Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1268 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.54% | — | Projectworlds Life Insurance Management System | 7/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in projectworlds Life Insurance Management System 1.0. This affects an unknown part of the file /editAgent.php. The manipulation of the argument agent_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed… | |
| Analizada | Media (6.9) | 0.54% | — | Projectworlds Life Insurance Management System | 7/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in projectworlds Life Insurance Management System 1.0. Affected by this issue is some unknown functionality of the file /deletePayment.php. The manipulation of the argument recipt_no leads to sql injection. The attack may be launched remotely. The… | |
| Analizada | Media (6.9) | 0.54% | — | Projectworlds Life Insurance Management System | 7/3/2025 | 17/6/2026 | A vulnerability classified as critical was found in projectworlds Life Insurance Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /deleteNominee.php. The manipulation of the argument nominee_id leads to sql injection. The attack can be launched remotely. The exploit has… | |
| Analizada | Media (6.9) | 0.54% | — | Projectworlds Life Insurance Management System | 7/3/2025 | 17/6/2026 | A vulnerability classified as critical has been found in projectworlds Life Insurance Management System 1.0. Affected is an unknown function of the file /clientStatus.php. The manipulation of the argument client_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to… | |
| Aplazada | Alta (7.2) | 0.64% | — | Awplife Album GalleryAI | 1/3/2025 | 17/6/2026 | The Album Gallery – WordPress Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.6.3 via deserialization of untrusted input from gallery meta. This makes it possible for authenticated attackers, with Editor-level access and above, to inject a PHP Object. No known… | |
| Aplazada | Alta (8.8) | 0.42% | — | Agito Computer Life4allAI | 24/2/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agito Computer Life4All allows SQL Injection. This issue affects Life4All: before 10.01.2025. | |
| Aplazada | Media (5.4) | 0.14% | — | Intel Battery Life Diagnostic ToolAI | 12/2/2025 | 17/6/2026 | Time-of-check time-of-use race condition for some Intel(R) Battery Life Diagnostic Tool software before version 2.4.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (7.5) | 0.38% | — | Tuya SmartlifeAI | 3/2/2025 | 5/7/2026 | Nedis SmartLife android app v1.4.0 was discovered to contain an API key disclosure vulnerability. | |
| Aplazada | Alta (7.5) | 0.37% | — | Nedis Smartlife Video DoorbellAINedis Smartlife IOSAI | 3/2/2025 | 5/7/2026 | An issue in Nedis SmartLife Video Doorbell (WIFICDP10GY), Nedis SmartLife IOS v1.4.0 causes users who are disconnected from a previous peer-to-peer connection with the device to still have access to live video feed. | |
| Aplazada | Alta (8.1) | 0.39% | 💥 PoC | LifestylestoreAI | 27/1/2025 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability in LifestyleStore v1.0 allows a remote attacker to execute unauthorized actions on behalf of an authenticated user, potentially leading to account modifications or data compromise. | |
| Analizada | Alta (7.5) | 0.50% | — | Oracle Agile Product Lifecycle Management | 21/1/2025 | 17/6/2026 | Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Install). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM Framework. Successful attacks of this… | |
| Analizada | Alta (8.1) | 0.50% | — | Oracle Agile Product Lifecycle Management | 21/1/2025 | 17/6/2026 | Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM Framework. Successful… | |
| Analizada | Media (6.5) | 0.43% | — | Oracle Agile Product Lifecycle Management | 21/1/2025 | 17/6/2026 | Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: SDK-Software Development Kit). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM Framework. Successful… | |
| Analizada | Crítica (9.9) | 0.64% | — | Oracle Agile Product Lifecycle Management | 21/1/2025 | 17/6/2026 | Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM Framework. While the… | |
| Analizada | Media (5.3) | 2.0% | 💥 Exploit | Awplife Event Monster | 14/1/2025 | 17/6/2026 | The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.3 via the Visitors List Export file. During the export, a CSV file is created in the wp-content folder with a hardcoded filename that is publicly… | |
| Analizada | Media (6.5) | 0.41% | — | IBM Engineering Lifecycle Optimization Publishing | 4/1/2025 | 17/6/2026 | IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to cause an unhandled SSL exception which could leave the connection in an unexpected or insecure state. | |
| Analizada | Alta (7.3) | 0.31% | — | IBM Engineering Lifecycle Optimization Publishing | 4/1/2025 | 17/6/2026 | IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | |
| Analizada | Alta (7.5) | 0.48% | — | IBM Engineering Lifecycle Optimization Publishing | 4/1/2025 | 17/6/2026 | IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to cause a denial of service using a complex regular expression. | |
| Analizada | Media (6.5) | 0.60% | — | IBM Engineering Lifecycle Optimization Publishing | 4/1/2025 | 17/6/2026 | IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. | |
| Analizada | Alta (7.5) | 0.20% | — | IBM Engineering Lifecycle Optimization Publishing | 4/1/2025 | 17/6/2026 | IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | |
| Analizada | Media (4) | 0.14% | — | Huawei Hilink AI Life | 28/12/2024 | 17/6/2026 | Huawei HiLink AI Life product has an identity authentication bypass vulnerability. Successful exploitation of this vulnerability may allow attackers to access restricted functions.(Vulnerability ID:HWPSIRT-2022-42291) This vulnerability has been assigned a (CVE)ID:CVE-2022-48470 | |
| Analizada | Crítica (9.8) | 0.34% | — | IBM Engineering Lifecycle Optimization - Engineering Insights | 25/12/2024 | 17/6/2026 | IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or perform unauthorized actions on the victims’ web browser. | |
| Analizada | Media (5.3) | 0.38% | — | IBM Engineering Lifecycle Optimization - Engineering Insights | 25/12/2024 | 17/6/2026 | IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | |
| Analizada | Media (4.8) | 0.28% | — | Liferay PortalLiferay Digital Experience Platform | 17/12/2024 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the edit Service Access Policy page in Liferay Portal 7.0.0 through 7.4.3.87, and Liferay DXP 7.4 GA through update 87, 7.3 GA through update 29, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into… | |
| Modificada | Media (4.6) | 0.34% | — | Liferay PortalLiferay Digital Experience Platform | 17/12/2024 | 17/6/2026 | Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.38, and Liferay DXP 7.4 GA through update 38 allows remote attackers to execute arbitrary web script or HTML via Dispatch name field |