Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

28 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.6)0.43%—OpencatsAI31/5/202622/7/2026
OpenCATS from version 0.9.1a contains an SQL injection vulnerability in DataGrid filter handling that allows authenticated attackers to inject SQL through crafted filters targeting the non-filterable Tags column in the Candidates DataGrid. Attackers can bypass column filterable restrictions by manipulating filter…
AplazadaAlta (8.4)0.40%—OpencatsAI31/5/202622/7/2026
OpenCATS through 0.9.7.4 contains a sql injection vulnerability in the sortDirection parameter of the DataGrid component that allows authenticated users to extract database contents. Attackers can inject malicious SQL via the sortDirection parameter in ajax/getDataGridPager.php to perform time-based blind injection…
AplazadaCrítica (9.3)0.66%—OpencatsAI10/5/202625/7/2026
OpenCATS 0.9.4 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by uploading malicious PHP files disguised as resume attachments. Attackers can upload PHP payloads through the careers job application endpoint and execute system commands via POST…
AplazadaCrítica (9.2)3.4%—OpencatsAI28/4/202614/7/2026
OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows unauthenticated attackers to execute arbitrary code by injecting PHP statements into the databaseConnectivity action parameter. Attackers can break out of the define() string context in config.php…
ModificadaMedia (5.4)0.43%—Opencats11/4/202317/6/2026
A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the state parameter at opencats/index.php?m=candidates.
ModificadaMedia (5.4)0.41%—Opencats11/4/202317/6/2026
A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the city parameter at opencats/index.php?m=candidates.
ModificadaMedia (4.3)0.23%—Opencats11/4/202317/6/2026
A Cross-Site Request Forgery (CSRF) in OpenCATS 0.9.7 allows attackers to force users into submitting web requests via unspecified vectors.
ModificadaMedia (5.4)0.35%—Opencats28/2/202317/6/2026
Cross-site request forgery is facilitated by OpenCATS failure to require CSRF tokens in POST requests. An attacker can exploit this issue by creating a dummy page that executes Javascript in an authenticated user's session when visited.
ModificadaMedia (5.4)0.53%—Opencats28/2/202317/6/2026
Improper neutralization of input during web page generation allows an authenticated attacker with access to a restricted account to submit malicious Javascript as the description for a calendar event, which would then be executed in other users' browsers if they browse to that event. This could result in stealing…
ModificadaMedia (6.1)57%—Opencats28/2/202317/6/2026
Improper neutralization of input during web page generation allows an unauthenticated attacker to submit malicious Javascript as the answer to a questionnaire which would then be executed when an authenticated user reviews the candidate's submission. This could be used to steal other users’ cookies and force users to…
ModificadaMedia (5.4)1.0%—Opencats28/2/202317/6/2026
An open redirect vulnerability exposes OpenCATS to template injection due to improper validation of user-supplied GET parameters.
ModificadaMedia (5.4)0.52%—Opencats27/1/202317/6/2026
Opencats v0.9.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /opencats/index.php?m=calendar. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description or Title text fields.
ModificadaMedia (6.1)1.4%—Opencats27/1/202317/6/2026
Opencats v0.9.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /opencats/index.php?m=settings&a=ajax_tags_upd.
ModificadaCrítica (9.8)1.1%—Opencats27/1/202317/6/2026
Opencats v0.9.7 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.
AnalizadaMedia (6.5)0.86%—Opencats19/10/202217/6/2026
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.
AnalizadaMedia (6.5)0.86%—Opencats19/10/202217/6/2026
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag deletion function.
AnalizadaMedia (6.5)0.86%—Opencats19/10/202217/6/2026
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the entriesPerPage variable.
AnalizadaMedia (6.5)0.86%—Opencats19/10/202217/6/2026
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag update function.
AnalizadaCrítica (9.8)2.1%—Opencats19/10/202217/6/2026
OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functionality.
AnalizadaMedia (6.1)1.5%—Opencats19/10/202217/6/2026
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the email parameter in the Check Email function.
AnalizadaMedia (6.1)1.5%—Opencats19/10/202217/6/2026
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the indexFile component.
AnalizadaMedia (6.1)1.5%—Opencats19/10/202217/6/2026
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback component.
AnalizadaMedia (6.1)1.4%—Opencats19/10/202217/6/2026
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the entriesPerPage parameter.
AnalizadaMedia (6.1)1.4%—Opencats19/10/202217/6/2026
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the joborderID parameter.
ModificadaCrítica (9.8)11%—Opencats15/12/202117/6/2026
OpenCATS through 0.9.6 allows remote attackers to execute arbitrary code by uploading an executable file via lib/FileUtility.php.