Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
2286 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.23% | — | Edubusinesssolutions Print Shop PRO Webdesk | 8/1/2026 | 17/6/2026 | Cross-Site Scripting (XSS) is present on the ctl00_Content01_fieldValue parameters on the /psp/appNet/TemplateOrder/TemplatePreview.aspx endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34 (fixed in 19.69). User-supplied input is stored and later rendered in HTML pages without proper output… | |
| Modificada | Media (6.1) | 0.26% | — | Edubusinesssolutions Print Shop PRO Webdesk | 8/1/2026 | 17/6/2026 | Cross-Site Scripting (XSS) is present on the LoginID parameter on the /PSP/app/web/reg/reg_display.asp endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34 (fixed in 19.76). Unsanitized user input is reflected in HTTP responses without proper HTML encoding or escaping. This allows attackers to… | |
| Modificada | Crítica (9.8) | 0.55% | — | Edubusinesssolutions Print Shop PRO Webdesk | 8/1/2026 | 17/6/2026 | SQL Injection is present on the hfInventoryDistFormID parameter in the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34 (fixed in 19.69). Unsanitized user input is incorporated directly into SQL queries without proper parameterization or escaping. This… | |
| Modificada | Media (6.8) | 0.18% | — | Edubusinesssolutions Print Shop PRO Webdesk | 8/1/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) is present on all functions in edu Business Solutions Print Shop Pro WebDesk version 18.34 (fixed in 19.76). The application does not implement proper CSRF tokens or other other protective measures, allowing a remote attacker to trick authenticated users into unknowingly executing… | |
| Modificada | Crítica (9.1) | 0.54% | — | Edubusinesssolutions Print Shop PRO Webdesk | 8/1/2026 | 17/6/2026 | There is an issue on the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34 (fixed in 19.69) that enables remote attacker to create financial discrepancies by purchasing items with a negative quantity. This vulnerability is possible due to reliance on… | |
| Aplazada | Alta (7.1) | 0.22% | — | Cmsjunkie Wp-businessdirectoryAI | 8/1/2026 | 7/10/2026 | Vulnerabilidad de Neutralización Incorrecta de Entrada Durante la Generación de Páginas Web ('cross-site scripting') en CMSJunkie - WordPress Business Directory Plugins WP-BusinessDirectory wp-businessdirectory permite XSS Reflejado. Este problema afecta a WP-BusinessDirectory: desde n/a hasta menor o igual a 3.1.5. | |
| Aplazada | Media (4.3) | 0.18% | — | BBR Plugins Better Business ReviewsAI | 6/1/2026 | 7/10/2026 | Vulnerabilidad de autorización faltante en BBR Plugins Better Business Reviews better-business-reviews permite explotar niveles de seguridad de control de acceso incorrectamente configurados. Este problema afecta a Better Business Reviews: desde n/a hasta menor o igual a 0.1.1. | |
| Aplazada | Media (5.3) | 0.29% | — | Fapi Business Fapi MemberAI | 16/12/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in FAPI Business s.r.o. FAPI Member fapi-member allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FAPI Member: from n/a through <= 2.2.30. | |
| Aplazada | Media (4.9) | 0.34% | — | Strategy11 Business DirectoryAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Strategy11 Team Business Directory business-directory-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Business Directory: from n/a through <= 6.4.19. | |
| Aplazada | Baja (2.9) | 0.32% | — | Shenzhen Sixun Software Sixun Shanghui Group Business Management SystemAI | 15/12/2025 | 7/10/2026 | Una falla de seguridad ha sido descubierta en Shenzhen Sixun Software Sixun Shanghui Group Business Management System 4.10.24.3. Afectada por este problema es alguna funcionalidad desconocida del archivo /ExportFiles/. La manipulación resulta en archivos o directorios accesibles. El ataque puede ser lanzado… | |
| Aplazada | Media (5.5) | 0.33% | — | Shenzhen Sixun Software Sixun Shanghui Group Business Management SystemAI | 15/12/2025 | 7/10/2026 | Se identificó una vulnerabilidad en el Sistema de Gestión Empresarial Sixun Shanghui Group Business Management System 4.10.24.3 de Shenzhen Sixun Software. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /API/GylOperator/UpdatePasswordBatch. La manipulación conduce a una recuperación de… | |
| Aplazada | Media (4.3) | 0.12% | — | Strategy11 Business DirectoryAI | 9/12/2025 | 8/10/2026 | Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en el plugin business-directory-plugin de Strategy11 Team Business Directory permite la falsificación de petición en sitios cruzados. Este problema afecta a Business Directory: desde n/a hasta menor o igual que 6.4.19. | |
