Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
315 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.24% | — | Softperfect Connection Quality Monitor | 24/7/2025 | 17/6/2026 | SoftPerfect Pty Ltd Connection Quality Monitor v1.1 was discovered to store all credentials in plaintext. | |
| Aplazada | Baja (2.1) | 0.32% | — | Conjure Position Department Service Quality Evaluation SystemAI | 29/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Conjure Position Department Service Quality Evaluation System up to 1.0.11. Affected by this issue is the function eval of the file public/assets/less/bootstrap-less/mixins/head.php. The manipulation of the argument payload leads to backdoor. The… | |
| Aplazada | Crítica (9.3) | 1.5% | — | Siemens Opcenter Execution FoundationAISiemens Opcenter IntelligenceAISiemens Opcenter QualityAISiemens Opcenter RdnlAI+3 | 16/12/2024 | 17/6/2026 | A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2501.0001), Opcenter Intelligence (All versions < V2501.0001), Opcenter Quality (All versions < V2512), Opcenter RDnL (All versions < V2410), SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3),… | |
| Aplazada | Media (5.3) | 0.17% | — | Opentext Application Lifecycle ManagementAIOpentext Quality CenterAI | 16/10/2024 | 17/6/2026 | Untrusted Search Path vulnerability in OpenText™ Application Lifecycle Management (ALM),Quality Center allows Code Inclusion. The vulnerability allows a user to archive a malicious DLLs on the system prior to the installation. This issue affects Application Lifecycle Management (ALM),Quality Center: 15.00, 15.01,… | |
| Aplazada | Crítica (9.3) | 1.1% | — | Siemens Opcenter QualityAISiemens Opcenter RdnlAISiemens Simatic PCS NEOAISiemens Sinec NMSAI+2 | 10/9/2024 | 17/6/2026 | A vulnerability has been identified in Opcenter Quality (All versions < V2406), Opcenter RDnL (All versions < V2410), SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 2), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1), SINEC NMS (All versions), SINEMA Remote Connect Client… | |
| Aplazada | Alta (7.5) | 0.77% | — | Proquality PqprintshippinglabelsAI | 30/4/2024 | 17/6/2026 | ProQuality pqprintshippinglabels before v.4.15.0 is vulnerable to Directory Traversal via the pqprintshippinglabels module. | |
| Aplazada | Crítica (9.8) | 0.59% | — | Mergentech Quality Management SystemAI | 25/3/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mergen Software Quality Management System allows SQL Injection. This issue affects Quality Management System: through 25032024. | |
| Modificada | Crítica (9.8) | 0.53% | — | Mergentech Quality Management System | 18/1/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mergen Software Quality Management System allows SQL Injection. This issue affects Quality Management System: before v1.2. | |
| Modificada | Alta (7.5) | 0.91% | — | Siemens Opcenter QualitySiemens Simatic PCS NEOSiemens Sinumerik Integrate Runmyhmi /automotiveSiemens Totally Integrated Automation Portal | 12/12/2023 | 17/6/2026 | A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All versions < V4.1), SINEC NMS (All versions < V2.0 SP1), Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal… | |
| Modificada | Alta (7.5) | 0.91% | — | Siemens Opcenter QualitySiemens Simatic PCS NEOSiemens Sinumerik Integrate Runmyhmi /automotiveSiemens Totally Integrated Automation Portal | 12/12/2023 | 17/6/2026 | A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All versions < V4.1), SINEC NMS (All versions < V2.0 SP1), Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal… | |
| Modificada | Alta (7.5) | 0.91% | — | Siemens Opcenter QualitySiemens Simatic PCS NEOSiemens Sinumerik Integrate Runmyhmi /automotiveSiemens Totally Integrated Automation Portal | 12/12/2023 | 17/6/2026 | A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All versions < V4.1), SINEC NMS (All versions < V2.0 SP1), Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal… | |
| Modificada | Media (6.1) | 0.49% | — | Siemens Opcenter QualitySiemens Simatic PCS NEOSiemens Sinumerik Integrate Runmyhmi /automotiveSiemens Totally Integrated Automation Portal | 12/12/2023 | 17/6/2026 | A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All versions < V4.1), SINEC NMS (All versions < V2.0 SP1), Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal… | |
| Modificada | Alta (8.8) | 0.94% | — | Siemens Opcenter QualitySiemens Simatic PCS NEOSiemens Sinumerik Integrate Runmyhmi /automotiveSiemens Totally Integrated Automation Portal | 12/12/2023 | 17/6/2026 | A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All versions < V4.1), SINEC NMS (All versions < V2.0 SP1), Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal… | |
| Modificada | Alta (8.8) | 0.21% | — | 10quality Post Gallery | 16/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in 10 Quality Post Gallery plugin <= 2.3.12 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Qualityunit Post Affiliate PRO | 3/9/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in QualityUnit Post Affiliate Pro plugin <= 1.25.0 versions. | |
| Modificada | Media (5.5) | 0.20% | — | Jenkins Testquality Updater | 26/1/2023 | 17/6/2026 | Jenkins TestQuality Updater Plugin 1.3 and earlier stores the TestQuality Updater password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system. | |
| Modificada | Media (6.5) | 0.72% | — | Jenkins Testquality Updater | 26/1/2023 | 17/6/2026 | A missing check in Jenkins TestQuality Updater Plugin 1.3 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified username and password. | |
| Modificada | Alta (8.8) | 0.52% | — | Jenkins Testquality Updater | 26/1/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins TestQuality Updater Plugin 1.3 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified username and password. | |
| Modificada | Alta (7.4) | 0.80% | — | Oracle Enterprise Data Quality | 18/10/2022 | 17/6/2026 | Vulnerability in the Oracle Enterprise Data Quality product of Oracle Fusion Middleware (component: Dashboard). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Data Quality.… | |
| Modificada | Alta (7.5) | 0.87% | — | Oracle Enterprise Data Quality | 18/10/2022 | 17/6/2026 | Vulnerability in the Oracle Enterprise Data Quality product of Oracle Fusion Middleware (component: Dashboard). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Data Quality.… | |
| Modificada | Alta (8.8) | 0.64% | — | Oracle Enterprise Data Quality | 18/10/2022 | 17/6/2026 | Vulnerability in the Oracle Enterprise Data Quality product of Oracle Fusion Middleware (component: Dashboard). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Data Quality.… | |
| Modificada | Alta (8.1) | 0.79% | — | Oracle Enterprise Data Quality | 18/10/2022 | 17/6/2026 | Vulnerability in the Oracle Enterprise Data Quality product of Oracle Fusion Middleware (component: Dashboard). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Data Quality.… | |
| Modificada | Media (5.3) | 0.50% | — | Avdorcis Crystal Quality | 13/9/2022 | 17/6/2026 | Avdor CIS - crystal quality Credentials Management Errors. The product is phone call recorder, you can hear all the recorded calls without authenticate to the system. Attacker sends crafted URL to the system: ip:port//V=2;ChannellD=number;Ext=number;Command=startLM;Client=number;Request=number;R=number number - id of… | |
| Modificada | Media (5.4) | 0.47% | — | IBM Engineering Test ManagementIBM Rational Quality Manager | 29/8/2022 | 17/6/2026 | IBM Engineering Test Management 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 210671. | |
| Modificada | Media (6.5) | 0.37% | — | IBM Engineering Requirements Quality Assistant On-premises | 18/7/2022 | 17/6/2026 | IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force Id: 208310. |