Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2621 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.15% | — | Thermofisher Torrent Suite Software | 4/12/2025 | 17/6/2026 | An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. One of the middlewares included in this application, LocalhostAuthMiddleware, authenticates users as ionadmin if the REMOTE_ADDR property in request.META is set to 127.0.0.1, to 127.0.1.1, or to ::1. Any user with local access to the… | |
| Analizada | Crítica (9.8) | 0.39% | — | Thermofisher Torrent Suite Software | 4/12/2025 | 17/6/2026 | The Thermo Fisher Torrent Suite Django application 5.18.1 has weak default credentials, which are stored as fixtures for the Django ORM API. The ionadmin user account can be used to authenticate to default deployments with the password ionadmin. The user guide recommends changing default credentials; however, a… | |
| Aplazada | Media (5.5) | 0.33% | — | Shsuishang ShopsuiteAI | 16/11/2025 | 17/6/2026 | A vulnerability was found in shsuishang ShopSuite ModulithShop up to 45a99398cec3b7ad7ff9383694f0b53339f2d35a. Affected by this issue is some unknown functionality of the component RSA/OAuth2/Database. The manipulation results in hard-coded credentials. The attack can be executed remotely. The exploit has been made… | |
| Aplazada | Baja (2.1) | 0.41% | — | Shsuishang ShopsuiteAI | 16/11/2025 | 17/6/2026 | A vulnerability was identified in shsuishang ShopSuite ModulithShop up to 45a99398cec3b7ad7ff9383694f0b53339f2d35a. Impacted is the function JwtAuthenticationFilter of the file src/main/java/com/suisung/shopsuite/common/security/JwtAuthenticationFilter.java. The manipulation leads to path traversal. It is possible to… | |
| Aplazada | Alta (8.6) | 0.74% | — | Ucancode E-xd++ Visualization Enterprise SuiteAI | 12/11/2025 | 17/6/2026 | UCanCode E-XD++ Visualization Enterprise Suite contains an untrusted pointer dereference vulnerability via the TKDRAWCAD.TKDrawCADCtrl.1 ActiveX control. This is because it exposes a RotateShape method that dereferences a user-supplied pointer without sufficient validation. A crafted input may cause the control to… | |
| Aplazada | Media (5.4) | 0.12% | — | Intel Killer Performance SuiteAI | 11/11/2025 | 17/6/2026 | Uncontrolled search path for some Intel(R) Killer(TM) Performance Suite software before version killer 4.0 40.25.509.1465 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of… | |
| Analizada | Alta (7.7) | 0.21% | — | Opswat Outpost Security Suite | 11/11/2025 | 17/6/2026 | An issue in Agnitum Outpost Security Suite 7.5.3 (3942.608.1810) and 7.6 (3984.693.1842) allows a local attacker to execute arbitrary code via the lock function. The manufacturer fixed the vulnerability in version 8.0 (4164.652.1856) from December 17, 2012. | |
| Aplazada | Alta (8.1) | 0.48% | — | Astra Security SuiteAI | 11/11/2025 | 17/6/2026 | The Astra Security Suite – Firewall & Malware Scan plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient validation of remote URLs for zip downloads and an easily guessable key in all versions up to, and including, 0.2. This makes it possible for unauthenticated attackers to upload arbitrary… | |
| Analizada | Media (6.5) | 0.33% | — | Salesagility Suitecrm | 8/11/2025 | 17/6/2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 8.6.0 through 8.9.0, there is an authenticated, blind (time-based) SQL-injection inside the appMetadata-operation of the GraphQL-API. This allows extraction of arbitrary data from the database, and… | |
| Analizada | Alta (8.8) | 0.34% | — | Salesagility Suitecrm | 8/11/2025 | 17/6/2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 8.9.0 and below contain a time-based blind SQL Injection vulnerability. This vulnerability allows an authenticated attacker to infer data from the database by measuring response times, potentially leading… | |
| Analizada | Media (6.1) | 0.20% | — | Salesagility Suitecrm | 8/11/2025 | 17/6/2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and below allow unauthenticated reflected Cross-Site Scripting (XSS). Successful exploitation could lead to full account takeover, for example by altering the login form to send credentials to an… | |
