Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

3560 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.6)0.47%—Rockwellautomation Thinmanager9/9/202517/6/2026
A server-side request forgery security issue exists within Rockwell Automation ThinManager® software due to the lack of input sanitization. Authenticated attackers can exploit this vulnerability by specifying external SMB paths, exposing the ThinServer® service account NTLM hash.
AnalizadaAlta (7.1)0.68%—Rockwellautomation 1756-en2tr Series A FirmwareRockwellautomation 1756-en2tr Series B FirmwareRockwellautomation 1756-en2tr Series C FirmwareRockwellautomation 1756-en4tr Firmware+19/9/202517/6/2026
A security issue exists in the protected mode of EN4TR devices, where sending specifically crafted messages during a Forward Close operation can cause the device to crash.
AnalizadaAlta (7.1)0.25%—Rockwellautomation 1756-en2tr Series A FirmwareRockwellautomation 1756-en2tr Series B FirmwareRockwellautomation 1756-en2tr Series C FirmwareRockwellautomation 1756-en4tr Firmware+19/9/202517/6/2026
A security issue exists in the protected mode of 1756-EN4TR and 1756-EN2TR communication modules, where a Concurrent Forward Close operation can trigger a Major Non-Recoverable (MNFR) fault. This condition may lead to unexpected system crashes and loss of device availability.
AnalizadaAlta (8.7)0.37%—Rockwellautomation Factorytalk Activation Manager9/9/202517/6/2026
A security issue exists within FactoryTalk Activation Manager. An error in the implementation of cryptography within the software could allow attackers to decrypt traffic. This could result in data exposure, session hijacking, or full communication compromise.
AnalizadaAlta (8.7)0.29%—Rockwellautomation Factorytalk Analytics Logixai9/9/20251/10/2026
An open database issue exists in the affected product and version. The security issue stems from an over permissive Redis instance. This could result in an attacker on the intranet accessing sensitive data and potential alteration of data.
AnalizadaAlta (8.2)0.41%—Rockwellautomation Controllogix 5580 Firmware9/9/20251/10/2026
A denial-of-service security issue exists in the affected product and version. The security issue stems from the controller repeatedly attempting to forward messages. The issue could result in a major nonrecoverable fault on the controller.
AnalizadaMedia (5.5)0.42%—Itsourcecode Student Information Management System9/9/202517/6/2026
A security vulnerability has been detected in itsourcecode Student Information Management System 1.0. This affects an unknown function of the file /admin/modules/room/index.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly…
AnalizadaMedia (5.5)0.42%—Itsourcecode Student Information Management System9/9/202517/6/2026
A weakness has been identified in itsourcecode Student Information Management System 1.0. The impacted element is an unknown function of the file /admin/modules/department/index.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made…
AnalizadaMedia (5.5)0.42%—Itsourcecode Student Information Management System8/9/202517/6/2026
A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is an unknown function of the file /admin/modules/instructor/index.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to…
AnalizadaMedia (5.5)0.42%—Itsourcecode Student Information Management System6/9/202517/6/2026
A vulnerability was determined in itsourcecode Student Information Management System 1.0. This affects an unknown part of the file /admin/login.php. Executing manipulation of the argument uname can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
AnalizadaMedia (6.7)0.14%—IBM Transformation Advisor3/9/202517/6/2026
IBM Transformation Advisor 2.0.1 through 4.3.1 incorrectly assigns privileges to security critical files which could allow a local root escalation inside a container running the IBM Transformation Advisor Operator Catalog image.
AnalizadaMedia (5.5)0.42%—Itsourcecode Student Information Management System2/9/202517/6/2026
A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is an unknown function of the file /admin/modules/course/index.php. Performing manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has…
AnalizadaMedia (5.5)0.42%—Itsourcecode Student Information Management System2/9/202517/6/2026
A vulnerability was identified in itsourcecode Student Information Management System 1.0. Impacted is an unknown function of the file /admin/modules/subject/index.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.
