Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1917 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.4) | 0.17% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 10/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an unauthenticated physical memory disclosure in DirectIo64.sys, reachable by unprivileged local users through a single IOCTL with no caller-identity check. The handler writes a… | |
| Pendiente de análisis | Media (6.9) | 0.16% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 8/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to issue arbitrary IN and OUT instructions to any x86 I/O port due to missing allowlist or port validation on… | |
| Pendiente de análisis | Alta (8.5) | 0.17% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 8/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to modify hardware configuration by exploiting exposed IOCTLs with no validation on device selection,… | |
| Pendiente de análisis | Media (6.9) | 0.15% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 14/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation and denial-of-service vulnerability in DirectIo64.sys that allows local attackers to read arbitrary Model-Specific Registers or write zero to any MSR through exposed… | |
| Pendiente de análisis | Alta (8.5) | 0.19% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 8/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a hard-coded credentials vulnerability in DirectIo64.sys that allows local attackers to perform arbitrary physical memory writes by extracting an 8-byte key embedded as a hardcoded literal… | |
| Pendiente de análisis | Media (6.9) | 0.16% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 10/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to clear arbitrary bits at any physical memory address due to missing validation of the physical address… | |
| Pendiente de análisis | Alta (8.5) | 0.15% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 8/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an improper access control vulnerability in the DirectIo64.sys kernel driver that allows unprivileged local users to perform privileged hardware operations by opening a handle to the… | |
| Aplazada | Media (6.1) | 0.15% | — | Yordam Information Technology Consulting Training AND Electronic Systems Industry AND Trade INC Library Information AND Document Automation ProgramAI | 4/9/2026 | 8/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows XSS Targeting HTML Attributes. This issue affects Library… | |
| Aplazada | Media (6.1) | 0.25% | — | Yordam Information Technology Consulting Training AND Electronic Systems Industry AND Trade INC Library Information AND Document Automation ProgramAI | 4/9/2026 | 8/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows Content Spoofing. This issue affects Library Information and… | |
| Aplazada | Alta (8.8) | 0.24% | — | TAC Information Services Internal AND External Trade INC Goldenhorn OneitAI | 4/9/2026 | 8/9/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TAC Information Services Internal and External Trade Inc. GOLDENHORN ONEIT allows Blind SQL Injection. This issue affects GOLDENHORN ONEIT: before Göbeklitepe. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Hospital Information SystemAI | 4/9/2026 | 8/9/2026 | A security flaw has been discovered in code-projects Hospital Information System 1.0. Affected by this vulnerability is the function getSinglePresp of the file includes/presp/PrespController.php. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Hospital Information SystemAI | 4/9/2026 | 4/9/2026 | A vulnerability was identified in code-projects Hospital Information System 1.0. Affected is the function viewReq of the file viewReq.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Hospital Information SystemAI | 4/9/2026 | 4/9/2026 | A vulnerability was determined in code-projects Hospital Information System 1.0. This impacts the function findBySearch of the file addReq.php. This manipulation of the argument Search causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Media (6.5) | 0.32% | — | IBM Netezza Performance Server | 3/9/2026 | 10/9/2026 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This omission may allow a remote attacker to exploit misconfigurations or naming collisions to redirect application requests to an unintended S3 bucket… | |
| Analizada | Media (5.9) | 0.18% | — | IBM Netezza Performance Server | 3/9/2026 | 10/9/2026 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques. | |
| Analizada | Media (4.3) | 0.29% | — | IBM Netezza Performance Server | 3/9/2026 | 10/9/2026 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files. | |
| Analizada | Media (5.9) | 0.20% | — | IBM Netezza Performance Server | 3/9/2026 | 10/9/2026 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques. | |
| Analizada | Alta (7.5) | 0.39% | — | IBM Netezza Performance Server | 3/9/2026 | 10/9/2026 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials that are hardcoded in the application source code, allowing unauthorized access to the container registry. The exposed secret enables attackers to pull private container images, potentially revealing proprietary code, configuration details, and… | |
| Pendiente de análisis | Alta (8.8) | 0.64% | — | Jenkins PerformanceAI | 2/9/2026 | 3/9/2026 | Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can be instantiated when deserializing cached performance reports stored in the build directory on the Jenkins controller, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller. | |
| Aplazada | Crítica (9.3) | 1.3% | — | Digitalni A Informacni Agentura Eobcanka IdentifikaceAI | 31/8/2026 | 1/9/2026 | Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Digitální a informační agentura (DIA) eObčanka-Identifikace on MacOS enables an attacker to register a custom URL scheme (czeeopauth://) for parameterized application execution. Prior to version 3.6.0, incoming… | |
| Aplazada | Baja (2.1) | 0.34% | — | Phpgurukul Student Information SystemAI | 29/8/2026 | 31/8/2026 | A weakness has been identified in PHPGurukul Student Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /student_edit1.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the… | |
| Aplazada | Media (6.1) | 0.25% | — | Ceviz Informatics INC WEB DesignAI | 28/8/2026 | 31/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ceviz Informatics Inc. Web Design allows Reflected XSS. This issue affects Web Design: through 25082026. | |
| Aplazada | Media (6.1) | 0.25% | — | Bilpark Informatics Technologies Industry AND Trade DoxbaseAI | 27/8/2026 | 28/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in BilPark Informatics Technologies Industry and Trade Inc. DoXBASE allows Cross Zone Scripting. This issue affects DoXBASE: through 27082026. NOTE: The vendor was contacted early about this disclosure but did not… | |
| Aplazada | Media (4.3) | 0.28% | — | Softtr Informatics Technology Trading Limited E-commerce PackAI | 27/8/2026 | 28/8/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Softtr Informatics Technology Trading Limited Company E-Commerce Pack allows Cross-Site Scripting (XSS). This issue affects E-Commerce Pack: before 5.03.01.49. | |
| Aplazada | Alta (8.4) | 0.38% | — | Informatik.hu-berlin FlairAI | 24/8/2026 | 24/9/2026 | The official Flair wheels for 0.15.0 and 0.15.1 still contain flair/models/clustering.py, whose ClusteringModel.load static method returns pickle.loads(joblib.load(str(model_file))) and so executes arbitrary Python while loading a model file. Loading a model supplied by an attacker therefore runs that attacker's code… |