Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3042▲ 436 respecto a la semana anterior
Críticas / altas1431▲ 190 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 168 respecto a la semana anterior
110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | — | — | Decolua 9routerAI | 30/9/2026 | 1/10/2026 | A vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the function fetch of the file src/shared/utils/ssrfGuard.js of the component Search Endpoint. Performing a manipulation of the argument provider_options.baseUrl results in server-side request forgery. The attack can be initiated… | |
| Aplazada | Media (6) | 0.43% | — | ASH LUAAI | 8/9/2026 | 8/9/2026 | AshLua exposes Ash read actions to Lua scripts run through an eval action. A read call accepts an operation (list, min, max, first, sum, avg) that builds an ad-hoc Ash.Query.Aggregate over a named field and returns its raw value. Ash field policies redact forbidden fields on returned records (replacing them with… | |
| Aplazada | Alta (8.2) | 0.52% | — | Ash-project ASH LUAAI | 7/9/2026 | 8/9/2026 | Improper Protection of Alternate Path vulnerability in ash-project ash_lua allows a user-supplied Lua script to read attributes that are not on the exposed-field allow-list. AshLua exposes Ash resources to Lua scripts, gated by a manifest declaring which fields are exposed. The read action's operation aggregate path… | |
| Aplazada | Crítica (10) | 0.48% | — | Apache KvrocksAIRedis LUAAICjsonAI | 25/6/2026 | 25/6/2026 | Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.0.4 through 2.15.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue. | |
| Aplazada | Media (5.3) | 0.28% | — | Decolua 9routerAI | 1/6/2026 | 22/7/2026 | A security vulnerability has been detected in decolua 9router up to 0.4.0. This issue affects the function isAuthenticated of the file src/dashboardGuard.js of the component HTTP Header Handler. The manipulation of the argument Host leads to improper authorization. The attack is possible to be carried out remotely.… | |
| Pendiente de análisis | Alta (8.1) | 0.17% | — | LuantiAI | 16/4/2026 | 17/6/2026 | Luanti 5 before 5.15.2 sometimes allows unintended access to an insecure environment. If at least one mod is listed as secure.trusted_mods or secure.http_mods, then a crafted mod can intercept the request for the insecure environment or HTTP API, and also receive access to it. | |
| Aplazada | Crítica (9.3) | 0.19% | — | LuantiAILuajitAI | 16/4/2026 | 17/6/2026 | Luanti 5 before 5.15.2, when LuaJIT is used, allows a Lua sandbox escape via a crafted mod. | |
| Aplazada | Media (5.5) | 0.54% | — | Decolua 9routerAI | 9/4/2026 | 17/6/2026 | A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function of the file /api of the component Administrative API Endpoint. The manipulation leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been disclosed… | |
| Aplazada | Baja (1.7) | 0.31% | — | Wikimedia ScribuntoAIWikimedia LuasandboxAI | 3/2/2026 | 17/6/2026 | Vulnerability in Wikimedia Foundation Scribunto, Wikimedia Foundation luasandbox. This vulnerability is associated with program files includes/Engines/LuaCommon/lualib/mwInit.Lua, library.C. This issue affects Scribunto: from * before 1.39.16, 1.43.6, 1.44.3, 1.45.1; luasandbox: from * before… | |
| Analizada | Crítica (9.3) | 0.37% | — | Quatuor Evaluacion DE Desempeno | 27/1/2026 | 17/6/2026 | An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_usuario' in '/evaluacion_objetivos_ver_auto.aspx', could allow an attacker to extract sensitive… | |
| Analizada | Crítica (9.3) | 0.37% | — | Quatuor Evaluacion DE Desempeno | 27/1/2026 | 17/6/2026 | An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_evaluacion' in '/evaluacion_objetivos_evalua_definido.aspx', could allow an attacker to extract… | |
| Analizada | Crítica (9.3) | 0.37% | — | Quatuor Evaluacion DE Desempeno | 27/1/2026 | 17/6/2026 | An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_usuario' in '/evaluacion_objetivos_anyo_sig_ver_auto.aspx', could allow an attacker to extract… | |
