Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1268 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.9)0.54%—Projectworlds Life Insurance Management System7/3/202517/6/2026
A vulnerability, which was classified as critical, was found in projectworlds Life Insurance Management System 1.0. This affects an unknown part of the file /editAgent.php. The manipulation of the argument agent_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed…
AnalizadaMedia (6.9)0.54%—Projectworlds Life Insurance Management System7/3/202517/6/2026
A vulnerability, which was classified as critical, has been found in projectworlds Life Insurance Management System 1.0. Affected by this issue is some unknown functionality of the file /deletePayment.php. The manipulation of the argument recipt_no leads to sql injection. The attack may be launched remotely. The…
AnalizadaMedia (6.9)0.54%—Projectworlds Life Insurance Management System7/3/202517/6/2026
A vulnerability classified as critical was found in projectworlds Life Insurance Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /deleteNominee.php. The manipulation of the argument nominee_id leads to sql injection. The attack can be launched remotely. The exploit has…
AnalizadaMedia (6.9)0.54%—Projectworlds Life Insurance Management System7/3/202517/6/2026
A vulnerability classified as critical has been found in projectworlds Life Insurance Management System 1.0. Affected is an unknown function of the file /clientStatus.php. The manipulation of the argument client_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to…
AplazadaAlta (7.2)0.64%—Awplife Album GalleryAI1/3/202517/6/2026
The Album Gallery – WordPress Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.6.3 via deserialization of untrusted input from gallery meta. This makes it possible for authenticated attackers, with Editor-level access and above, to inject a PHP Object. No known…
AplazadaAlta (8.8)0.42%—Agito Computer Life4allAI24/2/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agito Computer Life4All allows SQL Injection. This issue affects Life4All: before 10.01.2025.
AplazadaMedia (5.4)0.14%—Intel Battery Life Diagnostic ToolAI12/2/202517/6/2026
Time-of-check time-of-use race condition for some Intel(R) Battery Life Diagnostic Tool software before version 2.4.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaAlta (7.5)0.38%—Tuya SmartlifeAI3/2/20255/7/2026
Nedis SmartLife android app v1.4.0 was discovered to contain an API key disclosure vulnerability.
AplazadaAlta (7.5)0.37%—Nedis Smartlife Video DoorbellAINedis Smartlife IOSAI3/2/20255/7/2026
An issue in Nedis SmartLife Video Doorbell (WIFICDP10GY), Nedis SmartLife IOS v1.4.0 causes users who are disconnected from a previous peer-to-peer connection with the device to still have access to live video feed.
AplazadaAlta (8.1)0.39%💥 PoCLifestylestoreAI27/1/202517/6/2026
Cross Site Request Forgery (CSRF) vulnerability in LifestyleStore v1.0 allows a remote attacker to execute unauthorized actions on behalf of an authenticated user, potentially leading to account modifications or data compromise.
AnalizadaAlta (7.5)0.50%—Oracle Agile Product Lifecycle Management21/1/202517/6/2026
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Install). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM Framework. Successful attacks of this…
AnalizadaAlta (8.1)0.50%—Oracle Agile Product Lifecycle Management21/1/202517/6/2026
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM Framework. Successful…
AnalizadaMedia (6.5)0.43%—Oracle Agile Product Lifecycle Management21/1/202517/6/2026
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: SDK-Software Development Kit). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM Framework. Successful…
AnalizadaCrítica (9.9)0.64%—Oracle Agile Product Lifecycle Management21/1/202517/6/2026
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM Framework. While the…
AnalizadaMedia (5.3)2.0%💥 ExploitAwplife Event Monster14/1/202517/6/2026
The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.3 via the Visitors List Export file. During the export, a CSV file is created in the wp-content folder with a hardcoded filename that is publicly…
AnalizadaMedia (6.5)0.41%—IBM Engineering Lifecycle Optimization Publishing4/1/202517/6/2026
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to cause an unhandled SSL exception which could leave the connection in an unexpected or insecure state.
AnalizadaAlta (7.3)0.31%—IBM Engineering Lifecycle Optimization Publishing4/1/202517/6/2026
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
AnalizadaAlta (7.5)0.48%—IBM Engineering Lifecycle Optimization Publishing4/1/202517/6/2026
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to cause a denial of service using a complex regular expression.
AnalizadaMedia (6.5)0.60%—IBM Engineering Lifecycle Optimization Publishing4/1/202517/6/2026
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
AnalizadaAlta (7.5)0.20%—IBM Engineering Lifecycle Optimization Publishing4/1/202517/6/2026
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
AnalizadaMedia (4)0.14%—Huawei Hilink AI Life28/12/202417/6/2026
Huawei HiLink AI Life product has an identity authentication bypass vulnerability. Successful exploitation of this vulnerability may allow attackers to access restricted functions.(Vulnerability ID:HWPSIRT-2022-42291) This vulnerability has been assigned a (CVE)ID:CVE-2022-48470
AnalizadaCrítica (9.8)0.34%—IBM Engineering Lifecycle Optimization - Engineering Insights25/12/202417/6/2026
IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or perform unauthorized actions on the victims’ web browser.
AnalizadaMedia (5.3)0.38%—IBM Engineering Lifecycle Optimization - Engineering Insights25/12/202417/6/2026
IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
AnalizadaMedia (4.8)0.28%—Liferay PortalLiferay Digital Experience Platform17/12/202417/6/2026
Cross-site scripting (XSS) vulnerability in the edit Service Access Policy page in Liferay Portal 7.0.0 through 7.4.3.87, and Liferay DXP 7.4 GA through update 87, 7.3 GA through update 29, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into…
ModificadaMedia (4.6)0.34%—Liferay PortalLiferay Digital Experience Platform17/12/202417/6/2026
Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.38, and Liferay DXP 7.4 GA through update 38 allows remote attackers to execute arbitrary web script or HTML via Dispatch name field
Orbitaley — Vulnerabilidades