Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

3560 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.22%—IBM Transformation Extender Advanced1/10/202517/6/2026
IBM Transformation Extender Advanced 10.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
AnalizadaMedia (4.4)0.12%—IBM Transformation Extender Advanced1/10/202517/6/2026
IBM Transformation Extender Advanced 10.0.1 stores potentially sensitive information in log files that could be read by a local user.
AnalizadaAlta (8.8)0.45%—IBM Infosphere Information Server29/9/202517/6/2026
IBM InfoSphere 11.7.0.0 through 11.7.1.6 Information Server could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
AplazadaAlta (7.5)0.34%—Nanda Automation Technology AT Na2000AI29/9/202517/6/2026
AT_NA2000 from Nanda Automation Technology vendor has a denial-of-service vulnerability. For the processing of TCP RST packets, PLC AT_NA2000 has a wide acceptable range of sequence numbers. It does not require the sequence number to exactly match the next expected sequence value, just to be within the current receive…
AplazadaMedia (5.3)0.29%—Vimesoft Information Technologies AND Software Vimesoft Corporate Messaging PlatformAI26/9/202517/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Vimesoft Information Technologies and Software Inc. Vimesoft Corporate Messaging Platform allows Retrieve Embedded Sensitive Data. This issue affects Vimesoft Corporate Messaging Platform: from V1.3.0 before V2.0.0.
AplazadaAlta (8.6)0.45%—Yordam Information Technology Consulting Education AND Electrical Systems Industry Trade Yordam KatalogAI25/9/202517/6/2026
Path Traversal: 'dir/../../filename' vulnerability in Yordam Information Technology Consulting Education and Electrical Systems Industry Trade Inc. Yordam Katalog allows Path Traversal. This issue affects Yordam Katalog: before 21.7.
AplazadaMedia (4.3)0.24%—Divvydrive Information Technologies INC Divvydrive WEBAI24/9/202525/9/2026
Observable Timing Discrepancy vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive Web allows Cross-Domain Search Timing. This issue affects DivvyDrive Web: from 4.8.2.2 before 4.8.2.15.
AnalizadaBaja (2.1)0.38%—Campcodes Society Membership Information System23/9/202517/6/2026
A vulnerability was identified in Campcodes Society Membership Information System 1.0. This issue affects some unknown processing of the file /check_student.php. Such manipulation of the argument student_id leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be…
AplazadaMedia (4.3)0.29%—Nurul Amin WP System InformationAI22/9/202517/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Nurul Amin WP System Information wp-system-info allows Retrieve Embedded Sensitive Data.This issue affects WP System Information: from n/a through <= 1.5.
AnalizadaCrítica (9.1)0.74%—Accela Automation Platform19/9/202517/6/2026
Accela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticated administrative user can execute arbitrary Java code on the server, resulting in remote code execution. In addition, improper input validation allows for arbitrary file write and server-side request…
AplazadaMedia (4.7)0.23%—Pusula Communication Information Manageable Email Sending SystemAI19/9/202517/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Pusula Communication Information Internet Industry and Trade Ltd. Co. Manageable Email Sending System allows Exploiting Trust in Client. This issue affects Manageable Email Sending System: from <=2025.06 before 2025.08.06.
AnalizadaMedia (5.5)0.59%—Itsourcecode Student Information Management System18/9/202517/6/2026
A vulnerability was determined in itsourcecode Student Information Management System 1.0. The impacted element is an unknown function of the file /admin/modules/class/index.php. This manipulation of the argument classId causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed…
AplazadaCrítica (9.8)0.36%—Esbi Information AND Telecommunication Industry AND Trade Limited Company Auto Service SoftwareAI18/9/202517/6/2026
CWE - 89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ESBI Information and Telecommunication Industry and Trade Limited Company Auto Service Software allows SQL Injection. This issue affects Auto Service Software: before v.2025.10.01.
AnalizadaBaja (2.1)0.34%—Facebook-julykringcadayona Student Information System17/9/202525/9/2026
A vulnerability has been found in itsourcecode Student Information System 1.0. The affected element is an unknown function of the file /leveledit1.php. Such manipulation of the argument level_id leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be…
AplazadaCrítica (9.8)0.35%—Yordam Informatics Yordam Library Automation SystemAI17/9/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yordam Informatics Yordam Library Automation System allows SQL Injection. This issue affects Yordam Library Automation System: from 21.5 & 21.6 before 21.7.
AplazadaMedia (4.7)0.24%—Zirve Information Technologies INC Zirve NovaAI17/9/202525/9/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zirve Information Technologies Inc. Zirve Nova allows Cross-Site Scripting (XSS). This issue affects Zirve Nova: from 235 through 20250131.
AnalizadaAlta (8.1)0.39%—Executeautomation MCP Database Server16/9/202517/6/2026
The mcp-database-server (MCP Server) 1.1.0 and earlier, as distributed via the npm package @executeautomation/database-server, fails to implement adequate security controls to properly enforce a "read-only" mode. This vulnerability affects only the npm distribution; other distributions are not impacted. As a result,…
AplazadaMedia (4.3)0.22%💥 PoCUbit Information Technologies StoysAI16/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ubit Information Technologies STOYS allows Cross-Site Scripting (XSS). This issue affects STOYS: from 2 before 20250916.
AnalizadaMedia (5.5)0.43%—Itsourcecode Baptism Information Management System14/9/202517/6/2026
A vulnerability was found in itsourcecode Baptism Information Management System 1.0. This impacts an unknown function of the file /rptbaptismal.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used.
AnalizadaMedia (5.5)0.41%—Itsourcecode Baptism Information Management System14/9/202530/9/2026
A vulnerability was determined in itsourcecode Baptism Information Management System 1.0. Affected is an unknown function of the file /listbaptism.php. This manipulation of the argument bapt_id causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be…
AnalizadaBaja (2.3)0.12%—IBM Qradar Security Information AND Event Manager14/9/202517/6/2026
IBM QRadar SIEM 7.5 through 7.5 Update Pack 13 Independent Fix 01 could allow a local privileged user to perform unauthorized actions on configuration files due to improper permission assignment.
AnalizadaMedia (6.8)0.21%—IBM Security Verify Information Queue10/9/202517/6/2026
IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 could allow a privileged user to escalate their privileges and attack surface on the host due to the containers running with unnecessary privileges.
AnalizadaAlta (7.5)0.19%—IBM Security Verify Information Queue10/9/202517/6/2026
IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
AnalizadaMedia (6.5)0.37%—IBM Security Verify Information Queue10/9/202517/6/2026
IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 could allow a remote user to cause a denial of service due to improper handling of special characters that could lead to uncontrolled resource consumption.
AnalizadaAlta (7.3)0.55%—Rockwellautomation Factorytalk Optix9/9/202517/6/2026
A security issue exists within FactoryTalk Optix MQTT broker due to the lack of URI sanitization. This flaw enables the loading of remote Mosquito plugins, which can be used to achieve remote code execution.