In configurations that…
AplazadaMedia (5.4)0.24%—Codesolz Better Find AND ReplaceAI16/4/202617/6/2026
The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded image title in versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level…
AplazadaAlta (8.7)0.57%—Openfind MailgatesAIOpenfind MailauditAI16/4/202617/6/2026
MailGates/MailAudit developed by Openfind has a CRLF Injection vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read system files.
AplazadaCrítica (9.3)0.98%—Openfind MailgatesAIOpenfind MailauditAI16/4/202617/6/2026
MailGates/MailAudit developed by Openfind has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and execute arbitrary code.
AplazadaMedia (5.3)0.33%—Doofinder FOR WoocommerceAI8/4/202624/7/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Doofinder Doofinder for WooCommerce doofinder-for-woocommerce allows Retrieve Embedded Sensitive Data.This issue affects Doofinder for WooCommerce: from n/a through <= 2.10.13.
AplazadaCrítica (9.3)0.46%—DBTAIPeter Evans Find CommentAI7/4/202624/7/2026
dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to build applications. Inside the reusable workflow dbt-labs/actions/blob/main/.github/workflows/open-issue-in-repo.yml, the prep job uses peter-evans/find-comment to search for an existing comment…
AplazadaAlta (8.1)0.52%—Elated-themes FindallAI5/3/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes FindAll findall allows PHP Local File Inclusion.This issue affects FindAll: from n/a through <= 1.4.
AplazadaAlta (8.7)0.39%—Chamilo LMSAIElfinderAI20/2/202617/6/2026
Chamilo LMS 1.11.8 contains an arbitrary file upload vulnerability that allows authenticated users to upload and execute PHP files through the elfinder filemanager module. Attackers can upload files with image headers in the social myfiles section, rename them to PHP extensions, and execute arbitrary code by accessing…
AplazadaMedia (4.6)0.35%—Office Product KEY FinderAI11/2/202617/6/2026
Office Product Key Finder 1.5.4 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the registration code input. Attackers can create a specially crafted text file and paste it into the 'Name and Key' field to trigger an application crash.