Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 29 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
49 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.9) | 0.41% | — | Ramon-victor Freegpt-webuiAI | 4/9/2026 | 10/9/2026 | A security flaw has been discovered in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function getJailbreak of the file server/config.py of the component Jailbreak Mode. The manipulation results in race condition. It is possible to launch the attack remotely. The… | |
| Aplazada | Media (5.5) | 0.55% | — | Ramon-victor Freegpt-webuiAI | 4/9/2026 | 11/9/2026 | A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected by this issue is the function getJailbreak of the file server/backend.py of the component Jailbreak Mode. Executing a manipulation can lead to allocation of resources. The attack can be executed remotely. The… | |
| Aplazada | Media (5.5) | 0.66% | — | Ramon-victor Freegpt-webuiAI | 4/9/2026 | 8/9/2026 | A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected is the function _conversation of the file server/backend.py of the component Backend Conversation API. Such manipulation of the argument model leads to missing authentication. The attack… | |
| Aplazada | Media (5.5) | 0.63% | — | Ramon-victor Freegpt-webuiAI | 4/9/2026 | 8/9/2026 | A vulnerability has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function ChatCompletion.create of the file g4f/__init__.py of the component Authentication Check. Such manipulation leads to missing authentication. The attack may be performed from… | |
| Aplazada | Media (6.8) | 0.40% | — | VictoriametricsAI | 20/8/2026 | 18/9/2026 | VictoriaMetrics is a scalable solution for monitoring and managing time series data. Prior to 1.122.25, 1.136.12, and 1.146.0, vmrestore does not validate backup part path components before using lib/backup/actions/restore.go and lib/backup/fslocal/fslocal.go to write restored data below storageDataPath. An attacker… | |
| Aplazada | Baja (2.9) | 0.75% | — | VictoriametricsAI | 15/8/2026 | 20/8/2026 | A vulnerability was found in VictoriaMetrics up to 1.146.0. Impacted is the function requestHandler of the file app/vmauth/main.go of the component VMAuth Authentication Endpoint. Performing a manipulation results in improper restriction of excessive authentication attempts. The attack is possible to be carried out… | |
| Pendiente de análisis | Alta (7.1) | 0.33% | — | Johnsoncontrols Victor WEBAI | 23/7/2026 | 30/7/2026 | Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows capec-233. This issue affects victor Web: before 7.1. | |
| Pendiente de análisis | Alta (8.7) | 0.49% | — | Johnsoncontrols VictorAIJohnsoncontrols Ccure 9000AIJohnsoncontrols Victor Application ServerAI | 23/7/2026 | 6/8/2026 | Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and Johnson Controls Victor Application Server allows capec-586. This issue affects victor: before 8.0; CCure 9000: before 3.2; Victor Application Server: before 4.1. | |
| Pendiente de análisis | Alta (7.2) | 0.39% | — | Johnsoncontrols Ccure 9000AIJohnsoncontrols Victor Application ServerAI | 23/7/2026 | 30/7/2026 | Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery. This issue affects CCure 9000 and victor application server: from 2.9 through 3.0. | |
| Analizada | Media (4.8) | 0.12% | — | Victorkane Salesforce Suite | 10/7/2026 | 6/8/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Salesforce Suite allows Cross Site Request Forgery. This issue affects Salesforce Suite versions: from 0.0.0 to 5.1.3. | |
| Analizada | Alta (8.8) | 0.41% | — | Victoralagwu Cmssite | 12/4/2026 | 17/6/2026 | CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cat_id parameter. Attackers can send GET requests to category.php with malicious cat_id values to extract sensitive database information including usernames and… | |
| Analizada | Media (5.3) | 0.13% | — | Victoralagwu Cmssite | 5/4/2026 | 24/7/2026 | CMSsite 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting crafted pages that submit POST requests to the users.php endpoint with parameters like… | |
