Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
164 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.40% | — | LubeloggerAI | 18/9/2026 | 30/9/2026 | LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, an authenticated user could submit caller-controlled recordIds to the DuplicateRecordsToOtherVehicles endpoint while naming destination vehicleIds the user could edit. The endpoint authorized the… | |
| Aplazada | Alta (8.1) | 0.51% | — | LubeloggerAI | 18/9/2026 | 24/9/2026 | LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, authenticated non-administrative users could reach HandleTranslationFileUpload and influence the name passed from Controllers/FilesController.cs to RenameFile in Helper/FileHelper.cs. RenameFile… | |
| Aplazada | Crítica (9.3) | 0.76% | — | WavelogAI | 17/9/2026 | 24/9/2026 | Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /install/includes/interface_assets/triggers.php after installation without an installation lock or permission check. Unsanitized input reaches write_config() and write_configfile() in… | |
| Aplazada | Baja (1.9) | 1.1% | — | Release-it Conventional-changelogAI | 23/7/2026 | 27/7/2026 | A security vulnerability has been detected in release-it conventional-changelog up to 11.0.1. This affects the function writeChangelog of the file index.js of the component Changelog File Handler. Such manipulation of the argument infile leads to os command injection. The attack must be carried out locally. The… | |
| Aplazada | Crítica (9.3) | 0.45% | — | Melograno Venture Studio AmeliaAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Melograno Venture Studio Amelia ameliabooking allows Blind SQL Injection.This issue affects Amelia: from n/a through <= 2.4.2. | |
| Aplazada | Media (5.3) | 0.26% | — | Agilelogix Post TimelineAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Agile Logix Post Timeline post-timeline allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Timeline: from n/a through <= 2.4.1. | |
| Aplazada | Alta (8.8) | 0.32% | — | Iscripts ReservelogicAI | 12/3/2026 | 17/6/2026 | iScripts ReserveLogic contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the jqSearchDestination parameter. Attackers can send POST requests to the search endpoint with crafted SQL payloads to extract sensitive database information. | |
| Aplazada | Alta (8.1) | 0.47% | — | Themelogi NavianAI | 8/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in THEMELOGI Navian navian allows PHP Local File Inclusion.This issue affects Navian: from n/a through <= 1.5.4. | |
| Analizada | Media (6.1) | 0.27% | — | Realtimelogic Fuguhub | 22/12/2025 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability exists in FuguHub 8.1 when serving SVG files through the /fs/ file manager interface. FuguHub does not sanitize or restrict script execution inside SVG content. When a victim opens a crafted SVG containing an inline <script> element, the browser executes the… | |
| Aplazada | Media (6.4) | 0.22% | — | Divelogs WidgetAI | 12/12/2025 | 17/6/2026 | The Divelogs Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'latestdive' shortcode in all versions up to, and including, 1.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.5) | 0.30% | — | Agilelogix Store LocatorAI | 9/12/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agile Logix Store Locator WordPress agile-store-locator allows Blind SQL Injection.This issue affects Store Locator WordPress: from n/a through <= 1.6.2. | |
| Analizada | Crítica (9.3) | 0.23% | — | Onelogin Ruby-saml | 9/12/2025 | 17/6/2026 | The ruby-saml library implements the client side of an SAML authorization. Versions up to and including 1.12.4, are vulnerable to authentication bypass through the libxml2 canonicalization process used by Nokogiri for document transformation, which allows an attacker to execute a Signature Wrapping attack. When… | |
| Analizada | Crítica (9.3) | 0.39% | — | Onelogin Ruby-saml | 9/12/2025 | 17/6/2026 | The ruby-saml library is for implementing the client side of a SAML authorization. ruby-saml versions up to and including 1.12.4 contain an authentication bypass vulnerability due to an incomplete fix for CVE-2025-25292. ReXML and Nokogiri parse XML differently, generating entirely different document structures from… | |
