Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
–

18 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.1)0.23%—Roskus Prospero Flow CRMAILaravelAI4/9/20269/9/2026
Cross-Site Request Forgery (CSRF) in the OrderConfirmController at GET /order/confirm/{order_number} in Roskus Prospero Flow CRM before 5.15.11 allows an unauthenticated attacker to confirm any order on behalf of an authenticated user by directing them to a crafted page. Laravel's VerifyCsrfToken middleware enforces…
AplazadaMedia (4.8)0.48%—Roskus Prospero Flow CRMAI27/8/20261/9/2026
Unrestricted Upload of File with Dangerous Type in the product photo upload in Roskus Prospero Flow CRM before 5.16.0 allows an authenticated user holding the create product permission (routine Seller role) to execute arbitrary JavaScript in the application origin. The photo validation rule classifies the file only by…
AplazadaCrítica (9.3)0.51%—Roskus Prospero Flow CRMAI24/8/20261/9/2026
Authorization Bypass Through User-Controlled Key in the supplier API in Roskus Prospero Flow CRM 4.0.0 through 5.3.1 allows any authenticated user to read and modify another company's supplier record, and to reassign it to their own company, via a PUT request to /api/supplier/{id} setting company_id in the body.
AplazadaMedia (4.8)0.40%—Roskus Prospero Flow CRMAI24/8/20261/9/2026
Unrestricted Upload of File with Dangerous Type in the company logo upload in Roskus Prospero Flow CRM before 5.15.13 allows an authenticated user holding the create company and update company permissions to execute arbitrary JavaScript in the application origin via an SVG document containing an embedded script…
AplazadaMedia (5.3)0.44%—Prospero Flow CRMAI21/8/20261/9/2026
Authorization Bypass Through User-Controlled Key in the transaction save endpoint in Roskus Prospero Flow CRM 4.9.1 through 5.14.0 allows a user with transaction and accounting creation permissions to disclose another company's bank account name, bank name and card last four digits via a bank_account_id or…
AplazadaAlta (8.7)0.51%—Roskus Prospero Flow CRMAI21/8/20261/9/2026
Authorization Bypass Through User-Controlled Key in the transaction API in Roskus Prospero Flow CRM 5.0.0 through 5.3.5 allows an authenticated user to read the transactions of other companies on the same instance via an incremented identifier in GET /api/transaction/{id}, which is resolved without company scoping and…
AplazadaCrítica (9.3)0.53%—Roskus Prospero Flow CRMAI14/8/20261/9/2026
Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to authenticate as any employee onboarded through the standard flow, knowing only their email address, because the employee save controller falls back to the literal password…
AplazadaAlta (8.6)0.39%—Roskus Prospero Flow CRMAI14/8/20261/9/2026
Authorization Bypass Through User-Controlled Key in the payroll module in Roskus Prospero Flow CRM before 5.15.10 allows authenticated users holding the read payroll permission to view the salary and banking details of employees of any other company in the instance, and users holding the create payroll permission to…
AplazadaAlta (8.6)0.59%—Roskus Prospero Flow CRMAI13/8/20261/9/2026
Missing Authorization and Authorization Bypass Through User-Controlled Key in the product management component in Roskus Prospero Flow CRM before 5.4.7 allows authenticated users of any company to read the full sensitive data (price, cost, stock, SKU, and barcode) of another company's product and to hijack that…
AplazadaAlta (8.6)0.44%—Roskus Prospero Flow CRMAI11/8/20261/9/2026
Authorization Bypass Through User-Controlled Key in the ticket management component in Roskus Prospero Flow CRM before 5.4.9 allows authenticated users of any company to read the full content (title, description, and attachments) of tickets belonging to another company, to hijack another company's tickets by…
AplazadaAlta (8.6)0.44%—Roskus Prospero Flow CRMAI10/8/20261/9/2026
Authorization Bypass Through User-Controlled Key in the contact management component in Roskus Prospero Flow CRM before 5.4.8 allows authenticated users of any company to blindly overwrite the contact data of another company and to download that contact's personal data as a vCard via the contact's numeric identifier,…
AplazadaAlta (8.7)0.41%—Roskus Prospero Flow CRMAI10/8/20261/9/2026
Missing Authorization in the permission management component in Roskus Prospero Flow CRM before 5.2.1 allows any authenticated user to grant any role, including their own, the complete set of application permissions via a crafted POST request to the permission save endpoint, which performs no authorization check…
AplazadaMedia (5.3)0.53%—Roskus Prospero Flow CRMAI31/7/20261/9/2026
Cross-site Scripting in the lead index view in Roskus Prospero Flow CRM before 5.3.7 allows authenticated users holding the create or update lead permission to execute arbitrary JavaScript in the application origin via HTML markup stored in the lead name field, which the view renders through Blade's unescaped output…
AplazadaAlta (8.6)0.67%—Roskus Prospero Flow CRMAI27/7/20261/9/2026
Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authenticated low-privileged user to execute arbitrary JavaScript in another user's browser, including administrators, leading to session compromise and account takeover, via a payload stored in an email…
AplazadaMedia (6.9)0.64%—Roskus Prospero Flow CRMAI16/7/202616/7/2026
Authorization Bypass Through User-Controlled Key (CWE-639) in the Order and OrderItem REST API controllers in Roskus Prospero Flow CRM before 5.5.3 allows a remote, authenticated user to read, modify, and delete orders and order items belonging to any other company (tenant) via a sequential numeric {id} supplied to…
AplazadaMedia (6.9)0.64%—Roskus Prospero Flow CRMAI15/7/202615/7/2026
Authorization Bypass Through User-Controlled Key (CWE-639) in the Excel import handlers (CustomerImport, LeadImport, ProductImport) in Roskus Prospero Flow CRM before 5.14.0 allows a remote, authenticated user of any role or company to create customer, lead, and product records inside another company's tenant via a…
AplazadaAlta (8.7)0.66%—Prospero Flow CRMAI15/7/202615/7/2026
Missing Authorization (CWE-862) in BankAccountListController (app/Http/Controllers/Api/BankAccount/BankAccountListController.php), exposed at GET /api/bank-account, in Prospero Flow CRM <5.5.3, which allows a remote, authenticated attacker holding a low-privileged role (e.g. the "User"/"Usuario" role) to read…
AplazadaMedia (6.9)0.64%—Prospero Flow CRMAI3/7/20266/7/2026
Authorization Bypass Through User-Controlled Key (CWE-639) in CalendarDeleteEventController (app/Http/Controllers/Calendar/CalendarDeleteEventController.php), exposed at GET /calendar/event/delete/{id}, in Prospero Flow CRM before 5.5.3 allows a remote, authenticated attacker to delete arbitrary calendar events…