Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
3560 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.6) | 0.47% | — | Rockwellautomation Thinmanager | 9/9/2025 | 17/6/2026 | A server-side request forgery security issue exists within Rockwell Automation ThinManager® software due to the lack of input sanitization. Authenticated attackers can exploit this vulnerability by specifying external SMB paths, exposing the ThinServer® service account NTLM hash. | |
| Analizada | Alta (7.1) | 0.68% | — | Rockwellautomation 1756-en2tr Series A FirmwareRockwellautomation 1756-en2tr Series B FirmwareRockwellautomation 1756-en2tr Series C FirmwareRockwellautomation 1756-en4tr Firmware+1 | 9/9/2025 | 17/6/2026 | A security issue exists in the protected mode of EN4TR devices, where sending specifically crafted messages during a Forward Close operation can cause the device to crash. | |
| Analizada | Alta (7.1) | 0.25% | — | Rockwellautomation 1756-en2tr Series A FirmwareRockwellautomation 1756-en2tr Series B FirmwareRockwellautomation 1756-en2tr Series C FirmwareRockwellautomation 1756-en4tr Firmware+1 | 9/9/2025 | 17/6/2026 | A security issue exists in the protected mode of 1756-EN4TR and 1756-EN2TR communication modules, where a Concurrent Forward Close operation can trigger a Major Non-Recoverable (MNFR) fault. This condition may lead to unexpected system crashes and loss of device availability. | |
| Analizada | Alta (8.7) | 0.37% | — | Rockwellautomation Factorytalk Activation Manager | 9/9/2025 | 17/6/2026 | A security issue exists within FactoryTalk Activation Manager. An error in the implementation of cryptography within the software could allow attackers to decrypt traffic. This could result in data exposure, session hijacking, or full communication compromise. | |
| Analizada | Alta (8.7) | 0.29% | — | Rockwellautomation Factorytalk Analytics Logixai | 9/9/2025 | 1/10/2026 | An open database issue exists in the affected product and version. The security issue stems from an over permissive Redis instance. This could result in an attacker on the intranet accessing sensitive data and potential alteration of data. | |
| Analizada | Alta (8.2) | 0.41% | — | Rockwellautomation Controllogix 5580 Firmware | 9/9/2025 | 1/10/2026 | A denial-of-service security issue exists in the affected product and version. The security issue stems from the controller repeatedly attempting to forward messages. The issue could result in a major nonrecoverable fault on the controller. | |
| Analizada | Media (5.5) | 0.42% | — | Itsourcecode Student Information Management System | 9/9/2025 | 17/6/2026 | A security vulnerability has been detected in itsourcecode Student Information Management System 1.0. This affects an unknown function of the file /admin/modules/room/index.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly… | |
| Analizada | Media (5.5) | 0.42% | — | Itsourcecode Student Information Management System | 9/9/2025 | 17/6/2026 | A weakness has been identified in itsourcecode Student Information Management System 1.0. The impacted element is an unknown function of the file /admin/modules/department/index.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made… | |
| Analizada | Media (5.5) | 0.42% | — | Itsourcecode Student Information Management System | 8/9/2025 | 17/6/2026 | A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is an unknown function of the file /admin/modules/instructor/index.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to… | |
| Analizada | Media (5.5) | 0.42% | — | Itsourcecode Student Information Management System | 6/9/2025 | 17/6/2026 | A vulnerability was determined in itsourcecode Student Information Management System 1.0. This affects an unknown part of the file /admin/login.php. Executing manipulation of the argument uname can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Media (6.7) | 0.14% | — | IBM Transformation Advisor | 3/9/2025 | 17/6/2026 | IBM Transformation Advisor 2.0.1 through 4.3.1 incorrectly assigns privileges to security critical files which could allow a local root escalation inside a container running the IBM Transformation Advisor Operator Catalog image. | |
| Analizada | Media (5.5) | 0.42% | — | Itsourcecode Student Information Management System | 2/9/2025 | 17/6/2026 | A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is an unknown function of the file /admin/modules/course/index.php. Performing manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has… | |
