Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▲ 13 respecto a la semana anterior
Críticas / altas1459▲ 323 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
149 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.3) | 0.22% | — | ZoneminderAI | 28/9/2026 | 30/9/2026 | ZoneMinder before 1.38.4 fails to apply per-monitor access restrictions in the FramesController index endpoint. Authenticated users with Events view permission can call the frames API to list frame records from monitors they are denied access to, disclosing event and frame metadata across monitor boundaries. | |
| Pendiente de análisis | Alta (8.3) | 0.37% | — | ZoneminderAI | 28/9/2026 | 30/9/2026 | ZoneMinder before 1.38.4 contains static buffer overflow vulnerabilities in RemoteCameraHttp::GetResponse() that allow malicious HTTP cameras or intercepting attackers to overflow fixed-size buffers by sending oversized response headers. Attackers can send crafted HTTP responses with oversized status messages,… | |
| Pendiente de análisis | Alta (7.1) | 0.37% | — | ZoneminderAI | 28/9/2026 | 30/9/2026 | ZoneMinder versions 1.37.0 before 1.38.0 contain a path traversal vulnerability in the files view that allows authenticated users to read arbitrary files. The path parameter is not properly validated before being passed to output_file, enabling attackers with Events view permission to access sensitive files like… | |
| Aplazada | Media (6.5) | 0.34% | — | ZoneminderAI | 11/9/2026 | 30/9/2026 | ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low-privileged user with coarse `Events=View` and/or `Snapshots=View` permissions to directly fetch media for events belonging to monitors they are not allowed to… | |
| Aplazada | Alta (8.7) | 2.4% | — | ZoneminderAI | 28/8/2026 | 31/8/2026 | An authenticated OS command injection vulnerability exists in ZoneMinder's event export functionality. The exportFile HTTP request parameter is passed unsanitized into a shell command executed via PHP's exec(), allowing any authenticated user with View Events permission to execute arbitrary operating system commands… | |
| Aplazada | Alta (8.8) | 1.0% | — | ZoneminderAI | 11/8/2026 | 3/9/2026 | A remote code execution vulnerability in ZoneMinder 1.39.17 allows any authenticated user to execute OS commands by exploiting a broken permission check in the Filter class. The canEdit() and canDelete() methods invoke nonexistent methods on the ZM\User class, causing PHP __call() to return a truthy value that… | |
| Pendiente de análisis | Media (6.9) | 0.47% | — | California Courts Hearing Reminder ServiceAI | 9/7/2026 | 21/7/2026 | The Superior Court of California Hearing Reminder Service at https://www.hrs.courts.ca.gov exposes an API endpoint that returns court reminder records containing potentially sensitive information without authentication. | |
| Analizada | Media (4.6) | 0.24% | — | Broadcom Symantec Siteminder | 10/3/2026 | 17/6/2026 | Cross-site Scripting (XSS) allows an attacker to submit specially crafted data to the application which is returned unaltered in the resulting web page. | |
| Analizada | Alta (8.8) | 0.56% | — | Zoneminder | 21/2/2026 | 17/6/2026 | ZoneMinder is a free, open source closed-circuit television software application. In versions 1.36.37 and below and 1.37.61 through 1.38.0, there is a second-order SQL Injection vulnerability in the web/ajax/status.php file within the getNearEvents() function. Event field values (specifically Name and Cause) are… | |
| Modificada | Crítica (9.8) | 1.7% | — | Zoneminder | 18/2/2026 | 17/6/2026 | ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user input directly to the exec() function. NOTE: this is disputed by the Supplier because there is no unsanitized user input to web/views/image.php. | |
| Aplazada | Alta (8.5) | 0.28% | — | Minder GOAIHelmAI | 21/11/2025 | 17/6/2026 | Minder is an open source software supply chain security platform. In Minder Helm version 0.20241106.3386+ref.2507dbf and Minder Go versions from 0.0.72 to 0.0.83, Minder users may fetch content in the context of the Minder server, which may include URLs which the user would not normally have access to. This issue has… | |
