Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
4639 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.9) | 0.97% | — | Redhat Hardened ImagesRedhat Jboss Core ServicesRedhat Openshift Container PlatformRedhat Enterprise Linux+3 | 15/1/2026 | 1/9/2026 | A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML… | |
| Analizada | Baja (3.7) | 0.54% | — | Xmlsoft Libxml2Redhat Hardened ImagesRedhat Jboss Core ServicesRedhat Openshift Container Platform+3 | 15/1/2026 | 1/9/2026 | A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to… | |
| Aplazada | Alta (8.5) | 0.20% | — | HTC Vive Runtime ServiceAI | 13/1/2026 | 17/6/2026 | VIVE Runtime Service 1.0.0.4 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path by placing malicious executables in specific system directories to gain LocalSystem access during service… | |
| Aplazada | Media (5.3) | 0.26% | — | Pegasystems Customer Service FrameworkAI | 13/1/2026 | 17/6/2026 | Pega Customer Service Framework versions 8.7.0 through 25.1.0 are affected by a Unrestricted file upload vulnerability, where a privileged user could potentially upload a malicious file. | |
| Analizada | Crítica (9.1) | 1.6% | — | Zohocorp Manageengine Adselfservice Plus | 13/1/2026 | 17/6/2026 | Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper filter configurations. | |
| Analizada | Crítica (9.3) | 53% | 💥 PoC | Servicenow NOW Assist AI AgentsServicenow Virtual Agent API | 12/1/2026 | 17/6/2026 | A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersonate another user and perform the operations that the impersonated user is entitled to perform. ServiceNow has addressed this vulnerability by deploying a relevant security update to hosted instances… | |
| Aplazada | Media (4.9) | 6.2% | — | Cisco Identity Services EngineAICisco Identity Services Engine Passive Identity ConnectorAI | 7/1/2026 | 17/6/2026 | This vulnerability is due to improper parsing of XML that is processed by the web-based management interface of Cisco ISE and Cisco ISE-PIC. An attacker could exploit this vulnerability by uploading a malicious file to the application. A successful exploit could allow the attacker to read arbitrary files from the… | |
| Aplazada | Crítica (9.8) | 0.35% | — | Sfwebservice Inwave JobsAI | 6/1/2026 | 7/10/2026 | Missing Authorization vulnerability in Sfwebservice InWave Jobs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects InWave Jobs: from n/a through 3.5.8. | |
| Analizada | Media (4.8) | 0.19% | — | Centreon Dynamic Service Management | 5/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (DSM extenstio configuration modules) allows Stored XSS to user with elevated privileges. This issue affects Infra Monitoring: from 25.10.0 before 25.10.1, from 24.10.0 before 24.10.4,… | |
| Aplazada | Crítica (9.4) | 0.26% | — | Nuvationenergy Ncloud VPN ServiceAI | 3/1/2026 | 7/10/2026 | A vulnerability in Nuvation Energy nCloud VPN Service allowed Network Boundary Bridging.This issue affected the nCloud VPN Service and was fixed on 2025-12-1 (December, 2025). End users do not have to take any action to mitigate the issue. | |
| Aplazada | Alta (8.1) | 0.38% | — | Mars Multi-application Recovery ServiceAI | 2/1/2026 | 17/6/2026 | An SQL injection vulnerability has been reported to affect MARS (Multi-Application Recovery Service). The remote attackers can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: MARS (Multi-Application Recovery Service) 1.2.1.1686… | |
| Aplazada | Media (4.3) | 0.14% | — | Emendo SEB Co-marquage Service-public.frAI | 31/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in emendo_seb Co-marquage service-public.fr co-marquage-service-public allows Cross Site Request Forgery.This issue affects Co-marquage service-public.fr: from n/a through <= 0.5.77. | |
| Aplazada | Alta (8.8) | 0.34% | — | Echo Call Center Services Trade AND Industry INC Specto CMAI | 24/12/2025 | 7/10/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Echo Call Center Services Trade and Industry Inc. Specto CM allows Remote Code Inclusion. This issue affects Specto CM: before 17032025. | |
