Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1917 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.19%—Qianjin Network Information Technology 51jobAI27/2/202517/6/2026
An issue in Qianjin Network Information Technology (Shanghai) Co., Ltd 51Job iOS 14.22.0 allows attackers to access sensitive user information via supplying a crafted link.
AplazadaMedia (6.9)1.1%💥 ExploitAnhui Xufan Information Technology EasycvrAI23/2/202517/6/2026
A vulnerability has been found in Anhui Xufan Information Technology EasyCVR up to 2.7.0 and classified as problematic. This vulnerability affects unknown code of the file /api/v1/getbaseconfig. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to…
ModificadaMedia (5.4)0.39%—Wp-formassembly18/2/202517/6/2026
The WP-FormAssembly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'formassembly' shortcode in all versions up to, and including, 2.0.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AnalizadaAlta (7.5)0.18%—Intel Integrated Performance Primitives Cryptography14/2/202517/6/2026
Generation of weak initialization vector in an Intel(R) IPP Cryptography software library before version 2021.5 may allow an unauthenticated user to potentially enable information disclosure via local access.
AnalizadaMedia (4.8)0.23%—IBM Qradar Security Information AND Event Manager14/2/202517/6/2026
IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AplazadaAlta (7.1)0.15%—Jensmueller Easy Amazon Product InformationAI13/2/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in jensmueller Easy Amazon Product Information easy-amazon-product-information allows Stored XSS.This issue affects Easy Amazon Product Information: from n/a through <= 4.0.1.
AplazadaMedia (6.1)0.32%—Netvision Information IsoinightAI11/2/202517/6/2026
NetVision Information ISOinsight has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript code in the user's browser through phishing techniques.
AplazadaAlta (7.5)0.47%—Php-date-formatterAI5/2/202517/6/2026
A prototype pollution in the lib function of php-date-formatter v1.3.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.
AnalizadaMedia (6.5)0.15%—IBM Qradar Security Information AND Event Manager28/1/202517/6/2026
IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication channel that could be obtained by an unauthorized actor using man in the middle techniques.
AplazadaMedia (6.5)0.32%—Shanghai Xuan Ting Entertainment Information AND Technology Qidian ReaderAI27/1/202517/6/2026
An issue in Shanghai Xuan Ting Entertainment Information & Technology Co., Ltd Qidian Reader iOS 5.9.384 allows attackers to access sensitive user information via supplying a crafted link.
AplazadaMedia (6.5)0.32%—Shanghai Shizhi Information Technology ShihuoAI27/1/202517/6/2026
An issue in Shanghai Shizhi Information Technology Co., Ltd Shihuo iOS 8.16.0 allows attackers to access sensitive user information via supplying a crafted link.
AplazadaMedia (6.5)0.32%—Tianjin Xiaowu Information Technology CO LTD Beike Holdings IOSAI27/1/202517/6/2026
An issue in Tianjin Xiaowu Information technology Co., Ltd BeiKe Holdings iOS 1.3.50 allows attackers to access sensitive user information via supplying a crafted link.
AnalizadaMedia (4.3)0.38%—IBM Infosphere Information Server24/1/202517/6/2026
IBM InfoSphere Information Server 11.7 could allow a remote user to obtain sensitive version information that could aid in further attacks against the system.
AplazadaMedia (5.5)0.22%—Uyumsoft Informatin Systems Uyumsoft ERPAI23/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uyumsoft Informatin Systems Uyumsoft ERP allows XSS Using Invalid Characters, Reflected XSS. This issue affects Uyumsoft ERP: before Erp4.2109.166p45.
AplazadaAlta (7.1)0.37%—Kiroro Formatted PostAI22/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kiroro Formatted post formatted-post allows Reflected XSS.This issue affects Formatted post: from n/a through <= 1.01.
AplazadaMedia (6.1)0.41%—InformationpushAI17/1/202517/6/2026
Cross Site Scripting vulnerability in InformationPush master version allows a remote attacker to obtain sensitive information via the title, time and msg parameters
AnalizadaAlta (7.5)0.61%—IBM Infosphere Information Server17/1/202517/6/2026
IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
AplazadaMedia (6.5)0.21%—Villatheme Advanced Product Information FOR WoocommerceAI9/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Advanced Product Information for WooCommerce woo-advanced-product-information allows Stored XSS.This issue affects Advanced Product Information for WooCommerce: from n/a through <= 1.1.4.
AplazadaAlta (7.1)0.32%—Scott Farrell WP Hosting Performance CheckAI9/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Farrell wp Hosting Performance Check wp-hosting-performance-check allows Reflected XSS.This issue affects wp Hosting Performance Check: from n/a through <= 2.18.8.
ModificadaMedia (6.5)0.35%—Mbilalm Urdu Formatter7/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M Bilal M Urdu Formatter – Shamil urdu-formatter-shamil allows Stored XSS.This issue affects Urdu Formatter – Shamil: from n/a through <= 0.1.
AplazadaMedia (6.5)0.34%—FormafzarAI7/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in formafzar فرم ساز فرم افزار formafzar allows Stored XSS.This issue affects فرم ساز فرم افزار: from n/a through <= 2.0.
AplazadaMedia (6.4)0.31%—FormalooAI7/1/202517/6/2026
The Formaloo Form Maker & Customer Analytics for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'formaloo' shortcode in all versions up to, and including, 2.1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AplazadaMedia (4.3)0.19%—Swift Performance LiteAI2/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in swte Swift Performance Lite swift-performance-lite allows Cross Site Request Forgery.This issue affects Swift Performance Lite: from n/a through <= 2.3.6.20.
AplazadaMedia (6.5)0.32%—Torod Company FOR Information Technology TorodAI31/12/202417/6/2026
Missing Authorization vulnerability in Torod Company for Information Technology Torod torod allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Torod: from n/a through <= 1.7.
AplazadaAlta (8.8)0.72%—Changing Information Technology CgfidoAI31/12/202417/6/2026
The login mechanism via device authentication of CGFIDO from Changing Information Technology has an Authentication Bypass vulnerability. If a user visits a forged website, the agent program deployed on their device will send an authentication signature to the website. An unauthenticated remote attacker who obtains…