Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

71 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.24%—Aikaan IOT Management PlatformAI21/8/202517/6/2026
Aikaan IoT management platform v3.25.0325-5-g2e9c59796 sends a newly generated password to users in plaintext via email and also includes the same password as a query parameter in the account activation URL (e.g., https://domain.com/activate=xyz). This practice can result in password exposure via browser history,…
AplazadaCrítica (10)22%—Hikvision Integrated Security Management PlatformAIAlibaba FastjsonAI2/7/202517/6/2026
An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT deserializes untrusted user input, allowing an attacker to trigger…
AplazadaMedia (5.3)0.22%—Summerpearlgroup Vacation Rental Management PlatformAI26/5/202517/6/2026
A vulnerability was found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be launched remotely. Upgrading to version 1.0.2 is able…
AnalizadaMedia (5.3)0.38%—Summerpearlgroup Vacation Rental Management Platform26/5/202517/6/2026
A vulnerability was found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1. It has been classified as problematic. Affected is an unknown function of the component HTTP Response Header Handler. The manipulation leads to information disclosure. It is possible to launch the attack remotely.…
AnalizadaMedia (5.1)0.28%—Summerpearlgroup Vacation Rental Management Platform26/5/202517/6/2026
A vulnerability was found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1 and classified as problematic. This issue affects some unknown processing of the component Header Handler. The manipulation of the argument Host leads to open redirect. The attack may be initiated remotely. Upgrading to…
AnalizadaMedia (5.3)0.41%—Summerpearlgroup Vacation Rental Management Platform26/5/202517/6/2026
A vulnerability has been found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1 and classified as critical. This vulnerability affects unknown code of the component Listing Handler. The manipulation leads to authorization bypass. The attack can be initiated remotely. Upgrading to version 1.0.2 is…
AnalizadaMedia (5.1)0.44%—Summerpearlgroup Vacation Rental Management Platform26/5/202517/6/2026
A vulnerability, which was classified as problematic, was found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1. This affects an unknown part of the file /spgpm/updateListing. The manipulation of the argument spgLsTitle leads to cross site scripting. It is possible to initiate the attack…
AplazadaCrítica (9.3)0.73%—Zong YU Okcat Parking Management PlatformAI12/5/202517/6/2026
The web management interface of Okcat Parking Management Platform from ZONG YU has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
AplazadaCrítica (9.3)0.57%—Zong YU Okcat Parking Management PlatformAI12/5/202517/6/2026
The web management interface of Okcat Parking Management Platform from ZONG YU has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access system functions. These functions include opening gates, viewing license plates and parking records, and restarting the system.
AplazadaMedia (5.3)0.32%—Jinher Network Collaborative Management PlatformAI11/11/202417/6/2026
A vulnerability classified as critical has been found in Jinher Network Collaborative Management Platform 金和数字化智能办公平台 1.0. Affected is an unknown function of the file /C6/JHSoft.Web.AcceptAip/AcceptShow.aspx/. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The…
ModificadaMedia (5.3)0.28%—Redhat 3scale API Management Platform9/10/202417/6/2026
A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is known. Anyone can see the invoice if the URL is known or guessed.
AplazadaCrítica (9.8)0.51%—Hangzhou Xiongwei Technology Development Restaurant Digital Comprehensive Management PlatformAI26/7/202417/6/2026
An issue in Hangzhou Xiongwei Technology Development Co., Ltd. Restaurant Digital Comprehensive Management platform v1 allows an attacker to bypass authentication and perform arbitrary password resets.
AplazadaMedia (5.3)0.62%—Byzoro Smart S200 Management PlatformAI15/5/202417/6/2026
A vulnerability was found in Byzoro Smart S200 Management Platform up to 20240507. It has been rated as critical. This issue affects some unknown processing of the file /useratte/userattestation.php. The manipulation of the argument web_img leads to unrestricted upload. The attack may be initiated remotely. The…
AplazadaCrítica (9.8)0.80%—Zhongcheng Kexin Ticketing Management PlatformAI3/5/202417/6/2026
An arbitrary file upload vulnerability in Zhongcheng Kexin Ticketing Management Platform 20.04 allows attackers to execute arbitrary code via uploading a crafted file.
AplazadaMedia (6.3)1.0%—Byzoro Smart S80 Management PlatformAI20/4/202417/6/2026
A vulnerability classified as critical has been found in Byzoro Smart S80 Management Platform up to 20240411. Affected is an unknown function of the file /importhtml.php. The manipulation of the argument sql leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the…
AplazadaMedia (4.7)1.2%—Byzoro Smart S80 Management PlatformAI9/4/202417/6/2026
A vulnerability was found in Byzoro Smart S80 Management Platform up to 20240317. It has been rated as critical. Affected by this issue is some unknown functionality of the file /useratte/userattestation.php. The manipulation of the argument web_img leads to unrestricted upload. The attack may be launched remotely.…
AplazadaMedia (6.5)0.17%—Byzoro Networks Smart Multi-service Security Gateway Intelligent Management PlatformAI4/4/202417/6/2026
File Upload vulnerability in Byzoro Networks Smart multi-service security gateway intelligent management platform version S210, allows an attacker to obtain sensitive information via the uploadfile.php component.
AplazadaMedia (5.4)0.32%—Avsystem Unified Management PlatformAI18/3/202417/6/2026
An open redirect in the Login/Logout functionality of web management in AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS could allow attackers to redirect authenticated users to malicious websites.
AplazadaMedia (5.9)0.46%—Avsystem Unified Management PlatformAI18/3/202417/6/2026
Improper input validation in AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS can result in unauthenticated CPE (Customer Premises Equipment) devices storing arbitrarily large amounts of data during registration. This can potentially lead to DDoS attacks on the application database and, ultimately, affect…
AplazadaMedia (6.5)0.46%—Avsystem Unified Management PlatformAI18/3/202417/6/2026
Insecure storage of LDAP passwords in the authentication functionality of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allows members (with read access to the application database) to decrypt the LDAP passwords of users who successfully authenticate to web management via LDAP.
ModificadaMedia (5.5)0.21%—Avsystem Unified Management Platform18/3/202417/6/2026
Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with local access to the UMP application server) to access credentials to authenticate to all services, and to decrypt sensitive data stored in the database.
AplazadaAlta (7.7)0.26%—Byzoro Smart S42 Management PlatformAI7/3/202417/6/2026
File Upload vulnerability in Byzro Network Smart s42 Management Platform v.S42 allows a local attacker to execute arbitrary code via the useratte/userattestation.php component.
AplazadaAlta (7.8)1.1%—Baizhuo Network Smart S200 Management PlatformAI5/3/202417/6/2026
SQL Injection vulnerability in Baizhuo Network Smart s200 Management Platform v.S200 allows a local attacker to obtain sensitive information and escalate privileges via the /importexport.php component.
AnalizadaCrítica (9.8)2.3%—Byzoro Smart S42 Management Platform27/2/202417/6/2026
A vulnerability has been found in Byzoro Smart S42 Management Platform up to 20240219 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /useratte/userattestation.php. The manipulation of the argument hidwel leads to unrestricted upload. The attack can be launched…
AnalizadaAlta (7.5)100%⚠ Explotación activaSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.