Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
3560 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.16% | — | IBM Infosphere Information Server | 8/12/2025 | 7/10/2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Analizada | Crítica (9.1) | 0.41% | — | Sprecher-automation Sprecon-e-c FirmwareSprecher-automation Sprecon-e-p FirmwareSprecher-automation Sprecon-e-t3 Firmware | 2/12/2025 | 25/9/2026 | Sprecher Automations SPRECON-E series uses default cryptographic keys that allow an unprivileged remote attacker to access all encrypted communications, thereby compromising confidentiality and integrity. | |
| Analizada | Media (4) | 0.07% | — | Sprecher-automation Sprecon-e-c FirmwareSprecher-automation Sprecon-e-p FirmwareSprecher-automation Sprecon-e-t3 Firmware | 2/12/2025 | 25/9/2026 | Insufficient encryption strength in Sprecher Automation SPRECON-E-C, SPRECON-E-P, and SPRECON-E-T3 allows a local unprivileged attacker to extract data from update images and thus obtain limited information about the architecture and internal processes. | |
| Analizada | Crítica (9.8) | 0.46% | — | Sprecher-automation Sprecon-e-c FirmwareSprecher-automation Sprecon-e-p FirmwareSprecher-automation Sprecon-e-t3 Firmware | 2/12/2025 | 25/9/2026 | Sprecher Automations SPRECON-E-C, SPRECON-E-P, SPRECON-E-T3 is vulnerable to attack by an unauthorized remote attacker via default cryptographic keys. The use of these keys allows the attacker to read, modify, and write projects and data, or to access any device via remote maintenance. | |
| Analizada | Baja (2.1) | 0.31% | — | Facebook-julykringcadayona Student Information System | 24/11/2025 | 17/6/2026 | A vulnerability was identified in itsourcecode Student Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /schedule_edit1.php. Such manipulation of the argument schedule_id leads to sql injection. The attack may be launched remotely. The exploit is publicly available and… | |
| Analizada | Baja (2.1) | 0.31% | — | Facebook-julykringcadayona Student Information System | 18/11/2025 | 17/6/2026 | A vulnerability was determined in itsourcecode Student Information System 1.0. The affected element is an unknown function of the file /enrollment_edit1.php. Executing manipulation of the argument en_id can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may… | |
| Analizada | Baja (2) | 0.26% | — | Fabian Student Information System | 16/11/2025 | 17/6/2026 | A vulnerability was identified in code-projects Student Information System 2.0. The impacted element is an unknown function of the file /editprofile.php. Such manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used. | |
| Analizada | Baja (2.1) | 0.36% | — | Fabian Student Information System | 16/11/2025 | 17/6/2026 | A vulnerability was determined in code-projects Student Information System 2.0. The affected element is an unknown function of the file /register.php. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Baja (2.1) | 0.35% | — | Fabian Student Information System | 16/11/2025 | 17/6/2026 | A vulnerability was found in code-projects Student Information System 2.0. Impacted is an unknown function of the file /editprofile.php. The manipulation results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. | |
| Analizada | Media (5.5) | 0.43% | — | Fabian Student Information System | 16/11/2025 | 17/6/2026 | A vulnerability has been found in code-projects Student Information System 2.0. This issue affects some unknown processing of the file /register.php. The manipulation leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (5.5) | 0.43% | — | Fabian Student Information System | 16/11/2025 | 17/6/2026 | A flaw has been found in code-projects Student Information System 2.0. This vulnerability affects unknown code of the file /index.php. Executing manipulation of the argument Username can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. | |
| Analizada | Media (5.5) | 0.43% | — | Fabian Student Information System | 16/11/2025 | 17/6/2026 | A vulnerability was detected in code-projects Student Information System 2.0. This affects an unknown part of the file /searchquery.php. Performing manipulation of the argument s results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. | |
