Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 236 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
239 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.31% | — | Glpi-project GlpiAI | 25/9/2026 | 25/9/2026 | GLPI is a free asset and IT management software package. From 0.85 until 10.0.26 and 11.0.8, a low-privileged authenticated user can create, update, or delete knowledge base comments and translations without the required authorization for the affected content. This issue is fixed in versions 11.0.8 and 10.0.26. | |
| Aplazada | Alta (8.5) | 0.28% | — | GlpiAI | 25/9/2026 | 29/9/2026 | GLPI is a free asset and IT management software package. From 11.0.6 until 11.0.8, an authenticated technician can store active markup in supplier website fields. Any user who opens the affected item's suppliers list triggers the stored cross-site scripting payload. This issue is fixed in version 11.0.8. | |
| Aplazada | Alta (7.1) | 1.0% | — | GlpiAI | 25/9/2026 | 25/9/2026 | GLPI is a free asset and IT management software package. From 9.4.0 until 10.0.26 and 11.0.8, an attacker with the READ right on logs can craft a URL for the history tab that injects attacker-controlled values into a database query. This permits SQL injection through the history tab endpoint. This issue is fixed in… | |
| Aplazada | Media (5.9) | 0.45% | — | GlpiAI | 25/9/2026 | 29/9/2026 | GLPI is a free asset and IT management software package. From 0.84 until 10.0.26 and 11.0.8, an administrator holding the Update auth and sync or Update auth, sync and 2FA right can change the authentication method and disable two-factor authentication for user accounts outside the administrator's entity scope. The… | |
| Aplazada | Media (6) | 0.31% | — | GlpiAI | 25/9/2026 | 25/9/2026 | GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a low-privileged authenticated user can use the new API (v2) to perform update operations that the same user is normally forbidden to perform through the user interface. The API update flow does not consistently enforce the applicable… | |
| Aplazada | Alta (7.1) | 0.30% | — | GlpiAI | 25/9/2026 | 29/9/2026 | GLPI is a free asset and IT management software package. From 11.0.5 until 11.0.8, under certain conditions, permission logic can grant access to a document without confirming that the document is linked to the targeted item. A user can use an unrelated item that the user is permitted to view to read a document linked… | |
| Aplazada | Alta (7.5) | 0.57% | — | GlpiAI | 25/9/2026 | 25/9/2026 | GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, a technician can manipulate the authtype value through the API to change another user's authentication method. Under configurations using the legacy API REST interface or SSO logins, this can change a super-administrator's… | |
| Aplazada | Alta (7.5) | 0.39% | — | GlpiAI | 25/9/2026 | 29/9/2026 | GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, an attacker can craft a URL for a dashboard that reflects attacker-controlled markup without sufficient output encoding. A user who opens the crafted URL triggers reflected cross-site scripting in the dashboard. This issue is fixed in… | |
| Aplazada | Alta (7.7) | 0.36% | — | GlpiAI | 25/9/2026 | 28/9/2026 | GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, the time-based one-time password verification endpoint does not limit failed submissions per user. An attacker who has obtained a user's primary authentication credentials can repeatedly submit TOTP values against the MFA verification… | |
| Aplazada | Media (4.6) | 0.40% | — | GlpiAI | 25/9/2026 | 29/9/2026 | GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, an authenticated hotliner or technician can submit crafted criteria through the user import feature to bypass the configured default LDAP filter. This allows access to LDAP objects that the default filter was intended to… | |
| Aplazada | Crítica (9.4) | 0.34% | — | GlpiAI | 25/9/2026 | 29/9/2026 | GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can use Form import with a crafted illustration or scene identifier that traverses outside the intended custom-asset directory. The imported file can be written to an executable server location, allowing a malicious… | |
