Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1917 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.2) | 0.38% | — | Newforma Project Center | 9/10/2025 | 30/9/2026 | Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture the NTLMv2 hash of the customer-configured NIX service account. | |
| Analizada | Crítica (9.8) | 0.68% | — | IBM Transformation Extender Advanced | 6/10/2025 | 17/6/2026 | IBM Standards Processing Engine 10.0.1.10 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe java deserialization. By sending specially crafted input, an attacker could exploit this vulnerability to execute arbitrary code on the system. | |
| Aplazada | Media (5.5) | 0.69% | — | Four-faith Water Conservancy Informatization PlatformAI | 6/10/2025 | 17/6/2026 | A vulnerability was detected in Four-Faith Water Conservancy Informatization Platform up to 2.2. This affects an unknown part of the file /aloneReport/index.do/../../aloneReport/download.do;othersusrlogout.do. Performing manipulation of the argument fileName results in path traversal. It is possible to initiate the… | |
| Aplazada | Media (5.5) | 0.69% | — | Four-faith Water Conservancy Informatization PlatformAI | 6/10/2025 | 17/6/2026 | A security vulnerability has been detected in Four-Faith Water Conservancy Informatization Platform up to 2.2. Affected by this issue is some unknown functionality of the file /stAlarmConfigure/index.do/../../aloneReport/download.do;otherlogout.do. Such manipulation of the argument fileName leads to path traversal.… | |
| Aplazada | Media (4.1) | 0.21% | — | Isin Basi Advertisement Information Technologies Trade INC WorkifAI | 3/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Isin Basi Advertisement Information Technologies Trade Inc. IT's Workif allows Cross-Site Scripting (XSS). This issue affects IT's Workif: through 20251003. NOTE: The vendor was contacted early about this… | |
| Analizada | Media (6.2) | 0.11% | — | IBM Transformation Extender Advanced | 1/10/2025 | 17/6/2026 | IBM Transformation Extender Advanced 10.0.1 could allow a local user to perform unauthorized actions due to improper access controls. | |
| Analizada | Alta (7.5) | 0.27% | — | IBM Transformation Extender Advanced | 1/10/2025 | 17/6/2026 | IBM Transformation Extender Advanced 10.0.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. | |
| Analizada | Alta (8.8) | 0.22% | — | IBM Transformation Extender Advanced | 1/10/2025 | 17/6/2026 | IBM Transformation Extender Advanced 10.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. | |
| Analizada | Media (4.4) | 0.12% | — | IBM Transformation Extender Advanced | 1/10/2025 | 17/6/2026 | IBM Transformation Extender Advanced 10.0.1 stores potentially sensitive information in log files that could be read by a local user. | |
| Aplazada | Media (5.5) | 0.33% | — | Storage Performance Development KIT SpdkAI | 1/10/2025 | 17/6/2026 | Storage Performance Development Kit (SPDK) 25.05 is vulnerable to Buffer Overflow in the NVMe-oF target component in SPDK - lib/nvmf. | |
| Analizada | Alta (8.8) | 0.45% | — | IBM Infosphere Information Server | 29/9/2025 | 17/6/2026 | IBM InfoSphere 11.7.0.0 through 11.7.1.6 Information Server could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input. | |
| Analizada | Media (5.5) | 0.97% | — | Four-faith Water Conservancy Informatization | 26/9/2025 | 17/6/2026 | A flaw has been found in Four-Faith Water Conservancy Informatization Platform 1.0. This affects an unknown function of the file /sysRole/index.do/../../generalReport/download.do;usrlogout.do.do. Executing manipulation of the argument fileName can lead to path traversal. It is possible to launch the attack remotely.… | |
| Aplazada | Media (5.3) | 0.29% | — | Vimesoft Information Technologies AND Software Vimesoft Corporate Messaging PlatformAI | 26/9/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Vimesoft Information Technologies and Software Inc. Vimesoft Corporate Messaging Platform allows Retrieve Embedded Sensitive Data. This issue affects Vimesoft Corporate Messaging Platform: from V1.3.0 before V2.0.0. | |
| Aplazada | Alta (8.6) | 0.45% | — | Yordam Information Technology Consulting Education AND Electrical Systems Industry Trade Yordam KatalogAI | 25/9/2025 | 17/6/2026 | Path Traversal: 'dir/../../filename' vulnerability in Yordam Information Technology Consulting Education and Electrical Systems Industry Trade Inc. Yordam Katalog allows Path Traversal. This issue affects Yordam Katalog: before 21.7. | |
