Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 23% | — | Rosariosis | 24/2/2022 | 17/6/2026 | An unauthenticated SQL Injection vulnerability exists in RosarioSIS before 7.6.1 via the votes parameter in ProgramFunctions/PortalPollsNotes.fnc.php. | |
| Modificada | Media (5.4) | 0.71% | — | Rosariosis | 24/2/2022 | 17/6/2026 | A Cross Site Scripting (XSS) vulnerability exists in RosarioSIS before 4.3 via the SanitizeMarkDown function in ProgramFunctions/MarkDownHTML.fnc.php. | |
| Modificada | Media (5.4) | 0.73% | — | Rosariosis | 24/2/2022 | 17/6/2026 | A Cross Site Scripting (XSS) vulnerability exists in RosarioSIS before 7.6.1 via the xss_clean function in classes/Security.php, which allows remote malicious users to inject arbitrary JavaScript or HTML. An example of affected components are all Markdown input fields. | |
| Modificada | Media (6.1) | 2.3% | — | Rosariosis | 1/2/2022 | 9/7/2026 | Reflected Cross-site scripting (XSS) vulnerability in RosarioSIS 8.2.1 allows attackers to inject arbitrary HTML via the search_term parameter in the modules/Scheduling/Courses.php script. | |
| Modificada | Crítica (9.8) | 51% | — | Rosariosis | 29/11/2021 | 17/6/2026 | An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allows remote attackers to execute PostgreSQL statements (e.g., SELECT, INSERT, UPDATE, and DELETE) through /Side.php via the syear parameter. | |
| Modificada | Media (6.1) | 1.4% | — | Rosariosis Student Information System | 12/8/2020 | 17/6/2026 | Reflected Cross-Site Scripting vulnerability in Modules.php in RosarioSIS Student Information System < 6.5.1 allows remote attackers to execute arbitrary web script via embedding javascript or HTML tags in a GET request. | |
| Modificada | Media (6.1) | 6.4% | — | Rosariosis | 15/7/2020 | 17/6/2026 | RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the PrintSchedules.php script. A remote attacker could exploit this vulnerability using the include_inactive parameter in a crafted URL. | |
| Modificada | Media (6.1) | 1.5% | — | Rosariosis | 15/7/2020 | 17/6/2026 | RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Search.inc.php script. A remote attacker could exploit this vulnerability using the advanced parameter in a crafted URL. | |
| Modificada | Media (6.1) | 5.6% | — | Rosariosis | 15/7/2020 | 17/6/2026 | RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Preferences.php script. A remote attacker could exploit this vulnerability using the tab parameter in a crafted URL. | |
| Modificada | Media (6.1) | 1.5% | — | Rosariosis | 14/7/2020 | 17/6/2026 | RosarioSIS through 6.8-beta allows modules/Custom/NotifyParents.php XSS because of the href attributes for AddStudents.php and User.php. | |
| Modificada | Alta (8.8) | 1.2% | — | Risi Gestao DE Horarios | 21/3/2019 | 17/6/2026 | RISI Gestao de Horarios v3201.09.08 rev.23 allows SQL Injection. | |
| Modificada | Media (6.8) | 0.33% | — | Riverbed Rios | 4/4/2017 | 17/6/2026 | Riverbed RiOS before 9.0.1 does not properly restrict shell access in single-user mode, which makes it easier for physically proximate attackers to obtain root privileges and access decrypted data by replacing the /opt/tms/bin/cli file. | |
| Modificada | Media (6.4) | 0.36% | — | Riverbed Rios | 4/4/2017 | 17/6/2026 | Riverbed RiOS through 9.6.0 has a weak default password for the secure vault, which makes it easier for physically proximate attackers to defeat the secure-vault protection mechanism by leveraging knowledge of the password algorithm and the appliance serial number. NOTE: the vendor believes that this does not meet the… | |
| Modificada | Media (4.6) | 0.28% | — | Riverbed Rios | 4/4/2017 | 17/6/2026 | Riverbed RiOS through 9.6.0 does not require a bootloader password, which makes it easier for physically proximate attackers to defeat the secure-vault protection mechanism via a crafted boot. NOTE: the vendor believes that this does not meet the definition of a vulnerability. The product contains correct… | |
| Modificada | Media (4.6) | 0.42% | — | Riverbed Rios | 4/4/2017 | 17/6/2026 | Riverbed RiOS through 9.6.0 deletes the secure vault with the rm program (not shred or srm), which makes it easier for physically proximate attackers to obtain sensitive information by reading raw disk blocks. | |
| Modificada | Media (5.4) | 0.27% | — | Magzter Touriosity Travelmag | 21/10/2014 | 17/6/2026 | The Touriosity Travelmag (aka com.magzter.touriositytravelmag) application 3.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Nobexrc Musica DE Barrios Sonideros | 19/10/2014 | 17/6/2026 | The musica de barrios sonideros (aka com.nobexinc.wls_93155702.rc) application 3.3.10 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Baja (3.5) | 0.88% | — | Ontariosystems Artiva ArchitectOntariosystems Artiva HealthcareOntariosystems Artiva RMOntariosystems Artiva Workstation | 15/4/2014 | 17/6/2026 | The Artiva Agency Single Sign-On (SSO) implementation in Artiva Workstation 1.3.x before 1.3.9, Artiva Rm 3.1 MR7, Artiva Healthcare 5.2 MR5, and Artiva Architect 3.2 MR5, when the domain-name option is enabled, allows remote attackers to login to arbitrary domain accounts by using the corresponding username on a… | |
| Modificada | Alta (10) | 8.5% | — | Riorey Rios | 16/10/2009 | 16/6/2026 | RioRey RIOS 4.6.6 and 4.7.0 uses an undocumented, hard-coded username (dbadmin) and password (sq!us3r) for an SSH tunnel, which allows remote attackers to gain privileges via port 8022. |