Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
397 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.29% | — | Teconcedev Mayosis CoreAI | 26/5/2026 | 24/7/2026 | Missing Authorization vulnerability in TeconceTheme Mayosis Core allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Mayosis Core: from n/a through 5.4.7. | |
| Aplazada | Media (4.8) | 0.14% | — | ILM Informatique OpenconcertoAI | 4/5/2026 | 17/6/2026 | Plaintext storage of a password vulnerability in ILM Informatique OpenConcerto allows Retrieve Embedded Sensitive Data. This issue affects OpenConcerto: 1.7.5. | |
| Aplazada | Baja (2.4) | 0.14% | — | ILM Informatique OpenconcertoAI | 4/5/2026 | 17/6/2026 | Incorrect Permission Assignment for Critical Resource vulnerability in ILM Informatique OpenConcerto allows Replace Binaries. This issue affects OpenConcerto: 1.7.5. | |
| Analizada | Media (6.2) | 0.14% | — | IBM Concert | 7/4/2026 | 24/7/2026 | IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack. | |
| Aplazada | Media (5.5) | 0.41% | 💥 PoC | Code-projects Concert Ticket Reservation SystemAI | 5/4/2026 | 24/7/2026 | A weakness has been identified in code-projects Concert Ticket Reservation System 1.0. This affects an unknown part of the file /ConcertTicketReservationSystem-master/login.php of the component Parameter Handler. Executing a manipulation of the argument Email can lead to sql injection. The attack may be launched… | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Concert Ticket Reservation SystemAI | 5/4/2026 | 24/7/2026 | A security flaw has been discovered in code-projects Concert Ticket Reservation System 1.0. Affected by this issue is some unknown functionality of the file /ConcertTicketReservationSystem-master/process_search.php of the component Parameter Handler. Performing a manipulation of the argument searching results in sql… | |
| Analizada | Media (5.9) | 0.19% | — | IBM Concert | 25/3/2026 | 17/6/2026 | IBM Concert 1.0.0 through 2.2.0 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques. | |
| Analizada | Alta (7.5) | 0.20% | — | IBM Concert | 25/3/2026 | 17/6/2026 | IBM Concert 1.0.0 through 2.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information | |
| Analizada | Media (5.5) | 0.17% | — | IBM Concert | 25/3/2026 | 17/6/2026 | IBM Concert 1.0.0 through 2.2.0 could allow an attacker to access sensitive information in memory due to the buffer not properly clearing resources. | |
| Analizada | Media (5.5) | 0.15% | — | IBM Concert | 25/3/2026 | 17/6/2026 | IBM Concert 1.0.0 through 2.2.0 could allow a local user to obtain sensitive information due to missing function level access control. | |
| Analizada | Media (5.5) | 0.12% | — | IBM Concert | 25/3/2026 | 17/6/2026 | IBM Concert 1.0.0 through 2.2.0 could allow a privileged user to perform unauthorized actions due to improper restriction of channel communication to intended endpoints. | |
| Analizada | Media (5.5) | 0.09% | — | IBM Concert | 25/3/2026 | 17/6/2026 | IBM Concert 1.0.0 through 2.2.0 contains hard-coded credentials that could be obtained by a local user. | |
| Aplazada | Baja (1.9) | 0.16% | — | Tootallnate OnceAI | 3/3/2026 | 17/6/2026 | Versions of the package @tootallnate/once before 3.0.1 are vulnerable to Incorrect Control Flow Scoping in promise resolving when AbortSignal option is used. The Promise remains in a permanently pending state after the signal is aborted, causing any await or .then() usage to hang indefinitely. This can cause a… | |
| Aplazada | Crítica (9.3) | 0.39% | — | Teconcentheme Emerce CoreAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Emerce Core emerce-core allows Blind SQL Injection.This issue affects Emerce Core: from n/a through <= 1.8. | |
| Aplazada | Crítica (9.3) | 0.29% | — | Teconceatheme Uroan CoreAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Uroan Core uroan-core allows Blind SQL Injection.This issue affects Uroan Core: from n/a through <= 1.4.4. | |
| Aplazada | Crítica (9.3) | 0.29% | — | Teconcetech Woodly CoreAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Woodly Core woodly-core allows Blind SQL Injection.This issue affects Woodly Core: from n/a through <= 1.4. | |
| Aplazada | Crítica (9.3) | 0.29% | — | Teconcetheme Saasplate CoreAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Saasplate Core saasplate-core allows Blind SQL Injection.This issue affects Saasplate Core: from n/a through <= 1.2.8. | |
| Aplazada | Crítica (9.3) | 0.29% | — | Teconcetheme Nestbyte CoreAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Nestbyte Core nestbyte-core allows Blind SQL Injection.This issue affects Nestbyte Core: from n/a through <= 1.2. | |
| Aplazada | Crítica (9.3) | 0.29% | — | Teconcetheme Medinik CoreAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Medinik Core medinik-core allows Blind SQL Injection.This issue affects Medinik Core: from n/a through <= 1.3.6. | |
| Aplazada | Crítica (9.3) | 0.29% | — | Teconceptheme Electio CoreAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Electio Core electio-core allows Blind SQL Injection.This issue affects Electio Core: from n/a through <= 1.4. | |
| Aplazada | Crítica (9.3) | 0.39% | — | Teconcesstheme Crete CoreAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Crete Core crete-core allows Blind SQL Injection.This issue affects Crete Core: from n/a through <= 1.4.3. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Teconceappstore AllmartAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Allmart allmart-core allows Blind SQL Injection.This issue affects Allmart: from n/a through <= 1.1. | |
| Aplazada | Crítica (9.3) | 0.43% | 💥 PoC | Teconceptheme Coven CoreAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Coven Core coven-core allows Blind SQL Injection.This issue affects Coven Core: from n/a through <= 1.3. | |
| Analizada | Alta (7.4) | 0.10% | — | IBM Concert | 17/2/2026 | 17/6/2026 | IBM Concert 1.0.0 through 2.1.0 could allow a local user with specific knowledge about the system's architecture to escalate their privileges due to incorrect file permissions for critical resources. | |
| Analizada | Media (4.3) | 0.15% | — | IBM Concert | 17/2/2026 | 17/6/2026 | IBM Concert 1.0.0 through 2.1.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. |