Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
–

1917 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.64%💥 PoCOretnom23 Lost AND Found Information System4/8/20239/7/2026
Cross Site Scripting (XSS) vulnerability in sourcecodester Lost and Found Information System 1.0 allows remote attackers to run arbitrary code via the First Name, Middle Name and Last Name fields on the Create User page.
ModificadaCrítica (9.8)0.49%—Oretnom23 Lost AND Found Information System23/7/202317/6/2026
A vulnerability has been found in SourceCodester Lost and Found Information System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=delete_category of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql…
ModificadaMedia (6.5)0.54%—IBM Infosphere Information Server19/7/202317/6/2026
IBM InfoSphere Information Server v11.7 podría permitir a un usuario autenticado obtener información confidencial debido a una configuración de seguridad insegura en "InfoSphere Data Flow Designer". IBM X-Force ID: 259352.
ModificadaMedia (6.1)0.50%—Solarwinds Database Performance Analyzer18/7/202317/6/2026
XSS attack was possible in DPA 2023.2 due to insufficient input validation
ModificadaMedia (5.3)0.71%—IBM Infosphere Information Server17/7/202317/6/2026
IBM InfoSphere Information Server v11.7 podría permitir a un atacante remoto obtener información del sistema utilizando una consulta especialmente manipulada que podría ayudar en futuros ataques contra el sistema. ID de IBM X-Force: 257695.
ModificadaCrítica (9.8)0.49%—Oretnom23 Lost AND Found Information System15/7/202317/6/2026
A vulnerability classified as critical has been found in SourceCodester Lost and Found Information System 1.0. This affects an unknown part of the file /classes/Master.php?f=save_item of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. It is possible to initiate the…
ModificadaCrítica (9.8)0.49%—Oretnom23 Lost AND Found Information System15/7/202317/6/2026
A vulnerability was found in SourceCodester Lost and Found Information System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /classes/Master.php?f=save_inquiry of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection.…
ModificadaCrítica (9.8)3.8%💥 ExploitOretnom23 Lost AND Found Information System28/6/202317/6/2026
Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=system_info/contact_information.
ModificadaAlta (7.5)0.39%—IBM Qradar Security Information AND Event Manager27/6/202317/6/2026
IBM QRadar SIEM 7.5.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 248147.
ModificadaMedia (5.4)0.37%—IBM Qradar Security Information AND Event Manager27/6/202317/6/2026
IBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 248144.
ModificadaMedia (4.3)0.44%—IBM Qradar Security Information AND Event Manager27/6/202317/6/2026
IBM QRadar SIEM 7.5.0 could allow an authenticated user to perform unauthorized actions due to hazardous input validation. IBM X-Force ID: 248134.
ModificadaMedia (6.5)0.63%—IBM Qradar Security Information AND Event Manager27/6/202317/6/2026
IBM QRadar SIEM 7.5.0 is vulnerable to information exposure allowing a delegated Admin tenant user with a specific domain security profile assigned to see data from other domains. IBM X-Force ID: 230403.
ModificadaMedia (5.4)0.57%—Performance Indicator System Project Performance Indicator System9/6/202317/6/2026
A vulnerability was found in SourceCodester Performance Indicator System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/addproduct.php. The manipulation of the argument prodname leads to cross site scripting. The attack can be launched remotely.…
ModificadaAlta (8.8)0.73%—Oretnom23 Lost AND Found Information System9/6/202317/6/2026
A vulnerability has been found in SourceCodester Lost and Found Information System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file admin\inquiries\view_inquiry.php. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been…
ModificadaAlta (8.8)0.73%—Oretnom23 Lost AND Found Information System9/6/202317/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Lost and Found Information System 1.0. Affected is an unknown function of the file admin\user\manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been…
ModificadaAlta (8.8)0.73%—Oretnom23 Lost AND Found Information System31/5/202317/6/2026
A vulnerability was found in SourceCodester Lost and Found Information System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/?page=user/list. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to…
ModificadaMedia (5.4)0.55%—Oretnom23 Lost AND Found Information System31/5/202317/6/2026
A vulnerability was found in SourceCodester Lost and Found Information System 1.0. It has been classified as problematic. This affects an unknown part of the file admin/?page=user/manage_user of the component Manage User Page. The manipulation of the argument First Name/Middle Name/Last Name leads to basic cross site…
ModificadaAlta (7.5)1.1%—Fighting Cock Information System Project Fighting Cock Information System31/5/202317/6/2026
SQL Injection vulnerability found in Fighting Cock Information System v.1.0 allows a remote attacker to obtain sensitive information via the edit_breed.php parameter.
ModificadaCrítica (9.1)0.77%💥 PoCBUS Dispatch AND Information System Project BUS Dispatch AND Information System28/5/202317/6/2026
A vulnerability classified as critical has been found in code-projects Bus Dispatch and Information System 1.0. Affected is an unknown function of the file delete_bus.php. The manipulation of the argument busid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the…
ModificadaAlta (8.8)0.26%—Wordpress Performance LAB25/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WordPress Performance Team Performance Lab plugin <= 2.2.0 versions.
ModificadaAlta (8.8)0.26%💥 PoCInternet-formation Wp-advanced-search24/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Mathieu Chartier WordPress WP-Advanced-Search plugin <= 3.3.8 versions.
ModificadaCrítica (9.8)1.4%—IBM Infosphere Information Server22/5/202317/6/2026
IBM InfoSphere Information Server 11.7 is affected by a remote code execution vulnerability due to insecure deserialization in an RMI service. IBM X-Force ID: 255285.
ModificadaMedia (5.4)0.37%—IBM Infosphere Information Server19/5/202317/6/2026
IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 251213.
ModificadaMedia (5.5)0.12%—IBM Infosphere Information Server19/5/202317/6/2026
IBM InfoSphere Information Server 11.7 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 244373.
ModificadaCrítica (9.8)0.68%—IBM Infosphere Information Server19/5/202317/6/2026
IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 243163.