| Analizada | Alta (8.3) | 0.27% | — | Salesagility Suitecrm | 8/11/2025 | 17/6/2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and prior, 8.0.0-beta.1 through 8.9.0 allow a low-privileged user with a restrictive role to view and create work items through the Resource Calendar and project screens, even when the related… | |
| Analizada | Alta (8.8) | 0.34% | — | Salesagility Suitecrm | 8/11/2025 | 17/6/2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and prior, 8.0.0-beta.1 through 8.9.0 contain a privilege escalation vulnerability where user sessions are not invalidated upon account deactivation. An inactive user with an active session can… | |
| Analizada | Alta (8.6) | 0.43% | — | Salesagility Suitecrm | 8/11/2025 | 17/6/2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.7 and below and 8.0.0-beta.1 through 8.9.0 8.0.0-beta.1, an attacker can craft a malicious call_id that alters the logic of the SQL query or injects arbitrary SQL. An attack can lead to… | |
| Analizada | Alta (8.8) | 0.39% | — | Salesagility Suitecrm | 6/11/2025 | 15/7/2026 | SuiteCRM versions prior to 7.12.6 contain a type confusion vulnerability within the processing of the ‘module’ parameter within the ‘deleteAttachment’ functionality. Successful exploitation allows remote unauthenticated attackers to alter database objects including changing the email address of the administrator. | |
| Analizada | Crítica (9.3) | 0.69% | — | Salesagility Suitecrm | 6/11/2025 | 15/7/2026 | SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the processing of the ‘uid’ parameter within the ‘export’ functionality. Successful exploitation allows remote unauthenticated attackers to ultimately execute arbitrary code. | |
| Aplazada | Crítica (9.8) | 0.47% | — | Ce21 SuiteAI | 4/11/2025 | 17/6/2026 | The CE21 Suite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.3.1 via the log file. This makes it possible for unauthenticated attackers to extract sensitive data including authentication credentials, which can be used to log in as other users as long as… | |
| Aplazada | Crítica (9.8) | 0.46% | — | Ce21 SuiteAI | 4/11/2025 | 17/6/2026 | The CE21 Suite plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the wp_ajax_nopriv_ce21_single_sign_on_save_api_settings AJAX action in versions 2.2.1 to 2.3.1. This makes it possible for unauthenticated attackers to update the plugin's API settings… | |
| Analizada | Crítica (9.8) | 0.55% | — | IBM Maximo Application Suite | 28/10/2025 | 25/9/2026 | IBM Maximo Application Suite 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application. | |
| Analizada | Media (5.1) | 0.19% | — | Salesagility Suitecrm | 27/10/2025 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability reflected in SuiteCRM v7.14.1. This vulnerability allows an attacker to execute JavaScript code by modifying the HTTP Referer header to include an arbitrary domain with malicious JavaScript code at the end. The server will attempt to block the arbitrary domain but will allow… | |
| Aplazada | Media (6.4) | 0.17% | — | Hasleo Backup SuiteAI | 27/10/2025 | 17/6/2026 | A weakness has been identified in Hasleo Backup Suite up to 5.2. Impacted is an unknown function of the component HasleoImageMountService/HasleoBackupSuiteService. This manipulation causes unquoted search path. The attack is restricted to local execution. The attack's complexity is rated as high. The exploitability is… | |
| Aplazada | Media (6.3) | 0.51% | — | Productivity SuiteAI | 23/10/2025 | 17/6/2026 | A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and delete arbitrary directories on the target machine. | |
| Aplazada | Media (6.3) | 0.51% | — | Productivity SuiteAI | 23/10/2025 | 17/6/2026 | A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and create arbitrary directories on the target machine. | |
| Aplazada | Alta (8.3) | 0.62% | — | Productivity SuiteAI | 23/10/2025 | 17/6/2026 | A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and delete arbitrary files on the target machine. | |
| Aplazada | Crítica (9.3) | 0.66% | — | Productivity SuiteAI | 23/10/2025 | 17/6/2026 | A binding to an unrestricted IP address vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and read, write, or delete arbitrary files and folders on the target machine |