Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2865▼ 160 respecto a la semana anterior
Críticas / altas1384▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
50 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.46% | — | KimaiAI | 15/9/2026 | 23/9/2026 | Kimai is an open-source time tracking application. Prior to 2.58.0, ExportController::createExportTemplate() and ExportController::editExportTemplate() inherit only the class-level create_export permission, which ROLE_TEAMLEAD receives by default, and omit the create_export_template permission required by the API… | |
| Aplazada | Alta (7.1) | 0.58% | — | KimaiAI | 15/9/2026 | 30/9/2026 | Kimai is an open-source time tracking application. Prior to 2.59.0, the KIMAI_SESSION cookie issued after password verification but before TOTP completion is accepted by every /api route because config/packages/security.yaml protects the API with IS_AUTHENTICATED and App\API\Authentication\ApiRequestMatcher routes an… | |
| Aplazada | Media (5.3) | 0.43% | — | KimaiAI | 15/9/2026 | 23/9/2026 | Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/project/{id}/rate/{rate}, /en/admin/customer/{id}/rate/{rate}, and /en/admin/activity/{id}/rate/{rate} independently resolve the authorized parent identifier and the attacker-selected child rate identifier without… | |
| Aplazada | Media (5.3) | 0.45% | — | KimaiAI | 15/9/2026 | 23/9/2026 | Kimai is an open-source time tracking application. Prior to 2.58.0, POST /api/teams/{id}/members/{userId} and POST /api/teams/{id}/activities/{activityId} verify that a teamlead may edit the Team but do not verify access_user for the referenced User or view access for the referenced Activity. A teamlead can add users… | |
| Aplazada | Crítica (9.1) | 1.3% | — | KimaiAI | 15/9/2026 | 30/9/2026 | Kimai is an open-source time tracking application. Prior to 2.58.0, the official Docker image sets APP_SECRET to the public value change_this_to_something_unique in Dockerfile, and .docker/entrypoint.sh neither replaces nor rejects that value before Symfony uses it as kernel.secret. An unauthenticated attacker who… | |
| Aplazada | Media (5.3) | 0.30% | — | KimaiAI | 15/9/2026 | 23/9/2026 | Kimai is an open-source time tracking application. Prior to 2.58.0, TimesheetController exposes GET /api/timesheets/{id}/stop and GET /api/timesheets/{id}/restart, which reuse an authenticated browser session and perform state-changing operations through GET requests without a request-forgery defense. A remote… | |
| Aplazada | Media (5.3) | 0.46% | — | KimaiAI | 15/9/2026 | 23/9/2026 | Kimai is an open-source time tracking application. Prior to 2.58.0, PATCH /api/timesheets/{id}/restart, PATCH /api/timesheets/{id}/duplicate, and the web duplicate workflow can derive a new record from an owned historical timesheet after the user's access to its project or activity has been revoked. TimesheetVoter… | |
| Aplazada | Media (5.3) | 0.43% | — | KimaiAI | 15/9/2026 | 30/9/2026 | Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/activity/create/{project} and /en/admin/project/create/{customer} require only the generic create_activity or create_project capability and do not verify edit access to the supplied Project or Customer object. A user… | |
| Aplazada | Media (5.3) | 0.45% | — | KimaiAI | 15/9/2026 | 23/9/2026 | Kimai is an open-source time tracking application. Prior to 2.57.0, PATCH /api/timesheets/{id} and POST /api/timesheets accept a user-controlled project identifier through TimesheetApiEditForm and FormTrait, and ProjectRepository::getQueryBuilderForFormType() places that identifier in an unconditional OR branch that… | |
| Aplazada | Media (6.3) | 0.50% | — | KimaiAI | 15/9/2026 | 23/9/2026 | Kimai is an open-source time tracking application. Prior to 2.57.0, the GET /api/timesheets list endpoint accepts user and users[] target identifiers from a caller with view_other_timesheet but does not apply access_user or verify that a ROLE_TEAMLEAD requester leads a team containing each target user.… | |
| Aplazada | Media (6.3) | 0.22% | — | KimaiAI | 11/9/2026 | 23/9/2026 | Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request forgery issues in their default team creation shortcuts for projects, customers, and activities. These endpoints are exposed through `GET` routes and directly create or reuse a `Team`, add the current… | |
| Aplazada | Media (5.3) | 0.35% | — | KimaiAI | 11/9/2026 | 23/9/2026 | Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain a server-side request forgery vulnerability in their invoice PDF preview and generation workflow. If an attacker can control Markdown content that is later rendered into an invoice PDF, such as `Customer.invoiceText`, the server-side… | |