| Analizada | Alta (7.1) | 0.16% | — | Rockwellautomation Arena | 14/11/2025 | 7/10/2026 | Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the parsing of DOE files. Local attackers are able to exploit this issue to potentially execute arbitrary code on affected installations of Arena®. Exploiting the vulnerability requires opening a… | |
| Aplazada | Alta (8.1) | 0.37% | — | Optimus Brokerage AutomationAI | 14/11/2025 | 7/10/2026 | Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechanism for Forgotten Password, Authentication Bypass by Assumed-Immutable Data vulnerability in Optimus Software Brokerage Automation allows Exploiting Trust in Client, Authentication Bypass, Manipulate Registry Information. This issue affects… | |
| Analizada | Media (6.5) | 0.24% | — | IBM Qradar Security Information AND Event Manager | 12/11/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5.0 UP14 stores user credentials in configuration files in source control which can be read by an authenticated user. | |
| Aplazada | Alta (7.3) | 0.25% | — | Divvydrive Information Technologies INC Digital Corporate WarehouseAI | 12/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in DivvyDrive Information Technologies Inc. Digital Corporate Warehouse allows Stored XSS. This issue affects Digital Corporate Warehouse: before v.4.8.2.22. | |
| Aplazada | Alta (8.1) | 0.28% | — | Premierturk Information Technologies INC Excavation Management Information SystemAI | 11/11/2025 | 17/6/2026 | Files or Directories Accessible to External Parties, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Premierturk Information Technologies Inc. Excavation Management Information System allows Footprinting, Functionality Misuse. This issue affects Excavation Management Information… | |
| Aplazada | Alta (8.9) | 0.14% | — | Rockwellautomation Studio 5000 Simulation InterfaceAI | 11/11/2025 | 17/6/2026 | A local code execution security issue exists within Studio 5000® Simulation Interface™ via the API. This vulnerability allows any Windows user on the system to extract files using path traversal sequences, resulting in execution of scripts with Administrator privileges on system reboot. | |
| Aplazada | Alta (8.9) | 0.17% | — | Rockwellautomation Studio 5000 Simulation InterfaceAI | 11/11/2025 | 17/6/2026 | A local server-side request forgery (SSRF) security issue exists within Studio 5000® Simulation Interface™ via the API. This vulnerability allows any Windows user on the system to trigger outbound SMB requests, enabling the capture of NTLM hashes. | |
| Analizada | Media (6.1) | 0.21% | — | IBM Business Automation WorkflowIBM Process Federation Server | 6/11/2025 | 17/6/2026 | IBM Business Automation Workflow containers 24.0.0 through 24.0.0-IF006, 24.0.1 through 24.0.1-IF004, 25.0.0 through 25.0.0-IF001 and IBM Business Automation Workflow traditional with Process Federation Server 24.0.0 through 24.0.1 and 25.0.0 are vulnerable to cross-site scripting. This vulnerability allows an… | |
| Analizada | Media (4.3) | 0.26% | — | Funnelkit Automations | 5/11/2025 | 17/6/2026 | The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.6.4.1. This is due to the plugin not properly verifying that a user is authorized to perform administrative actions in the… | |
| Analizada | Media (5.3) | 0.37% | — | Funnelkit Automations | 5/11/2025 | 17/6/2026 | The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.4.1 via the '/wc-coupons/' REST API endpoint. This is due to the endpoint being marked as a public API (`public_api =… | |
| Analizada | Media (5.4) | 0.18% | — | IBM Cloud PAK FOR Business Automation | 3/11/2025 | 17/6/2026 | IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 001, 24.0.1 through 24.0.1 Interim Fix 004, 24.0.0 through 24.0.0 Interim Fix 006, and earlier unsupported releases IBM Business Automation Workflow is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to… | |
| Analizada | Crítica (9.1) | 0.76% | — | IBM Infosphere Information Server | 3/11/2025 | 17/6/2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | |
| Analizada | Alta (7.4) | 0.27% | — | IBM Cloud PAK FOR Business Automation | 3/11/2025 | 17/6/2026 | IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an attacker to access unauthorized content or perform unauthorized actions using man in the middle techniques due to improper access controls. |