Vulnerabilidades CVE

A continuación la lista de las últimas vulnerabilidades publicadas por el instituto NIST:

CVE ID Publicado Severidad CVSS Descripción
CVE-2025-46257 2025-06-05 MEDIUM 4.3 Cross-Site Request Forgery (CSRF) vulnerability in BdThemes Element Pack Pro allows Cross Site Request Forgery.This issue affects Element Pack Pro:…
CVE-2025-5670 2025-06-05 MEDIUM 6.3 A vulnerability, which was classified as critical, has been found in PHPGurukul Medical Card Generation System 1.0. This issue affects…
CVE-2025-5669 2025-06-05 MEDIUM 6.3 A vulnerability classified as critical was found in PHPGurukul Medical Card Generation System 1.0. This vulnerability affects unknown code of…
CVE-2025-5668 2025-06-05 MEDIUM 6.3 A vulnerability classified as critical has been found in PHPGurukul Medical Card Generation System 1.0. This affects an unknown part…
CVE-2025-49009 2025-06-05 MEDIUM 6.2 Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in versions prior to 1.50.8…
CVE-2025-48493 2025-06-05 N/A 0.0 The Yii 2 Redis extension provides the redis key-value store support for the Yii framework 2.0. On failing connection, the…
CVE-2025-5667 2025-06-05 HIGH 7.3 A vulnerability was found in FreeFloat FTP Server 1.0. It has been rated as critical. Affected by this issue is…
CVE-2025-5666 2025-06-05 HIGH 7.3 A vulnerability was found in FreeFloat FTP Server 1.0. It has been declared as critical. Affected by this vulnerability is…
CVE-2025-5665 2025-06-05 HIGH 7.3 A vulnerability was found in FreeFloat FTP Server 1.0. It has been classified as critical. Affected is an unknown function…
CVE-2025-5664 2025-06-05 HIGH 7.3 A vulnerability was found in FreeFloat FTP Server 1.0 and classified as critical. This issue affects some unknown processing of…
CVE-2025-5663 2025-06-05 HIGH 7.3 A vulnerability has been found in PHPGurukul Auto Taxi Stand Management System 1.0 and classified as critical. This vulnerability affects…
CVE-2025-5661 2025-06-05 LOW 2.4 A vulnerability, which was classified as problematic, was found in code-projects Traffic Offense Reporting System 1.0. This affects an unknown…
CVE-2025-5382 2025-06-05 MEDIUM 6.8 Improper access control in users MFA feature in Devolutions Server 2025.1.7.0 and earlier allows a user with user management permission…
CVE-2025-47827 2025-06-05 N/A 0.0 In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately,…
CVE-2025-3768 2025-06-05 MEDIUM 5.0 Improper access control in Tor network blocking feature in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass…
CVE-2025-30084 2025-06-05 N/A 0.0 A stored XSS vulnerability in RSMail! component 1.19.20 - 1.22.26 for Joomla was discovered. The issue occurs within the dashboard…
CVE-2025-27754 2025-06-05 MEDIUM 6.5 A stored XSS vulnerability in RSBlog! component 1.11.6 - 1.14.4 for Joomla was discovered. The vulnerability allows authenticated users to…
CVE-2025-27753 2025-06-05 N/A 0.0 A SQLi vulnerability in RSMediaGallery component 1.7.4 - 2.1.6 for Joomla was discovered. The vulnerability is due to the use…
CVE-2025-27445 2025-06-05 N/A 0.0 A path traversal vulnerability in RSFirewall component 2.9.7 - 3.1.5 for Joomla was discovered. This vulnerability allows authenticated users to…
CVE-2025-0691 2025-06-05 MEDIUM 5.0 Improper access control in permissions component in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the "Edit…
CVE-2025-5660 2025-06-05 MEDIUM 6.3 A vulnerability, which was classified as critical, has been found in PHPGurukul Complaint Management System 2.0. Affected by this issue…
CVE-2025-5659 2025-06-05 MEDIUM 6.3 A vulnerability classified as critical was found in PHPGurukul Complaint Management System 2.0. Affected by this vulnerability is an unknown…
CVE-2025-5658 2025-06-05 MEDIUM 6.3 A vulnerability classified as critical has been found in PHPGurukul Complaint Management System 2.0. Affected is an unknown function of…
CVE-2025-5701 2025-06-05 CRITICAL 9.8 The HyperComments plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to…
CVE-2025-5657 2025-06-05 MEDIUM 6.3 A vulnerability was found in PHPGurukul Complaint Management System 2.0. It has been rated as critical. This issue affects some…
