Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1917 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 2.7% | 💥 Exploit | Giorgi FormalityAI | 20/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Michele Giorgi Formality formality allows PHP Local File Inclusion.This issue affects Formality: from n/a through <= 1.5.9. | |
| Aplazada | Alta (7) | 0.20% | — | Lenovo 510 FHD WEB CameraAILenovo Performance FHD WEB CameraAI | 18/8/2025 | 17/6/2026 | A potential vulnerability was reported in the Lenovo 510 FHD and Performance FHD web cameras that could allow an attacker with physical access to write arbitrary firmware updates to the device over a USB connection. | |
| Aplazada | Baja (1.9) | 0.14% | — | Euro Information CIC Banque ET Compte EN LigneAI | 18/8/2025 | 17/6/2026 | A vulnerability was found in Euro Information CIC banque et compte en ligne App 12.56.0 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.cic_prod.bad. The manipulation leads to improper export of android application components. It is possible… | |
| Aplazada | Alta (7.3) | 0.13% | — | Intel Connectivity Performance SuiteAI | 12/8/2025 | 17/6/2026 | Time-of-check Time-of-use race condition for some Intel(R) Connectivity Performance Suite software installers before version 40.24.11210 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (6.4) | 0.19% | — | Solarwinds Database Performance Analyzer | 12/8/2025 | 17/6/2026 | SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machine-in-the-middle (MITM) attack against users. This vulnerability requires additional software not installed by default, local access to the server and administrator level… | |
| Aplazada | Crítica (9.9) | 0.70% | — | SAP Landscape TransformationAI | 12/8/2025 | 17/6/2026 | SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor,… | |
| Analizada | Media (5.4) | 0.21% | — | IBM Qradar Security Information AND Event Manager | 1/8/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 12 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Aplazada | Crítica (10) | 1.5% | — | SMG Software Information PortalAI | 24/7/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SMG Software Information Portal allows Code Injection, Upload a Web Shell to a Web Server, Code Inclusion. This issue affects Information Portal: before… | |
| Aplazada | Media (6.5) | 0.28% | — | Dataprom Informatics Pacs-acssAI | 23/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dataprom Informatics PACS-ACSS allows Cross-Site Scripting (XSS). This issue affects PACS-ACSS: before 16.05.2025. | |
| Aplazada | Crítica (10) | 0.33% | — | Rolantis Information Technologies AgentisAI | 22/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rolantis Information Technologies Agentis allows SQL Injection. This issue affects Agentis: before 4.32. | |
| Aplazada | Media (6.1) | 0.19% | — | Rolantis Information Technologies AgentisAI | 22/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Rolantis Information Technologies Agentis allows Reflected XSS, DOM-Based XSS. This issue affects Agentis: before 4.32. | |
| Aplazada | Alta (8.7) | 0.42% | — | Unimax Hospital Information SystemAI | 17/7/2025 | 17/6/2026 | The Hospital Information System developed by UNIMAX has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Torod Company FOR Information Technology TorodAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Torod Company for Information Technology Torod torod allows SQL Injection.This issue affects Torod: from n/a through <= 2.1. | |
| Analizada | Media (5.4) | 0.19% | — | IBM Qradar Security Information AND Event Manager | 15/7/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 - 7.5.0 UP12 IF02 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Aplazada | Media (6.9) | 0.37% | — | Ergon Informatik AG Airlock IAMAI | 4/7/2025 | 17/6/2026 | Timing difference in password reset in Ergon Informatik AG's Airlock IAM 7.7.9, 8.0.8, 8.1.7, 8.2.4 and 8.3.1 allows unauthenticated attackers to enumerate usernames. | |
| Aplazada | Crítica (9.8) | 0.40% | — | Case Informatics Case ERPAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Case Informatics Case ERP allows SQL Injection. This issue affects Case ERP: before V2.0.1. | |
| Analizada | Media (5.9) | 0.17% | — | IBM Infosphere Information Server | 26/6/2025 | 17/6/2026 | IBM InfoSphere DataStage Flow Designer in IBM InfoSphere Information Server 11.7 discloses sensitive user information in API requests in clear text that could be intercepted using man in the middle techniques. | |
| Analizada | Ninguna (0) | 0.14% | — | Trellix System Information Reporter | 26/6/2025 | 17/6/2026 | A sensitive information exposure vulnerability in System Information Reporter (SIR) 1.0.3 and prior allows an authenticated non-admin local user to extract sensitive information stored in a registry backup folder. | |
| Analizada | Alta (7.2) | 0.16% | — | Trellix System Information Reporter | 26/6/2025 | 17/6/2026 | A path or symbolic link manipulation vulnerability in SIR 1.0.3 and prior versions allows an authenticated non-admin local user to overwrite system files with SIR backup files, which can potentially cause a system crash. This was achieved by adding a malicious entry to the registry under the Trellix SIR registry… | |
| Analizada | Ninguna (0) | 0.18% | — | Trellix System Information Reporter | 26/6/2025 | 17/6/2026 | A path traversal vulnerability in System Information Reporter (SIR) 1.0.3 and prior allowed an authenticated high privileged user to issue malicious ePO post requests to System Information Reporter, leading to creation of files anywhere on the filesystem and possibly overwriting existing files and exposing sensitive… | |
| Analizada | Alta (7.6) | 0.32% | — | IBM Infosphere Information Server | 25/6/2025 | 17/6/2026 | IBM InfoSphere Information Server 11.7 vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | |
| Analizada | Media (4.3) | 0.22% | — | IBM Infosphere Information Server | 21/6/2025 | 17/6/2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an authenticated user to delete another user's comments due to improper ownership management. | |
| Analizada | Alta (7.5) | 0.44% | — | IBM Infosphere Information Server | 21/6/2025 | 17/6/2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources. | |
| Analizada | Media (6.2) | 0.17% | — | IBM Qradar Security Information AND Event Manager | 19/6/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 stores potentially sensitive information in log files that could be read by a local user. | |
| Analizada | Alta (7.1) | 0.48% | — | IBM Qradar Security Information AND Event Manager | 19/6/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. |