| Aplazada | Alta (8.5) | 0.32% | — | GlpiAI | 25/9/2026 | 25/9/2026 | GLPI is a free asset and IT management software package. From 10.0.0 until 10.0.26 and 11.0.8, any logged-in GLPI user can exploit insufficient path validation in the profile-picture update flow to request deletion of an attacker-selected file hosted by the server. This issue is fixed in versions 11.0.8 and 10.0.26. | |
| Aplazada | Media (5.3) | 0.31% | — | GlpiAI | 25/9/2026 | 25/9/2026 | GLPI is a free asset and IT management software package. From 0.72 until 10.0.26 and 11.0.8, an authenticated user without the required permission can enable debug mode. The affected user-setting update does not enforce the privilege boundary intended to restrict debug-mode activation. This issue is fixed in versions… | |
| Aplazada | Alta (7.1) | 0.42% | — | Glpi DatainjectionAI | 10/7/2026 | 14/7/2026 | The DataInjection plugin for GLPI 2.15.6 (GLPI 11 builds) concatenates user-supplied CSV field values directly into SQL queries during CSV import, without parameterization or escaping, resulting in authenticated SQL injection. An authenticated user with access to the Data injection feature can embed SQL expressions… | |
| Aplazada | Alta (7.3) | 0.50% | — | Glpi TAG PluginAI | 9/7/2026 | 20/7/2026 | The Tag plugin for GLPI 11 before 2.14.4 stores the tag name without HTML sanitization and renders it into the Kanban badge markup via PluginTagTag::preKanbanContent() without output escaping, resulting in stored cross-site scripting. An authenticated user with TAG MANAGEMENT create or update rights can set a tag name… | |
| Aplazada | Media (6.3) | 0.46% | — | Glpi-project GlpiAI | 28/6/2026 | 30/6/2026 | A security vulnerability has been detected in glpi-project glpi 11.0.5/11.0.6/11.0.7. This affects the function Document::canViewFile of the file front/document.send.php of the component Document Handler. Such manipulation of the argument docid leads to authorization bypass. The attack can be executed remotely. This… | |
| Aplazada | Alta (7) | 0.39% | — | Glpi-project GlpiAI | 3/6/2026 | 22/7/2026 | GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0.7, an authenticated user with config READ permission can read a specific asset object. Upgrade to 11.0.7 or 10.0.25 to receive a patch. | |
| Aplazada | Alta (8.4) | 0.42% | — | GlpiAI | 3/6/2026 | 22/7/2026 | GLPI is a free asset and IT management software package. Starting in version 10.0.4 and prior to version 10.0.25, a technician can store an XSS payload in the asset locked tab. Upgrade to 10.0.25 or 11.0.7 to receive a patch. | |
| Aplazada | Media (5.9) | 0.30% | — | GlpiAI | 3/6/2026 | 22/7/2026 | GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 10.0.25 and 11.0.7, a technician can read arbitrary files inside the GLPI_DOC_DIR. Upgrade to 10.0.25 or 11.0.7 to receive a patch. | |
| Aplazada | Alta (7) | 0.40% | — | GlpiAI | 3/6/2026 | 21/8/2026 | GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to versions 10.0.25 and 11.0.7, low privilege users with access to planning can delete any object in GLPI. Upgrade to 11.0.7 or 10.0.25 to receive a patch. As a workaround, disable delete rights for User's planning. | |
| Aplazada | Alta (7) | 0.42% | — | GlpiAI | 3/6/2026 | 22/7/2026 | GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0.7, a technician can delete arbitrary files from the filesystem as long as the webserver has write rights on them. Upgrade to 10.0.25 or 11.0.7 to receive a patch. | |
| Aplazada | Alta (7.1) | 0.31% | — | GlpiAI | 2/6/2026 | 22/7/2026 | GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, a technician can store an XSS payload in a ITIL costs. This issue has been fixed in version 11.0.7. | |
| Aplazada | Alta (8.4) | 0.57% | — | GlpiAI | 2/6/2026 | 22/7/2026 | An unauthenticated user with write access to the knowledge base can store an XSS payload in a knowledge base item. This issue affects glpi: before 11.0.7. | |
| Analizada | Media (5.1) | 0.29% | — | Glpi-project Glpi | 19/5/2026 | 24/7/2026 | GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, an authenticated user with forms READ permission can export the structure of unauthorized forms. This issue has been fixed in version 11.0.7. | |
| Aplazada | Media (5.1) | 0.44% | — | Glpi-project OrderAI | 14/5/2026 | 17/6/2026 | Stored Cross-Site Scripting (XSS) in Stel Order v3.25.1 and earlier, located at the ‘/app/FrontController’ endpoint via the ‘legalName’ and ‘employeeID’ parameters. The lack of proper input sanitization allows an attacker to inject malicious code that is persistently stored in the database. When other users or… |