Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2517▼ 423 respecto a la semana anterior
Críticas / altas1296▲ 12 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)57▼ 471 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.35% | — | Curiosity WorkspaceAI | 16/9/2026 | 23/9/2026 | An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval. It did not grant application-wide administrator privileges, and the vulnerability could not be used to obtain root access to the application or… | |
| Aplazada | Crítica (9.9) | 0.55% | — | Eclipse AeriosAIKeycloakAIPostgresqlAIOpenldapAI | 8/9/2026 | 9/9/2026 | In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services. The Helm chart exposed the Keycloak service and its PostgreSQL backing database… | |
| Aplazada | Alta (8.3) | 0.27% | — | Eclipse AeriosAIEclipse FederatorAI | 3/9/2026 | 3/9/2026 | In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Federator component disables TLS certificate validation for outbound HTTPS connections by default. When the TLS_CERTIFICATE_VALIDATION environment variable is unset or set to false, the component configures… | |
| Aplazada | Alta (8.8) | 0.91% | — | Eclipse AeriosAI | 3/9/2026 | 3/9/2026 | Eclipse aeriOS Self-orchestrator versions prior to 1.2.1 contain a path traversal vulnerability in the REST API. User-controlled identifiers used to create, update, or delete Self-orchestrator resources were incorporated into filesystem paths without adequate validation or sanitization. An unauthenticated remote… | |
| Aplazada | Crítica (9) | 0.18% | — | Eclipse AeriosAIKrakendAI | 2/9/2026 | 3/9/2026 | In the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD instance included in the API Gateway component had the disable_jwk_security parameter hard-coded to true, with no option to override it through the Helm chart configuration. This setting disables TLS… | |
| Aplazada | Media (5.3) | 0.24% | — | RosariosisAI | 14/8/2026 | 14/8/2026 | A vulnerability was found in francoisjacquet RosarioSIS up to 12.8. This issue affects some unknown processing of the file Modules.php. Performing a manipulation results in cross-site request forgery. Remote exploitation of the attack is possible. Upgrading to version 12.9 is capable of addressing this issue. The… | |
| Aplazada | Media (5.3) | 0.34% | — | RosariosisAI | 14/8/2026 | 18/8/2026 | A vulnerability has been found in francoisjacquet RosarioSIS up to 12.7.4. This vulnerability affects unknown code of the file modules/Students/includes/Medical.inc.php of the component Student Medical Module. Such manipulation of the argument table leads to sql injection. The attack may be launched remotely.… | |
| Aplazada | Baja (2.1) | 0.46% | — | RosariosisAI | 14/8/2026 | 14/8/2026 | A flaw has been found in francoisjacquet RosarioSIS up to 12.8. This affects the function DBUpdate of the file Discipline/Referrals.php. This manipulation causes authorization bypass. The attack may be initiated remotely. The exploit has been published and may be used. Upgrading to version 12.9 is able to mitigate… | |
| Aplazada | Alta (7.3) | 0.28% | — | RosariosisAI | 22/4/2025 | 17/6/2026 | Francois Jacquet RosarioSIS v12.0.0 was discovered to contain a content spoofing vulnerability in the Theme configuration under the My Preferences module. This vulnerability allows attackers to manipulate application settings. | |
| Aplazada | Alta (7.1) | 0.14% | — | Riosisgroup RIO Video GalleryAI | 31/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in riosisgroup Rio Video Gallery rio-video-gallery allows Stored XSS.This issue affects Rio Video Gallery: from n/a through <= 2.3.6. | |
| Aplazada | Alta (7.6) | 0.58% | — | Setriosoft Bizcalendar-webAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in setriosoft bizcalendar-web bizcalendar-web allows SQL Injection.This issue affects bizcalendar-web: from n/a through <= 1.1.0.34. | |
| Aplazada | Crítica (9.8) | 0.95% | — | Setorinformatica Sistema Inteligente Para LaboratoriosAI | 26/4/2024 | 17/6/2026 | Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (RCE) vulnerability via the hprinter parameter. This vulnerability is triggered via a crafted POST request. | |
| Aplazada | Crítica (9.8) | 1.0% | — | Setorinformatica Sistema Inteligente Para LaboratoriosAI | 26/4/2024 | 17/6/2026 | Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (RCE) vulnerability via the hmsg parameter. This vulnerability is triggered via a crafted POST request. | |
| Aplazada | Baja (3.5) | 0.47% | — | RosariosisAI | 1/4/2024 | 17/6/2026 | ** DISPUTED ** A vulnerability was found in francoisjacquet RosarioSIS 11.5.1. It has been rated as problematic. This issue affects some unknown processing of the component Add Portal Note. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Modificada | Alta (8.8) | 0.23% | — | Mariosalexandrou Republish OLD Posts | 5/1/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Marios Alexandrou Republish Old Posts.This issue affects Republish Old Posts: from n/a through 1.21. | |
| Modificada | Alta (7.5) | 0.61% | — | Rosariosis | 12/5/2023 | 17/6/2026 | Storage of Sensitive Data in a Mechanism without Access Control in GitHub repository francoisjacquet/rosariosis prior to 11.0. | |
| Modificada | Media (5.4) | 2.2% | — | Rosariosis | 2/5/2023 | 17/6/2026 | RosarioSIS 10.8.4 is vulnerable to CSV injection via the Periods Module. | |
| Modificada | Media (6.5) | 0.54% | — | Rosariosis | 21/4/2023 | 17/6/2026 | Improper Access Control in GitHub repository francoisjacquet/rosariosis prior to 10.9.3. | |
| Modificada | Alta (7.5) | 1.0% | — | Rosariosis | 24/2/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository francoisjacquet/rosariosis prior to 10.8.2. | |
| Modificada | Crítica (9.8) | 0.65% | — | Curiosity Project Curiosity | 8/1/2023 | 17/6/2026 | A vulnerability classified as critical was found in corincerami curiosity. Affected by this vulnerability is an unknown functionality of the file app/controllers/image_controller.rb. The manipulation of the argument sol leads to sql injection. The patch is named d64fddd74ca72714e73f4efe24259ca05c8190eb. It is… | |
| Modificada | Crítica (9.8) | 0.87% | — | Rosariosis | 6/9/2022 | 17/6/2026 | Improper Handling of Length Parameter Inconsistency in GitHub repository francoisjacquet/rosariosis prior to 10.0. | |
| Modificada | Media (5.4) | 0.92% | — | Rosariosis | 1/9/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository francoisjacquet/rosariosis prior to 8.9.3. | |
| Modificada | Crítica (9.1) | 1.9% | — | Rosariosis | 13/6/2022 | 17/6/2026 | SQL Injection in GitHub repository francoisjacquet/rosariosis prior to 9.0. | |
| Modificada | Media (5.4) | 0.89% | — | Rosariosis | 9/6/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository francoisjacquet/rosariosis prior to 9.0.1. | |
| Modificada | Media (5.4) | 0.68% | — | Rosariosis | 8/6/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository francoisjacquet/rosariosis prior to 9.0. |