Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

196 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.1)0.40%—Phpgurukul Emergency Ambulance Hiring Portal20/6/202517/6/2026
A vulnerability classified as critical was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/add-ambulance.php. The manipulation of the argument ambregnum leads to sql injection. The attack can be launched remotely. The exploit has…
AnalizadaBaja (2.1)0.40%—Phpgurukul Emergency Ambulance Hiring Portal20/6/202517/6/2026
A vulnerability classified as critical has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected is an unknown function of the file /admin/bwdates-request-report-details.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to launch the attack remotely. The…
AnalizadaCrítica (9.3)0.57%—Cyberdata 011209 SIP Emergency Intercom Firmware9/6/202517/6/2026
CyberData 011209 Intercom could allow an authenticated attacker to upload arbitrary files to multiple locations within the system.
AnalizadaMedia (6.9)0.37%—Cyberdata 011209 SIP Emergency Intercom Firmware9/6/202517/6/2026
CyberData 011209 Intercom could allow an unauthenticated user to gather sensitive information through blind SQL injections.
AnalizadaAlta (8.7)0.42%—Cyberdata 011209 SIP Emergency Intercom Firmware9/6/202517/6/2026
CyberData 011209 Intercom does not properly store or protect web server admin credentials.
AnalizadaAlta (8.7)0.41%—Cyberdata 011209 SIP Emergency Intercom9/6/202517/6/2026
CyberData 011209 Intercom exposes features that could allow an unauthenticated to gain access and cause a denial-of-service condition or system disruption.
AnalizadaCrítica (9.3)0.52%—Cyberdata 011209 SIP Emergency Intercom Firmware9/6/202517/6/2026
CyberData 011209 Intercom could allow an unauthenticated user access to the Web Interface through an alternate path.
AnalizadaMedia (6.9)0.52%—Phpgurukul Emergency Ambulance Hiring Portal5/5/202517/6/2026
A vulnerability classified as critical was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/contact-us.php. The manipulation of the argument mobnum leads to sql injection. The attack can be launched remotely. The exploit has been…
AnalizadaMedia (6.9)0.52%—Phpgurukul Emergency Ambulance Hiring Portal5/5/202517/6/2026
A vulnerability classified as critical has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected is an unknown function of the file /admin/edit-ambulance.php. The manipulation of the argument dconnum leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed…
AnalizadaMedia (6.9)0.54%—Phpgurukul Emergency Ambulance Hiring Portal7/3/202517/6/2026
A vulnerability was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. It has been classified as critical. This affects an unknown part of the file /admin/admin-profile.php. The manipulation of the argument contactnumber leads to sql injection. It is possible to initiate the attack remotely. The exploit has…
AnalizadaMedia (6.9)0.59%—Phpgurukul Emergency Ambulance Hiring Portal7/3/202517/6/2026
A vulnerability was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/booking-details.php. The manipulation of the argument ambulanceregnum leads to sql injection. The attack may be launched remotely. The…
AnalizadaMedia (6.9)0.59%—Phpgurukul Emergency Ambulance Hiring Portal7/3/202517/6/2026
A vulnerability has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/search.php. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The exploit…
AnalizadaMedia (6.9)0.64%—Phpgurukul Emergency Ambulance Hiring Portal7/3/202517/6/2026
A vulnerability, which was classified as critical, was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected is an unknown function of the file /admin/about-us.php. The manipulation of the argument pagedes leads to sql injection. It is possible to launch the attack remotely. The exploit has been…
AplazadaCrítica (9.8)53%💥 PoCLinear Emerge E3-seriesAI2/10/202417/6/2026
The Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary OS commands via the login_id parameter when invoking the forgot_password functionality over HTTP.
AnalizadaMedia (5.4)0.30%—Themergency Foobox8/8/202417/6/2026
The Lightbox & Modal Popup WordPress Plugin – FooBox plugin for WordPress is vulnerable to DOM-based Stored Cross-Site Scripting via HTML data attributes in all versions up to, and including, 2.7.28 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
ModificadaCrítica (9.8)0.98%—75lb Deep-merge30/7/202417/6/2026
Prototype Pollution in 75lb deep-merge 1.1.1 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) and cause other impacts via merge methods of lodash to merge objects.
AnalizadaCrítica (10)0.54%—Intrado 911 Emergency Gateway Firmware26/6/202417/6/2026
Intrado 911 Emergency Gateway login form is vulnerable to an unauthenticated blind time-based SQL injection, which may allow an unauthenticated remote attacker to execute malicious code, exfiltrate data, or manipulate the database.
AplazadaAlta (7.2)1.0%—Document Merge ServiceAI11/6/202417/6/2026
Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Versions 6.5.1 and prior are vulnerable to remote code execution via server-side template injection which, when executed as root, can result in full takeover of the affected system. As of…
AplazadaMedia (5.7)0.26%—Merge Dicom ToolkitAI3/5/202417/6/2026
Use of Externally-Controlled Format String vulnerability in Merge DICOM Toolkit C/C++ on Windows. When MC_Open_Association() function is used to open DICOM Association and gets DICOM Application Context Name with illegal characters, it might result in an unhandled exception.
AplazadaMedia (4)0.19%—Merge Dicom ToolkitAI3/5/202417/6/2026
Use of Out-of-range Pointer Offset vulnerability in Merge DICOM Toolkit C/C++ on Windows. When deprecated MC_XML_To_Message() function is used to read a malformed DICOM XML file, it might result in memory access violation.
AplazadaMedia (4)0.19%—Merge Dicom ToolkitAI3/5/202417/6/2026
Out-of-bounds Read vulnerability in Merge DICOM Toolkit C/C++ on Windows. When MC_Open_File() function is used to read a malformed DICOM data, it might result in over-reading memory buffer and could cause memory access violation.
AnalizadaAlta (8.8)1.5%—Cisco Emergency Responder3/4/202417/6/2026
A vulnerability in Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a directory traversal attack, which could allow the attacker to perform arbitrary actions on an affected device. This vulnerability is due to insufficient protections for the web UI of an affected system. An attacker…
AnalizadaMedia (6.5)0.23%—Cisco Emergency Responder3/4/202417/6/2026
A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to conduct a CSRF attack, which could allow the attacker to perform arbitrary actions on an affected device. This vulnerability is due to insufficient protections for the web UI of an affected system. An attacker could exploit…
AnalizadaMedia (5.4)0.54%—Phpgurukul Emergency Ambulance Hiring Portal30/3/202417/6/2026
A vulnerability was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. It has been classified as problematic. Affected is an unknown function of the file /admin/search.php of the component Search Request Page. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The…
AnalizadaMedia (4.8)0.59%—Phpgurukul Emergency Ambulance Hiring Portal30/3/202417/6/2026
A vulnerability was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0 and classified as problematic. This issue affects some unknown processing of the file /admin/add-ambulance.php of the component Add Ambulance Page. The manipulation of the argument Ambulance Reg No/Driver Name leads to cross site scripting.…
Orbitaley — Vulnerabilidades