Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1917 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.95% | — | Setorinformatica Sistema Inteligente Para LaboratoriosAI | 26/4/2024 | 17/6/2026 | Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (RCE) vulnerability via the hprinter parameter. This vulnerability is triggered via a crafted POST request. | |
| Aplazada | Crítica (9.8) | 1.0% | — | Setorinformatica Sistema Inteligente Para LaboratoriosAI | 26/4/2024 | 17/6/2026 | Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (RCE) vulnerability via the hmsg parameter. This vulnerability is triggered via a crafted POST request. | |
| Aplazada | Media (6.5) | 0.74% | — | Wp-formassemblyAI | 24/4/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in FormAssembly / Drew Buschhorn WP-FormAssembly allows Path Traversal.This issue affects WP-FormAssembly: from n/a through 2.0.5. | |
| Aplazada | Media (6.5) | 0.31% | — | Wp-formassemblyAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FormAssembly / Drew Buschhorn WP-FormAssembly allows Stored XSS.This issue affects WP-FormAssembly: from n/a through 2.0.10. | |
| Analizada | Alta (8.1) | 0.34% | — | IBM Qradar Security Information AND Event Manager | 11/4/2024 | 17/6/2026 | IBM QRadar SIEM 7.5 could allow an unauthorized user to perform unauthorized actions due to improper certificate validation. IBM X-Force ID: 275706. | |
| Analizada | Media (4.8) | 0.55% | — | Nelzkie15 Human Resource Information System | 6/4/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Human Resource Information System 1.0. It has been classified as problematic. Affected is an unknown function of the file Superadmin_Dashboard/process/addbranches_process.php. The manipulation of the argument branches_name leads to cross site scripting. It is possible to… | |
| Analizada | Media (4.8) | 0.55% | — | Nelzkie15 Human Resource Information System | 6/4/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Human Resource Information System 1.0 and classified as problematic. This issue affects some unknown processing of the file Superadmin_Dashboard/process/addcorporate_process.php. The manipulation of the argument corporate_name leads to cross site scripting. The attack may be… | |
| Analizada | Crítica (9.8) | 0.96% | — | Nelzkie15 Human Resource Information System | 6/4/2024 | 17/6/2026 | A vulnerability has been found in SourceCodester Human Resource Information System 1.0 and classified as critical. This vulnerability affects unknown code of the file initialize/login_process.php. The manipulation of the argument hr_email/hr_password leads to sql injection. The attack can be initiated remotely. The… | |
| Analizada | Media (5.4) | 0.34% | 💥 PoC | IBM Qradar Security Information AND Event Manager | 27/3/2024 | 17/6/2026 | IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 285893. | |
| Analizada | Media (5.4) | 0.34% | — | IBM Qradar Security Information AND Event Manager | 27/3/2024 | 17/6/2026 | IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 275939. | |
| Modificada | Media (5.5) | 0.50% | — | IBM Infosphere Information Server | 21/3/2024 | 17/6/2026 | IBM InfoSphere Information Server 11.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 280361. | |
| Modificada | Media (5.5) | 0.17% | — | IBM Host Access Transformation Services | 15/3/2024 | 17/6/2026 | IBM Host Access Transformation Services (HATS) 9.6 through 9.6.1.4 and 9.7 through 9.7.0.3 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 210989. | |
| Aplazada | Alta (7.1) | 0.46% | — | Student Information ChatbotAI | 11/3/2024 | 17/6/2026 | Student Information Chatbot a0196ab allows SQL injection via the username to the login function in index.php. | |
| Analizada | Media (6.1) | 0.44% | 💥 PoC | Setorinformatica S.i.l. | 7/3/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Setor Informatica SIL 3.1 allows attackers to run arbitrary code via the hmessage parameter. | |
| Analizada | Alta (8.4) | 0.67% | — | Oretnom23 Lost AND Found Information System | 7/3/2024 | 17/6/2026 | Sourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at "?page=items/view&id=*" which can be escalated to the remote command execution. | |
| Modificada | Alta (7.5) | 0.41% | — | Oretnom23 Lost AND Found Information System | 6/3/2024 | 9/7/2026 | Sourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at "?page=items/view&id=*". | |
| Modificada | Media (6.7) | 0.20% | — | SGI Performance Co-pilotRedhat Enterprise Linux | 28/2/2024 | 17/6/2026 | A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels utilized by systemd services associated with PCP. While certain services operate within the confines of limited PCP user/group privileges, others are granted full root privileges. This disparity in… | |
| Analizada | Media (6.1) | 0.39% | — | IBM Infosphere Information Server | 28/2/2024 | 17/6/2026 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 273333. | |
| Aplazada | Crítica (9.1) | 0.64% | — | Bentley Alim WEBAIBentley Assetwise Alim WEBAIBentley Assetwise Information Integrity ServerAI | 26/2/2024 | 17/6/2026 | In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token when the user attempts to download files. This is fixed in Assetwise ALIM Web 23.00.04.04 and Assetwise Information Integrity Server 23.00.02.03. | |
| Analizada | Baja (2.7) | 0.60% | — | IBM Infosphere Information Server | 21/2/2024 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could allow an authenticated privileged user to obtain the absolute path of the web server installation which could aid in further attacks against the system. IBM X-Force ID: 275777. | |
| Analizada | Media (5.4) | 0.36% | — | IBM Infosphere Information Server | 21/2/2024 | 17/6/2026 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 256544. | |
| Modificada | Alta (8.8) | 0.21% | — | Blackbam Tinymce AND Tinymce Advanced Professsional Formats AND Styles | 21/2/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in David Stockl TinyMCE and TinyMCE Advanced Professsional Formats and Styles.This issue affects TinyMCE and TinyMCE Advanced Professsional Formats and Styles: from n/a through 1.1.2. | |
| Modificada | Crítica (9.8) | 0.72% | — | Unipa University Information System | 14/2/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UNI-PA University Marketing & Computer Internet Trade Inc. University Information System allows SQL Injection. This issue affects University Information System: before 12.12.2023. | |
| Modificada | Media (6.7) | 0.21% | — | Intel Performance Maximizer | 14/2/2024 | 17/6/2026 | Improper authorization in some Intel(R) PM software may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.8) | 0.16% | — | Intel AdvisorIntel Cluster CheckerIntel Distribution FOR PythonIntel Inspector+12 | 14/2/2024 | 17/6/2026 | Improper access control in the Intel(R) oneAPI DPC++/C++ Compiler before version 2022.2.1 for some Intel(R) oneAPI Toolkits before version 2022.3.1 may allow authenticated user to potentially enable escalation of privilege via local access. |