Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
4639 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.42% | — | Idvlabs Software AND Consulting Services INC OntimeAI | 7/7/2026 | 7/7/2026 | Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime allows Exploitation of Trusted Identifiers. This issue affects Ontime: through 04052026. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Real State ServicesAI | 5/7/2026 | 7/7/2026 | A security vulnerability has been detected in code-projects Real State Services 1.0. This issue affects some unknown processing of the file /pay.php. Such manipulation of the argument Bankname leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Real State ServicesAI | 5/7/2026 | 6/7/2026 | A weakness has been identified in code-projects Real State Services 1.0. This vulnerability affects unknown code of the file /builderHome.php. This manipulation of the argument loc causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be… | |
| Aplazada | Media (6.9) | 0.43% | — | Code-projects Real State ServicesAI | 5/7/2026 | 6/7/2026 | A vulnerability was detected in code-projects Real State Services 1.0. Affected by this vulnerability is an unknown functionality of the file /addprojectsale.php. The manipulation of the argument amen results in sql injection. The attack can be launched remotely. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Real State ServicesAI | 5/7/2026 | 6/7/2026 | A security vulnerability has been detected in code-projects Real State Services 1.0. Affected is an unknown function of the file /addprojectrent.php. The manipulation of the argument amen leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Real State ServicesAI | 5/7/2026 | 6/7/2026 | A weakness has been identified in code-projects Real State Services 1.0. This impacts an unknown function of the file /single-list_rent.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Real State ServicesAI | 5/7/2026 | 7/7/2026 | A security flaw has been discovered in code-projects Real State Services 1.0. This affects an unknown function of the file /normalHomeRent.php. Performing a manipulation of the argument loc results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Real State ServicesAI | 5/7/2026 | 6/7/2026 | A vulnerability was identified in code-projects Real State Services 1.0. The impacted element is an unknown function of the file /normalHomeSale.php. Such manipulation of the argument loc leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Entra Provisioning Service | 2/7/2026 | 8/7/2026 | Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Real State ServicesAI | 29/6/2026 | 29/6/2026 | A weakness has been identified in code-projects Real State Services 1.0. Impacted is an unknown function of the file /single-list_sale.php?action=add. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could… | |
| Aplazada | Alta (7.5) | 0.53% | — | MSI Nbfoundation ServiceAI | 25/6/2026 | 26/6/2026 | Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the MSIAPService.exe component | |
| Aplazada | Alta (8.1) | 0.72% | 💥 PoC | Vmware CRMAIVmware Pivotal.core.common.dllAIVmware Pivotal.engine.client.services.conversion.dllAI | 23/6/2026 | 25/6/2026 | An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll and Pivotal.Engine.Client.Services.Conversion.dll components. | |
| Pendiente de análisis | Crítica (9) | 2.5% | 💥 PoC | Manageengine Adselfservice PlusAIManageengine Recoverymanager PlusAIManageengine M365 Manager PlusAIManageengine Adaudit PlusAI | 23/6/2026 | 24/6/2026 | In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover. | |
| Modificada | Alta (8.8) | 0.37% | — | IBM Watson Speech Services Cartridge | 22/6/2026 | 23/7/2026 | IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. A privileged user could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | |
| Analizada | Alta (8.7) | 0.50% | — | Angular Language Service | 22/6/2026 | 26/6/2026 | The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. the client-side Angular Language Service VS Code extension configures the tooltip Markdown renderer with the isTrusted: true option (located in client/src/client.ts). This setting instructs VS Code to trust all… | |
| Analizada | Alta (8.7) | 0.24% | — | Angular Language Service | 22/6/2026 | 26/6/2026 | The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. Prior to 21.2.4, the client-side Angular Language Service VS Code extension reads the custom TypeScript SDK paths typescript.tsdk and js/ts.tsdk.path directly from workspace configurations (.vscode/settings.json)… | |
| Aplazada | Alta (8.1) | 0.49% | — | Doobidoo Mcp-memory-serviceAI | 19/6/2026 | 23/6/2026 | mcp-memory-service is a semantic memory layer for AI applications. Prior to version 10.65.3, the HTTP MCP JSON-RPC endpoint at `/mcp` requires only OAuth `read` scope for all requests, then dispatches `tools/call` directly to handlers that include mutating tools. A read-only OAuth client can call `store_memory` and… | |
| Aplazada | Alta (8.5) | 0.17% | — | Realtek Audio ServiceAI | 19/6/2026 | 29/9/2026 | Realtek Audio Service 1.0.0.55 contains an unquoted service path vulnerability in RtkAudioService64.exe that allows local attackers to escalate privileges by injecting malicious code. Attackers can place executable files in the unquoted service path directory to execute arbitrary code with LocalSystem privileges… | |
| Aplazada | Alta (8.5) | 0.17% | — | Realtimes Desktop ServiceAI | 19/6/2026 | 29/9/2026 | RealTimes Desktop Service 18.1.4 contains an unquoted service path vulnerability in the rpdsvc.exe binary that allows local attackers to escalate privileges. Attackers can place malicious executables in unquoted path directories to execute arbitrary code with LocalSystem privileges during service startup or system… | |
| Analizada | Alta (8.8) | 0.77% | — | Microsoft Azure AI BOT Service | 18/6/2026 | 24/6/2026 | Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Media (6.4) | 0.21% | — | Services Section BlockAI | 18/6/2026 | 18/6/2026 | The Services Section Block – Showcase Service Details in Grid or Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'link' Block Attribute in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Analizada | Alta (7.5) | 1.1% | — | Envoyproxy EnvoyRedhat Openshift Service Mesh | 17/6/2026 | 20/7/2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vulnerability in Envoy's HTTP/2 downstream request processing allows an unauthenticated remote client to trigger excessive memory consumption, potentially resulting in OOM… | |
| Analizada | Alta (7.5) | 0.50% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 17/6/2026 | 25/9/2026 | A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected… | |
| Analizada | Crítica (9.1) | 8.9% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 17/6/2026 | 25/9/2026 | A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of… | |
| Aplazada | Alta (7.4) | 0.28% | — | Chatway Live Chat - AI Chatbot Customer Support FAQ & Helpdesk Customer Service & Chat ButtonsAI | 15/6/2026 | 17/6/2026 | Subscriber Sensitive Data Exposure in Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons <= 1.4.8 versions. |