Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
2298 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3.3) | 0.10% | — | Hcltech Sametime | 5/3/2026 | 17/6/2026 | HCL Sametime for iOS is impacted by a sensitive information disclosure. Hostnames information is written in application logs and certain URLs. | |
| Analizada | Crítica (9.3) | 0.26% | — | Microchip Timepictra | 28/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimePictra allows Query System for Information.This issue affects TimePictra: from 11.0 through 11.3 SP2. | |
| Analizada | Crítica (9.3) | 0.44% | — | Microchip Timepictra | 28/2/2026 | 17/6/2026 | Missing Authentication for Critical Function vulnerability in Microchip TimePictra allows Configuration/Environment Manipulation.This issue affects TimePictra: from 11.0 through 11.3 SP2. | |
| Analizada | Media (6) | 0.43% | — | Iptime T5008 FirmwareIptime Ax2004m FirmwareIptime Ax3000q FirmwareIptime Ax6000m Firmware | 27/2/2026 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in EFM-Networks, Inc. IpTIME T5008, EFM-Networks, Inc. IpTIME AX2004M, EFM-Networks, Inc. IpTIME AX3000Q, EFM-Networks, Inc. IpTIME AX6000M allows Authentication Bypass.This issue affects ipTIME T5008: through 15.26.8; ipTIME AX2004M: through… | |
| Analizada | Alta (8.8) | 2.5% | — | Hackerbay Oneuptime | 25/2/2026 | 17/6/2026 | OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.7, an OS command injection vulnerability in `NetworkPathMonitor.performTraceroute()` allows any authenticated project user to execute arbitrary operating system commands on the Probe server by injecting shell metacharacters into… | |
| Analizada | Media (6.9) | 0.66% | — | Bytecodealliance Wasmtime | 24/2/2026 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implementation of the `wasi:http/types.fields` resource is susceptible to panics when too many fields are added to the set of headers. Wasmtime's implementation in the `wasmtime-wasi-http` crate is backed by… | |
| Analizada | Media (6.9) | 0.66% | — | Bytecodealliance Wasmtime | 24/2/2026 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implementation of WASI host interfaces are susceptible to guest-controlled resource exhaustion on the host. Wasmtime did not appropriately place limits on resource allocations requested by the guests. This… | |
| Analizada | Media (6.9) | 0.62% | — | Bytecodealliance Wasmtime | 24/2/2026 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. Starting with Wasmtime 39.0.0, the `component-model-async` feature became the default, which brought with it a new implementation of `[Typed]Func::call_async` which made it capable of calling async-typed guest export functions. However, that implementation had a bug leading to a… | |
| Modificada | Media (5.7) | 0.10% | — | Microchip Timeprovider 4100 Firmware | 24/2/2026 | 17/6/2026 | Download of Code Without Integrity Check vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5. | |
| Analizada | Crítica (9.9) | 0.62% | 💥 PoC | Hackerbay Oneuptime | 21/2/2026 | 17/6/2026 | OneUptime is a solution for monitoring and managing online services. In versions 9.5.13 and below, custom JavaScript monitor feature uses Node.js's node:vm module (explicitly documented as not a security mechanism) to execute user-supplied code, allowing trivial sandbox escape via a well-known one-liner that grants… | |
| Aplazada | Alta (7.5) | 0.34% | — | Mdalabar WOO Order Delivery Time LiteAI | 20/2/2026 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in mdalabar WooODT Lite byconsole-woo-order-delivery-time allows Identity Spoofing.This issue affects WooODT Lite: from n/a through <= 2.5.2. | |
| Aplazada | Alta (7.1) | 0.19% | — | Wpdiscover Timeline Event HistoryAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdiscover Timeline Event History timeline-event-history allows Reflected XSS.This issue affects Timeline Event History: from n/a through <= 3.2. | |
| Aplazada | Crítica (9.8) | 0.53% | — | Loftocean PatiotimeAI | 20/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in LoftOcean PatioTime patiotime allows Object Injection.This issue affects PatioTime: from n/a through < 2.1. | |