| Aplazada | Media (5.4) | 0.17% | — | Echo Call Center Services Trade AND Industry INC Specto CMAI | 24/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Echo Call Center Services Trade and Industry Inc. Specto CM allows Stored XSS. This issue affects Specto CM: before 17032025. | |
| Modificada | Crítica (10) | 0.33% | — | Eclipse Cyclone Data Distribution Service | 23/12/2025 | 5/7/2026 | Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certificate checks and execute commands with System privileges. | |
| Aplazada | Alta (7.3) | 0.45% | 💥 Exploit | Netbt Consulting Services INC E-faturaAI | 22/12/2025 | 17/6/2026 | Unquoted Search Path or Element vulnerability in NetBT Consulting Services Inc. E-Fatura allows Leveraging/Manipulating Configuration File Search Paths, Redirect Access to Libraries. This issue affects e-Fatura: before 1.2.15. | |
| Aplazada | Media (6.5) | 0.12% | — | Identity Agent FOR Terminal ServicesAI | 22/12/2025 | 17/6/2026 | An authenticated local user can obtain information that allows claiming security policy rules of another user due to sensitive information being printed in plaintext in Identity Agent for Terminal Services debug files. | |
| Aplazada | Alta (8.6) | 0.41% | — | Ltb-project Self Service PasswordAI | 19/12/2025 | 17/6/2026 | LDAP Tool Box Self Service Password 1.5.2 contains a password reset vulnerability that allows attackers to manipulate HTTP Host headers during token generation. Attackers can craft malicious password reset requests that generate tokens sent to a controlled server, enabling potential account takeover by intercepting… | |
| Aplazada | Alta (7.5) | 0.28% | — | Foundry Container ServiceAI | 18/12/2025 | 17/6/2026 | Due to a product misconfiguration in certain deployment types, it was possible from different pods in the same namespace to communicate with each other. This issue resulted in bypass of access control due to the presence of a vulnerable endpoint in Foundry Container Service that executed user-controlled commands… | |
| Aplazada | Alta (8.8) | 0.36% | — | Jthemes Sale Immigration LAW Visa Services Support Migration Agent ConsultingAI | 18/12/2025 | 5/10/2026 | Incorrect Privilege Assignment vulnerability in Jthemes Sale! Immigration law, Visa services support, Migration Agent Consulting immiex allows Privilege Escalation.This issue affects Sale! Immigration law, Visa services support, Migration Agent Consulting: from n/a through <= 1.5.8. | |
| Aplazada | Alta (7.1) | 0.23% | — | GG Soft Software Services INC PaperworkAI | 17/12/2025 | 28/9/2026 | Authorization Bypass Through User-Controlled Key vulnerability in GG Soft Software Services Inc. PaperWork allows Exploitation of Trusted Identifiers. This issue affects PaperWork: from 5.2.0.9427 before 6.0. | |
| Aplazada | Alta (7.6) | 0.24% | — | Aksis Computer Services AND Consulting INC AxonboardAI | 11/12/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Aksis Computer Services and Consulting Inc. AxOnboard allows Exploitation of Trusted Identifiers. This issue affects AxOnboard: from 3.2.0 before 3.3.0. | |
| Aplazada | Baja (3.5) | 0.20% | — | TAC Information Services Internal AND External Trade INC GoldenhornAI | 10/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TAC Information Services Internal and External Trade Inc. GoldenHorn allows Cross-Site Scripting (XSS). This issue affects GoldenHorn: before 4.25.1121.1. | |
| Analizada | Media (6.5) | 0.27% | — | IBM Storage Defender Resiliency Service | 8/12/2025 | 7/10/2026 | IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.18 could disclose sensitive user credentials in log files. | |
| Analizada | Baja (1.9) | 0.28% | — | Alokjaiswal Hotel-management-services-using-mysql-and-php | 7/12/2025 | 17/6/2026 | A vulnerability was found in alokjaiswal Hotel-Management-services-using-MYSQL-and-php up to 5f8b60a7aa6c06a5632de569d4e3f6a8cd82f76f. Affected by this vulnerability is an unknown functionality of the file /dishsub.php. The manipulation of the argument item.name results in cross site scripting. It is possible to… |