| Analizada | Alta (7.5) | 0.40% | — | Openjsf Messageformat | 24/9/2025 | 17/6/2026 | The messageformat package, an implementation of the Unicode MessageFormat 2 specification for JavaScript, is vulnerable to prototype pollution due to improper handling of message key paths in versions prior to 2.3.0. The flaw arises when processing nested message keys containing special characters (e.g., __proto__ ),… | |
| Aplazada | Media (5.3) | 0.35% | — | Openjsf MessageformatAI | 24/9/2025 | 17/6/2026 | The Runtime components of messageformat package for Node.js before 3.0.2 contain a prototype pollution vulnerability. Due to insufficient validation of nested message keys during the processing of message data, an attacker can manipulate the prototype chain of JavaScript objects by providing specially crafted input.… | |
| Aplazada | Media (4.3) | 0.24% | — | Divvydrive Information Technologies INC Divvydrive WEBAI | 24/9/2025 | 25/9/2026 | Observable Timing Discrepancy vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive Web allows Cross-Domain Search Timing. This issue affects DivvyDrive Web: from 4.8.2.2 before 4.8.2.15. | |
| Analizada | Baja (2.1) | 0.38% | — | Campcodes Society Membership Information System | 23/9/2025 | 17/6/2026 | A vulnerability was identified in Campcodes Society Membership Information System 1.0. This issue affects some unknown processing of the file /check_student.php. Such manipulation of the argument student_id leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be… | |
| Aplazada | Media (6.5) | 0.17% | — | Pencidesign Penci Shortcodes AND PerformanceAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci Shortcodes & Performance penci-shortcodes allows DOM-Based XSS.This issue affects Penci Shortcodes & Performance: from n/a through < 6.1. | |
| Aplazada | Media (4.3) | 0.29% | — | Nurul Amin WP System InformationAI | 22/9/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Nurul Amin WP System Information wp-system-info allows Retrieve Embedded Sensitive Data.This issue affects WP System Information: from n/a through <= 1.5. | |
| Analizada | Media (5.5) | 0.97% | — | Four-faith Water Conservancy Informatization | 19/9/2025 | 17/6/2026 | A security vulnerability has been detected in Four-Faith Water Conservancy Informatization Platform 1.0. Affected by this vulnerability is an unknown functionality of the file /history/historyDownload.do;usrlogout.do. The manipulation of the argument fileName leads to path traversal. Remote exploitation of the attack… | |
| Analizada | Media (5.5) | 0.97% | — | Four-faith Water Conservancy Informatization | 19/9/2025 | 30/9/2026 | A vulnerability was detected in Four-Faith Water Conservancy Informatization Platform 1.0. Affected by this issue is some unknown functionality of the file /history/historyDownload.do;otheruserLogin.do;getfile. The manipulation of the argument fileName results in path traversal. The attack can be executed remotely.… | |
| Aplazada | Media (4.7) | 0.23% | — | Pusula Communication Information Manageable Email Sending SystemAI | 19/9/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Pusula Communication Information Internet Industry and Trade Ltd. Co. Manageable Email Sending System allows Exploiting Trust in Client. This issue affects Manageable Email Sending System: from <=2025.06 before 2025.08.06. | |
| Analizada | Media (5.5) | 0.59% | — | Itsourcecode Student Information Management System | 18/9/2025 | 17/6/2026 | A vulnerability was determined in itsourcecode Student Information Management System 1.0. The impacted element is an unknown function of the file /admin/modules/class/index.php. This manipulation of the argument classId causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed… | |
| Aplazada | Crítica (9.8) | 0.36% | — | Esbi Information AND Telecommunication Industry AND Trade Limited Company Auto Service SoftwareAI | 18/9/2025 | 17/6/2026 | CWE - 89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ESBI Information and Telecommunication Industry and Trade Limited Company Auto Service Software allows SQL Injection. This issue affects Auto Service Software: before v.2025.10.01. |