Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2624▼ 223 respecto a la semana anterior
Críticas / altas1373▲ 144 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.1)0.19%—Hashicorp PackerAI17/8/202628/8/2026
Packer up to 1.15.4 is vulnerable to an issue in the third-party plugin installer that may allow unintended file system modification and could lead to code execution. A user who installs a plugin from a malicious or compromised source may be affected. This vulnerability (CVE-2026-19589) is fixed in Packer 1.16.0.
ModificadaMedia (4.5)0.50%—Oretnom23 Packers AND Movers Management System6/2/20255/7/2026
Cross Site Request Forgery (CSRF) in Users.php in SourceCodester Packers and Movers Management System 1.0 allows attackers to create unauthorized admin accounts via crafted requests sent to an authenticated admin user.
AnalizadaMedia (6.4)1.0%—Oretnom23 Packers AND Movers Management System3/2/202517/6/2026
SourceCodester Packers and Movers Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in Users.php. An attacker can inject a malicious script into the username or name field during user creation.
AplazadaAlta (7.5)0.40%—Cpacker MemgptAI27/12/202417/6/2026
Incorrect access control in the /users endpoint of Cpacker MemGPT v0.3.17 allows attackers to access sensitive data.
AnalizadaAlta (8.8)0.92%—Oretnom23 Packers AND Movers Management System24/10/202417/6/2026
A SQL injection vulnerability in Sourcecodester Packers and Movers Management System v1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in /mpms/admin/?page=services/manage_service&id
ModificadaAlta (7.2)1.2%—Oretnom23 Packers AND Movers Management System30/11/202317/6/2026
SQL injection vulnerability in Packers and Movers Management System v.1.0 allows a remote attacker to execute arbitrary code via crafted payload to the /mpms/admin/?page=user/manage_user&id file.
ModificadaCrítica (9.8)0.63%—Oretnom23 Packers AND Movers Management System26/10/202317/6/2026
Sourcecodester Packers and Movers Management System v1.0 is vulnerable to SQL Injection via mpms/?p=services/view_service&id.
ModificadaCrítica (9.8)0.99%—Oretnom23 Packers AND Movers Management System28/9/202317/6/2026
Sourcecodester Packers and Movers Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /inquiries/view_inquiry.php.
ModificadaMedia (5.3)1.8%—Hashicorp Packer25/8/201817/6/2026
An Amazon Web Services (AWS) developer who does not specify the --owners flag when describing images via AWS CLI, and therefore not properly validating source software per AWS recommended security best practices, may unintentionally load an undesired and potentially malicious Amazon Machine Image (AMI) from the…
ModificadaBaja (3.3)0.29%—Roderich Schupp Par-packer Module13/1/201216/6/2026
The par_mktmpdir function in the PAR module before 1.003 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to overwrite files when another user extracts a PAR packed program, a different vulnerability in a…
ModificadaBaja (3.3)0.33%—Roderich Schupp Par-packer Module13/1/201216/6/2026
The par_mktmpdir function in the PAR::Packer module before 1.012 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to overwrite files when another user extracts a PAR packed program. NOTE: a similar…