AnalizadaMedia (5.5)0.42%—Itsourcecode Student Information Management System2/9/202517/6/2026
A vulnerability was determined in itsourcecode Student Information Management System 1.0. This issue affects some unknown processing of the file /admin/modules/student/index.php. This manipulation of the argument studentId causes sql injection. The attack may be initiated remotely. The exploit has been publicly…
ModificadaAlta (7.5)2.3%💥 PoCRedhat Build OF Apache Camel FOR Spring BootRedhat FuseRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Expansion Pack+42/9/20256/10/2026
A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol…
AnalizadaMedia (5.5)0.41%—Facebook-julykringcadayona Student Information System30/8/202517/6/2026
A security vulnerability has been detected in itsourcecode Student Information System 1.0. This affects an unknown function of the file /course_edit1.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
AnalizadaBaja (2.1)0.40%—Itsourcecode Student Information Management System29/8/202517/6/2026
A vulnerability was found in code-projects Student Information Management System 1.0. The impacted element is an unknown function of the file /login.php. The manipulation of the argument uname results in cross site scripting. The attack may be performed from a remote location. The exploit has been made public and…
AnalizadaMedia (5.5)0.49%—Nelzkie15 Human Resource Information System26/8/202517/6/2026
A vulnerability has been found in SourceCodester Human Resource Information System 1.0. Affected by this issue is some unknown functionality of the file /Superadmin_Dashboard/process/editemployee_process.php. Such manipulation of the argument employee_file201 leads to unrestricted upload. The attack may be launched…
AnalizadaMedia (5.5)0.49%—Nelzkie15 Human Resource Information System26/8/202517/6/2026
A flaw has been found in SourceCodester Human Resource Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /Admin_Dashboard/process/editemployee_process.php. This manipulation of the argument employee_file201 causes unrestricted upload. The attack may be initiated remotely.…
AnalizadaMedia (5.4)0.18%—IBM Qradar Incident ForensicsIBM Qradar Security Information AND Event Manager22/8/202517/6/2026
IBM QRadar SIEM 7.5 through 7.5.0 Dashboard is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AnalizadaAlta (7.8)0.15%—IBM Qradar Incident ForensicsIBM Qradar Security Information AND Event Manager22/8/202517/6/2026
IBM QRadar SIEM 7.5 through 7.5.0 UP13 could allow an authenticated user to escalate their privileges via a misconfigured cronjob due to execution with unnecessary privileges.
AplazadaMedia (4.3)0.20%—Wpsoul Greenshift Animation AND Page Builder BlocksAI22/8/202517/6/2026
Missing Authorization vulnerability in wpsoul Greenshift greenshift-animation-and-page-builder-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Greenshift: from n/a through <= 12.1.1.
AplazadaAlta (8.8)0.62%—Funnelkit Funnel Builder FOR Woocommerce CheckoutAIFunnelkit Automations Email Marketing Automation AND CRM FOR Wordpress AND WoocommerceAI19/8/202517/6/2026
Multiple FunnelKit plugins are vulnerable to Sensitive Information Exposure via the wf_get_cookie shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including authentication cookies of other site users, which may make privilege escalation…
AplazadaCrítica (9.3)0.37%—Rockwellautomation CompactlogixAI18/8/202517/6/2026
A security issue exists due to improper handling of malformed CIP Forward Close packets during fuzzing. The controller enters a solid red Fault LED state and becomes unresponsive. Upon power cycle, the controller will enter recoverable fault where the MS LED and Fault LED become flashing red and reports fault code…
AplazadaBaja (1.9)0.14%—Euro Information CIC Banque ET Compte EN LigneAI18/8/202517/6/2026
A vulnerability was found in Euro Information CIC banque et compte en ligne App 12.56.0 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.cic_prod.bad. The manipulation leads to improper export of android application components. It is possible…