| Analizada | Baja (2.1) | 0.31% | — | Carmelogarcia Employee Profile Management System | 8/12/2025 | 17/6/2026 | A flaw has been found in code-projects Employee Profile Management System 1.0. Affected is an unknown function of the file /print_personnel_report.php. This manipulation of the argument per_id causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. | |
| Modificada | Baja (2.1) | 0.38% | — | Carmelogarcia Employee Profile Management System | 7/12/2025 | 17/6/2026 | A security flaw has been discovered in code-projects Employee Profile Management System 1.0. Impacted is an unknown function of the file /profiling/add_file_query.php. The manipulation of the argument per_file results in unrestricted upload. The attack may be launched remotely. The exploit has been released to the… | |
| Analizada | Baja (2) | 0.26% | — | Carmelogarcia Employee Profile Management System | 7/12/2025 | 17/6/2026 | A vulnerability was identified in code-projects Employee Profile Management System 1.0. This issue affects some unknown processing of the file /view_personnel.php. The manipulation of the argument per_address/dr_school/other_school leads to cross site scripting. The attack may be initiated remotely. The exploit is… | |
| Modificada | Baja (2.1) | 0.35% | — | Carmelogarcia Employee Profile Management System | 7/12/2025 | 17/6/2026 | A vulnerability was determined in code-projects Employee Profile Management System 1.0. This vulnerability affects unknown code of the file /view_personnel.php. Executing a manipulation of the argument per_id can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and… | |
| Analizada | Baja (2.1) | 0.32% | — | Carmelogarcia Courier Management System | 19/11/2025 | 17/6/2026 | A weakness has been identified in code-projects Courier Management System 1.0. This affects an unknown function of the file /add-office.php. This manipulation of the argument OfficeName causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited. | |
| Analizada | Baja (2.1) | 0.37% | — | Carmelogarcia Courier Management System | 17/11/2025 | 17/6/2026 | A vulnerability was determined in code-projects Courier Management System 1.0. Affected by this issue is some unknown functionality of the file /search-edit.php. This manipulation of the argument Consignment causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be… | |
| Analizada | Baja (2) | 0.38% | — | Carmelogarcia Courier Management System | 17/11/2025 | 17/6/2026 | A vulnerability was identified in code-projects Courier Management System 1.0. This affects an unknown part of the file /add-new-officer.php. Such manipulation of the argument ManagerName leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used. | |
| Analizada | Alta (8.7) | 0.38% | — | Elog Project Elog | 31/10/2025 | 17/6/2026 | ELOG allows an authenticated user to modify another user's profile. An attacker can edit a target user's email address, then request a password reset, and take control of the target account. By default, ELOG is not configured to allow self-registration. | |
| Modificada | Alta (7.1) | 0.32% | — | Elog Project Elog | 31/10/2025 | 17/6/2026 | ELOG allows an authenticated user to modify or overwrite the configuration file, resulting in denial of service. If the execute facility is specifically enabled with the "-x" command line flag, attackers could execute OS commands on the host machine. By default, ELOG is not configured to allow shell commands or… | |
| Analizada | Alta (8.6) | 0.32% | — | Elog Project Elog | 31/10/2025 | 17/6/2026 | ELOG allows an authenticated user to upload arbitrary HTML files. The HTML content is executed in the context of other users when they open the file. Because ELOG includes usernames and password hashes in certain HTTP requests, an attacker can obtain the target's credentials and replay them or crack the password hash… | |
| Analizada | Media (5.5) | 0.42% | — | Carmelogarcia Courier Management System | 27/10/2025 | 17/6/2026 | A vulnerability was identified in code-projects Courier Management System 1.0. This impacts an unknown function of the file /courier/edit-courier.php. The manipulation of the argument OfficeName leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be… | |
| Analizada | Baja (2.1) | 0.40% | — | Carmelogarcia Courier Management System | 9/10/2025 | 17/6/2026 | A weakness has been identified in code-projects Courier Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /add-courier.php. Executing manipulation of the argument Shippername can lead to sql injection. The attack can be launched remotely. The exploit has been made available… |