CVE-2025-5656 2025-06-05 MEDIUM 6.3 A vulnerability was found in PHPGurukul Complaint Management System 2.0. It has been declared as critical. This vulnerability affects unknown…
CVE-2025-5341 2025-06-05 MEDIUM 6.4 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site…
CVE-2025-5655 2025-06-05 MEDIUM 6.3 A vulnerability was found in PHPGurukul Complaint Management System 2.0. It has been classified as critical. This affects an unknown…
CVE-2025-5654 2025-06-05 MEDIUM 6.3 A vulnerability was found in PHPGurukul Complaint Management System 2.0 and classified as critical. Affected by this issue is some…
CVE-2025-5653 2025-06-05 MEDIUM 6.3 A vulnerability has been found in PHPGurukul Complaint Management System 2.0 and classified as critical. Affected by this vulnerability is…
CVE-2025-5652 2025-06-05 MEDIUM 6.3 A vulnerability, which was classified as critical, was found in PHPGurukul Complaint Management System 2.0. Affected is an unknown function…
CVE-2025-5651 2025-06-05 LOW 3.5 A vulnerability, which was classified as problematic, has been found in code-projects Traffic Offense Reporting System 1.0. This issue affects…
CVE-2025-5650 2025-06-05 HIGH 7.3 A vulnerability classified as critical was found in 1000projects Online Notice Board 1.0. This vulnerability affects unknown code of the…
CVE-2025-4568 2025-06-05 N/A 0.0 Improper neutralization of input provided by an unauthorized user into changes__reference_id parameter in URL allows for boolean-based Blind SQL Injection…
CVE-2025-5649 2025-06-05 MEDIUM 5.3 A vulnerability classified as critical has been found in SourceCodester Student Result Management System 1.0. This affects an unknown part…
CVE-2025-5648 2025-06-05 LOW 2.5 A vulnerability was found in Radare2 5.9.9. It has been classified as problematic. Affected is the function r_cons_pal_init in the…
CVE-2025-5647 2025-06-05 LOW 2.5 A vulnerability was found in Radare2 5.9.9 and classified as problematic. This issue affects the function r_cons_context_break_pop in the library…
CVE-2025-5646 2025-06-05 LOW 2.5 A vulnerability has been found in Radare2 5.9.9 and classified as problematic. This vulnerability affects the function r_cons_rainbow_free in the…
CVE-2025-5645 2025-06-05 LOW 2.5 A vulnerability, which was classified as problematic, was found in Radare2 5.9.9. This affects the function r_cons_pal_init in the library…
CVE-2025-5644 2025-06-05 LOW 2.5 A vulnerability, which was classified as problematic, has been found in Radare2 5.9.9. Affected by this issue is the function…
CVE-2025-5643 2025-06-05 LOW 2.5 A vulnerability classified as problematic was found in Radare2 5.9.9. Affected by this vulnerability is the function cons_stack_load in the…
CVE-2025-5642 2025-06-05 LOW 2.5 A vulnerability classified as problematic has been found in Radare2 5.9.9. Affected is the function r_cons_pal_init in the library /libr/cons/pal.c…
CVE-2025-5641 2025-06-05 LOW 2.5 A vulnerability was found in Radare2 5.9.9. It has been rated as problematic. This issue affects the function r_cons_is_breaked in…
CVE-2025-5683 2025-06-05 N/A 0.0 When loading a specifically crafted ICNS format image file in QImage then it will trigger a crash. This issue affects Qt…
CVE-2025-5640 2025-06-05 LOW 3.3 A vulnerability was found in PX4-Autopilot 1.12.3. It has been classified as problematic. This affects the function MavlinkReceiver::handle_message_trajectory_representation_waypoints of the…
CVE-2025-5639 2025-06-05 HIGH 7.3 A vulnerability was found in PHPGurukul Notice Board System 1.0 and classified as critical. Affected by this issue is some…
CVE-2025-3055 2025-06-05 HIGH 8.1 The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation…
CVE-2025-3054 2025-06-05 HIGH 8.8 The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation…
CVE-2025-5638 2025-06-05 MEDIUM 6.3 A vulnerability has been found in PHPGurukul Notice Board System 1.0 and classified as critical. Affected by this vulnerability is…
CVE-2025-5637 2025-06-05 HIGH 7.3 A vulnerability, which was classified as critical, was found in PCMan FTP Server 2.0.7. Affected is an unknown function of…