Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
2110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.42% | — | Projectworlds Online Notes Sharing Platform | 14/8/2025 | 17/6/2026 | A vulnerability has been found in projectworlds Online Notes Sharing Platform 1.0. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument User leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (5.5) | 0.63% | — | Dahuatech Monitoring Platform | 9/8/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Dinstar Monitoring Platform 甘肃省危险品库监控平台 1.0. Affected is an unknown function of the file /itc/$%7BappPath%7D/login_getPasswordErrorNum.action. The manipulation of the argument userBean.loginName leads to sql injection. It is possible to launch the attack… | |
| Analizada | Media (5.5) | 4.4% | — | Xuanshao Spring-shiro-training | 9/8/2025 | 17/6/2026 | A vulnerability was found in wangzhixuan spring-shiro-training up to 94812c1fd8f7fe796c931f4984ff1aa0671ab562. It has been declared as critical. This vulnerability affects unknown code of the file /role/add. The manipulation leads to command injection. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.37% | — | Zlt2000 Microservices-platformAIVmware Spring BootAI | 8/8/2025 | 17/6/2026 | A vulnerability has been found in zlt2000 microservices-platform up to 6.0.0 and classified as problematic. This vulnerability affects unknown code of the file /actuator of the component Spring Actuator Interface. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has… | |
| Aplazada | Alta (8.6) | 0.21% | — | EG4 Monitoring CenterAI | 8/8/2025 | 17/6/2026 | The affected product allows firmware updates to be downloaded from EG4's website, transferred via USB dongles, or installed through EG4's Monitoring Center (remote, cloud-connected interface) or via a serial connection, and can install these files without integrity checks. The TTComp archive format used for the… | |
| Analizada | Crítica (9.8) | 0.50% | — | IBM Tivoli Monitoring | 6/8/2025 | 17/6/2026 | IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash. | |
| Analizada | Crítica (9.8) | 0.50% | — | IBM Tivoli Monitoring | 6/8/2025 | 17/6/2026 | IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash. | |
| Aplazada | Alta (7.1) | 0.28% | — | Roche Diagnostics Navify MonitoringAI | 5/8/2025 | 17/6/2026 | Improper Input Validation vulnerability in Roche Diagnostics navify Monitoring allows an attacker to manipulate input data, which may lead to a denial of service (DoS) due to negatively impacting the server's performance. This vulnerability has no impact on data confidentiality or integrity. This issue affects navify… | |
| Analizada | Media (6.1) | 0.18% | — | IBM Engineering Lifecycle Optimization | 5/8/2025 | 17/6/2026 | IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.03 could be susceptible to cross-site scripting due to no validation of URIs. | |
| Aplazada | Media (6.4) | 0.33% | — | Ocean Social SharingAI | 2/8/2025 | 17/6/2026 | The Ocean Social Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via social icon titles in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Analizada | Baja (2.1) | 0.42% | — | Fabian Online Ordering System | 28/7/2025 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Online Ordering System 1.0. Affected is an unknown function of the file /admin/product.php. The manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.5) | 0.44% | — | Fabian Online Ordering System | 28/7/2025 | 17/6/2026 | A vulnerability classified as critical was found in code-projects Online Ordering System 1.0. This vulnerability affects unknown code of the file /signup.php. The manipulation of the argument firstname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (5.5) | 0.52% | — | Fabian Online Ordering System | 27/7/2025 | 17/6/2026 | A vulnerability was found in code-projects Online Ordering System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/edit_product.php. The manipulation of the argument Name leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.5) | 0.51% | — | Fabian Online Ordering System | 27/7/2025 | 17/6/2026 | A vulnerability was found in code-projects Online Ordering System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/product.php. The manipulation of the argument Name leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.5) | 0.51% | — | Fabian Online Ordering System | 27/7/2025 | 17/6/2026 | A vulnerability was found in code-projects Online Ordering System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/delete_member.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to… | |
| Analizada | Media (5.5) | 0.51% | — | Fabian Online Ordering System | 27/7/2025 | 17/6/2026 | A vulnerability has been found in code-projects Online Ordering System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/user.php. The manipulation of the argument un leads to sql injection. The attack can be launched remotely. The exploit has been disclosed… | |
| Analizada | Media (5.5) | 0.51% | — | Fabian Online Ordering System | 27/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in code-projects Online Ordering System 1.0. Affected is an unknown function of the file /admin/delete_user.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Baja (2.1) | 0.51% | — | Carmelo Food Ordering Review System | 25/7/2025 | 17/6/2026 | A vulnerability was found in code-projects Food Review System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/approve_reservation.php. The manipulation of the argument occasion leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to… | |
| Analizada | Baja (2.1) | 0.45% | — | Phpgurukul BP Monitoring Management System | 25/7/2025 | 17/6/2026 | A vulnerability classified as critical was found in PHPGurukul BP Monitoring Management System 1.0. This vulnerability affects unknown code of the file /bwdates-report-result.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Alta (8.8) | 0.40% | — | IBM Engineering Systems Design Rhapsody | 23/7/2025 | 17/6/2026 | IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system. | |
| Analizada | Alta (8.8) | 0.42% | — | IBM Engineering Systems Design Rhapsody | 23/7/2025 | 17/6/2026 | IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system. | |
| Analizada | Alta (7.5) | 0.10% | — | IBM Engineering Systems Design Rhapsody | 23/7/2025 | 17/6/2026 | IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 transmits sensitive information without encryption that could allow an attacker to obtain highly sensitive information. | |
| Analizada | Baja (2.1) | 0.37% | 💥 PoC | Carmelo Food Ordering Review System | 22/7/2025 | 17/6/2026 | A vulnerability was found in code-projects Food Ordering Review System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /user/reservation_page.php. The manipulation of the argument reg_Id leads to sql injection. The attack can be launched remotely. The… | |
| Aplazada | Alta (7.1) | 0.29% | — | Turpak Automatic Station Monitoring SystemAI | 21/7/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Turpak Automatic Station Monitoring System allows Privilege Escalation. This issue affects Automatic Station Monitoring System: before 5.0.6.51. | |
| Analizada | Media (5.5) | 0.43% | — | Carmelo Food Ordering Review System | 18/7/2025 | 17/6/2026 | A vulnerability classified as critical was found in code-projects Food Ordering Review System 1.0. This vulnerability affects unknown code of the file /pages/signup_function.php. The manipulation of the argument fname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… |