| Aplazada | Media (5.3) | 0.30% | — | KimaiAI | 2/9/2026 | 2/9/2026 | Kimai versions before 2.65.0 contain an authorization bypass vulnerability in the REST API timesheet collection endpoint that fails to enforce activity-team access controls. Users with view_other_timesheet permission can list timesheets using activities restricted to teams they do not belong to, bypassing intended… | |
| Aplazada | Media (5.3) | 0.25% | — | KimaiAI | 2/9/2026 | 2/9/2026 | Kimai (kimai/kimai) through 2.65.0 contains a business logic / improper authorization vulnerability in the default team creation endpoints. An authenticated user with project permission-management privileges can create or use a customer, project, or activity whose name matches an existing team; because the endpoints… | |
| Aplazada | Media (5.3) | 0.24% | — | KimaiAI | 2/9/2026 | 2/9/2026 | Kimai before 2.63.0 contains an improper authorization vulnerability in team access endpoints that allows authenticated users with team edit permissions and read-only access to grant team access to customers, projects, or activities. Attackers can exploit insufficient permission checks by sending POST requests to team… | |
| Aplazada | Media (5.3) | 0.29% | — | KimaiAI | 2/9/2026 | 2/9/2026 | Kimai versions from 2.61.0 before 2.63.0 fail to disable admin-only work-contract preferences for low-privilege users in the PATCH /api/users/{id}/preferences endpoint. Although the web interface gates these employment-contract fields behind the contract_other_profile admin permission, the… | |
| Aplazada | Media (5.3) | 0.33% | — | KimaiAI | 2/9/2026 | 4/9/2026 | Kimai before 2.65.0 fails to properly validate permissions when removing team access to activities, projects, and customers via API endpoints. Authenticated users with edit_team permission can revoke team access without the required permissions_activity check, bypassing authorization controls. | |
| Aplazada | Crítica (9.3) | 0.45% | — | KimaiAI | 26/8/2026 | 3/9/2026 | Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), which maps permissions only to own_timesheet or other_timesheet. As a result, any authenticated user with ROLE_TEAMLEAD (or a role holding edit_other_timesheet/delete_other_timesheet) can read, modify, and permanently… | |
| Aplazada | Baja (2) | 0.26% | — | KimaiAI | 26/8/2026 | 31/8/2026 | Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call getApiToken() and getPlainApiToken() methods. Attackers with template creation permissions can embed these method calls in invoice templates to leak hashed API tokens in rendered invoice output. | |
| Aplazada | Media (5.3) | 0.36% | — | KimaiAI | 26/8/2026 | 31/8/2026 | Kimai before 2.53.0 contains an open redirect vulnerability in the SAML authentication success handler that accepts unvalidated RelayState POST parameters as redirect destinations. Attackers with IdP access can supply malicious RelayState values to redirect authenticated users to attacker-controlled URLs for… | |
| Aplazada | Media (6.3) | 0.31% | — | KimaiAI | 26/8/2026 | 31/8/2026 | Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthenticated attackers to enumerate valid usernames via X-AUTH-USER header. Attackers can measure response time differences when the password hasher runs only for existing users, enabling username enumeration with no login… | |
| Aplazada | Alta (8.7) | 0.43% | — | KimaiAI | 26/8/2026 | 31/8/2026 | Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and export templates, allowing administrators to access arbitrary configuration keys. Attackers with admin privileges can upload malicious templates to exfiltrate server-wide secrets including LDAP bind passwords and SAML… | |
| Aplazada | Alta (8.7) | 0.26% | — | KimaiAI | 26/8/2026 | 31/8/2026 | Kimai before 2.57.0 contains an improper authorization vulnerability in the favorite timesheet add and remove endpoints that allows authenticated users to manipulate other users' bookmarks. Attackers can add or remove timesheet entries from another user's favorite list by referencing their timesheet identifier,… | |
| Aplazada | Alta (8.7) | 0.53% | — | KimaiAI | 26/8/2026 | 31/8/2026 | Kimai before 2.58.0 contains an authentication bypass vulnerability where password reset links remain valid after password changes because the LoginLink signature covers only the user id, not the password hash. Attackers who intercept or cache a password reset link can use it up to 2 additional times within a 1-hour… | |
| Aplazada | Alta (8.7) | 0.36% | — | KimaiAI | 26/8/2026 | 3/9/2026 | Kimai before 2.63.0 contains a business logic / improper authorization vulnerability in the team update API endpoint (PATCH /api/teams/{id}), which removes all existing team members before validating the submitted replacement member list. An authenticated teamlead (or other user) with permission to edit a team can… |