Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

2109 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.3)0.57%—IBM Engineering AI HUB17/7/202624/7/2026
IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input during web page generation.
AnalizadaMedia (5.4)0.30%—IBM Engineering AI HUB17/7/202624/7/2026
IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary script code due to improper neutralization of input during web page generation.
AnalizadaAlta (7.5)0.55%—IBM Engineering Lifecycle Management17/7/202611/8/2026
IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ) Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 DOORS could allow a remote attacker to cause a denial of service due to improper handling of XML entity expansion.
AplazadaCrítica (9.8)0.47%—GIS Informatics Engineering Consulting Laboratory Gislab Laboratory Management SystemAI17/7/202617/7/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management System allows SQL Injection. This issue affects GisLab Laboratory Management System: from 1.4.03 through…
AplazadaMedia (6.5)0.36%—GIS Informatics Engineering Consulting Laboratory RND AND Software Services Gislab Laboratory Management SystemAI17/7/202617/7/2026
Authorization bypass through User-Controlled key vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management System allows Exploitation of Trusted Identifiers. This issue affects GisLab Laboratory Management System: from 1.4.03 through 08072026.
AnalizadaCrítica (9.6)0.48%—Broadcom Spring Authorization Server16/7/20264/9/2026
Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1.5.6, from 1.4.0 through 1.4.9, from 1.3.0 through 1.3.10.
AplazadaCrítica (9)0.64%—DataeaseAIAmazon Redshift DriverAISpringframework Spring FrameworkAI15/7/202616/7/2026
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase Redshift datasource connections can load attacker-controlled rsjdbc.ini configuration from System.getProperty("java.io.tmpdir"), setting socketFactory=org.springframework.context.support.FileSystemXmlApplicationContext so…
AnalizadaAlta (8.2)0.52%💥 PoCMicrosoft Azure Spring Cloud14/7/202624/7/2026
Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network.
Pendiente de análisisCrítica (9.6)0.84%—Centreon-open-ticketsAICentreon Infra MonitoringAI13/7/202613/7/2026
This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets module that leads to Remote Code Execution. The message_confirm field is stored without sanitization and rendered via Smarty with no security policy enabled, allowing any authenticated user, to inject and execute…
AplazadaMedia (6.9)0.48%—Nezha MonitoringAI10/7/202613/7/2026
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to 2.2.5, the GET /api/v1/ddns and GET /api/v1/notification endpoints return full resource objects including plaintext third-party API credentials, including Cloudflare API tokens, TencentCloud SecretKeys, Slack,…
AplazadaMedia (5.3)0.42%—Easy Upload Files During CheckoutAI10/7/202610/7/2026
The Easy Upload Files During Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 3.0.1. This is due to missing authorization checks in the ufdc_custom_init() function, which processes the 'eufdc-delete' parameter without any nonce verification, capability check, or…
AplazadaMedia (6.9)0.15%—InputsharingAI10/7/202610/7/2026
Improper export of android application components in InputSharing prior to version 2.7.01.4 allows local attackers to access sharing data.
Pendiente de análisisMedia (6.9)0.47%—California Courts Hearing Reminder ServiceAI9/7/202621/7/2026
The Superior Court of California Hearing Reminder Service at https://www.hrs.courts.ca.gov exposes an API endpoint that returns court reminder records containing potentially sensitive information without authentication.
AplazadaBaja (2.1)0.29%—Flask-dashboard Flask-monitoringdashboardAI8/7/20268/7/2026
A vulnerability has been found in flask-dashboard Flask-MonitoringDashboard up to 5.0.2. Affected by this issue is some unknown functionality. Such manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The project was…
AplazadaAlta (7.5)0.63%—String UtilAI7/7/20268/7/2026
String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service. The trim and rtrim functions stripped trailing whitespace with s/\s*$//u. Because \s* matches greedily and the $ anchor fails whenever a non-whitespace character follows the whitespace, the regex engine retries the…
AplazadaMedia (4.2)0.29%—Csv-stringifyAIActualbudget ActualAI7/7/20269/7/2026
Actual is a local-first personal finance tool. Prior to 26.6.0, exportToCSV and exportQueryToCSV in packages/loot-core/src/server/transactions/export/export-to-csv.ts pass user-controlled Payee, Notes, Account, and Category strings to csv-stringify with no cast callback and no formula-prefix neutralization. Strings…
Pendiente de análisisAlta (7.1)0.57%—Amazon Research AND Engineering StudioAI7/7/20268/7/2026
AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create and manage secure virtual desktops and computing resources on AWS. Improper link resolution before file access issue (CWE-59) in the Auth.GetUserPrivateKey API. An authenticated remote user could read…
AplazadaAlta (7)0.19%—React-native-receive-sharing-intentAI2/7/202614/7/2026
react-native-receive-sharing-intent contains a path traversal vulnerability that allows a co-resident malicious application to write files outside the intended cache directory by supplying a crafted _display_name value containing dot-dot path components through a malicious ContentProvider. Attackers can fire an…
AplazadaMedia (6.1)0.25%—Eksagate Electronic Engineering AND Computer Industry Trade Sysguard 6001AI30/6/202630/6/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. SYSGUARD 6001 allows Stored XSS. This issue affects SYSGUARD 6001: from 2.0.2 before 6.1.4.0. NOTE: The vendor was contacted and it was learned that the…
AplazadaCrítica (9.8)0.47%—Eksagate Electronic Engineering AND Computer Industry Trade Sysguard 6001AI30/6/202630/6/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. SYSGUARD 6001 allows Blind SQL Injection. This issue affects SYSGUARD 6001: from 2.0.2 before 6.1.16.0. NOTE: The vendor was contacted and it was…
AplazadaMedia (5.5)0.51%—Sourcecodester Simple Food Ordering SystemAI29/6/202629/6/2026
A flaw has been found in SourceCodester Simple Food Ordering System 1.0. The affected element is an unknown function of the file /cart.php. Executing a manipulation of the argument item_price can lead to business logic errors. The attack may be performed from remote. The exploit has been published and may be used.
AnalizadaMedia (4.4)0.14%—Fortra File Integrity Monitoring23/6/202629/6/2026
Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0 may assign incorrect or elevated effective permissions to users created by the tetool import command while FIM is running, particularly when the import also creates or changes roles or role-permission relationships.
AnalizadaMedia (4.8)0.24%—Fortra File Integrity Monitoring23/6/202628/6/2026
Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0.1 contain a stored cross-site scripting (XSS) vulnerability in the Asset View UI component. An authenticated user with sufficient privileges to create or modify affected node or database configuration fields could store…
AnalizadaAlta (8.8)0.76%—Broadcom Spring Statemachine23/6/202622/9/2026
Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to remote code execution inside the application JVM. Affected versions: Spring…
AnalizadaMedia (6.1)0.25%—IBM Engineering Workflow Management22/6/20261/10/2026
IBM Engineering Workflow Management 7.0.2 through 7.0.2 Interim Fix 035, 7.0.3 through 7.0.3 Interim Fix 017, and 7.1 through 7.1 Interim Fix 004 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the…