Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.55% | — | Timgreen Python Book | 15/11/2024 | 17/6/2026 | python_book V1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter. | |
| Analizada | Crítica (9.8) | 0.99% | — | Timgreen Python Book | 15/11/2024 | 17/6/2026 | The user avatar upload function in python_book V1.0 has an arbitrary file upload vulnerability. | |
| Analizada | Media (5.1) | 0.39% | — | Timgeyssens Ui-o-matic | 12/11/2024 | 17/6/2026 | A vulnerability has been found in TimGeyssens UIOMatic 5 and classified as critical. This vulnerability affects unknown code of the file /src/UIOMatic/wwwroot/backoffice/resources/uioMaticObject.r. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Crítica (9.3) | 0.26% | — | Timgreen Dingfanzu CMS | 8/11/2024 | 17/6/2026 | dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=addAdmin. | |
| Analizada | Media (6.3) | 0.19% | — | Timgreen Dingfanzu CMS | 28/10/2024 | 17/6/2026 | dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=editAdmin&id=17 | |
| Analizada | Media (6.3) | 0.19% | — | Timgreen Dingfanzu CMS | 28/10/2024 | 17/6/2026 | dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=delAdmin&id=17 | |
| Analizada | Media (6.1) | 0.28% | — | Timgreen Dingfanzu CMS | 16/10/2024 | 17/6/2026 | dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the addPro parameter of the component doAdminAction.php which allows a remote attacker to execute arbitrary code | |
| Analizada | Media (4.7) | 0.21% | — | Timgreen Dingfanzu CMS | 25/9/2024 | 17/6/2026 | dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/doAdminAction.php?act=delCate&id=31 | |
| Analizada | Media (6.3) | 0.19% | — | Timgreen Dingfanzu CMS | 25/9/2024 | 17/6/2026 | dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=addCate | |
| Modificada | Alta (7.5) | 1.1% | — | Hzeller Timg | 1/9/2023 | 17/6/2026 | Buffer Overflow vulnerability in hzeller timg v.1.5.1 and before allows a remote attacker to cause a denial of service via the 0x61200000045c address. | |
| Modificada | Media (5.5) | 0.27% | — | Hzeller Timg | 31/10/2022 | 17/6/2026 | timg v1.4.4 was discovered to contain a memory leak via the function timg::QueryBackgroundColor() at /timg/src/term-query.cc. | |
| Modificada | Crítica (9.8) | 1.5% | — | Catimg Project Catimg | 9/7/2018 | 17/6/2026 | A heap-based buffer overflow exists in stbi__bmp_load_cont in stb_image.h in catimg 2.4.0. |