Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3059▲ 556 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

269 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.3)0.54%—Astrojs NetlifyAI30/9/202630/9/2026
Astro is a web framework for content-driven websites. From 5.2.0 until 8.2.4, the @astrojs/netlify adapter generates regular expressions for Netlify Image CDN remote-image allowlists without anchoring them to the beginning of the URL. Because Netlify evaluates these expressions with RegExp.test(), an allowed origin…
AplazadaMedia (5.3)0.30%—Iflytek Astron-agentAI23/9/202623/9/2026
A security vulnerability has been detected in iFlytek astron-agent up to 1.0.6. Affected by this vulnerability is the function UrlCheckTool.checkUrl of the component debugToolV2 API endpoint. The manipulation of the argument endPoint leads to server-side request forgery. The attack can be initiated remotely. Upgrading…
AplazadaMedia (5.3)0.23%—Iflytek Astron-agentAI23/9/202625/9/2026
A weakness has been identified in iFlytek astron-agent up to 1.0.7. Affected is an unknown function of the file console/backend/commons/src/main/resources/mapper/ChatBotMarketMapper.xml of the component getBotList API endpoint. Executing a manipulation of the argument sortDirection can lead to sql injection. It is…
AplazadaBaja (2)0.40%—Codeastro QR Code Attendance Management SystemAI20/9/202621/9/2026
A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0. This affects the function Save of the file app/Controllers/UserController.php. The manipulation of the argument role_id results in improper privilege management. The attack can be executed remotely. The exploit is now public and may be…
AplazadaAlta (7.5)0.24%—Gastromenm WEB PanelAI4/9/20268/9/2026
Observable response discrepancy vulnerability in GastroMenum GastroMenum Web Panel allows Account Footprinting. This issue affects GastroMenum Web Panel: before 31.08.2026.
AplazadaMedia (4.3)0.16%—Gastromenum Ticket AND QR Menu SystemAI4/9/20268/9/2026
Missing Authorization vulnerability in Gastromenum Gastromenum Ticket and QR Menu System allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Gastromenum Ticket and QR Menu System: before 2026.08.31.
AplazadaMedia (5.4)0.13%—Gastromenum Ticket AND QR Menu SystemAI4/9/20268/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gastromenum Gastromenum Ticket and QR Menu System allows Stored XSS. This issue affects Gastromenum Ticket and QR Menu System: before 2026.08.31.
AplazadaMedia (6.3)0.71%—AstroAI2/9/20269/9/2026
Astro is a web framework for content-driven websites. Prior to 7.2.4, Astro stripped a configured non-root base path from request pathnames using a string-prefix check without verifying a path-segment boundary. With base "/app", a request to "/appX/admin" resolved internally to the protected "/admin" route while…
AplazadaAlta (8.6)0.45%—Iflytek Astron-agentAI29/8/202610/9/2026
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow identifiers and overwrite other tenants' workflows or copy private workflows to read their definitions.
AplazadaBaja (2.1)0.37%—Codeastro Online JOB PortalAI21/8/202626/8/2026
A vulnerability was identified in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /users/update-profile.php. The manipulation of the argument Name leads to unrestricted upload. The attack can be initiated remotely. The exploit is publicly available and might be…
AplazadaMedia (5.5)0.43%—Codeastro Apartment Visitor Management SystemAI20/8/202624/8/2026
A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file password-recovery.php. The manipulation of the argument email leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly…
AplazadaMedia (5.5)0.43%—Codeastro Apartment Visitor Management SystemAI20/8/202625/8/2026
A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. Affected is an unknown function of the file /apartment-visitor/forgotpw.php. Executing a manipulation of the argument secode can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and…
AplazadaMedia (6.5)0.38%—Astro Vercel AdapterAI17/8/20269/9/2026
Astro is a web framework for content-driven websites. From 10.0.3 until 11.0.3, the Astro Vercel adapter in packages/integrations/vercel/src/serverless/entrypoint.ts accepts x_astro_path for the public /_isr function based only on the x-vercel-isr header, allowing unauthenticated GET requests to render routes…
AplazadaMedia (4.3)0.18%—Astro Booking EngineAI14/8/202629/9/2026
The Astro Booking Engine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.0. This is due to missing nonce validation on the options deletion functionality. This makes it possible for unauthenticated attackers to delete all plugin settings via a forged request…
AplazadaBaja (3.7)0.27%—AstroAINetlifyAI12/8/20269/9/2026
Astro is a web framework for content-driven websites. Prior to 8.1.2, the Astro Netlify adapter converts each image.remotePatterns entry into a regular expression written to .netlify/v1/config.json under images.remote_images for Netlify's Image CDN allowlist. In packages/integrations/netlify/src/index.ts,…
AplazadaMedia (5.1)0.26%—AstroAI12/8/20269/9/2026
Astro is a web framework for content-driven websites. From 7.0.0 until 7.0.6, the composable astro/hono pipeline installs security.checkOrigin only through the middleware() primitive, while actions() and pages() can dispatch to user code independently. Mounting actions() before middleware(), as in the…
AplazadaMedia (5.3)0.55%—AstroAI12/8/20269/9/2026
Astro is a web framework for content-driven websites. From 2.9.0 until 7.1.0, Astro's server-side View Transition CSS generator interpolates animation properties into an inline style element without escaping them for CSS and HTML contexts. An attacker-controlled View Transition animation value such as duration can…
AplazadaCrítica (9.8)0.47%—Codeastro Membership Management SystemAI30/7/202631/7/2026
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.
AplazadaCrítica (9.8)0.47%—Codeastro Membership Management SystemAI30/7/20263/8/2026
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1.
AplazadaCrítica (9.8)0.47%—Codeastro Membership Management SystemAI30/7/202631/7/2026
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1.
AplazadaCrítica (9.8)0.47%—Codeastro Membership Management SystemAI30/7/20261/10/2026
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType.
AplazadaCrítica (9.8)0.47%—Codeastro Membership Management SystemAI30/7/20261/10/2026
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id.
AplazadaCrítica (9.8)0.47%—Codeastro Membership Management SystemAI30/7/20261/10/2026
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.
AplazadaMedia (4.3)0.37%—AstroAI27/7/202628/7/2026
Astro is a web framework for content-driven websites. In versions 1.0.0 through 4.0.18, the source.title and enclosure.type item fields in packages/astro-rss/src/index.ts are interpolated directly into XML template strings without XML-character escaping before being parsed by fast-xml-parser. Both fields are validated…
AplazadaMedia (5.1)0.54%—AstroAI27/7/202628/7/2026
Astro is a web framework for content-driven websites. Versions prior to 7.0.6 are vulnerable to XSS through unescaped spread attribute names in renderHTMLElement. The fix for CVE-2026-54298 (GHSA-jrpj-wcv7-9fh9) added an INVALID_ATTR_NAME_CHAR guard to addAttribute() so that spread-prop attribute names containing "'…