Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

2110 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.41%—Ctfer.io MonitoringAI16/3/202617/6/2026
The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, metrics and distributed traces). Prior to 0.2.1, due to a mis-written NetworkPolicy, a malicious actor can pivot from a component to any other namespace. This breaks the security-by-default property…
AplazadaMedia (5.3)0.29%—Swit WP Sessions Time Monitoring Full AutomaticAI13/3/202617/6/2026
Missing Authorization vulnerability in activity-log.com WP Sessions Time Monitoring Full Automatic activitytime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Sessions Time Monitoring Full Automatic: from n/a through <= 1.1.3.
AplazadaAlta (8.6)0.15%—Easy File Sharing WEB ServerAI11/3/202617/6/2026
Easy File Sharing Web Server 7.2 contains a local structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by creating a malicious username. Attackers can craft a username with a payload containing 4059 bytes of padding followed by a nseh value and seh pointer…
AnalizadaAlta (7.1)0.84%—Wanderingastronomer Vociferous11/3/202617/6/2026
Vociferous provides cross-platform, offline speech-to-text with local AI refinement. Prior to 4.4.2, the vulnerability exists in src/api/system.py within the export_file route. The application accepts a JSON payload containing a filename and content. While the developer intended for a native UI dialog to handle the…
AnalizadaAlta (8.5)0.19%—Schneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Ecostruxure Power Operation10/3/202624/6/2026
CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges when a locally authenticated attacker sends a crafted data stream, triggering unsafe deserialization.
AplazadaMedia (4.3)0.13%—Font Pairing Preview FOR Landing PagesAI7/3/202617/6/2026
The Font Pairing Preview For Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to modify the plugin's font pairing…
AnalizadaMedia (5.4)0.15%—IBM Engineering Requirements Management Doors Next3/3/202617/6/2026
IBM Engineering Requirements Management DOORS Next 7.1, and 7.2 could allow an authenticated user to view and edit data beyond their authorized access permissions.
ModificadaCrítica (9.3)0.18%—Portwell Engineering Toolkits3/3/202625/6/2026
An improper restriction of operations within the bounds of a memory buffer vulnerability in Portwell Engineering Toolkits version 4.8.2 could allow a local authenticated attacker to read and write to arbitrary memory via the Portwell Engineering Toolkits driver. Successful exploitation of this vulnerability could…
AnalizadaBaja (1.9)0.24%—Codeastro Food Ordering System25/2/202617/6/2026
A security vulnerability has been detected in CodeAstro Food Ordering System 1.0. This affects an unknown function of the file food_ordering.exe. Such manipulation leads to stack-based buffer overflow. The attack can only be performed from a local environment. The exploit has been disclosed publicly and may be used.
AnalizadaMedia (5.5)0.59%—Emiloi E-logbook With Health Monitoring System FOR Covid-1924/2/202617/6/2026
A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This vulnerability affects unknown code of the file /check_profile_old.php. The manipulation of the argument profile_id leads to sql injection. Remote exploitation of the attack is possible. The exploit…
AplazadaCrítica (9.8)0.37%—Order UP Online Ordering SystemAI23/2/202617/6/2026
SQL Injection vulnerability in the /api/integrations/getintegrations endpoint of Order Up Online Ordering System 1.0 allows an unauthenticated attacker to access sensitive backend database data via a crafted store_id parameter in a POST request.
AplazadaAlta (7.3)0.22%—Mecode Informatics AND Engineering Services LTD EnvantyAI19/2/202617/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in MeCODE Informatics and Engineering Services Ltd. Envanty allows Parameter Injection. This issue affects Envanty: before 1.0.6. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. The vulnerability was learned to be…
AplazadaMedia (6.4)0.24%—Display During Conditional ShortcodeAI18/2/202617/6/2026
The Display During Conditional Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access…
AplazadaMedia (5.5)0.44%—Huace Monitoring AND Early Warning SystemAI17/2/202617/6/2026
A weakness has been identified in Huace Monitoring and Early Warning System 2.2. Affected by this issue is some unknown functionality of the file /Web/SysManage/ProjectRole.aspx. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been…
AplazadaCrítica (9.4)0.39%—E-kalite Software Hardware Engineering Design AND Internet Services Industry AND Trade LTD CO TurboardAI11/2/202617/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard allows Reflected XSS. This issue affects Turboard: from 2025.07 before 2026.02. NOTE: This CVE record…
AnalizadaCrítica (9.8)2.5%💥 PoCMicrosoft Azure Conversation Authoring Client Library10/2/202617/6/2026
Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.
AnalizadaMedia (5.1)0.18%—Flowring Agentflow10/2/202617/6/2026
AgentFlow developed by Flowring has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to inject persistent JavaScript codes that are executed in users' browsers upon page load.
AnalizadaMedia (5.1)0.21%—Flowring Agentflow10/2/202617/6/2026
AgentFlow developed by Flowring has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.
AnalizadaAlta (8.7)0.46%—Flowring Agentflow10/2/202617/6/2026
Agentflow developed by Flowring has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
AnalizadaCrítica (9.3)0.55%—Flowring Agentflow10/2/202617/6/2026
Agentflow developed by Flowring has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify, and delete database contents by using a specific functionality.
AnalizadaCrítica (9.3)0.54%—Flowring Agentflow10/2/202617/6/2026
Agentflow developed by Flowring has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to exploit a specific functionality to obtain arbitrary user authentication token and log into the system as any user.
AplazadaAlta (8.7)0.34%—Flowring DocpediaAI10/2/202617/6/2026
Docpedia developed by Flowring has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
AplazadaAlta (8.7)0.49%—Flowring DocpediaAI10/2/202617/6/2026
Docpedia developed by Flowring has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.
AnalizadaMedia (5.5)0.38%—Projectworlds Online Food Ordering System8/2/202617/6/2026
A flaw has been found in projectworlds Online Food Ordering System 1.0. This affects an unknown function of the file /view-ticket.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.
AnalizadaMedia (5.4)0.16%—IBM Engineering Lifecycle Management3/2/202617/6/2026
IBM Engineering Lifecycle Management - Global Configuration Management 7.0.3 through 7.0.3 Interim Fix 017, and 7.1.0 through 7.1.0 Interim Fix 004 IBM Global Configuration Management is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI…