Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1917 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.19% | — | Qianjin Network Information Technology 51jobAI | 27/2/2025 | 17/6/2026 | An issue in Qianjin Network Information Technology (Shanghai) Co., Ltd 51Job iOS 14.22.0 allows attackers to access sensitive user information via supplying a crafted link. | |
| Aplazada | Media (6.9) | 1.1% | 💥 Exploit | Anhui Xufan Information Technology EasycvrAI | 23/2/2025 | 17/6/2026 | A vulnerability has been found in Anhui Xufan Information Technology EasyCVR up to 2.7.0 and classified as problematic. This vulnerability affects unknown code of the file /api/v1/getbaseconfig. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Modificada | Media (5.4) | 0.39% | — | Wp-formassembly | 18/2/2025 | 17/6/2026 | The WP-FormAssembly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'formassembly' shortcode in all versions up to, and including, 2.0.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Alta (7.5) | 0.18% | — | Intel Integrated Performance Primitives Cryptography | 14/2/2025 | 17/6/2026 | Generation of weak initialization vector in an Intel(R) IPP Cryptography software library before version 2021.5 may allow an unauthenticated user to potentially enable information disclosure via local access. | |
| Analizada | Media (4.8) | 0.23% | — | IBM Qradar Security Information AND Event Manager | 14/2/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Aplazada | Alta (7.1) | 0.15% | — | Jensmueller Easy Amazon Product InformationAI | 13/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in jensmueller Easy Amazon Product Information easy-amazon-product-information allows Stored XSS.This issue affects Easy Amazon Product Information: from n/a through <= 4.0.1. | |
| Aplazada | Media (6.1) | 0.32% | — | Netvision Information IsoinightAI | 11/2/2025 | 17/6/2026 | NetVision Information ISOinsight has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript code in the user's browser through phishing techniques. | |
| Aplazada | Alta (7.5) | 0.47% | — | Php-date-formatterAI | 5/2/2025 | 17/6/2026 | A prototype pollution in the lib function of php-date-formatter v1.3.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload. | |
| Analizada | Media (6.5) | 0.15% | — | IBM Qradar Security Information AND Event Manager | 28/1/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication channel that could be obtained by an unauthorized actor using man in the middle techniques. | |
| Aplazada | Media (6.5) | 0.32% | — | Shanghai Xuan Ting Entertainment Information AND Technology Qidian ReaderAI | 27/1/2025 | 17/6/2026 | An issue in Shanghai Xuan Ting Entertainment Information & Technology Co., Ltd Qidian Reader iOS 5.9.384 allows attackers to access sensitive user information via supplying a crafted link. | |
| Aplazada | Media (6.5) | 0.32% | — | Shanghai Shizhi Information Technology ShihuoAI | 27/1/2025 | 17/6/2026 | An issue in Shanghai Shizhi Information Technology Co., Ltd Shihuo iOS 8.16.0 allows attackers to access sensitive user information via supplying a crafted link. | |
| Aplazada | Media (6.5) | 0.32% | — | Tianjin Xiaowu Information Technology CO LTD Beike Holdings IOSAI | 27/1/2025 | 17/6/2026 | An issue in Tianjin Xiaowu Information technology Co., Ltd BeiKe Holdings iOS 1.3.50 allows attackers to access sensitive user information via supplying a crafted link. | |
| Analizada | Media (4.3) | 0.38% | — | IBM Infosphere Information Server | 24/1/2025 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could allow a remote user to obtain sensitive version information that could aid in further attacks against the system. | |
| Aplazada | Media (5.5) | 0.22% | — | Uyumsoft Informatin Systems Uyumsoft ERPAI | 23/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uyumsoft Informatin Systems Uyumsoft ERP allows XSS Using Invalid Characters, Reflected XSS. This issue affects Uyumsoft ERP: before Erp4.2109.166p45. | |
| Aplazada | Alta (7.1) | 0.37% | — | Kiroro Formatted PostAI | 22/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kiroro Formatted post formatted-post allows Reflected XSS.This issue affects Formatted post: from n/a through <= 1.01. | |
| Aplazada | Media (6.1) | 0.41% | — | InformationpushAI | 17/1/2025 | 17/6/2026 | Cross Site Scripting vulnerability in InformationPush master version allows a remote attacker to obtain sensitive information via the title, time and msg parameters | |
| Analizada | Alta (7.5) | 0.61% | — | IBM Infosphere Information Server | 17/1/2025 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. | |
| Aplazada | Media (6.5) | 0.21% | — | Villatheme Advanced Product Information FOR WoocommerceAI | 9/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Advanced Product Information for WooCommerce woo-advanced-product-information allows Stored XSS.This issue affects Advanced Product Information for WooCommerce: from n/a through <= 1.1.4. | |
| Aplazada | Alta (7.1) | 0.32% | — | Scott Farrell WP Hosting Performance CheckAI | 9/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Farrell wp Hosting Performance Check wp-hosting-performance-check allows Reflected XSS.This issue affects wp Hosting Performance Check: from n/a through <= 2.18.8. | |
| Modificada | Media (6.5) | 0.35% | — | Mbilalm Urdu Formatter | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M Bilal M Urdu Formatter – Shamil urdu-formatter-shamil allows Stored XSS.This issue affects Urdu Formatter – Shamil: from n/a through <= 0.1. | |
| Aplazada | Media (6.5) | 0.34% | — | FormafzarAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in formafzar فرم ساز فرم افزار formafzar allows Stored XSS.This issue affects فرم ساز فرم افزار: from n/a through <= 2.0. | |
| Aplazada | Media (6.4) | 0.31% | — | FormalooAI | 7/1/2025 | 17/6/2026 | The Formaloo Form Maker & Customer Analytics for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'formaloo' shortcode in all versions up to, and including, 2.1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (4.3) | 0.19% | — | Swift Performance LiteAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in swte Swift Performance Lite swift-performance-lite allows Cross Site Request Forgery.This issue affects Swift Performance Lite: from n/a through <= 2.3.6.20. | |
| Aplazada | Media (6.5) | 0.32% | — | Torod Company FOR Information Technology TorodAI | 31/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Torod Company for Information Technology Torod torod allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Torod: from n/a through <= 1.7. | |
| Aplazada | Alta (8.8) | 0.72% | — | Changing Information Technology CgfidoAI | 31/12/2024 | 17/6/2026 | The login mechanism via device authentication of CGFIDO from Changing Information Technology has an Authentication Bypass vulnerability. If a user visits a forged website, the agent program deployed on their device will send an authentication signature to the website. An unauthenticated remote attacker who obtains… |