Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

227 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.67%—Microsoft Purview Data Governance21/8/202517/6/2026
Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.
AplazadaAlta (8.1)0.58%—Ancoratthemes CitygovAI27/6/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes CityGov citygov allows PHP Local File Inclusion.This issue affects CityGov: from n/a through <= 1.9.
AnalizadaCrítica (9.8)0.33%—IBM Security Verify Governance6/6/202517/6/2026
IBM Security Verify Governance 10.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
AnalizadaAlta (8.8)0.89%—Govicture Rx1800 Firmware9/5/202517/6/2026
Victure RX1800 EN_V1.0.0_r12_110933 was discovered to contain a command injection vulnerability.
AnalizadaAlta (8.8)0.56%—Govicture Rx1800 Firmware9/5/202517/6/2026
Incorrect access control in Victure RX1800 EN_V1.0.0_r12_110933 allows attackers to enable SSH and Telnet services without authentication.
AnalizadaMedia (6.8)0.44%—Govicture Rx1800 Firmware9/5/202517/6/2026
An issue in Victure RX1800 EN_V1.0.0_r12_110933 allows physically proximate attackers to execute arbitrary code or gain root access.
ModificadaCrítica (9.8)0.65%—Govicture Rx1800 Firmware9/5/20255/7/2026
Victure RX1800 EN_V1.0.0_r12_110933 was discovered to utilize a weak default password which includes the last 8 digits of the Mac address.
AnalizadaMedia (5.4)0.23%—IBM Security Verify Governance9/4/202517/6/2026
IBM Security Verify Governance 10.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AplazadaCrítica (9.9)0.78%—Govind Visual Text EditorAI26/3/202517/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Govind Visual Text Editor visual-text-editor allows Remote Code Inclusion.This issue affects Visual Text Editor: from n/a through <= 1.2.1.
AnalizadaMedia (4.9)0.24%—IBM Security Verify Governance29/1/202517/6/2026
IBM Security Verify Governance 10.0.2 Identity Manager uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does not also use a salt as part of the input.
AnalizadaMedia (5.9)0.24%—IBM Security Verify Governance29/1/202517/6/2026
IBM Security Verify Governance 10.0.2 Identity Manager can transmit user credentials in clear text that could be obtained by an attacker using man in the middle techniques.
AplazadaMedia (6.5)0.32%—Shenzhen Intellirocks Tech CO LTD Govee HomeAI27/1/202517/6/2026
An issue in Shenzhen Intellirocks Tech Co. Ltd Govee Home iOS 6.5.01 allows attackers to access sensitive user information via supplying a crafted payload.
AplazadaCrítica (10)0.61%—Govee HomeAI19/12/202417/6/2026
Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote attacker to control devices owned by other users via changing "device", "sku" and "type" fields' values. This issue affects Govee Home applications on Android and iOS in versions before 5.9.
AnalizadaAlta (8.8)0.16%—Govicture Pc420 Firmware18/9/202417/6/2026
Victure PC420 1.1.39 was discovered to use a weak encryption key for the file enabled_telnet.dat on the Micro SD card.
AnalizadaMedia (6.5)0.35%—Govicture Pc420 Firmware18/9/202417/6/2026
Victure PC420 1.1.39 was discovered to use a weak and partially hardcoded key to encrypt data.
AnalizadaAlta (8.8)0.40%—Govicture Pc420 Firmware18/9/202417/6/2026
Victure PC420 1.1.39 was discovered to contain a hardcoded root password which is stored in plaintext.
AnalizadaMedia (5.7)0.43%—Nukeviet EgovernmentNukeviet10/6/202417/6/2026
nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before are vulnerable to arbitrary code execution via the /admin/extensions/upload.php component.
AnalizadaAlta (8.8)0.84%—Nukeviet EgovernmentNukeviet10/6/202417/6/2026
nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before have a Deserialization vulnerability which results in code execution via /admin/extensions/download.php and /admin/extensions/upload.php.
AnalizadaMedia (5.9)0.32%—IBM Security Verify Governance20/3/202417/6/2026
IBM Security Verify Governance 10.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 258375.
ModificadaMedia (4.3)0.32%—SAP Master Data Governance FOR Material Data13/2/202417/6/2026
SAP Master Data Governance for Material Data - versions 618, 619, 620, 621, 622, 800, 801, 802, 803, 804, does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow an attacker to read some sensitive information but no impact to integrity and…
ModificadaMedia (4.3)0.67%💥 PoCCentralsquare Click2gov Building Permit12/1/202417/6/2026
An issue was discovered in CentralSquare Click2Gov Building Permit before October 2023. Lack of access control protections allows remote attackers to arbitrarily delete the contractors from any user's account when the user ID and contractor information is known.
ModificadaMedia (6.1)0.50%—Gov.uk Govuk Tech Docs4/1/202414/7/2026
govuk_tech_docs versions from 2.0.2 to before 3.3.1 are vulnerable to a cross-site scripting vulnerability. Malicious JavaScript may be executed in the user's browser if a malicious search result is displayed on the search page.
ModificadaMedia (5.3)0.63%—SAP Master Data Governance12/12/202317/6/2026
SAP Master Data Governance File Upload application allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing ‘traverse to parent directory’ are passed through to the file APIs. As a result, it has a low impact to the confidentiality.
ModificadaMedia (5.3)0.86%—Catalisgov Cms36030/11/202317/6/2026
Catalis (previously Icon Software) CMS360 allows a remote, unauthenticated attacker to view sensitive court documents by modifying document and other identifiers in URLs. The impact varies based on the intention and configuration of a specific CMS360 installation.
ModificadaAlta (8.8)0.27%—Wpgov Anac XML Bandi DI Gara18/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi ANAC XML Bandi di Gara.This issue affects ANAC XML Bandi di Gara: from n/a through 7.5.
Orbitaley — Vulnerabilidades