Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

24 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.3)0.24%—Zserge JsmnAI24/9/202625/9/2026
zserge jsmn commit 25647e6 is vulnerable to Buffer Overflow in example/jsondump.c dump().
AplazadaCrítica (9.3)0.40%—Sergey Aiwu Ai-copilot-content-generatorAI13/7/202613/7/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sergey AIWU ai-copilot-content-generator allows Blind SQL Injection.This issue affects AIWU: from n/a through <= 1.5.4.
AplazadaCrítica (9.8)0.48%—Sergey AiwuAI1/6/202622/7/2026
Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation. This issue affects AIWU: from n/a through 1.4.17.
AplazadaMedia (5.5)0.72%—Serge-chat SergeAI20/4/202617/6/2026
A weakness has been identified in serge-chat serge up to 1.4TB. The impacted element is the function download_model/delete_model of the file api/src/serge/routers/model.py of the component Model API Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched remotely. The exploit…
AnalizadaMedia (5.1)0.27%—Sergestec Exito16/10/202517/6/2026
Stored Cross-Site Scripting (XSS) in Sergestec's Exito v8.0, consisting of a stored XSS due to a lack of proper validation of user input by sending a POST request using the 'obs' parameter in '/admin/index.php?action=product_update'. This vulnerability could allow a remote user to send a specially crafted query to an…
AnalizadaAlta (7.1)0.34%—Sergestec Exito16/10/202517/6/2026
Insecure direct object reference (IDOR) vulnerability in Sergestec's Exito v8.0. This vulnerability allows an attacker to access data belonging to other customers through the 'id' parameter in '/admin/ticket_a4.php'.
AplazadaCrítica (9.3)0.38%—Sergestec SistickAI16/10/202517/6/2026
SQL injection in Sergestec's SISTICK v7.2. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'id' parameter in '/index.php?view=ticket_detail'.
AnalizadaCrítica (9.3)0.46%—Sergestec Exito16/10/202530/9/2026
SQL injection in Sergestec's Exito v8.0. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'cat' parameter in '/public.php'.
AplazadaMedia (6.1)0.39%—SergeAI20/3/202517/6/2026
A stored cross-site scripting (XSS) vulnerability exists in Serge version 0.9.0. The vulnerability is due to improper neutralization of input during web page generation in the chat prompt. An attacker can exploit this vulnerability by sending a crafted message containing malicious HTML/JavaScript code, which will be…
ModificadaAlta (10)2.7%—Serge Gebhardt DIR Listing22/7/201016/6/2026
Directory traversal vulnerability in the Directory Listing (dir_listing) extension 1.1.0 and earlier for TYPO3 allows remote attackers to have an unspecified impact via unknown vectors.
ModificadaMedia (5)1.2%—Sergey Lyubka Mongoose31/12/200916/6/2026
Mongoose 2.8.0 and earlier allows remote attackers to obtain the source code for a web page by appending ::$DATA to the URI.
ModificadaMedia (4)2.3%—Sergey Lyubka Mongoose21/4/200916/6/2026
Directory traversal vulnerability in Mongoose 2.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
ModificadaMedia (5)7.3%—Sergey Lyubka Simple Httpd13/12/200716/6/2026
Sergey Lyubka Simple HTTPD (shttpd) 1.3 on Windows allows remote attackers to cause a denial of service via a request that includes an MS-DOS device name, as demonstrated by the /aux URI.
ModificadaMedia (5)8.4%—Sergey Lyubka Simple Httpd26/6/200716/6/2026
Sergey Lyubka Simple HTTPD (shttpd) 1.38 allows remote attackers to obtain sensitive information (script source code) via a URL with a trailing encoded space (%20).
ModificadaMedia (6.8)4.4%—Sergey Oblomov ISO Wincmd31/12/200616/6/2026
Multiple stack-based buffer overflows in the (1) LoadTree, (2) ReadHeader, and (3) LoadXBOXTree functions in the ISO (iso_wincmd) plugin 1.7.3.3 and earlier for Total Commander allow user-assisted remote attackers to execute arbitrary code via a long pathname in an ISO image.
ModificadaAlta (7.5)3.8%—Sergey Korostel PHP Upload Center7/12/200616/6/2026
PHP remote file inclusion vulnerability in activate.php in PHP Upload Center 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the footerpage parameter.
ModificadaAlta (7.5)64%—Sergey Lyubka Simple Httpd10/10/200616/6/2026
Stack-based buffer overflow in Sergey Lyubka Simple HTTPD (shttpd) 1.34 allows remote attackers to execute arbitrary code via a long URI.
ModificadaMedia (4.3)3.0%—Serge REY Gtd-php29/3/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Serge Rey gtd-php (aka Getting Things Done) 0.5 allow remote attackers to inject arbitrary web script or HTML via the Description field in (1) newProject.php, (2) newList.php, and (3) newWaitingOn.php; the Title field in (4) newProject.php, (5) newList.php, (6)…
ModificadaMedia (5)1.5%—Sergey Korostel PHP Upload Center14/3/200616/6/2026
PHP Upload Center stores password hashes under the web root with insufficient access control, which allows remote attackers to download each password hash via a direct request for the upload/users/[USERNAME] file.
ModificadaAlta (7.5)2.0%—Sergey Korostel PHP Upload Center14/3/200616/6/2026
Sergey Korostel PHP Upload Center allows remote attackers to execute arbitrary PHP code by uploading a file whose name ends in a .php.li extension, which can be accessed from the upload directory.
ModificadaMedia (5)3.1%—Sergey Korostel PHP Upload CenterAI1/12/200516/6/2026
Directory traversal vulnerability in index.php in PHP Upload Center allows remote attackers to read arbitrary files via "../" sequences in the filename parameter.
ModificadaAlta (7.5)1.5%—Sergey Kiselev Sgallery2/5/200516/6/2026
SQL injection vulnerability in imageview.php for SGallery 1.01 allows remote attackers to execute arbitrary SQL commands via the (1) idalbum or (2) idimage parameters.
ModificadaMedia (5)1.6%—Sergey Kiselev Sgallery2/5/200516/6/2026
imageview.php in SGallery 1.01 allows remote attackers to obtain sensitive information via an HTTP request with (1) idalbum and (2) idimage unset, which reveals the installation path in an error message for the sql_fetch_row function.
ModificadaAlta (7.5)2.0%—Sergey Kiselev Sgallery12/1/200516/6/2026
PHP remote file inclusion vulnerability in SGallery 1.01 allows local and possibly remote attackers to execute arbitrary PHP code by modifying the DOCUMENT_ROOT parameter to reference a URL on a remote web server that contains (1) config.php or (2) sql_layer.php.