Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1917 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.41%—Nomysoft Informatics NomysemAI12/11/202417/6/2026
Missing Authentication for Critical Function, Missing Authorization vulnerability in Nomysoft Informatics Nomysem allows Collect Data as Provided by Users. This issue affects Nomysem: before 13.10.2024.
ModificadaAlta (7.8)0.39%—Artifex GhostscriptDebian LinuxSuse Linux Enterprise High Performance ComputingSuse Linux Enterprise Server+110/11/202417/6/2026
An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.
ModificadaMedia (5.5)0.29%—Artifex GhostscriptDebian LinuxSuse Linux Enterprise High Performance ComputingSuse Linux Enterprise Server+110/11/202417/6/2026
An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bounds read when reading color in Indexed color space.
ModificadaAlta (7.8)0.39%—Artifex GhostscriptDebian LinuxSuse Linux Enterprise High Performance ComputingSuse Linux Enterprise Server+110/11/202417/6/2026
An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution.
ModificadaAlta (7.8)0.36%—Artifex GhostscriptDebian LinuxSuse Linux Enterprise High Performance ComputingSuse Linux Enterprise Server+110/11/202417/6/2026
An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution.
AplazadaAlta (8.8)1.7%—Wuhan Tianyu Information Industry CO LTD Tianyu CPE RouterAI24/10/202417/6/2026
Wuhan Tianyu Information Industry Co., Ltd Tianyu CPE Router CommonCPExCPETS_v3.2.468.11.04_P4 was discovered to contain a command injection vulnerability via the component at_command.asp.
AnalizadaMedia (6.3)0.61%—Informatik.hu-berlin Flair17/10/202417/6/2026
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack…
AnalizadaCrítica (9.8)3.0%💥 ExploitInternet-formation Wp-advanced-search10/10/202417/6/2026
The WP-Advanced-Search WordPress plugin before 3.3.9.2 does not sanitize and escape the t parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks
AnalizadaAlta (7.5)1.0%—Apache Formatting Objects Processor9/10/202417/6/2026
Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affects Apache XML Graphics FOP: 2.9. Users are recommended to upgrade to version 2.10, which fixes the issue.
AplazadaMedia (6.1)0.26%—MF Teacher Performance Management SystemAI27/9/202417/6/2026
Cross-site scripting vulnerability exists in MF Teacher Performance Management System version 6. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product.
AplazadaAlta (7.5)0.91%—Centro DE Tecnologia DA Informacao Renato Archer Invesalius3AI25/9/202417/6/2026
Directory Traversal vulnerability in Centro de Tecnologia da Informaco Renato Archer InVesalius3 v3.1.99995 allows attackers to write arbitrary files unto the system via a crafted .inv3 file.
AplazadaAlta (8.8)0.42%—Exnet Informatics Ferry Reservation SystemAI23/9/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Exnet Informatics Software Ferry Reservation System allows Reflected XSS. This issue affects Ferry Reservation System: before 240805-002.
AplazadaCrítica (9.3)0.37%—Exnet Informatics Software Ferry Reservation SystemAI23/9/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Exnet Informatics Software Ferry Reservation System allows SQL Injection. This issue affects Ferry Reservation System: before 240805-002.
AplazadaMedia (4.4)0.29%—Performance CO PilotAIPerformance CO Pilot PmpostAI19/9/202417/6/2026
A vulnerability was found in Performance Co-Pilot (PCP). This flaw can only be exploited if an attacker has access to a compromised PCP system account. The issue is related to the pmpost tool, which is used to log messages in the system. Under certain conditions, it runs with high-level privileges.
AplazadaMedia (5.5)0.26%—SGI Performance Co-pilotAI19/9/202417/6/2026
A vulnerability was found in Performance Co-Pilot (PCP). This flaw allows an attacker to send specially crafted data to the system, which could cause the program to misbehave or crash.
AplazadaAlta (8.5)0.38%—Yordam Information Technology Mobile Library ApplicationAI18/9/202417/6/2026
Missing Authentication for Critical Function, Missing Authorization vulnerability in Yordam Information Technology Mobile Library Application allows Retrieve Embedded Sensitive Data. This issue affects Mobile Library Application: before 5.0.
AplazadaMedia (6.9)0.38%—Yordam Information Technology Yordam Library Automation SystemAI18/9/202417/6/2026
Improper Restriction of Excessive Authentication Attempts vulnerability in Yordam Information Technology Yordam Library Automation System allows Interface Manipulation. This issue affects Yordam Library Automation System: before 20.1.
AplazadaAlta (7.5)1.9%💥 ExploitXian Daxi Information Technology Officeweb365AI10/9/202417/6/2026
Arbitrary File Read vulnerability in Xi'an Daxi Information Technology Co., Ltd OfficeWeb365 v.7.18.23.0 and v8.6.1.0 allows a remote attacker to obtain sensitive information via the "Pic/Indexes" interface
AplazadaCrítica (9.4)0.61%—Siemens Simatic BatchAISiemens Simatic Information ServerAISiemens Simatic PCS 7AISiemens Simatic Process HistorianAI+210/9/202417/6/2026
A vulnerability has been identified in SIMATIC BATCH V9.1 (All versions), SIMATIC Information Server 2020 (All versions < V2020 SP2 Update 5), SIMATIC Information Server 2022 (All versions < V2022 SP1 Update 2), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC06), SIMATIC Process Historian 2020 (All versions < V2020 SP2…
AplazadaBaja (2)0.40%—Opentext Performance CenterAI21/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText Performance Center on Windows allows Cross-Site Scripting (XSS).This issue affects Performance Center: 12.63.
AplazadaMedia (5.1)0.62%—Opentext Performance CenterAI21/8/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in OpenText Performance Center on Windows allows Retrieve Embedded Sensitive Data.This issue affects Performance Center: 12.63.
AnalizadaMedia (6.5)0.62%—IBM Infosphere Information Server15/8/202417/6/2026
IBM InfoSphere Information Server could allow an authenticated user to consume file space resources due to unrestricted file uploads. IBM X-Force ID: 298279.
AnalizadaMedia (4.9)0.63%—IBM Infosphere Information Server15/8/202417/6/2026
IBM InfoSphere Information Server 11.7 could allow a privileged user to obtain sensitive information from authentication request headers. IBM X-Force ID: 298277.
AnalizadaMedia (5.4)0.14%—Intel Integrated Performance PrimitivesIntel Oneapi Base Toolkit14/8/202417/6/2026
Uncontrolled search path in some Intel(R) IPP software before version 2021.11 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaMedia (5.4)0.14%—Intel Graphics Performance Analyzers14/8/202417/6/2026
Uncontrolled search path in some Intel(R) GPA software before version 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.