| Aplazada | Alta (8.1) | 0.53% | — | Loftocean PatiotimeAI | 20/2/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LoftOcean PatioTime patiotime allows PHP Local File Inclusion.This issue affects PatioTime: from n/a through < 2.1. | |
| Analizada | Media (5.3) | 0.27% | — | Nestersoft Worktime | 19/2/2026 | 17/6/2026 | Any unauthenticated user can reset the WorkTime on-prem database configuration by sending a specific HTTP request to the WorkTime server. No authorization check is applied here. | |
| Analizada | Media (6.1) | 0.16% | — | Nestersoft Worktime | 19/2/2026 | 17/6/2026 | The server API endpoint /report/internet/urls reflects received data into the HTML response without applying proper encoding or filtering. This allows an attacker to execute arbitrary JavaScript in the victim's browser if the victim opens a URL prepared by the attacker. | |
| Analizada | Alta (7.8) | 0.11% | — | Nestersoft Worktime | 19/2/2026 | 17/6/2026 | An attacker can exploit the update behavior of the WorkTime monitoring daemon to elevate privileges on the local system to NT Authority\SYSTEM. A malicious executable must be named WTWatch.exe and dropped in the C:\ProgramData\wta\ClientExe directory, which is writable by "Everyone". The executable will then be run by… | |
| Analizada | Alta (8.8) | 0.26% | — | Nestersoft Worktime | 19/2/2026 | 17/6/2026 | An authenticated attacker with minimal permissions can exploit a SQL injection in the WorkTime server "widget" API endpoint to inject SQL queries. If the Firebird backend is used, attackers are able to retrieve all data from the database backend. If the MSSQL backend is used the attacker can execute arbitrary SQL… | |
| Analizada | Crítica (9.8) | 0.46% | — | Nestersoft Worktime | 19/2/2026 | 17/6/2026 | An unauthenticated attacker can inject OS commands when calling a server API endpoint in NesterSoft WorkTime. The server API call to generate and download the WorkTime client from the WorkTime server is vulnerable in the “guid” parameter. This allows an attacker to execute arbitrary commands on the WorkTime server as… | |
| Aplazada | Alta (7.5) | 0.53% | — | Villatheme Sales Countdown TimerAI | 19/2/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in villatheme Sales Countdown Timer for WooCommerce and WordPress sctv-sales-countdown-timer allows PHP Local File Inclusion.This issue affects Sales Countdown Timer for WooCommerce and WordPress: from… | |
| Aplazada | Media (5.9) | 0.18% | — | HurrytimerAI | 19/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nabil Lemsieh HurryTimer hurrytimer allows Stored XSS.This issue affects HurryTimer: from n/a through <= 2.14.2. | |
| Modificada | Alta (7.5) | 0.53% | — | Projectworlds Online Time Table Generator | 18/2/2026 | 8/9/2026 | Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to obtain sensitive information (including plaintext password field values) via direct HTTP GET requests to these endpoints without a valid session. | |
| Modificada | Crítica (9.1) | 0.58% | — | Projectworlds Online Time Table Generator | 18/2/2026 | 8/9/2026 | Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized administrative operations (e.g.,adding records, deleting records) via direct HTTP requests to affected endpoints without a valid session. | |
| Aplazada | Alta (8.6) | 0.27% | — | Time@workAI | 18/2/2026 | 17/6/2026 | When hours are entered in time@work, version 7.0.5, it performs a query to display the projects assigned to the user. If the query URL is copied and opened in a new browser window, the ‘IDClient’ parameter is vulnerable to a blind authenticated SQL injection. If the request is made with the TWAdmin user with the… | |
| Aplazada | Alta (8.9) | 0.97% | — | Iptime A6004mxAI | 16/2/2026 | 17/6/2026 | A vulnerability was found in EFM iptime A6004MX 14.18.2. Affected is the function commit_vpncli_file_upload of the file /cgi/timepro.cgi. The manipulation results in unrestricted upload. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about… |