Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1917 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.76%—Changing Information Technology CgfidoAI31/12/202417/6/2026
The passwordless login mechanism in CGFIDO from Changing Information Technology has an Authentication Bypass vulnerability, allowing remote attackers with regular privileges to send a crafted request to switch to the identity of any user, including administrators.
AplazadaCrítica (9.9)0.61%—Arne Informatics Piramit AutomationAI25/12/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arne Informatics Piramit Automation allows Blind SQL Injection. This issue affects Piramit Automation: before 27.09.2024.
AplazadaAlta (7.8)0.70%—SysteminformationAI20/12/202417/6/2026
systeminformation is a System and OS information library for node.js. In affected versions SSIDs are not sanitized when before they are passed as a parameter to cmd.exe in the `getWindowsIEEE8021x` function. This means that malicious content in the SSID can be executed as OS commands. This vulnerability may enable an…
AnalizadaMedia (5.2)0.27%—IBM Infosphere Information Server19/12/202417/6/2026
IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.
AplazadaAlta (8)0.24%—BD Diagnostic SolutionsAIBD Synapsys Informatics SolutionAIBD Kiestra SCUAI17/12/202417/6/2026
Default credentials are used in the above listed BD Diagnostic Solutions products. If exploited, threat actors may be able to access, modify or delete data, including sensitive information such as protected health information (PHI) and personally identifiable information (PII). Exploitation of this vulnerability may…
AplazadaCrítica (9.8)0.45%—Mobil365 Informatics Saha365 APPAI17/12/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mobil365 Informatics Saha365 App allows SQL Injection. This issue affects Saha365 App: before 30.09.2024.
AnalizadaMedia (6.5)0.54%—IBM Infosphere Information Server12/12/202417/6/2026
IBM InfoSphere Information Server 11.7 could allow an authenticated user to GUI to not load or stop working due to improper input validation.
AnalizadaAlta (7.8)0.21%—Ivanti Performance Manager11/12/202417/6/2026
Under specific circumstances, insecure permissions in Ivanti Performance Manager before version 2024.3 HF1, 2024.1 HF1, or 2023.3 HF1 allows a local authenticated attacker to achieve local privilege escalation.
AnalizadaMedia (4.3)0.30%—IBM Infosphere Information Server11/12/202417/6/2026
IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further attacks against the system.
AnalizadaMedia (6.5)0.34%—IBM Infosphere Information Server11/12/202417/6/2026
IBM InfoSphere DataStage Flow Designer (InfoSphere Information Server 11.7) could allow an authenticated user to obtain sensitive information that could aid in further attacks against the system.
AplazadaCrítica (9.8)0.45%—Eryaz Information Technologies Natracar B2B Dealer Management ProgramAI9/12/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eryaz Information Technologies NatraCar B2B Dealer Management Program allows SQL Injection. This issue affects NatraCar B2B Dealer Management Program: through 09.12.2024. NOTE: The vendor was contacted and it was…
AnalizadaMedia (5.4)0.23%—IBM Qradar Security Information AND Event Manager7/12/202417/6/2026
IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AplazadaAlta (8.1)6.4%💥 ExploitSwiftperformance Swift Performance LiteAI6/12/202417/6/2026
The Swift Performance Lite plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 2.3.7.1 via the 'ajaxify' function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those…
AplazadaAlta (8.8)0.43%—Infodom Performa 365AI3/12/202417/6/2026
An issue in InfoDom Performa 365 v4.0.1 allows authenticated attackers to elevate their privileges to Administrator via a crafted payload sent to /api/users.
AplazadaAlta (8.8)0.55%—Infodom Performa 365AI3/12/202417/6/2026
An authenticated arbitrary file upload vulnerability in the /documentCache/upload endpoint of InfoDom Performa 365 v4.0.1 allows attackers to execute arbitrary code via uploading a crafted SVG file.
AplazadaAlta (8.8)0.86%—Beijing Digital China Yunke Information Technology YunkeAI3/12/202417/6/2026
An issue in Beijing Digital China Yunke Information Technology Co.Ltd v.7.2.6.120 allows a remote attacker to execute arbitrary code via the code/function/dpi/web_auth/customizable.php file
AplazadaMedia (6.5)0.24%—Berg Informatik Stripe DonationAI1/12/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Berg Informatik Stripe Donation bin-stripe-donation allows Stored XSS.This issue affects Stripe Donation: from n/a through <= 1.2.5.
AplazadaCrítica (9.8)1.9%💥 PoCInformation Technology Wawp Automation WEB PlatformAI28/11/202417/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Information Technology Wawp automation-web-platform allows Authentication Bypass.This issue affects Wawp: from n/a through < 3.0.18.
AnalizadaAlta (7.8)0.51%—Irfanview Formats22/11/202417/6/2026
IrfanView PIC File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious…
AnalizadaAlta (7.8)0.50%—Irfanview Formats22/11/202417/6/2026
IrfanView PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a…
AnalizadaAlta (7.8)0.51%—Irfanview Formats22/11/202417/6/2026
IrfanView SHP File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious…
AnalizadaAlta (7.8)0.51%—Irfanview Formats22/11/202417/6/2026
IrfanView PNT File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious…
AplazadaAlta (7.5)0.63%—Teknogis Informatics Closed Circuit Vehicle Tracking SoftwareAI21/11/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknogis Informatics Closed Circuit Vehicle Tracking Software allows SQL Injection, Blind SQL Injection. This issue affects Closed Circuit Vehicle Tracking Software: through 21.11.2024. NOTE: The vendor was contacted…
AplazadaCrítica (9.8)1.1%—XI AN Daxi Information Technology Officeweb365AI19/11/202417/6/2026
File Upload vulnerability in Xi'an Daxi Information technology OfficeWeb365 v.8.6.1.0 and v7.18.23.0 allows a remote attacker to execute arbitrary code via the pw/savedraw component.
AnalizadaMedia (5.4)0.17%—Intel Integrated Performance PrimitivesIntel Oneapi Base Toolkit13/11/202417/6/2026
Uncontrolled search path for some Intel(R) IPP software for Windows before version 2021.12.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
Orbitaley — Vulnerabilidades