Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
5401 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 1.00% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by Improper Input Validation which allows an attacker to inject executable code and can carry out attacks such as XSS, SQL Injection, Command Injection etc. | |
| Analizada | Crítica (9.8) | 0.24% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak passwords or use brute-force techniques to gain unauthorized access to user accounts. | |
| Analizada | Media (5.3) | 0.27% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by Spamming Vulnerability which can allow the actor to excessive spamming can consume server bandwidth and processing resources which may lead to Denial of Service. | |
| Analizada | Crítica (9.8) | 0.29% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicious scripts, gaining full control over the server. | |
| Analizada | Media (6.5) | 0.25% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's session and use it carry out unauthorized transaction behalf of the user. | |
| Analizada | Alta (7.5) | 0.32% | — | Hcltech Aftermarket Cloud | 26/3/2026 | 17/6/2026 | HCL Aftermarket DPC is affected by File Discovery which allows attacker could exploit this issue to read sensitive files present in the system and may use it to craft further attacks. | |
| Aplazada | Baja (2.9) | 0.57% | — | Kodcloud KodboxAI | 26/3/2026 | 17/6/2026 | A security flaw has been discovered in kalcaddle kodbox 1.64. Impacted is the function can of the file /workspace/source-code/app/controller/explorer/auth.class.php of the component Password-protected Share Handler. Performing a manipulation results in improper authentication. The attack is possible to be carried out… | |
| Aplazada | Baja (2.9) | 0.40% | — | Kodcloud KodboxAI | 26/3/2026 | 17/6/2026 | A vulnerability was identified in kalcaddle kodbox 1.64. This issue affects the function Add of the file app/controller/explorer/userShare.class.php of the component Public Share Handler. Such manipulation leads to unrestricted upload. The attack can be executed remotely. This attack is characterized by high… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Quantumcloud ChatbotAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuantumCloud ChatBot chatbot allows Blind SQL Injection.This issue affects ChatBot: from n/a through <= 7.7.9. | |
| En análisis | Alta (8.6) | 1.2% | 💥 Exploit | Vmware Spring Cloud Config | 24/3/2026 | 4/9/2026 | Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configured search directories.This issue affects Spring Cloud: from 3.1.X before 3.1.13,… | |
| Pendiente de análisis | Crítica (9.4) | 0.41% | — | Salesforce Marketing Cloud EngagementAI | 23/3/2026 | 17/6/2026 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 30th, 2026. | |
| Aplazada | Baja (2.9) | 0.55% | — | Kodcloud KodboxAI | 23/3/2026 | 17/6/2026 | A security vulnerability has been detected in kalcaddle kodbox 1.64. This impacts the function loginAfter/tfaVerify of the file /workspace/source-code/plugins/client/controller/tfa/index.class.php of the component Password Login. The manipulation leads to improper authentication. The attack is possible to be carried… | |
| Aplazada | Baja (2) | 3.4% | — | Kodcloud KodboxAI | 23/3/2026 | 17/6/2026 | A weakness has been identified in kalcaddle kodbox 1.64. This affects the function checkBin of the file /workspace/source-code/plugins/fileThumb/app.php of the component fileThumb Endpoint. Executing a manipulation can lead to os command injection. The attack can be executed remotely. The exploit has been made… | |
| Aplazada | Baja (1.3) | 0.20% | — | Kodcloud KodboxAI | 23/3/2026 | 17/6/2026 | A security flaw has been discovered in kalcaddle kodbox 1.64. The impacted element is an unknown function of the file /workspace/source-code/plugins/oauth/controller/bind/index.class.php of the component loginSubmit API. Performing a manipulation of the argument third results in cross-site request forgery. Remote… | |
| Aplazada | Baja (2.1) | 0.35% | — | Kodcloud KodboxAI | 23/3/2026 | 17/6/2026 | A vulnerability was identified in kalcaddle kodbox 1.64. The affected element is the function PathDriverUrl of the file /workspace/source-code/app/controller/explorer/editor.class.php of the component fileGet Endpoint. Such manipulation of the argument path leads to server-side request forgery. The attack may be… | |
| Aplazada | Baja (2.9) | 0.42% | — | Kodcloud KodboxAI | 23/3/2026 | 17/6/2026 | A vulnerability was determined in kalcaddle kodbox 1.64. Impacted is the function shareSafeGroup of the file /workspace/source-code/app/controller/explorer/shareOut.class.php of the component Site-level API key Handler. This manipulation of the argument sk causes use of hard-coded cryptographic key . The attack may be… | |
| Aplazada | Media (5.5) | 0.47% | — | Acrel Environmental Monitoring Cloud PlatformAI | 22/3/2026 | 17/6/2026 | A vulnerability was found in Acrel Environmental Monitoring Cloud Platform 1.1.0. This issue affects some unknown processing. Performing a manipulation results in unrestricted upload. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this… | |
| Analizada | Alta (8.6) | 1.0% | — | Fit2cloud Sqlbot | 20/3/2026 | 17/6/2026 | SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a critical SQL Injection vulnerability in the /api/v1/datasource/uploadExcel endpoint that enables Remote Code Execution (RCE), allowing any authenticated user (even the lowest-privileged) to fully… | |
| Analizada | Alta (8.7) | 0.48% | — | Fit2cloud Sqlbot | 20/3/2026 | 17/6/2026 | SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a Server-Side Request Forgery (SSRF) vulnerability that allows an attacker to retrieve arbitrary system and application files from the server. An attacker can exploit the /api/v1/datasource/check… | |
| Analizada | Alta (8.6) | 0.77% | — | Fit2cloud Sqlbot | 19/3/2026 | 17/6/2026 | SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a Stored Prompt Injection vulnerability that chains three flaws: a missing permission check on the Excel upload API allowing any authenticated user to upload malicious terminology, unsanitized storage… | |
| Analizada | Crítica (9.8) | 0.90% | — | Microsoft Azure Cloud Shell | 19/3/2026 | 17/6/2026 | Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.5) | 0.52% | — | Wgstart Wgcloud | 19/3/2026 | 17/6/2026 | There is an arbitrary file read vulnerability in the test connection function of backend database management in wgcloud v3.6.3 and before, which can be used to read any file on the victim's server. | |
| Analizada | Alta (7.5) | 0.40% | — | Wgstart Wgcloud | 19/3/2026 | 17/6/2026 | The backend database management connection test feature in wgcloud v3.6.3 has a server-side request forgery (SSRF) vulnerability. This issue can be exploited to make the server send requests to probe the internal network, remotely download malicious files, and perform other dangerous operations. | |
| Analizada | Crítica (9.8) | 0.92% | — | Wgstart Wgcloud | 19/3/2026 | 17/6/2026 | An issue in wgcloud v.2.3.7 and before allows a remote attacker to execute arbitrary code via the test connection function | |
| Aplazada | Baja (2.4) | 0.46% | — | Google Cloud StorageAICraftcms Craft CMSAICraftcms Google Cloud StorageAI | 18/3/2026 | 17/6/2026 | The Google Cloud Storage for Craft CMS plugin provides a Google Cloud Storage integration for Craft CMS. In versions on the 2.x branch prior to 2.2.1, the `DefaultController->actionLoadBucketData()` endpoint allows unauthenticated users with a valid CSRF token to view a list of buckets that the plugin is allowed to… |