Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

4214 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.3%💥 PoCRedhat Build OF Apache Camel FOR Spring BootRedhat FuseRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Expansion Pack+42/9/20256/10/2026
A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol…
AnalizadaMedia (5.4)0.18%—IBM Edge Application Manager20/8/202517/6/2026
IBM Edge Application Manager 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
AnalizadaMedia (4.4)0.11%—IBM Edge Application Manager20/8/202517/6/2026
IBM Edge Application Manager 4.5 could allow a local user to read or modify resources that they should not have authorization to access due to incorrect permission assignment.
AplazadaAlta (8.8)0.36%—Touch Lebanon Mobile APPAI20/8/202517/6/2026
A vulnerability in the password reset workflow of the Touch Lebanon Mobile App 2.20.2 allows an attacker to bypass the OTP reset password mechanism. By manipulating the reset process, an unauthorized user may be able to reset the password and gain access to the account without needing to provide a legitimate…
ModificadaAlta (7.5)0.45%—IBM Websphere Application Server14/8/202517/6/2026
IBM WebSphere Application Server Liberty 18.0.0.2 through 25.0.0.8 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
AnalizadaAlta (7.5)0.27%—IBM Websphere Application Server14/8/202517/6/2026
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for TLS connections.
AnalizadaMedia (4.8)0.18%—IBM Websphere Application Server12/8/202517/6/2026
IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AnalizadaAlta (7.5)0.40%—IBM Websphere Application Server12/8/202517/6/2026
IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 could allow a remote attacker to bypass security restrictions caused by a failure to honor JMS messaging configuration
AnalizadaMedia (5.5)0.49%—Microsoft Azure APP Service ON Azure Stack12/8/202517/6/2026
Exposure of private personal information to an unauthorized actor in Azure Stack allows an authorized attacker to disclose information locally.
AnalizadaAlta (7.8)0.12%—Netapp SAN Host Utilities7/8/202517/6/2026
The installer for SAN Host Utilities for Windows versions prior to 8.0 is susceptible to a vulnerability which when successfully exploited could allow a local user to escalate their privileges.
AnalizadaAlta (7.5)0.42%—IBM Websphere Application Server7/8/202517/6/2026
IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 could allow a remote attacker to bypass security restrictions caused by a failure to honor security configuration.
AplazadaMedia (5.4)0.36%—Partner Software ApplicationAIPartner Software Partner WEB ApplicationAI2/8/202517/6/2026
Partner Software's Partner Software application and Partner Web application allows an authenticated user to add notes on the 'Notes' page when viewing a job but does not completely sanitize input, making it possible to add notes with HTML tags and JavaScript, enabling an attacker to add a note containing malicious…
AplazadaAlta (8.8)0.66%—Partner Software ApplicationAIPartner Software Partner WEB ApplicationAI2/8/202517/6/2026
Partner Software's Partner Software application and Partner Web application do not sanitize files uploaded on the "reports" tab, allowing an authenticated attacker to upload a malicious file and compromise the device. By default, the software runs as SYSTEM, heightening the severity of the vulnerability.
AplazadaCrítica (9.8)2.1%—Gardyn Home KIT FirmwareAIGardyn Home KIT Mobile ApplicationAIGardyn Home KIT Cloud APIAI25/7/202517/6/2026
Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 allow command injection through vulnerable methods that do not sanitize input before passing content to the operating system for execution. The vulnerability may allow an attacker to execute…
AplazadaCrítica (9.1)0.49%—Gardyn Home KIT FirmwareAIGardyn Home KIT Mobile ApplicationAIGardyn Home KIT Cloud APIAI25/7/202517/6/2026
Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 use weak default credentials for secure shell access. This may result in attackers gaining access to exposed Gardyn Home Kits.
AplazadaCrítica (9.4)0.28%💥 PoCGardyn Home KIT FirmwareAIGardyn Home KIT Mobile ApplicationAIGardyn Home KIT Cloud APIAI25/7/202517/6/2026
A Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 leaving the string vulnerable to interception and modification through a Man-in-the-Middle attack.…
AplazadaAlta (8.7)0.46%—Sitecore JSS React Sample ApplicationAI25/7/202517/6/2026
An information disclosure vulnerability exits in Sitecore JSS React Sample Application 11.0.0 - 14.0.1 that may cause page content intended for one user to be shown to another user.
AnalizadaMedia (5.4)0.40%—Zohocorp Manageengine Applications Manager23/7/202517/6/2026
Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in the File/Directory monitor.
AplazadaBaja (1.9)0.14%—Genshin Albedo CAT House APPAI21/7/202517/6/2026
A vulnerability was found in Genshin Albedo Cat House App 1.0.2 on Android. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.house.auscat. The manipulation leads to improper export of android application components.…
AnalizadaMedia (5.5)0.46%—Anisha Online Appointment Booking System17/7/202517/6/2026
A vulnerability classified as critical was found in code-projects Online Appointment Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/addmanagerclinic.php. The manipulation of the argument clinic leads to sql injection. The attack can be launched remotely. The exploit…
AnalizadaMedia (5.5)0.46%—Anisha Online Appointment Booking System17/7/202517/6/2026
A vulnerability classified as critical has been found in code-projects Online Appointment Booking System 1.0. Affected is an unknown function of the file /admin/deletedoctorclinic.php. The manipulation of the argument clinic leads to sql injection. It is possible to launch the attack remotely. The exploit has been…
AnalizadaMedia (5.5)0.45%💥 PoCAnisha Online Appointment Booking System17/7/202517/6/2026
A vulnerability was found in code-projects Online Appointment Booking System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/adddoctor.php. The manipulation of the argument Username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…
AnalizadaMedia (5.5)0.44%—Anisha Online Appointment Booking System17/7/202517/6/2026
A vulnerability was found in code-projects Online Appointment Booking System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/deletedoctor.php. The manipulation of the argument did leads to sql injection. The attack may be launched remotely. The exploit has been…
AnalizadaMedia (5.5)0.45%—Anisha Online Appointment Booking System17/7/202517/6/2026
A vulnerability has been found in code-projects Online Appointment Booking System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/addclinic.php. The manipulation of the argument cid leads to sql injection. The attack can be launched remotely. The exploit…
AnalizadaMedia (5.5)0.45%—Anisha Online Appointment Booking System17/7/202517/6/2026
A vulnerability, which was classified as critical, was found in code-projects Online Appointment Booking System 1.0. Affected is an unknown function of the file /admin/adddoctorclinic.php. The manipulation of the argument clinic leads to sql injection. It is possible to launch the attack remotely. The exploit has been…