Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1917 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.15% | — | Intel Integrated Performance Primitives CryptographyIntel Oneapi Base Toolkit | 14/8/2024 | 17/6/2026 | Uncontrolled search path for some Intel(R) IPP Cryptography software before version 2021.11 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.4) | 0.13% | — | Intel Connectivity Performance SuiteAI | 14/8/2024 | 17/6/2026 | Incorrect default permissions for some Intel(R) Connectivity Performance Suite software installers before version 2.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (4.3) | 0.42% | — | IBM Infosphere Information Server | 6/8/2024 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 297429 | |
| Modificada | Media (6.1) | 0.40% | — | Oretnom23 Lost AND Found Information System | 29/7/2024 | 9/7/2026 | Cross Site Scripting vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the page parameter to php-lfis/admin/index.php. | |
| Modificada | Crítica (9.8) | 0.79% | — | Oretnom23 Lost AND Found Information System | 29/7/2024 | 9/7/2026 | SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the id parameter to php-lfis/admin/categories/manage_category.php. | |
| Modificada | Alta (8.8) | 0.81% | — | Oretnom23 Lost AND Found Information System | 29/7/2024 | 9/7/2026 | SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via id parameter to php-lfis/admin/categories/view_category.php. | |
| Modificada | Media (5.4) | 0.30% | — | Oretnom23 Lost AND Found Information System | 29/7/2024 | 9/7/2026 | Cross Site Scripting vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the first, last, middle name fields in the User Profile page. | |
| Modificada | Crítica (9.8) | 0.54% | — | IBM Infosphere Information ServerIBM Infosphere Information Server ON Cloud | 26/7/2024 | 17/6/2026 | IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. IBM X-Force ID: 297719. | |
| Modificada | Media (4.6) | 0.24% | — | IBM Infosphere Information Server | 24/7/2024 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could disclose sensitive user information to another user with physical access to the machine. IBM X-Force ID: 294727. | |
| Aplazada | Alta (7.5) | 0.77% | — | Tf2-item-formatAI | 23/7/2024 | 17/6/2026 | TF2 Item Format helps users format TF2 items to the community standards. Versions of `tf2-item-format` since at least `4.2.6` and prior to `5.9.14` are vulnerable to a Regular Expression Denial of Service (ReDoS) attack when parsing crafted user input. This vulnerability can be exploited by an attacker to perform DoS… | |
| Aplazada | Media (6.5) | 0.36% | — | Pruvasoft Informatics Apinizer Management ConsoleAI | 18/7/2024 | 17/6/2026 | Improper Restriction of XML External Entity Reference vulnerability in PruvaSoft Informatics Apinizer Management Console allows Data Serialization External Entities Blowup. This issue affects Apinizer Management Console: before 2024.05.1. | |
| Aplazada | Media (6.5) | 0.31% | — | Pruvasoft Informatics Apinizer Management ConsoleAI | 18/7/2024 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in PruvaSoft Informatics Apinizer Management Console allows Authentication Bypass. This issue affects Apinizer Management Console: before 2024.05.1. | |
| Aplazada | Crítica (9.6) | 0.37% | — | Pruvasoft Informatics Apinizer Management ConsoleAI | 18/7/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in PruvaSoft Informatics Apinizer Management Console allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Apinizer Management Console: before 2024.05.1. | |
| Aplazada | Crítica (9.9) | 0.44% | — | Pruvasoft Informatics Apinizer Management ConsoleAI | 18/7/2024 | 17/6/2026 | Incorrect Permission Assignment for Critical Resource vulnerability in PruvaSoft Informatics Apinizer Management Console allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Apinizer Management Console: before 2024.05.1. | |
| Modificada | Media (5.4) | 0.24% | — | IBM Infosphere Information Server | 12/7/2024 | 17/6/2026 | IBM InfoSphere Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 297720. | |
| Modificada | Media (5.4) | 0.26% | — | IBM Infosphere Information Server | 30/6/2024 | 17/6/2026 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 286831. | |
| Modificada | Media (5.4) | 0.26% | — | IBM Infosphere Information Server | 30/6/2024 | 17/6/2026 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 276102. | |
| Modificada | Media (5.4) | 0.27% | — | IBM Infosphere Information Server | 30/6/2024 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could allow an authenticated user to read or modify sensitive information by bypassing authentication using insecure direct object references. IBM X-Force ID: 288182. | |
| Modificada | Media (5.4) | 0.26% | — | IBM Infosphere Information Server | 30/6/2024 | 17/6/2026 | IBM InfoSphere Information Server 11.7 is vulnerable stored to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 287136. | |
| Modificada | Media (4.3) | 0.33% | — | IBM Infosphere Information Server | 30/6/2024 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system. IBM X-Force ID: 275775. | |
| Modificada | Media (5.4) | 0.24% | — | IBM Infosphere Information Server | 30/6/2024 | 17/6/2026 | IBM InfoSphere Information Server 11.7 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 275774. | |
| Modificada | Media (5.3) | 0.45% | — | IBM Infosphere Information Server | 30/6/2024 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further attacks against the system. IBM X-Force ID: 290342. | |
| Modificada | Alta (8.8) | 0.26% | — | IBM Infosphere Information Server | 30/6/2024 | 17/6/2026 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 289234. | |
| Modificada | Media (6.1) | 0.34% | — | IBM Infosphere Information Server | 30/6/2024 | 17/6/2026 | IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 287172. | |
| Modificada | Media (5.3) | 0.36% | — | IBM Infosphere Information Server | 30/6/2024 | 17/6/2026 | IBM InfoSphere Information Server 11.7 returns sensitive information in URL information that could be used in further attacks against the system. IBM X-Force ID: 275776. |