Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
3560 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.23% | — | Wawp Automation-web-platformAI | 31/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Information Technology Wawp automation-web-platform allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wawp: from n/a through <= 4.4. | |
| Modificada | Crítica (9.8) | 0.41% | — | Matio Project Matio | 30/12/2025 | 30/9/2026 | An issue was discovered in matio 1.5.28. A heap-based memory corruption can occur in Mat_VarCreateStruct() when the nfields value does not match the actual number of strings in the fields array. This leads to out-of-bounds reads and invalid memory frees during cleanup, potentially causing a segmentation fault or heap… | |
| Aplazada | Media (5.1) | 0.24% | — | Netvision Information IsoinsightAI | 30/12/2025 | 7/10/2026 | ISOinsight developed by NetVision Information has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks. | |
| Aplazada | Alta (8.6) | 0.05% | — | Kings Information & Network Kess EnterpriseAI | 29/12/2025 | 7/10/2026 | Exposure of Sensitive Information to an Unauthorized Actor, Missing Encryption of Sensitive Data, Files or Directories Accessible to External Parties vulnerability in Kings Information & Network Co. KESS Enterprise on Windows allows Privilege Escalation, Modify Existing Service, Modify Shared File.This issue affects… | |
| Aplazada | Alta (7.6) | 0.33% | — | Verisay Communication AND Information Technology Industry AND Trade TrizbiAI | 25/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Communication and Information Technology Industry and Trade Ltd. Co. Trizbi allows Cross-Site Scripting (XSS). This issue affects Trizbi: before 2.144.4. | |
| Aplazada | Alta (7.6) | 0.31% | — | Verisay Communication AND Information Technology Industry AND Trade TitarusAI | 25/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Communication and Information Technology Industry and Trade Ltd. Co. Titarus allows Cross-Site Scripting (XSS). This issue affects Titarus: before 2.144.4. | |
| Aplazada | Alta (7.6) | 0.31% | — | Verisay Communication AND Information Technology Industry AND Trade LTD CO AidangoAI | 25/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Communication and Information Technology Industry and Trade Ltd. Co. Aidango allows Cross-Site Scripting (XSS). This issue affects Aidango: before 2.144.4. | |
| Analizada | Media (5.5) | 0.38% | — | Fabian Student Information System | 24/12/2025 | 17/6/2026 | A flaw has been found in code-projects Student Information System 1.0. This issue affects some unknown processing of the file /searchresults.php. Executing manipulation of the argument searchbox can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. | |
| Analizada | Baja (2) | 0.26% | — | Fabian Student Information System | 24/12/2025 | 17/6/2026 | A vulnerability was detected in code-projects Student Information System 1.0. This vulnerability affects unknown code of the file /profile.php. Performing manipulation of the argument firstname/lastname results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and… | |
| Aplazada | Alta (7.3) | 0.25% | — | Inductiveautomation IgnitionAI | 18/12/2025 | 28/8/2026 | Ignition by Inductive Automation, when installed with default OS service account settings, may expose the host system to an elevated code execution risk via the gateway backup restore functionality. An authenticated user with Gateway Administrator privileges can import a malicious gateway backup (.gwbk) file… | |
| Aplazada | Media (6.3) | 0.21% | — | Proliz Software LTD OBS Student Affairs Information SystemAI | 17/12/2025 | 28/9/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Software Ltd. OBS (Student Affairs Information System)0 allows Reflected XSS. This issue affects OBS (Student Affairs Information System)0: before 26.5009. | |
| Analizada | Alta (8.1) | 13% | — | Systeminformation | 16/12/2025 | 30/9/2026 | systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` function in systeminformation is vulnerable to OS command injection on Windows systems. The optional `drive` parameter is directly concatenated into a PowerShell command without sanitization, allowing… | |