| Aplazada | Media (5.4) | 0.32% | — | SAP Businessobjects Business Intelligence PlatformAI | 9/12/2025 | 7/10/2026 | SAP BusinessObjects Business Intelligence Platform permite a un atacante remoto no autenticado enviar solicitudes manipuladas a través del parámetro URL que controla el mensaje de error de la página de inicio de sesión. Esto puede hacer que el servidor recupere URLs proporcionadas por el atacante, lo que resulta en un… | |
| Analizada | Media (5.3) | 0.18% | — | Knime Business HUB | 8/12/2025 | 7/10/2026 | Una comprobación de permisos errónea en KNIME Business Hub antes de la versión 1.17.0 permitió a un usuario autenticado guardar trabajos de otros usuarios como si hubieran sido guardados por el propietario del trabajo. El atacante debe tener permisos para acceder a los trabajos, pero luego estos se guardaron en el… | |
| Aplazada | Alta (7.8) | 0.18% | — | Avast AntivirusAIAVG AntivirusAINorton AntivirusAIAvast ONEAI+1 | 1/12/2025 | 25/9/2026 | Desbordamiento de búfer basado en montículo, vulnerabilidad de escritura fuera de límites en Avast Antivirus en macOS de un archivo Mach-O manipulado puede permitir la ejecución local de código o la denegación de servicio de la protección del antivirus. Este problema afecta a Antivirus: desde 15.7 anterior a 3.9.2025. | |
| Aplazada | Media (5.3) | 0.27% | — | Chamber Dashboard Business DirectoryAI | 25/11/2025 | 17/6/2026 | The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to unauthorized data export due to a missing capability check on the cdash_watch_for_export() function in all versions up to, and including, 3.3.11. This makes it possible for unauthenticated attackers to export business directory information,… | |
| Analizada | Media (5.4) | 0.17% | — | WhatsappWhatsapp Business | 18/11/2025 | 17/6/2026 | Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac v2.25.23.83 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device. We have not seen evidence of exploitation in… | |
| Aplazada | Baja (2) | 0.28% | — | Iqbolshoh Php-business-websiteAI | 17/11/2025 | 7/10/2026 | Una vulnerabilidad de seguridad ha sido detectada en el sitio web de negocios PHP de Iqbolshoh hasta 10677743a8dfc281f85291a27cf63a0bce043c24. Esto afecta una parte desconocida del archivo /admin/about.php. La manipulación conduce a una carga sin restricciones. Es posible iniciar el ataque de forma remota. El exploit… | |
| Aplazada | Media (5.3) | 0.23% | — | SAP Business ONEAI | 11/11/2025 | 17/6/2026 | Due to information disclosure vulnerability in anonymous API provided by SAP Business One (SLD), an attacker with normal user access could gain access to unauthorized information. As a result, it has a low impact on the confidentiality of the application but no impact on the integrity and availability. | |
| Analizada | Media (6.8) | 0.28% | — | SAP Business Connector | 11/11/2025 | 17/6/2026 | Due to a Path Traversal vulnerability in SAP Business Connector, an attacker authenticated as an administrator with adjacent access could read, write, overwrite, and delete arbitrary files on the host system. Successful exploitation could enable the attacker to execute arbitrary operating system commands on the… | |
| Analizada | Media (6.1) | 0.23% | — | SAP Business Connector | 11/11/2025 | 17/6/2026 | Due to an Open Redirect vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious URL that, if accessed by a victim, redirects them to an attacker-controlled site displayed within an embedded frame. Successful exploitation could allow the attacker to steal sensitive information and… | |
| Analizada | Media (6.8) | 0.81% | — | SAP Business Connector | 11/11/2025 | 17/6/2026 | Due to an OS Command Injection vulnerability in SAP Business Connector, an authenticated attacker with administrative access and adjacent network access could upload specially crafted content to the server. If processed by the application, this content enables execution of arbitrary operating system commands.… | |
| Analizada | Media (6.1) | 0.24% | — | SAP Business Connector | 11/11/2025 | 17/6/2026 | Due to a Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated victim accesses this link, the injected input is processed during web page generation, resulting in the execution of… | |
| Analizada | Media (6.1) | 0.21% | — | IBM Business Automation WorkflowIBM Process Federation Server | 6/11/2025 | 17/6/2026 | IBM Business Automation Workflow containers 24.0.0 through 24.0.0-IF006, 24.0.1 through 24.0.1-IF004, 25.0.0 through 25.0.0-IF001 and IBM Business Automation Workflow traditional with Process Federation Server 24.0.0 through 24.0.1 and 25.0.0 are vulnerable to cross-site scripting. This vulnerability allows an… | |
| Analizada | Media (5.4) | 0.18% | — | IBM Cloud PAK FOR Business Automation | 3/11/2025 | 17/6/2026 | IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 001, 24.0.1 through 24.0.1 Interim Fix 004, 24.0.0 through 24.0.0 Interim Fix 006, and earlier unsupported releases IBM Business Automation Workflow is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to… |