Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
34 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 1.8% | — | Aimstack AIM | 10/4/2024 | 17/6/2026 | A critical Remote Code Execution (RCE) vulnerability was identified in the aimhubio/aim project, specifically within the `/api/runs/search/run/` endpoint, affecting versions >= 3.0.0. The vulnerability resides in the `run_search_api` function of the `aim/web/api/runs/views.py` file, where improper restriction of user… | |
| Analizada | Alta (8.1) | 18% | ⚠ Explotación activa | Acclaimsystems Usaherds | 21/12/2021 | 17/6/2026 | Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials. | |
| Modificada | Alta (8.6) | 1.9% | — | Aimstack AIM | 23/11/2021 | 17/6/2026 | Aim is an open-source, self-hosted machine learning experiment tracking tool. Versions of Aim prior to 3.1.0 are vulnerable to a path traversal attack. By manipulating variables that reference files with “dot-dot-slash (../)” sequences and its variations or by using absolute file paths, it may be possible to access… | |
| Modificada | Alta (7.5) | 1.3% | — | Oneorzero Aims | 1/11/2011 | 16/6/2026 | SQL injection vulnerability in lib/ooz_access.php in OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers to execute arbitrary SQL commands via the cookieName variable. | |
| Modificada | Alta (10) | 3.1% | — | Oneorzero Aims | 1/11/2011 | 16/6/2026 | OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers to bypass authentication and obtain administrator privileges via a crafted oozimsrememberme cookie. | |
| Modificada | Media (4) | 2.3% | 💥 Exploit | Oneorzero Aims | 14/9/2011 | 16/6/2026 | Directory traversal vulnerability in index.php in OneOrZero AIMS 2.6.0 Members Edition allows remote authenticated users to read arbitrary files via directory traversal sequences in the controller parameter in a show_report action. | |
| Modificada | Media (6.5) | 0.90% | 💥 Exploit | Oneorzero Aims | 14/9/2011 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in OneOrZero AIMS 2.6.0 Members Edition and 2.7.0 Trial Edition allow remote authenticated users to execute arbitrary SQL commands via the (1) id parameter in a saved_search action and (2) item_types parameter in a show_item_search action in the… | |
| Modificada | Alta (7.5) | 44% | 💥 Exploit | Aimstats | 22/4/2007 | 16/6/2026 | Static code injection vulnerability in process.php in AimStats 3.2 allows remote attackers to inject PHP code into config.php via the number parameter in an update action. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Aimstats | 22/4/2007 | 16/6/2026 | Static code injection vulnerability in process.php in AimStats 3.2 and earlier allows remote attackers to inject PHP code into config.php via the databasehost parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. |