| Aplazada | Alta (7.1) | 0.20% | — | Rockwellautomation Micro850AIRockwellautomation Micro870AI | 15/12/2025 | 7/10/2026 | A security issue was found in the IPv6 stack in the Micro850 and Micro870 controllers when the controllers received multiple malformed packets during fuzzing. The controllers will go into recoverable fault with fault code 0xFE60. To recover the controller, clear the fault. | |
| Aplazada | Alta (7.6) | 0.25% | — | Netiket Information Technologies ApplylogicAI | 11/12/2025 | 7/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Netiket Information Technologies Ltd. Co. ApplyLogic allows Exploitation of Trusted Identifiers. This issue affects ApplyLogic: through 01.12.2025. | |
| Analizada | Media (6.5) | 0.39% | — | Pagerduty Runbook Automation | 10/12/2025 | 17/6/2026 | PagerDuty Runbook through 2025-06-12 exposes stored secrets directly in the webpage DOM at the configuration page. Although these secrets appear masked as password fields, the actual secret values are present in the page source and can be revealed by simply modifying the input field type from "password" to "text"… | |
| Aplazada | Media (4.3) | 0.22% | — | IM Park Information Technology Electronics Press Publishing AND Advertising Education LTD CO DijidemiAI | 10/12/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Im Park Information Technology, Electronics, Press, Publishing and Advertising, Education Ltd. Co. DijiDemi allows Exploitation of Trusted Identifiers. This issue affects DijiDemi: through 28.11.2025. | |
| Aplazada | Baja (3.5) | 0.20% | — | TAC Information Services Internal AND External Trade INC GoldenhornAI | 10/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TAC Information Services Internal and External Trade Inc. GoldenHorn allows Cross-Site Scripting (XSS). This issue affects GoldenHorn: before 4.25.1121.1. | |
| Aplazada | Crítica (9.3) | 0.57% | — | GTT TAX Information SystemAI | 10/12/2025 | 17/6/2026 | Bypass vulnerability in the authentication method in the GTT Tax Information System application, related to the Active Directory (LDAP) login method. Authentication is performed through a local WebSocket, but the web application does not properly validate the authenticity or origin of the data received, allowing an… | |
| Aplazada | Alta (7.1) | 0.21% | — | Nomysoft Information Technology Training AND Consulting INC NomysemAI | 10/12/2025 | 17/6/2026 | Incorrect Use of Privileged APIs vulnerability in NomySoft Information Technology Training and Consulting Inc. Nomysem allows Privilege Escalation. This issue affects Nomysem: through May 2025. | |
| Aplazada | Alta (8.7) | 0.37% | — | Automation Systems Engineering 432es-ig3 Series AAIAutomation Systems Engineering Guardlink Ethernet IP InterfaceAI | 9/12/2025 | 17/6/2026 | A security issue exists within 432ES-IG3 Series A, which affects GuardLink® EtherNet/IP Interface, resulting in denial-of-service. A manual power cycle is required to recover the device. | |
| Aplazada | Media (5.4) | 0.19% | — | Talent Software E-bap AutomationAI | 9/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Software e-BAP Automation allows Reflected XSS. This issue affects e-BAP Automation: before 42957. | |
| Aplazada | Media (6.5) | 0.32% | — | Wealcoder Animation Addons FOR ElementorAI | 9/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Wealcoder Animation Addons for Elementor animation-addons-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Animation Addons for Elementor: from n/a through <= 2.4.5. | |
| Aplazada | Media (4.3) | 0.13% | — | Flashyapp WP Flashy Marketing AutomationAI | 9/12/2025 | 7/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Flashyapp WP Flashy Marketing Automation wp-flashy-marketing-automation allows Cross Site Request Forgery.This issue affects WP Flashy Marketing Automation: from n/a through <= 2.0.8. | |
| Aplazada | Media (5.3) | 0.32% | — | Talent Software E-bap AutomationAI | 9/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Software e-BAP Automation allows Cross-Site Scripting (XSS). This issue affects e-BAP Automation: from 1.8.96 before v.41815. | |
| Analizada | Baja (2.7) | 0.29% | — | IBM Qradar Security Information AND Event Manager | 9/12/2025 | 1/10/2026 | IBM QRadar SIEM 7.5 - 7.5.0 UP14 IF01 is affected by an information disclosure vulnerability involving exposure of directory information. IBM has addressed this vulnerability in the latest update. |