Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
173 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.21% | — | Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI | 4/8/2026 | 26/8/2026 | URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Phishing. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. | |
| Aplazada | Media (5.3) | 0.33% | — | Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI | 4/8/2026 | 26/8/2026 | Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Account Footprinting. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. | |
| Aplazada | Media (6.5) | 0.44% | — | Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI | 4/8/2026 | 26/8/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Path Traversal. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. | |
| Aplazada | Media (5.4) | 0.23% | — | Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI | 4/8/2026 | 26/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Stored XSS. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. | |
| Aplazada | Crítica (9.8) | 0.52% | — | Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI | 4/8/2026 | 26/8/2026 | Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Innotim Software Telecommunications AND Consulting Trade Logsign SiemAI | 31/7/2026 | 26/8/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects Logsign SIEM: before 6.4.115. | |
| Aplazada | Alta (8.6) | 0.39% | — | Consul-mcp-serverAI | 29/7/2026 | 30/7/2026 | In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing a connected client to override the server's configured Consul address via a request header. This may allow a malicious client to redirect the server's Consul API traffic to an attacker-controlled… | |
| Aplazada | Crítica (10) | 0.54% | — | Hashicorp Consul-mcp-serverAI | 29/7/2026 | 30/7/2026 | In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4. | |
| Aplazada | Alta (8.1) | 0.47% | — | Magarsus Consulting LTD Idm-mfaAI | 22/7/2026 | 22/7/2026 | Improper validation of specified type of input vulnerability in Magarsus Consulting Ltd. Co. IDM-MFA allows Authentication Bypass. This issue affects IDM-MFA: from 2025.11.27 before 2026.03.10. | |
| Aplazada | Media (5.4) | 0.23% | — | Bifra Engineering Consulting LTD Q-smart Next PollAI | 20/7/2026 | 20/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bifra Engineering Consulting Ltd. Q-smart NexT Poll allows Stored XSS. This issue affects Q-smart NexT Poll: before 1.8.7. | |
| Aplazada | Crítica (9.8) | 0.47% | — | GIS Informatics Engineering Consulting Laboratory Gislab Laboratory Management SystemAI | 17/7/2026 | 17/7/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management System allows SQL Injection. This issue affects GisLab Laboratory Management System: from 1.4.03 through… | |
| Aplazada | Media (6.5) | 0.36% | — | GIS Informatics Engineering Consulting Laboratory RND AND Software Services Gislab Laboratory Management SystemAI | 17/7/2026 | 17/7/2026 | Authorization bypass through User-Controlled key vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management System allows Exploitation of Trusted Identifiers. This issue affects GisLab Laboratory Management System: from 1.4.03 through 08072026. | |
| Aplazada | Crítica (9.8) | 0.58% | — | Semtek Informatics Software Consulting Trade LTD CO Sem-pmpAI | 10/7/2026 | 10/7/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics Software Consulting Trade Ltd. Co. SEM-PMP allows Command Line Execution through SQL Injection. This issue affects SEM-PMP: through 23042026. | |
| Aplazada | Media (5.4) | 0.23% | — | Twiser Informatics Technology Consulting Trade AND Education INC Okrs & GoalsAI | 9/7/2026 | 9/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Twiser Informatics Technology Consulting, Trade and Education Inc. OKRs & Goals allows Stored XSS. This issue affects OKRs & Goals: from 28220 before 28398. | |
| Aplazada | Media (4.7) | 0.13% | — | Hashicorp Consul-templateAI | 8/7/2026 | 9/7/2026 | The consul-template library before version 0.42.1 is vulnerable to a path redirection issue in the writeToFile template helper that may allow template output to be written outside the intended directory or to overwrite an existing file. This vulnerability (CVE-2026-14361) is fixed in consul-template 0.42.1. | |
| Aplazada | Media (6.5) | 0.38% | — | Nomysoft Informatics Education AND Consulting INC NomysemAI | 8/7/2026 | 8/7/2026 | Exposure of sensitive information due to incompatible policies vulnerability in NOMYSOFT Informatics Education and Consulting Inc. Nomysem allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Nomysem: through 08072026. NOTE: The vendor was contacted early about this disclosure but did… | |
| Aplazada | Alta (7.5) | 0.42% | — | Idvlabs Software AND Consulting Services INC OntimeAI | 7/7/2026 | 7/7/2026 | Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime allows Exploitation of Trusted Identifiers. This issue affects Ontime: through 04052026. | |
| Aplazada | Crítica (9.8) | 0.45% | — | Soagen Informatics Technologies Software AND Consulting ApinizerAI | 11/6/2026 | 17/6/2026 | Improper neutralization of special elements used in an expression language statement ('expression language injection') vulnerability in Soagen Informatics Technologies Software and Consulting Inc. Apinizer allows Code Injection. This issue affects Apinizer: from 2026.04.0 before 2026.04.6. | |
| Aplazada | Alta (8.8) | 0.45% | — | Basamak Information Technology Consulting AND Organization Trade DernekwebAI | 18/5/2026 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Basamak Information Technology Consulting and Organization Trade Ltd. Co. DernekWeb allows Stored XSS. This issue affects DernekWeb: through 30122025. | |
| Aplazada | Media (4.7) | 0.14% | — | Hashicorp Consul-templateAI | 12/5/2026 | 17/6/2026 | The consul-template library before version 0.42.0 is vulnerable to a sandbox path bypass in the file template helper that may allow reading an out-of-sandbox file. This vulnerability (CVE-2026-5061) is fixed in consul-template 0.42.0. | |
| Aplazada | Alta (7.2) | 1.7% | — | Profelis Information AND Consulting Trade AND Industry Limited Company SambaboxAI | 4/5/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Information and Consulting Trade and Industry Limited Company SambaBox allows OS Command Injection. This issue affects SambaBox: from 5.1 before 5.3. | |
| Aplazada | Baja (1.9) | 1.1% | — | Raine Consult Consult LLM MCPAI | 30/3/2026 | 17/6/2026 | A vulnerability was detected in raine consult-llm-mcp up to 2.5.3. Affected by this vulnerability is the function child_process.execSync of the file src/server.ts. The manipulation of the argument git_diff.base_ref/git_diff.files results in os command injection. The attack is only possible with local access. The… | |
| Pendiente de análisis | Media (6.8) | 0.55% | — | Hashicorp ConsulAI | 12/3/2026 | 17/6/2026 | HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5. | |
| Aplazada | Alta (8.1) | 0.58% | — | Ancorathemes ConsultorAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Consultor | Consulting, Accounting & Legal Counsel WordPress Theme consultor allows PHP Local File Inclusion.This issue affects Consultor | Consulting, Accounting & Legal Counsel… | |
| Aplazada | Crítica (9.8) | 0.36% | — | Database Software Training Consulting LTD Databank Accreditation SoftwareAI | 19/2/2026 | 25/6/2026 | Authorization Bypass Through User-Controlled SQL Primary Key vulnerability in DATABASE Software Training Consulting Ltd. Databank Accreditation Software allows SQL Injection. This issue affects Databank Accreditation Software: before 2026/04. |