| Analizada | Media (5.5) | 0.42% | — | Itsourcecode Student Information Management System | 2/9/2025 | 17/6/2026 | A vulnerability was identified in itsourcecode Student Information Management System 1.0. Impacted is an unknown function of the file /admin/modules/subject/index.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used. | |
| Analizada | Media (5.5) | 0.42% | — | Itsourcecode Student Information Management System | 2/9/2025 | 17/6/2026 | A vulnerability was determined in itsourcecode Student Information Management System 1.0. This issue affects some unknown processing of the file /admin/modules/student/index.php. This manipulation of the argument studentId causes sql injection. The attack may be initiated remotely. The exploit has been publicly… | |
| Modificada | Alta (7.5) | 2.3% | 💥 PoC | Redhat Build OF Apache Camel FOR Spring BootRedhat FuseRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Expansion Pack+4 | 2/9/2025 | 6/10/2026 | A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol… | |
| Analizada | Media (5.5) | 0.41% | — | Facebook-julykringcadayona Student Information System | 30/8/2025 | 17/6/2026 | A security vulnerability has been detected in itsourcecode Student Information System 1.0. This affects an unknown function of the file /course_edit1.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. | |
| Analizada | Baja (2.1) | 0.40% | — | Itsourcecode Student Information Management System | 29/8/2025 | 17/6/2026 | A vulnerability was found in code-projects Student Information Management System 1.0. The impacted element is an unknown function of the file /login.php. The manipulation of the argument uname results in cross site scripting. The attack may be performed from a remote location. The exploit has been made public and… | |
| Analizada | Media (5.5) | 0.49% | — | Nelzkie15 Human Resource Information System | 26/8/2025 | 17/6/2026 | A vulnerability has been found in SourceCodester Human Resource Information System 1.0. Affected by this issue is some unknown functionality of the file /Superadmin_Dashboard/process/editemployee_process.php. Such manipulation of the argument employee_file201 leads to unrestricted upload. The attack may be launched… | |
| Analizada | Media (5.5) | 0.49% | — | Nelzkie15 Human Resource Information System | 26/8/2025 | 17/6/2026 | A flaw has been found in SourceCodester Human Resource Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /Admin_Dashboard/process/editemployee_process.php. This manipulation of the argument employee_file201 causes unrestricted upload. The attack may be initiated remotely.… | |
| Analizada | Media (5.4) | 0.18% | — | IBM Qradar Incident ForensicsIBM Qradar Security Information AND Event Manager | 22/8/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5.0 Dashboard is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Alta (7.8) | 0.15% | — | IBM Qradar Incident ForensicsIBM Qradar Security Information AND Event Manager | 22/8/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5.0 UP13 could allow an authenticated user to escalate their privileges via a misconfigured cronjob due to execution with unnecessary privileges. | |
| Aplazada | Media (4.3) | 0.20% | — | Wpsoul Greenshift Animation AND Page Builder BlocksAI | 22/8/2025 | 17/6/2026 | Missing Authorization vulnerability in wpsoul Greenshift greenshift-animation-and-page-builder-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Greenshift: from n/a through <= 12.1.1. | |
| Aplazada | Alta (8.8) | 0.62% | — | Funnelkit Funnel Builder FOR Woocommerce CheckoutAIFunnelkit Automations Email Marketing Automation AND CRM FOR Wordpress AND WoocommerceAI | 19/8/2025 | 17/6/2026 | Multiple FunnelKit plugins are vulnerable to Sensitive Information Exposure via the wf_get_cookie shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including authentication cookies of other site users, which may make privilege escalation… | |
| Aplazada | Crítica (9.3) | 0.37% | — | Rockwellautomation CompactlogixAI | 18/8/2025 | 17/6/2026 | A security issue exists due to improper handling of malformed CIP Forward Close packets during fuzzing. The controller enters a solid red Fault LED state and becomes unresponsive. Upon power cycle, the controller will enter recoverable fault where the MS LED and Fault LED become flashing red and reports fault code… | |
| Aplazada | Baja (1.9) | 0.14% | — | Euro Information CIC Banque ET Compte EN LigneAI | 18/8/2025 | 17/6/2026 | A vulnerability was found in Euro Information CIC banque et compte en ligne App 12.56.0 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.cic_prod.bad. The manipulation leads to improper export of android application components. It is possible… |