Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1917 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.76% | — | Changing Information Technology CgfidoAI | 31/12/2024 | 17/6/2026 | The passwordless login mechanism in CGFIDO from Changing Information Technology has an Authentication Bypass vulnerability, allowing remote attackers with regular privileges to send a crafted request to switch to the identity of any user, including administrators. | |
| Aplazada | Crítica (9.9) | 0.61% | — | Arne Informatics Piramit AutomationAI | 25/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arne Informatics Piramit Automation allows Blind SQL Injection. This issue affects Piramit Automation: before 27.09.2024. | |
| Aplazada | Alta (7.8) | 0.70% | — | SysteminformationAI | 20/12/2024 | 17/6/2026 | systeminformation is a System and OS information library for node.js. In affected versions SSIDs are not sanitized when before they are passed as a parameter to cmd.exe in the `getWindowsIEEE8021x` function. This means that malicious content in the SSID can be executed as OS commands. This vulnerability may enable an… | |
| Analizada | Media (5.2) | 0.27% | — | IBM Infosphere Information Server | 19/12/2024 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. | |
| Aplazada | Alta (8) | 0.24% | — | BD Diagnostic SolutionsAIBD Synapsys Informatics SolutionAIBD Kiestra SCUAI | 17/12/2024 | 17/6/2026 | Default credentials are used in the above listed BD Diagnostic Solutions products. If exploited, threat actors may be able to access, modify or delete data, including sensitive information such as protected health information (PHI) and personally identifiable information (PII). Exploitation of this vulnerability may… | |
| Aplazada | Crítica (9.8) | 0.45% | — | Mobil365 Informatics Saha365 APPAI | 17/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mobil365 Informatics Saha365 App allows SQL Injection. This issue affects Saha365 App: before 30.09.2024. | |
| Analizada | Media (6.5) | 0.54% | — | IBM Infosphere Information Server | 12/12/2024 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could allow an authenticated user to GUI to not load or stop working due to improper input validation. | |
| Analizada | Alta (7.8) | 0.21% | — | Ivanti Performance Manager | 11/12/2024 | 17/6/2026 | Under specific circumstances, insecure permissions in Ivanti Performance Manager before version 2024.3 HF1, 2024.1 HF1, or 2023.3 HF1 allows a local authenticated attacker to achieve local privilege escalation. | |
| Analizada | Media (4.3) | 0.30% | — | IBM Infosphere Information Server | 11/12/2024 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further attacks against the system. | |
| Analizada | Media (6.5) | 0.34% | — | IBM Infosphere Information Server | 11/12/2024 | 17/6/2026 | IBM InfoSphere DataStage Flow Designer (InfoSphere Information Server 11.7) could allow an authenticated user to obtain sensitive information that could aid in further attacks against the system. | |
| Aplazada | Crítica (9.8) | 0.45% | — | Eryaz Information Technologies Natracar B2B Dealer Management ProgramAI | 9/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eryaz Information Technologies NatraCar B2B Dealer Management Program allows SQL Injection. This issue affects NatraCar B2B Dealer Management Program: through 09.12.2024. NOTE: The vendor was contacted and it was… | |
| Analizada | Media (5.4) | 0.23% | — | IBM Qradar Security Information AND Event Manager | 7/12/2024 | 17/6/2026 | IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Aplazada | Alta (8.1) | 6.4% | 💥 Exploit | Swiftperformance Swift Performance LiteAI | 6/12/2024 | 17/6/2026 | The Swift Performance Lite plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 2.3.7.1 via the 'ajaxify' function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those… | |
| Aplazada | Alta (8.8) | 0.43% | — | Infodom Performa 365AI | 3/12/2024 | 17/6/2026 | An issue in InfoDom Performa 365 v4.0.1 allows authenticated attackers to elevate their privileges to Administrator via a crafted payload sent to /api/users. | |
| Aplazada | Alta (8.8) | 0.55% | — | Infodom Performa 365AI | 3/12/2024 | 17/6/2026 | An authenticated arbitrary file upload vulnerability in the /documentCache/upload endpoint of InfoDom Performa 365 v4.0.1 allows attackers to execute arbitrary code via uploading a crafted SVG file. | |
| Aplazada | Alta (8.8) | 0.86% | — | Beijing Digital China Yunke Information Technology YunkeAI | 3/12/2024 | 17/6/2026 | An issue in Beijing Digital China Yunke Information Technology Co.Ltd v.7.2.6.120 allows a remote attacker to execute arbitrary code via the code/function/dpi/web_auth/customizable.php file | |
| Aplazada | Media (6.5) | 0.24% | — | Berg Informatik Stripe DonationAI | 1/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Berg Informatik Stripe Donation bin-stripe-donation allows Stored XSS.This issue affects Stripe Donation: from n/a through <= 1.2.5. | |
| Aplazada | Crítica (9.8) | 1.9% | 💥 PoC | Information Technology Wawp Automation WEB PlatformAI | 28/11/2024 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Information Technology Wawp automation-web-platform allows Authentication Bypass.This issue affects Wawp: from n/a through < 3.0.18. | |
| Analizada | Alta (7.8) | 0.51% | — | Irfanview Formats | 22/11/2024 | 17/6/2026 | IrfanView PIC File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious… | |
| Analizada | Alta (7.8) | 0.50% | — | Irfanview Formats | 22/11/2024 | 17/6/2026 | IrfanView PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a… | |
| Analizada | Alta (7.8) | 0.51% | — | Irfanview Formats | 22/11/2024 | 17/6/2026 | IrfanView SHP File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious… | |
| Analizada | Alta (7.8) | 0.51% | — | Irfanview Formats | 22/11/2024 | 17/6/2026 | IrfanView PNT File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious… | |
| Aplazada | Alta (7.5) | 0.63% | — | Teknogis Informatics Closed Circuit Vehicle Tracking SoftwareAI | 21/11/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknogis Informatics Closed Circuit Vehicle Tracking Software allows SQL Injection, Blind SQL Injection. This issue affects Closed Circuit Vehicle Tracking Software: through 21.11.2024. NOTE: The vendor was contacted… | |
| Aplazada | Crítica (9.8) | 1.1% | — | XI AN Daxi Information Technology Officeweb365AI | 19/11/2024 | 17/6/2026 | File Upload vulnerability in Xi'an Daxi Information technology OfficeWeb365 v.8.6.1.0 and v7.18.23.0 allows a remote attacker to execute arbitrary code via the pw/savedraw component. | |
| Analizada | Media (5.4) | 0.17% | — | Intel Integrated Performance PrimitivesIntel Oneapi Base Toolkit | 13/11/2024 | 17/6/2026 | Uncontrolled search path for some Intel(R) IPP software for Windows before version 2021.12.0 may allow an authenticated user to potentially enable escalation of privilege via local access. |