Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 29 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
63 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.9) | 0.63% | — | Opensourcepos Open Source Point OF SaleAI | 15/8/2026 | 20/8/2026 | A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This affects the function Login::index of the file app/Config/Filters.php of the component Login Endpoint. The manipulation results in improper restriction of excessive authentication attempts. The attack may be launched remotely. The… | |
| Aplazada | Alta (7.5) | 0.50% | — | Openlink Virtuoso-opensourceAI | 23/6/2026 | 23/6/2026 | An issue in the sqlo_untry component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | |
| Aplazada | Alta (7.5) | 0.50% | — | Openlink Virtuoso-opensourceAI | 23/6/2026 | 23/6/2026 | An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | |
| Aplazada | Alta (7.5) | 0.68% | — | Openlink Virtuoso-opensourceAI | 23/6/2026 | 15/7/2026 | An issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | |
| Aplazada | Alta (7.5) | 0.50% | — | Openlink Virtuoso-opensourceAI | 23/6/2026 | 25/6/2026 | An issue in the t_set_push component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | |
| Aplazada | Alta (7.5) | 0.50% | — | Openlink Virtuoso-opensourceAI | 23/6/2026 | 23/6/2026 | An issue in the sslr_qst_get component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | |
| Aplazada | Alta (7.5) | 0.68% | — | Openlink Virtuoso-opensourceAI | 23/6/2026 | 15/7/2026 | An issue in the st_compare component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | |
| Aplazada | Alta (7.5) | 0.50% | — | Openlink Virtuoso-opensourceAI | 23/6/2026 | 23/6/2026 | An issue in the sqlo_tb_col_preds component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | |
| Aplazada | Alta (7.5) | 0.35% | — | Openlink Virtuoso-opensourceAI | 23/6/2026 | 25/6/2026 | An issue in the sqlo_natural_join_cond component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | |
| Aplazada | Alta (7.5) | 0.68% | — | Openlink Virtuoso-opensourceAI | 23/6/2026 | 15/7/2026 | An issue in the sqlo_strip_in_join component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | |
| Aplazada | Alta (7.5) | 0.50% | — | Openlink Virtuoso-opensourceAI | 23/6/2026 | 25/6/2026 | An issue in the sqlo_key_part_best component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | |
| Aplazada | Alta (7.5) | 0.68% | — | Openlink Virtuoso-opensourceAI | 23/6/2026 | 15/7/2026 | An issue in the sqlo_place_dt_set component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | |
| Aplazada | Alta (8.8) | 0.27% | — | MGB Opensource GuestbookAI | 30/5/2026 | 22/7/2026 | MGB OpenSource Guestbook 0.7.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send GET requests to email.php with crafted SQL payloads in the 'id' parameter to extract sensitive… | |
| Aplazada | Media (6.3) | 0.27% | — | Opensourcepos Open Source Point OF SaleAI | 18/5/2026 | 17/6/2026 | A flaw has been found in opensourcepos Open Source Point of Sale up to 3.4.2. Impacted is the function Login of the file app/Models/Employee.php of the component Employee Login. This manipulation causes use of weak hash. Remote exploitation of the attack is possible. The attack is considered to have high complexity.… | |
| Aplazada | Media (5.3) | 0.57% | — | Opensourcepos Open Source Point OF SaleAI | 18/5/2026 | 17/6/2026 | A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This issue affects the function getPicThumb of the file app/Controllers/Items.php. The manipulation of the argument pic_filename results in path traversal. The attack may be launched remotely. The patch is identified as… | |
| Analizada | Media (5.4) | 0.24% | — | Opensourcepos Open Source Point OF Sale | 7/4/2026 | 24/7/2026 | Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Daily Sales management table. The customer_name column is configured with escape: false in the bootstrap-table column… | |
| Analizada | Media (5.4) | 0.24% | — | Opensourcepos Open Source Point OF Sale | 7/4/2026 | 24/7/2026 | Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Stock Locations configuration feature. The application fails to properly sanitize user input supplied through the stock_location… | |
| Analizada | Media (6.5) | 0.35% | — | Opensourcepos Open Source Point OF Sale | 27/3/2026 | 17/6/2026 | Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Prior to version 3.4.2, an Insecure Direct Object Reference (IDOR) vulnerability allows an authenticated low-privileged user to access the password change functionality of other users,… | |
| Analizada | Alta (8.1) | 0.43% | — | Opensource-workshop Connect-cms | 23/3/2026 | 17/6/2026 | Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Versions 1.41.1 and 2.41.1 contain… | |
| Analizada | Alta (7.5) | 0.47% | — | Opensource-workshop Connect-cms | 23/3/2026 | 17/6/2026 | Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Versions 1.41.1 and 2.41.1 contain a patch. | |
| Analizada | Media (6.8) | 0.46% | — | Opensource-workshop Connect-cms | 23/3/2026 | 17/6/2026 | Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, a Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Versions 1.41.1 and 2.41.1 contain a… | |
| Analizada | Media (4.8) | 0.35% | — | Opensource-workshop Connect-cms | 23/3/2026 | 17/6/2026 | Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, a Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Versions 1.41.1 and 2.41.1 contain a patch. | |
| Analizada | Alta (8.7) | 0.44% | — | Opensource-workshop Connect-cms | 23/3/2026 | 17/6/2026 | Connect-CMS is a content management system. In versions 1.35.0 through 1.41.0 and 2.35.0 through 2.41.0, a DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin list view. Versions 1.41.1 and 2.41.1 contain a patch. | |
| Analizada | Alta (8.8) | 0.79% | — | Opensource-workshop Connect-cms | 23/3/2026 | 17/6/2026 | Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an authenticated user may be able to execute arbitrary code in the Code Study Plugin. Versions 1.41.1 and 2.41.1 contain a patch. | |
| Analizada | Alta (8.8) | 0.46% | — | Opensourcepos Open Source Point OF Sale | 20/3/2026 | 17/6/2026 | Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Versions contain an SQL Injection in the Items search functionality. When the custom attribute search feature is enabled (search_custom filter), user-supplied input from the search GET parameter is… |