| Analizada | Media (6.1) | 0.22% | — | Rems Medicine Reminder APP | 7/11/2025 | 17/6/2026 | Sourcecodester Medicine Reminder App v1.0 is vulnerable to Cross-Site Scripting (XSS) in the "Medicine Name" and "Notes (Optional)" fields when creating an "Upcoming Reminder", allowing an attacker to inject arbitrary potentially malicious HTML/JavaScript code that executes in the victim's browser upon clicking the… | |
| Aplazada | Media (4.3) | 0.16% | — | Storepro Subscription Renewal Reminders FOR WoocommerceAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in storepro Subscription Renewal Reminders for WooCommerce subscriptions-renewal-reminders allows Cross Site Request Forgery.This issue affects Subscription Renewal Reminders for WooCommerce: from n/a through <= 1.4.1. | |
| Analizada | Media (5.1) | 0.36% | — | Oretnom23 Task Reminder System | 14/1/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Task Reminder System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Maintenance Section. The manipulation of the argument System Name leads to cross site scripting. The attack can be launched remotely.… | |
| Aplazada | Media (5.9) | 0.31% | — | Wpdevelop Email-remindersAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevelop Email Reminders email-reminders allows Stored XSS.This issue affects Email Reminders: from n/a through <= 2.0.5. | |
| Aplazada | Media (6.4) | 0.35% | — | Email RemindersAI | 10/12/2024 | 17/6/2026 | The Email Reminders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Crítica (9.9) | 37% | — | ZoneminderAI | 31/10/2024 | 17/6/2026 | ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder v1.37.* <= 1.37.64 is vulnerable to boolean-based SQL Injection in function of web/ajax/event.php. This is fixed in 1.37.65. | |
| Modificada | Media (6.6) | 0.49% | — | Zoneminder | 15/10/2024 | 5/7/2026 | RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a crafted payload and escalate privileges allowing execution of any commands on the remote system. | |
| Analizada | Media (6.5) | 0.19% | — | Lucasgarcia Posts Reminder | 17/9/2024 | 17/6/2026 | The Posts reminder WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Analizada | Crítica (9.8) | 6.2% | — | Zoneminder | 12/8/2024 | 17/6/2026 | ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability. This vulnerability is fixed in 1.36.34 and 1.37.61. | |
| Analizada | Media (6.1) | 0.40% | — | Zoneminder | 12/8/2024 | 17/6/2026 | ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder has a cross-site scripting vulnerability in the montagereview via the displayinterval, speed, and scale parameters. This vulnerability is fixed in 1.36.34 and 1.37.61. | |
| Analizada | Media (6.1) | 0.35% | — | Zoneminder | 12/8/2024 | 17/6/2026 | ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder has a cross-site scripting vulnerability in the filter view via the filter[Id]. This vulnerability is fixed in 1.36.34 and 1.37.61. | |
| Analizada | Media (6.5) | 0.51% | — | Zoneminder | 12/8/2024 | 17/6/2026 | ZoneMinder is a free, open source Closed-circuit television software application. In WWW/AJAX/watch.php, Line: 51 takes a few parameter in sql query without sanitizing it which makes it vulnerable to sql injection. This vulnerability is fixed in 1.36.34. | |
| Aplazada | Media (5.7) | 0.46% | — | Go-gitAILfprojects MinderAI | 18/6/2024 | 17/6/2026 | Minder is an open source Software Supply Chain Security Platform. Minder's Git provider is vulnerable to a denial of service from a maliciously configured GitHub repository. The Git provider clones users repositories using the `github.com/go-git/go-git/v5` library on lines `L55-L89`. The Git provider does the… | |
| Aplazada | Media (5.3) | 0.53% | — | Lfprojects MinderAI | 27/5/2024 | 17/6/2026 | Minder by Stacklok is an open source software supply chain security platform. Minder prior to version 0.0.51 is vulnerable to a denial-of-service (DoS) attack which could allow an attacker to crash the Minder server and deny other users access to it. The root cause of the vulnerability is that Minders sigstore… |