Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2509▼ 448 respecto a la semana anterior
Críticas / altas1286▼ 7 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 464 respecto a la semana anterior
93 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.31% | — | Mojox AuthenticationAINET Saml2AI | 6/9/2026 | 8/9/2026 | MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor. parse_assertion in MojoX::Authentication::Model::SAML2 calls Net::SAML2::Binding::POST->new with no cacert, cert_text or anchors argument, then passes… | |
| Aplazada | Media (5.3) | 0.32% | — | Mojo JWTAI | 17/7/2026 | 20/7/2026 | Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison. The decode() method compares the supplied signature to the recomputed HMAC with Perl's eq operator, which stops at the first differing byte, so the comparison time varies with the number of matching leading… | |
| Aplazada | Crítica (9.1) | 0.25% | — | MojoliciousAI | 14/7/2026 | 15/7/2026 | Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle. _csrf_token generates and caches one token per session and returns the same value on every call, and _csrf_field places that value in a hidden `csrf_token` input. When a response… | |
| Aplazada | Media (6.5) | 0.53% | — | Mojo JsonAI | 6/7/2026 | 6/7/2026 | Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder. The pure-Perl decode path (`_decode_value` dispatching to `_decode_array` and `_decode_object`) recurses with no depth limit, so a small deeply nested JSON document can consume excessive memory. This path… | |
| Aplazada | Crítica (9.1) | 0.52% | — | Mojolicious Plugin WEB Auth Oauth2AI | 23/6/2026 | 23/6/2026 | Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no state generator is specified in the constructor, the module defaults to using a SHA-1 hash of predictable and low-entropy sources, including the epoch time (which is leaked via the HTTP Date header)… | |
| Aplazada | Media (5.3) | 0.42% | — | Mojolicious Sessions StorableAI | 18/6/2026 | 22/6/2026 | Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurely. The default session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, the heap address of an anonymous hash, and the PID. These are predictable or low-entropy sources that are… | |
| Aplazada | Alta (8.8) | 0.23% | — | Mojoomla School ManagementAI | 3/6/2026 | 22/7/2026 | Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalation. This issue affects School Management: from n/a through 93.2.0. | |
| Aplazada | Alta (7.6) | 0.23% | — | Mojoomla School ManagementAI | 3/6/2026 | 22/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla School Management allows SQL Injection. This issue affects School Management: from n/a through 93.2.0. | |
| Aplazada | Media (5.3) | 0.40% | — | Mojolicious Plugin StatsdAIPerl NET Statsd TinyAI | 26/5/2026 | 24/7/2026 | Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections. The metric names and set values were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. Version 0.06 changes the module from being a statsd client to using a… | |
| Aplazada | Crítica (10) | 0.67% | — | MojoportalAI | 13/2/2026 | 17/6/2026 | A zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execute arbitrary commands via uploading a crafted zip file. | |
| Aplazada | Crítica (9.3) | 0.28% | — | Mojoomla WpchurchAI | 7/1/2026 | 30/9/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla WPCHURCH allows Blind SQL Injection.This issue affects WPCHURCH: from n/a through 2.7.0. | |
| Aplazada | Alta (8.1) | 0.49% | — | Mojoomla WpchurchAI | 6/1/2026 | 30/9/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mojoomla WPCHURCH allows PHP Local File Inclusion.This issue affects WPCHURCH: from n/a through 2.7.0. | |
| Aplazada | Media (4.3) | 0.23% | — | Mojofywp WP Affiliate DisclosureAI | 21/12/2025 | 17/6/2026 | Vulnerability in mojofywp WP Affiliate Disclosure wp-affiliate-disclosure.This issue affects WP Affiliate Disclosure: from n/a through 1.2.6. | |
| Aplazada | Crítica (9.9) | 0.37% | — | Mojoomla School ManagementAI | 31/8/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Mojoomla School Management allows Upload a Web Shell to a Web Server.This issue affects School Management: from n/a through 1.93.1 (02-07-2025). | |
| Aplazada | Media (6.5) | 0.23% | — | Mojoomla School ManagementAI | 26/8/2025 | 17/6/2026 | Missing Authorization vulnerability in Mojoomla School Management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects School Management: from n/a through 93.2.0. | |
| Aplazada | Alta (8.5) | 0.34% | — | Mojoomla WpgymAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPGYM allows SQL Injection. This issue affects WPGYM: from n/a through 65.0. | |
| Aplazada | Alta (7.1) | 0.25% | — | Mojoomla School ManagementAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla School Management allows Reflected XSS. This issue affects School Management: from n/a through 92.0.0. | |
| Aplazada | Alta (7.1) | 0.26% | — | Mojoomla WpcrmAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla WPCRM - CRM for Contact form CF7 & WooCommerce wpcrm allows Reflected XSS.This issue affects WPCRM - CRM for Contact form CF7 & WooCommerce: from n/a through <= 3.2.0. | |
| Aplazada | Crítica (9.3) | 0.45% | — | Mojoomla School ManagementAI | 17/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla School Management allows Blind SQL Injection. This issue affects School Management: from n/a through 92.0.0. | |
| Aplazada | Alta (7.5) | 0.72% | — | Mojoomla School ManagementAIPHPAI | 17/6/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in mojoomla School Management allows PHP Local File Inclusion. This issue affects School Management: from n/a through 93.0.0. | |
| Aplazada | Alta (7.5) | 0.67% | — | Mojoomla WpgymAI | 17/6/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in mojoomla WPGYM allows PHP Local File Inclusion. This issue affects WPGYM: from n/a through 65.0. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Mojoomla WpcrmAI | 17/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPCRM - CRM for Contact form CF7 & WooCommerce wpcrm allows SQL Injection.This issue affects WPCRM - CRM for Contact form CF7 & WooCommerce: from n/a through <= 3.2.0. | |
| Aplazada | Crítica (9.1) | 0.42% | — | Mojolicious Plugin CaptchapngAI | 16/6/2025 | 17/6/2026 | Mojolicious::Plugin::CaptchaPNG version 1.05 for Perl uses a weak random number source for generating the captcha. That version uses the built-in rand() function for generating the captcha text as well as image noise, which is insecure. | |
| Aplazada | Alta (7) | 0.28% | — | Mojolicious Plugin CsrfAI | 11/6/2025 | 17/6/2026 | Mojolicious::Plugin::CSRF 1.03 for Perl uses a weak random number source for generating CSRF tokens. That version of the module generates tokens as an MD5 of the process id, the current time, and a single call to the built-in rand() function. | |
| Aplazada | Crítica (9.9) | 0.42% | — | Mojoomla Hospital Management SystemAI | 23/5/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla Hospital Management System allows Upload a Web Shell to a Web Server. This issue affects Hospital Management System: from 47.0(20 through 11. |