| Analizada | Alta (8.8) | 0.40% | — | Victoralagwu Cmssite | 5/4/2026 | 24/7/2026 | CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'post' parameter. Attackers can send GET requests to post.php with malicious 'post' values to extract sensitive database information or perform time-based blind SQL… | |
| Aplazada | Alta (8.1) | 0.58% | — | Magentech VictoAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magentech Victo victo allows PHP Local File Inclusion.This issue affects Victo: from n/a through <= 1.4.16. | |
| Analizada | Alta (8.8) | 0.42% | — | Victor CMS Project Victor CMS | 3/2/2026 | 17/6/2026 | Victor CMS version 1.0 contains a SQL injection vulnerability in the 'post' parameter on post.php that allows remote attackers to manipulate database queries. Attackers can exploit this vulnerability by sending crafted UNION SELECT payloads to extract database information through boolean-based, error-based, and… | |
| Analizada | Alta (8.6) | 0.55% | — | Victor CMS Project Victor CMS | 3/2/2026 | 17/6/2026 | Victor CMS 1.0 contains an authenticated file upload vulnerability that allows administrators to upload PHP files with arbitrary content through the user_image parameter. Attackers can upload a malicious PHP shell to the /img/ directory and execute system commands by accessing the uploaded file with a 'cmd' parameter. | |
| Analizada | Media (5.1) | 0.28% | — | Victor CMS Project Victor CMS | 3/2/2026 | 17/6/2026 | Victor CMS 1.0 contains a stored cross-site scripting vulnerability in the 'comment_author' POST parameter that allows attackers to inject malicious scripts. Attackers can submit crafted JavaScript payloads through the comment submission form to execute arbitrary code in victim browsers. | |
| Analizada | Alta (8.7) | 0.69% | — | Victor CMS Project Victor CMS | 27/1/2026 | 17/6/2026 | Victor CMS 1.0 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the profile image upload feature. Attackers can upload a PHP shell to the /img directory and execute system commands by accessing the uploaded file via web browser. | |
| Aplazada | Baja (2.7) | 0.34% | — | VictoriametricsAI | 25/11/2025 | 17/6/2026 | VictoriaMetrics is a scalable solution for monitoring and managing time series data. In versions from 1.0.0 to before 1.110.23, from 1.111.0 to before 1.122.8, and from 1.123.0 to before 1.129.1, affected versions are vulnerable to DoS attacks because the snappy decoder ignored VictoriaMetrics request size limits… | |
| Aplazada | Crítica (9.8) | 0.47% | — | Victorthemes SeilAI | 6/11/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in VictorThemes Seil seil allows Object Injection.This issue affects Seil: from n/a through <= 1.7.1. | |
| Aplazada | Media (4.3) | 0.51% | — | Uriahs Victor PrintusAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Uriahs Victor Printus printus-cloud-printing-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Printus: from n/a through <= 1.2.6. | |
| Aplazada | Media (6.5) | 0.22% | — | Victortihai Morningtime LiteAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in victortihai MorningTime Lite morningtime-lite allows Stored XSS.This issue affects MorningTime Lite: from n/a through <= 1.3.2. | |
| Aplazada | Alta (7.1) | 0.14% | — | Victoracano CazambaAI | 27/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in victoracano Cazamba cazamba allows Reflected XSS.This issue affects Cazamba: from n/a through <= 1.2. | |
| Modificada | Media (4.3) | 0.22% | — | Victorfreitas Wpupper Share Buttons | 21/2/2025 | 17/6/2026 | The WPUpper Share Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.51. This is due to missing or incorrect nonce validation on the 'save_custom_css_request' function. This makes it possible for unauthenticated attackers to inject custom CSS to modify a… | |
| Aplazada | Alta (7.1) | 0.14% | — | Victor Barkalov Custom Links ON Admin Dashboard ToolbarAI | 7/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Victor Barkalov Custom Links On Admin Dashboard Toolbar customize-wpadmin allows Stored XSS.This issue affects Custom Links On Admin Dashboard Toolbar: from n/a through <= 3.3. |