Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

4214 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.51%—Anisha Online Appointment Booking System17/7/202517/6/2026
A vulnerability, which was classified as critical, has been found in code-projects Online Appointment Booking System 1.0. This issue affects some unknown processing of the file /admin/getmanagerregion.php. The manipulation of the argument city leads to sql injection. The attack may be initiated remotely. The exploit…
AnalizadaAlta (7.5)0.46%—IBM Websphere Application Server16/7/202517/6/2026
IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 are vulnerable to a denial of service, caused by a stack-based overflow. An attacker can send a specially crafted request that cause the server to consume excessive memory resources.
AnalizadaMedia (5.5)0.49%—Anisha Online Appointment Booking System14/7/202517/6/2026
A vulnerability was found in code-projects Online Appointment Booking System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /cover.php. The manipulation of the argument uname/psw leads to sql injection. The attack may be launched remotely. The exploit has been…
AnalizadaMedia (5.5)0.52%—Anisha Online Appointment Booking System13/7/202517/6/2026
A vulnerability has been found in code-projects Online Appointment Booking System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /get_town.php. The manipulation of the argument countryid leads to sql injection. The attack can be launched remotely. The exploit has…
AnalizadaMedia (5.5)0.45%—Anisha Online Appointment Booking System13/7/202517/6/2026
A vulnerability, which was classified as critical, was found in code-projects Online Appointment Booking System 1.0. Affected is an unknown function of the file /getclinic.php. The manipulation of the argument townid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed…
AnalizadaMedia (5.5)0.45%—Anisha Online Appointment Booking System13/7/202517/6/2026
A vulnerability, which was classified as critical, has been found in code-projects Online Appointment Booking System 1.0. This issue affects some unknown processing of the file /getdoctordaybooking.php. The manipulation of the argument cid leads to sql injection. The attack may be initiated remotely. The exploit has…
AnalizadaMedia (5.5)0.45%—Anisha Online Appointment Booking System13/7/202517/6/2026
A vulnerability, which was classified as critical, has been found in code-projects Online Appointment Booking System 1.0. This issue affects some unknown processing of the file /getDay.php. The manipulation of the argument cidval leads to sql injection. The attack may be initiated remotely. The exploit has been…
AnalizadaMedia (5.5)0.45%—Anisha Online Appointment Booking System13/7/202517/6/2026
A vulnerability classified as critical was found in code-projects Online Appointment Booking System 1.0. This vulnerability affects unknown code of the file /cancelbookingpatient.php. The manipulation of the argument appointment leads to sql injection. The attack can be initiated remotely. The exploit has been…
AnalizadaMedia (5.5)0.45%—Anisha Online Appointment Booking System13/7/202517/6/2026
A vulnerability classified as critical has been found in code-projects Online Appointment Booking System 1.0. This affects an unknown part of the file /ulocateus.php. The manipulation of the argument doctorname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to…
ModificadaMedia (5.5)0.17%—Redhat Data GridRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Expansion PackInfinispan26/6/202517/6/2026
A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.
AnalizadaCrítica (9.8)13%—IBM Websphere Application Server25/6/202517/6/2026
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects.
AplazadaCrítica (10)0.32%—Ataturk University Ata-aof Mobile ApplicationAI24/6/202517/6/2026
Cleartext Transmission of Sensitive Information, Use of Hard-coded Credentials vulnerability in Ataturk University ATA-AOF Mobile Application allows Authentication Abuse, Authentication Bypass. This issue affects ATA-AOF Mobile Application: before 20.06.2025.
AplazadaMedia (6.4)0.29%—Simply Schedule Appointments Appointment Booking CalendarAI14/6/202517/6/2026
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ssa_admin_upcoming_appointments, ssa_admin_upcoming_appointments, and ssa_past_appointments shortcodes in all versions up to, and including, 1.6.8.30 due to…
AplazadaBaja (2.9)0.48%—Tenda Tdsee APPAI9/6/202517/6/2026
A vulnerability was found in Tenda TDSEE App up to 1.7.12. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /app/ConfirmSmsCode of the component Password Reset Confirmation Code Handler. The manipulation leads to improper restriction of excessive…
AplazadaMedia (4.3)0.18%—Fasterthemes Fastbook Responsive Appointment Booking AND Scheduling SystemAI6/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in FasterThemes FastBook fastbook-responsive-appointment-booking-and-scheduling-system allows Cross Site Request Forgery.This issue affects FastBook: from n/a through <= 1.1.
AnalizadaMedia (5.5)0.10%—Wire-webapp22/5/202517/6/2026
wire-webapp is the web application for the open-source messaging service Wire. A bug fix caused a regression causing an issue with function to delete local data. Instructing the client to delete its local database on user logout does not result in deletion. This is the case for both temporary clients (marking the…
AplazadaMedia (5.6)0.14%—Wire-webappAI22/5/202517/6/2026
wire-webapp is the web application for the open-source messaging service Wire. A change caused a regression resulting in sessions not being properly invalidated. A user that logged out of the Wire webapp, could have been automatically logged in again after re-opening the application. This does not happen when the user…
AplazadaAlta (8.8)0.34%—Rocketapps WprojectAI19/5/202517/6/2026
Incorrect Privilege Assignment vulnerability in Rocket Apps wProject.This issue affects wProject: from n/a before 5.8.0.
AplazadaAlta (7.1)0.22%—Rocketapps WprojectAI19/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rocket Apps wProject allows Reflected XSS.This issue affects wProject: from n/a before 5.8.0.
AplazadaAlta (8.2)0.32%—Rocketapps WprojectAI19/5/202517/6/2026
Missing Authorization vulnerability in Rocket Apps wProject.This issue affects wProject: from n/a before 5.8.0.
AnalizadaAlta (7.6)0.24%—IBM Websphere Application Server14/5/202517/6/2026
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AplazadaAlta (8.8)0.19%—Webappick ChallanAIWebappick PDF Invoice FOR WoocommerceAI7/5/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WebAppick Challan webappick-pdf-invoice-for-woocommerce allows Privilege Escalation.This issue affects Challan: from n/a through <= 3.7.58.
AnalizadaAlta (7.5)0.95%—Apache HttpclientNetapp Ontap Tools24/4/202517/6/2026
A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release
AnalizadaBaja (2.7)0.34%—IBM Websphere Application Server22/4/202517/6/2026
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
AplazadaAlta (7.1)0.29%—Weptile Mobile APP FOR WoocommerceAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weptile Mobile App for WooCommerce mobile-app-for-woocommerce allows Stored XSS.This issue affects Mobile App for WooCommerce: from n/a through <= 0.4.61.