Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

3076 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.67%—Simplyscheduleappointments Appointment Booking CalendarAI28/5/202617/6/2026
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'append_where_sql' parameter in all versions up to, and including, 1.6.11.8 due to insufficient escaping on the user supplied parameter and lack of sufficient…
AnalizadaMedia (6.5)0.45%—IBM Aspera High-speed Transfer EndpointIBM Aspera High-speed Transfer Server27/5/202617/6/2026
IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a potential arbitrary file read in the asperahttpd component. An authenticated user may be able to take advantage…
AnalizadaAlta (7.5)0.48%—IBM Aspera High-speed Transfer EndpointIBM Aspera High-speed Transfer Server27/5/202617/6/2026
IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a potential denial of service in the asperahttpd component. An unauthenticated user can cause the asperahttpd…
AnalizadaAlta (8.8)0.61%—IBM Aspera High-speed Transfer EndpointIBM Aspera High-speed Transfer Server27/5/202617/6/2026
IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a buffer overflow in the asperahttpd component. This vulnerability could allow an authenticated user to execute…
AnalizadaCrítica (9.8)0.94%—IBM Aspera High-speed Transfer EndpointIBM Aspera High-speed Transfer Server27/5/202617/6/2026
IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a buffer overflow in the asperahttpd component. This vulnerability could be exploited to cause a denial of service…
AplazadaMedia (5.3)0.44%—Simply Schedule AppointmentsAI27/5/202623/7/2026
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to denial of service in all versions up to, and including, 1.6.11.5. This is due to a publicly accessible REST API endpoint (/wp-json/ssa/v1/async) that calls PHP's sleep() function on a user-supplied…
AplazadaMedia (5.5)0.55%—Sourcecodester Edoc Doctor Appointment SystemAI26/5/202624/7/2026
A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown part of the file /admin/delete-session.php. The manipulation of the argument ID leads to missing authorization. Remote exploitation of the attack is possible. The exploit has been disclosed publicly…
Pendiente de análisisMedia (4.1)0.26%—Checkpoint Multi-domain ManagementAI26/5/202620/7/2026
When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Compliance Best Practices in another Management Domain, where the administrator has no access permissions, bypassing…
Pendiente de análisisMedia (5.3)0.40%—Checkpoint Http-based ServiceAI26/5/202624/7/2026
A Check Point HTTP-based service can incorrectly handle malformed HTTP requests. The issue is related to HTTP request parsing and validation.
Pendiente de análisisMedia (5.6)0.25%—Checkpoint DLPAICheckpoint Usercheck WEB PortalAI26/5/202624/7/2026
When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific conditions, an attacker who can access the UserCheck Ask page could attempt to manipulate the Security Gateway's stored DLP/UserCheck incident information. This could lead to disruptions such as…
Pendiente de análisisAlta (7.5)0.50%—Checkpoint Identity AwarenessAICheckpoint Security GatewayAI26/5/202624/7/2026
When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway.
AplazadaMedia (4.6)0.20%—Hitachi OPS Center AnalyzerAIHitachi OPS Center Analyzer ViewpointAIHitachi Infrastructure Analytics AdvisorAI26/5/202624/7/2026
Missing password field masking vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view, Hitachi Ops Center Analyzer probe modules), Hitachi Ops Center Analyzer viewpoint, Hitachi Infrastructure Analytics Advisor (Data Center Analytics, Analytics probe modules). This issue affects Hitachi…
AnalizadaAlta (8.8)2.7%⚠ Explotación activa💥 PoCMicrosoft Sharepoint Server22/5/202623/7/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AplazadaMedia (6.3)0.27%—Opensourcepos Open Source Point OF SaleAI18/5/202617/6/2026
A flaw has been found in opensourcepos Open Source Point of Sale up to 3.4.2. Impacted is the function Login of the file app/Models/Employee.php of the component Employee Login. This manipulation causes use of weak hash. Remote exploitation of the attack is possible. The attack is considered to have high complexity.…
AplazadaMedia (5.3)0.57%—Opensourcepos Open Source Point OF SaleAI18/5/202617/6/2026
A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This issue affects the function getPicThumb of the file app/Controllers/Items.php. The manipulation of the argument pic_filename results in path traversal. The attack may be launched remotely. The patch is identified as…
AplazadaMedia (4.3)0.15%—LatepointAI14/5/202617/6/2026
The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 5.3.2. This is due to missing nonce verification on the request_cancellation() function. This makes it possible for unauthenticated attackers to cancel a logged-in customer's bookings via a forged…
AplazadaMedia (5.1)0.29%—Elecom Wireless LAN Access PointAI13/5/202617/6/2026
ELECOM wireless LAN access point devices implement CSRF protection mechanism, but with inadequate handling of CSRF tokens. If a user views a malicious page while logged in, the user may be tricked to do unintended operations.
AplazadaMedia (5.1)0.33%—Elecom Wireless LAN Access PointAI13/5/202617/6/2026
ELECOM wireless LAN access point devices do not check if language parameter has an appropriate value. If a user views a malicious page while logged in, the admin page on the user's web browser may become broken.
AplazadaMedia (4.8)0.25%—Elecom Wireless LAN Access PointAI13/5/202617/6/2026
Stored cross-site scripting vulnerability exists in ELECOM wireless LAN access point devices. If one of the administrators input malicious data, an arbitrary script may be executed in another administrative user's web browser.
AplazadaCrítica (9.3)2.3%—Elecom Wireless LAN Access PointAI13/5/202617/6/2026
ELECOM wireless LAN access point devices contain an OS command injection in processing of username parameter. If processing a crafted request, an arbitrary OS command may be executed. No authentication is required.
AplazadaCrítica (9.3)0.72%—Elecom Wireless LAN Access PointAI13/5/202617/6/2026
ELECOM wireless LAN access point devices do not require authentication to access some specific URLs. The affected product may be operated without authentication.
AplazadaAlta (8.6)1.7%—Elecom Wireless LAN Access PointAI13/5/202617/6/2026
ELECOM wireless LAN access point devices contain an OS command injection vulnerability in processing of ping_ip_addr parameter. If processing a crafted request sent by a logged-in user, an arbitrary OS command may be executed.
AplazadaMedia (6.9)0.12%—Elecom Wireless LAN Access PointAI13/5/202617/6/2026
ELECOM wireless LAN access point devices use a hard-coded cryptographic key when creating backups of configuration files. An attacker who knows the encryption key can tamper the configuration file of the product, and a victim administrator may be tricked to use a crafted configuration file.
AnalizadaMedia (5.5)0.31%—Microsoft Powerpoint12/5/202617/6/2026
Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally.
AnalizadaAlta (8)2.1%—Microsoft Sharepoint Server12/5/202617/6/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.