Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.3) | 0.24% | — | Zserge JsmnAI | 24/9/2026 | 25/9/2026 | zserge jsmn commit 25647e6 is vulnerable to Buffer Overflow in example/jsondump.c dump(). | |
| Aplazada | Crítica (9.3) | 0.40% | — | Sergey Aiwu Ai-copilot-content-generatorAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sergey AIWU ai-copilot-content-generator allows Blind SQL Injection.This issue affects AIWU: from n/a through <= 1.5.4. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Sergey AiwuAI | 1/6/2026 | 22/7/2026 | Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation. This issue affects AIWU: from n/a through 1.4.17. | |
| Aplazada | Media (5.5) | 0.72% | — | Serge-chat SergeAI | 20/4/2026 | 17/6/2026 | A weakness has been identified in serge-chat serge up to 1.4TB. The impacted element is the function download_model/delete_model of the file api/src/serge/routers/model.py of the component Model API Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched remotely. The exploit… | |
| Analizada | Media (5.1) | 0.27% | — | Sergestec Exito | 16/10/2025 | 17/6/2026 | Stored Cross-Site Scripting (XSS) in Sergestec's Exito v8.0, consisting of a stored XSS due to a lack of proper validation of user input by sending a POST request using the 'obs' parameter in '/admin/index.php?action=product_update'. This vulnerability could allow a remote user to send a specially crafted query to an… | |
| Analizada | Alta (7.1) | 0.34% | — | Sergestec Exito | 16/10/2025 | 17/6/2026 | Insecure direct object reference (IDOR) vulnerability in Sergestec's Exito v8.0. This vulnerability allows an attacker to access data belonging to other customers through the 'id' parameter in '/admin/ticket_a4.php'. | |
| Aplazada | Crítica (9.3) | 0.38% | — | Sergestec SistickAI | 16/10/2025 | 17/6/2026 | SQL injection in Sergestec's SISTICK v7.2. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'id' parameter in '/index.php?view=ticket_detail'. | |
| Analizada | Crítica (9.3) | 0.46% | — | Sergestec Exito | 16/10/2025 | 30/9/2026 | SQL injection in Sergestec's Exito v8.0. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'cat' parameter in '/public.php'. | |
| Aplazada | Media (6.1) | 0.39% | — | SergeAI | 20/3/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in Serge version 0.9.0. The vulnerability is due to improper neutralization of input during web page generation in the chat prompt. An attacker can exploit this vulnerability by sending a crafted message containing malicious HTML/JavaScript code, which will be… | |
| Modificada | Alta (10) | 2.7% | — | Serge Gebhardt DIR Listing | 22/7/2010 | 16/6/2026 | Directory traversal vulnerability in the Directory Listing (dir_listing) extension 1.1.0 and earlier for TYPO3 allows remote attackers to have an unspecified impact via unknown vectors. | |
| Modificada | Media (5) | 1.2% | — | Sergey Lyubka Mongoose | 31/12/2009 | 16/6/2026 | Mongoose 2.8.0 and earlier allows remote attackers to obtain the source code for a web page by appending ::$DATA to the URI. | |
| Modificada | Media (4) | 2.3% | — | Sergey Lyubka Mongoose | 21/4/2009 | 16/6/2026 | Directory traversal vulnerability in Mongoose 2.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI. | |
| Modificada | Media (5) | 7.3% | — | Sergey Lyubka Simple Httpd | 13/12/2007 | 16/6/2026 | Sergey Lyubka Simple HTTPD (shttpd) 1.3 on Windows allows remote attackers to cause a denial of service via a request that includes an MS-DOS device name, as demonstrated by the /aux URI. | |
| Modificada | Media (5) | 8.4% | — | Sergey Lyubka Simple Httpd | 26/6/2007 | 16/6/2026 | Sergey Lyubka Simple HTTPD (shttpd) 1.38 allows remote attackers to obtain sensitive information (script source code) via a URL with a trailing encoded space (%20). | |
| Modificada | Media (6.8) | 4.4% | — | Sergey Oblomov ISO Wincmd | 31/12/2006 | 16/6/2026 | Multiple stack-based buffer overflows in the (1) LoadTree, (2) ReadHeader, and (3) LoadXBOXTree functions in the ISO (iso_wincmd) plugin 1.7.3.3 and earlier for Total Commander allow user-assisted remote attackers to execute arbitrary code via a long pathname in an ISO image. | |
| Modificada | Alta (7.5) | 3.8% | — | Sergey Korostel PHP Upload Center | 7/12/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in activate.php in PHP Upload Center 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the footerpage parameter. | |
| Modificada | Alta (7.5) | 64% | — | Sergey Lyubka Simple Httpd | 10/10/2006 | 16/6/2026 | Stack-based buffer overflow in Sergey Lyubka Simple HTTPD (shttpd) 1.34 allows remote attackers to execute arbitrary code via a long URI. | |
| Modificada | Media (4.3) | 3.0% | — | Serge REY Gtd-php | 29/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Serge Rey gtd-php (aka Getting Things Done) 0.5 allow remote attackers to inject arbitrary web script or HTML via the Description field in (1) newProject.php, (2) newList.php, and (3) newWaitingOn.php; the Title field in (4) newProject.php, (5) newList.php, (6)… | |
| Modificada | Media (5) | 1.5% | — | Sergey Korostel PHP Upload Center | 14/3/2006 | 16/6/2026 | PHP Upload Center stores password hashes under the web root with insufficient access control, which allows remote attackers to download each password hash via a direct request for the upload/users/[USERNAME] file. | |
| Modificada | Alta (7.5) | 2.0% | — | Sergey Korostel PHP Upload Center | 14/3/2006 | 16/6/2026 | Sergey Korostel PHP Upload Center allows remote attackers to execute arbitrary PHP code by uploading a file whose name ends in a .php.li extension, which can be accessed from the upload directory. | |
| Modificada | Media (5) | 3.1% | — | Sergey Korostel PHP Upload CenterAI | 1/12/2005 | 16/6/2026 | Directory traversal vulnerability in index.php in PHP Upload Center allows remote attackers to read arbitrary files via "../" sequences in the filename parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Sergey Kiselev Sgallery | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in imageview.php for SGallery 1.01 allows remote attackers to execute arbitrary SQL commands via the (1) idalbum or (2) idimage parameters. | |
| Modificada | Media (5) | 1.6% | — | Sergey Kiselev Sgallery | 2/5/2005 | 16/6/2026 | imageview.php in SGallery 1.01 allows remote attackers to obtain sensitive information via an HTTP request with (1) idalbum and (2) idimage unset, which reveals the installation path in an error message for the sql_fetch_row function. | |
| Modificada | Alta (7.5) | 2.0% | — | Sergey Kiselev Sgallery | 12/1/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in SGallery 1.01 allows local and possibly remote attackers to execute arbitrary PHP code by modifying the DOCUMENT_ROOT parameter to reference a URL on a remote web server that contains (1) config.php or (2) sql_layer.php. |