Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1917 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.41% | — | Nomysoft Informatics NomysemAI | 12/11/2024 | 17/6/2026 | Missing Authentication for Critical Function, Missing Authorization vulnerability in Nomysoft Informatics Nomysem allows Collect Data as Provided by Users. This issue affects Nomysem: before 13.10.2024. | |
| Modificada | Alta (7.8) | 0.39% | — | Artifex GhostscriptDebian LinuxSuse Linux Enterprise High Performance ComputingSuse Linux Enterprise Server+1 | 10/11/2024 | 17/6/2026 | An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution. | |
| Modificada | Media (5.5) | 0.29% | — | Artifex GhostscriptDebian LinuxSuse Linux Enterprise High Performance ComputingSuse Linux Enterprise Server+1 | 10/11/2024 | 17/6/2026 | An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bounds read when reading color in Indexed color space. | |
| Modificada | Alta (7.8) | 0.39% | — | Artifex GhostscriptDebian LinuxSuse Linux Enterprise High Performance ComputingSuse Linux Enterprise Server+1 | 10/11/2024 | 17/6/2026 | An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution. | |
| Modificada | Alta (7.8) | 0.36% | — | Artifex GhostscriptDebian LinuxSuse Linux Enterprise High Performance ComputingSuse Linux Enterprise Server+1 | 10/11/2024 | 17/6/2026 | An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution. | |
| Aplazada | Alta (8.8) | 1.7% | — | Wuhan Tianyu Information Industry CO LTD Tianyu CPE RouterAI | 24/10/2024 | 17/6/2026 | Wuhan Tianyu Information Industry Co., Ltd Tianyu CPE Router CommonCPExCPETS_v3.2.468.11.04_P4 was discovered to contain a command injection vulnerability via the component at_command.asp. | |
| Analizada | Media (6.3) | 0.61% | — | Informatik.hu-berlin Flair | 17/10/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack… | |
| Analizada | Crítica (9.8) | 3.0% | 💥 Exploit | Internet-formation Wp-advanced-search | 10/10/2024 | 17/6/2026 | The WP-Advanced-Search WordPress plugin before 3.3.9.2 does not sanitize and escape the t parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks | |
| Analizada | Alta (7.5) | 1.0% | — | Apache Formatting Objects Processor | 9/10/2024 | 17/6/2026 | Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affects Apache XML Graphics FOP: 2.9. Users are recommended to upgrade to version 2.10, which fixes the issue. | |
| Aplazada | Media (6.1) | 0.26% | — | MF Teacher Performance Management SystemAI | 27/9/2024 | 17/6/2026 | Cross-site scripting vulnerability exists in MF Teacher Performance Management System version 6. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. | |
| Aplazada | Alta (7.5) | 0.91% | — | Centro DE Tecnologia DA Informacao Renato Archer Invesalius3AI | 25/9/2024 | 17/6/2026 | Directory Traversal vulnerability in Centro de Tecnologia da Informaco Renato Archer InVesalius3 v3.1.99995 allows attackers to write arbitrary files unto the system via a crafted .inv3 file. | |
| Aplazada | Alta (8.8) | 0.42% | — | Exnet Informatics Ferry Reservation SystemAI | 23/9/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Exnet Informatics Software Ferry Reservation System allows Reflected XSS. This issue affects Ferry Reservation System: before 240805-002. | |
| Aplazada | Crítica (9.3) | 0.37% | — | Exnet Informatics Software Ferry Reservation SystemAI | 23/9/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Exnet Informatics Software Ferry Reservation System allows SQL Injection. This issue affects Ferry Reservation System: before 240805-002. | |
| Aplazada | Media (4.4) | 0.29% | — | Performance CO PilotAIPerformance CO Pilot PmpostAI | 19/9/2024 | 17/6/2026 | A vulnerability was found in Performance Co-Pilot (PCP). This flaw can only be exploited if an attacker has access to a compromised PCP system account. The issue is related to the pmpost tool, which is used to log messages in the system. Under certain conditions, it runs with high-level privileges. | |
| Aplazada | Media (5.5) | 0.26% | — | SGI Performance Co-pilotAI | 19/9/2024 | 17/6/2026 | A vulnerability was found in Performance Co-Pilot (PCP). This flaw allows an attacker to send specially crafted data to the system, which could cause the program to misbehave or crash. | |
| Aplazada | Alta (8.5) | 0.38% | — | Yordam Information Technology Mobile Library ApplicationAI | 18/9/2024 | 17/6/2026 | Missing Authentication for Critical Function, Missing Authorization vulnerability in Yordam Information Technology Mobile Library Application allows Retrieve Embedded Sensitive Data. This issue affects Mobile Library Application: before 5.0. | |
| Aplazada | Media (6.9) | 0.38% | — | Yordam Information Technology Yordam Library Automation SystemAI | 18/9/2024 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in Yordam Information Technology Yordam Library Automation System allows Interface Manipulation. This issue affects Yordam Library Automation System: before 20.1. | |
| Aplazada | Alta (7.5) | 1.9% | 💥 Exploit | Xian Daxi Information Technology Officeweb365AI | 10/9/2024 | 17/6/2026 | Arbitrary File Read vulnerability in Xi'an Daxi Information Technology Co., Ltd OfficeWeb365 v.7.18.23.0 and v8.6.1.0 allows a remote attacker to obtain sensitive information via the "Pic/Indexes" interface | |
| Aplazada | Crítica (9.4) | 0.61% | — | Siemens Simatic BatchAISiemens Simatic Information ServerAISiemens Simatic PCS 7AISiemens Simatic Process HistorianAI+2 | 10/9/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC BATCH V9.1 (All versions), SIMATIC Information Server 2020 (All versions < V2020 SP2 Update 5), SIMATIC Information Server 2022 (All versions < V2022 SP1 Update 2), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC06), SIMATIC Process Historian 2020 (All versions < V2020 SP2… | |
| Aplazada | Baja (2) | 0.40% | — | Opentext Performance CenterAI | 21/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText Performance Center on Windows allows Cross-Site Scripting (XSS).This issue affects Performance Center: 12.63. | |
| Aplazada | Media (5.1) | 0.62% | — | Opentext Performance CenterAI | 21/8/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in OpenText Performance Center on Windows allows Retrieve Embedded Sensitive Data.This issue affects Performance Center: 12.63. | |
| Analizada | Media (6.5) | 0.62% | — | IBM Infosphere Information Server | 15/8/2024 | 17/6/2026 | IBM InfoSphere Information Server could allow an authenticated user to consume file space resources due to unrestricted file uploads. IBM X-Force ID: 298279. | |
| Analizada | Media (4.9) | 0.63% | — | IBM Infosphere Information Server | 15/8/2024 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could allow a privileged user to obtain sensitive information from authentication request headers. IBM X-Force ID: 298277. | |
| Analizada | Media (5.4) | 0.14% | — | Intel Integrated Performance PrimitivesIntel Oneapi Base Toolkit | 14/8/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) IPP software before version 2021.11 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (5.4) | 0.14% | — | Intel Graphics Performance Analyzers | 14/8/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) GPA software before version 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access. |