Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
1917 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.1) | 0.55% | — | IBM Qradar Security Information AND Event Manager | 19/6/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 could allow a privileged user to modify configuration files that would allow the upload of a malicious autoupdate file to execute arbitrary commands. | |
| Aplazada | Media (5.4) | 0.26% | — | Euroinformation MoneticopaiementAIPrestashopAI | 12/6/2025 | 17/6/2026 | Multiple SQL injection vulnerabilities in the EuroInformation MoneticoPaiement module before 1.1.1 for PrestaShop allow remote attackers to execute arbitrary SQL commands via the TPE, societe, MAC, reference, or aliascb parameter to transaction.php, validation.php, or callback.php. | |
| Aplazada | Media (5.5) | 0.29% | — | Developer FormatterAI | 6/6/2025 | 17/6/2026 | The Developer Formatter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS in all versions up to, and including, 2015.0.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject… | |
| Analizada | Media (6.5) | 0.22% | — | IBM Infosphere Information ServerIBM Infosphere Information Server ON Cloud | 1/6/2025 | 17/6/2026 | IBM InfoSphere Information Server 11.7 stores credential information for database authentication in a cleartext parameter file that could be viewed by an authenticated user. | |
| Analizada | Media (4.3) | 0.28% | — | IBM Infosphere Information ServerIBM Infosphere Information Server ON Cloud | 15/5/2025 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could disclose sensitive information to an authenticated user that could aid in further attacks against the system through a directory listing. | |
| Aplazada | Alta (7.7) | 0.35% | — | SAP Landscape TransformationAI | 13/5/2025 | 17/6/2026 | Under certain conditions, SAP Landscape Transformation's PCL Basis module does not perform the necessary authorization checks, allowing authenticated users to access restricted functionalities or data. This can lead to a high impact on confidentiality with no impact on the integrity or availability of the application. | |
| Aplazada | Alta (7.3) | 0.20% | — | Shanghai Bairui Information Technology SunloginclientAI | 11/5/2025 | 17/6/2026 | A vulnerability classified as critical has been found in Shanghai Bairui Information Technology SunloginClient 15.8.3.19819. This affects an unknown part in the library process.dll of the file sunlogin_guard.exe. The manipulation leads to uncontrolled search path. Local access is required to approach this attack. The… | |
| Analizada | Media (5.4) | 0.28% | — | Giorgi Formality | 2/5/2025 | 17/6/2026 | The Formality plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ parameter in all versions up to, and including, 1.5.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Analizada | Media (4.8) | 0.35% | — | Fabian Student Information Management System | 29/4/2025 | 17/6/2026 | A vulnerability was found in code-projects Student Information Management System 1.0 and classified as critical. Affected by this issue is the function cancel. The manipulation of the argument first_name/last_name leads to stack-based buffer overflow. The attack needs to be approached locally. The exploit has been… | |
| Analizada | Crítica (9.8) | 0.48% | — | Newforma Project Center | 28/4/2025 | 17/6/2026 | Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed. | |
| Analizada | Crítica (9.8) | 1.6% | — | Academiaerp Student Information System | 26/4/2025 | 17/6/2026 | An arbitrary file upload vulnerability via writefile.php of Serosoft Academia Student Information System (SIS) EagleR-1.0.118 allows attackers to execute arbitrary code via ../ in the filePath parameter. | |
| Analizada | Baja (3.7) | 0.18% | — | IBM Infosphere Information Server | 23/4/2025 | 17/6/2026 | IBM InfoSphere Information Server 11.7 DataStage Flow Designer transmits sensitive information via URL or query parameters that could be exposed to an unauthorized actor using man in the middle techniques. | |
| Analizada | Media (4.3) | 0.30% | — | IBM Infosphere Information Server | 23/4/2025 | 17/6/2026 | IBM InfoSphere Information 11.7 Server authenticated user to obtain sensitive information when a detailed technical error message is returned in a request. This information could be used in further attacks against the system. | |
| Analizada | Media (6.3) | 0.25% | — | IBM Infosphere Information Server | 23/4/2025 | 17/6/2026 | IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. | |
| Aplazada | Crítica (9.8) | 0.42% | — | HPE Performance Cluster ManagerAI | 22/4/2025 | 17/6/2026 | A vulnerability in the cmdb service of the HPE Performance Cluster Manager (HPCM) could allow an attacker to gain access to an arbitrary file on the server host. | |
| Analizada | Alta (8.1) | 0.41% | — | HPE Performance Cluster Manager | 21/4/2025 | 17/6/2026 | A vulnerability in the HPE Performance Cluster Manager (HPCM) GUI could allow an attacker to bypass authentication. | |
| Aplazada | Media (6.6) | 0.49% | 💥 PoC | Internet-formation Wp-advanced-searchAI | 16/4/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Mathieu Chartier WP-Advanced-Search wp-advanced-search allows Upload a Web Shell to a Web Server.This issue affects WP-Advanced-Search: from n/a through <= 3.3.9.4. | |
| Aplazada | Media (4.3) | 0.21% | — | Bjoern WP Performance PackAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Bjoern WP Performance Pack wp-performance-pack allows Cross Site Request Forgery.This issue affects WP Performance Pack: from n/a through <= 2.5.4. | |
| Aplazada | Crítica (9.9) | 0.74% | — | SAP Landscape TransformationAI | 8/4/2025 | 17/6/2026 | SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor,… | |
| Aplazada | Media (5.3) | 0.50% | — | Smackcoders INC AIO Performance Profiler Monitor Optimize Compress DebugAI | 1/4/2025 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in Smackcoders Inc., AIO Performance Profiler, Monitor, Optimize, Compress & Debug all-in-one-performance-accelerator allows Retrieve Embedded Sensitive Data.This issue affects AIO Performance Profiler, Monitor, Optimize, Compress & Debug: from n/a through… | |
| Analizada | Media (6.1) | 0.26% | — | Formatter Suite Project Formatter Suite | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Formatter Suite allows Cross-Site Scripting (XSS).This issue affects Formatter Suite: from 0.0.0 before 2.1.0. | |
| Analizada | Media (6.1) | 0.26% | — | Chapterthree Rapidoc OAS Field Formatter | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal RapiDoc OAS Field Formatter allows Cross-Site Scripting (XSS).This issue affects RapiDoc OAS Field Formatter: from 0.0.0 before 1.0.1. | |
| Analizada | Media (6.1) | 0.26% | — | Upstreamable Link Field Display Mode Formatter | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Link field display mode formatter allows Cross-Site Scripting (XSS).This issue affects Link field display mode formatter: from 0.0.0 before 1.6.0. | |
| Analizada | Media (5.3) | 0.35% | — | IBM Infosphere Information Server | 29/3/2025 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | |
| Analizada | Alta (7.5) | 0.30% | — | IBM Infosphere Information Server | 29/3/2025 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could disclose sensitive user credentials from log files during new installation of the product. |