| Analizada | Crítica (9.3) | 0.37% | — | Quatuor Evaluacion DE Desempeno | 27/1/2026 | 17/6/2026 | An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_usuario' in '/evaluacion_objetivos_anyo_sig_evalua.aspx', could allow an attacker to extract… | |
| Analizada | Crítica (9.3) | 0.37% | — | Quatuor Evaluacion DE Desempeno | 27/1/2026 | 17/6/2026 | An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameters 'Id_usuario' and 'Id_evaluacion’ in ‘/evaluacion_hca_ver_auto.asp', could allow an attacker to extract… | |
| Analizada | Crítica (9.3) | 0.37% | — | Quatuor Evaluacion DE Desempeno | 27/1/2026 | 17/6/2026 | An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_usuario' and 'Id_evaluacion’ in ‘/evaluacion_hca_evalua.aspx’, could allow an attacker to extract… | |
| Analizada | Crítica (9.3) | 0.37% | — | Quatuor Evaluacion DE Desempeno | 27/1/2026 | 17/6/2026 | An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_usuario' and 'Id_evaluacion’ in ‘/evaluacion_competencias_evalua_old.aspx’, could allow an attacker… | |
| Analizada | Crítica (9.3) | 0.37% | — | Quatuor Evaluacion DE Desempeno | 27/1/2026 | 17/6/2026 | An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_usuario' in ‘/evaluacion_acciones_ver_auto.aspx’, could allow an attacker to extract sensitive… | |
| Analizada | Crítica (9.3) | 0.37% | — | Quatuor Evaluacion DE Desempeno | 27/1/2026 | 17/6/2026 | An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter ‘Id_usuario' in ‘/evaluacion_acciones_evalua.aspx’, could allow an attacker to extract sensitive… | |
| Analizada | Crítica (9.3) | 0.37% | — | Quatuor Evaluacion DE Desempeno | 27/1/2026 | 17/6/2026 | An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_usuario' and 'Id_evaluacion' en ‘/evaluacion_inicio.aspx’, could allow an attacker to extract… | |
| Analizada | Crítica (9.3) | 0.37% | — | Quatuor Evaluacion DE Desempeno | 27/1/2026 | 17/6/2026 | An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_usuario’ in '/evaluacion_competencias_evalua.aspx', could allow an attacker to extract sensitive… | |
| Analizada | Crítica (9.3) | 0.37% | — | Quatuor Evaluacion DE Desempeno | 27/1/2026 | 17/6/2026 | An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'txAny' in '/evaluacion_competencias_autoeval_list.aspx', could allow an attacker to extract sensitive… | |
| Analizada | Alta (7.3) | 0.45% | — | Silentmatt Javascript Expression Evaluator | 14/11/2025 | 17/6/2026 | npm package `expr-eval` is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance model to achieve arbitrary code execution. The npm expr-eval-fork package resolves this issue. | |
| Analizada | Crítica (9.8) | 2.3% | — | Jorenbroekema Javascript Expression EvaluatorSilentmatt Javascript Expression Evaluator | 5/11/2025 | 17/6/2026 | The expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressions with user-defined variables. However, due to insufficient input validation, an attacker can pass a crafted context object or use MEMBER of the context object into the evaluate() function and… | |
| Aplazada | Media (6.9) | 0.45% | — | LuanoxAI | 16/9/2025 | 17/6/2026 | Luanox is a module host for Lua packages. Prior to 0.1.1, a file traversal vulnerability can cause potential denial of service by overwriting Phoenix runtime files. Package names like ../../package are not properly filtered and pass the validity check of the rockspec verification system. This causes the uploaded file… | |
| Analizada | Media (5.5) | 0.49% | — | 1000projects Online Student Project Report Submission AND Evaluation System | 15/9/2025 | 17/6/2026 | A vulnerability was identified in 1000projects Online Student Project Report Submission and Evaluation System 1.0. The impacted element is an unknown function of the file /admin/controller/student_controller.php. Such manipulation of the argument new_image leads to unrestricted upload. The attack may be performed from… |