Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 321 respecto a la semana anterior
Críticas / altas1271▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 108 respecto a la semana anterior
–

1918 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.81%—Solarwinds Database Performance Analyzer25/4/202317/6/2026
No exception handling vulnerability which revealed sensitive or excessive information to users.
ModificadaMedia (6.1)0.41%—Rarathemes Vryasage Marketing Performance23/4/202317/6/2026
Reflected Cross-Site Scripting (XSS) vulnerability in VryaSage Marketing Performance plugin <= 2.0.0 versions.
ModificadaAlta (8.8)0.95%—Employee Performance Evaluation System Project Employee Performance Evaluation System14/4/202317/6/2026
Employee Performance Evaluation System v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file uploaded to the server.
ModificadaMedia (5.5)0.23%—Mlit National Land Numerical Information Data Conversion Tool11/4/202317/6/2026
National land numerical information data conversion tool all versions improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the PC may be accessed by an attacker.
ModificadaMedia (5.4)0.34%—Prolizyazilim Student Affairs Information System7/4/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Proliz OBS allows Stored XSS for an authenticated user. This issue affects OBS: before 23.04.01.
ModificadaAlta (8.2)0.57%—Jenkins Performance Publisher2/4/202317/6/2026
Jenkins Performance Publisher Plugin 8.09 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
ModificadaAlta (8.8)2.9%—Apache Unstructured Information Management Architecture30/3/202317/6/2026
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache UIMA DUCC. When using the "Distributed UIMA Cluster Computing" (DUCC) module of Apache UIMA, an authenticated user that has the permissions to modify…
ModificadaMedia (6.1)0.38%—Tussendoor Open RDW Kenteken Voertuiginformatie23/3/202317/6/2026
Reflected Cross-Site Scripting (XSS) vulnerability in Tussendoor internet & marketing Open RDW kenteken voertuiginformatie plugin <= 2.0.14 versions.
ModificadaAlta (7.2)0.74%—IBM Qradar Security Information AND Event Manager22/3/202317/6/2026
IBM QRadar SIEM 7.4 and 7.5 is vulnerable to privilege escalation, allowing a user with some admin capabilities to gain additional admin capabilities. IBM X-Force ID: 239425.
ModificadaMedia (5.4)0.34%—University Information Management System Project University Information Management System20/3/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Izmir Katip Celebi University UBYS allows Stored XSS. This issue affects UBYS: before 23.03.16.
ModificadaMedia (6.1)0.64%—Siri-informatica Wi40010/3/20239/7/2026
A cross-site scripting (XSS) vulnerability in the check_login function of SIPE s.r.l WI400 between version 8 and 11 included allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the f parameter.
ModificadaMedia (6.1)0.36%—Ubit Student Information Management System7/3/202317/6/2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in UBIT Information Technologies Student Information Management System. This issue affects Student Information Management System: before 20211126.
ModificadaMedia (6.1)0.36%—Ubit Student Information Management System7/3/202317/6/2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in UBIT Information Technologies Student Information Management System. This issue affects Student Information Management System: before 20211126.
ModificadaMedia (5.4)0.38%—IBM Infosphere Information Server21/2/202317/6/2026
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 247646.
ModificadaAlta (7.5)1.4%—IBM Infosphere Information Server17/2/202317/6/2026
IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 246333
ModificadaAlta (7.5)0.39%—IBM Qradar Security Information AND Event Manager17/2/202317/6/2026
IBM QRadar SIEM 7.4 and 7.5 is vulnerable to information exposure allowing a non-tenant user with a specific domain security profile assigned to see some data from other domains. IBM X-Force ID: 230402.
ModificadaMedia (5.5)0.13%—IBM Infosphere Information Server17/2/202317/6/2026
IBM InfoSphere Information Server 11.7 could allow a local user to obtain sensitive information from a log files. IBM X-Force ID: 246463.
ModificadaMedia (4.6)0.35%—IBM Infosphere Information Server8/2/202317/6/2026
IBM Infosphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 245423.
ModificadaMedia (5.4)0.43%—IBM Infosphere Information Server1/2/202317/6/2026
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 243161.
ModificadaMedia (5.3)0.71%—IBM Infosphere Information Server20/1/202317/6/2026
IBM InfoSphere Information Server 11.7 podría permitir que un ataque remoto provoque que algunos de los componentes queden inutilizables hasta que se reinicie el proceso. ID de IBM X-Force: 237583.
ModificadaAlta (7.5)0.42%—Solarwinds Database Performance Analyzer20/1/202317/6/2026
En DPA 2022.4 y versiones anteriores, los volcados de memoria del montón generados contienen información sensible en texto no cifrado.
ModificadaMedia (5.4)0.40%—Solarwinds Database Performance Analyzer20/1/202317/6/2026
En Database Performance Analyzer (DPA) 2022.4 y versiones anteriores, ciertos vectores de URL son susceptibles a cross-site scripting reflejado autenticado.
ModificadaAlta (7.5)0.31%—IBM Qradar Security Information AND Event Manager17/1/202317/6/2026
IBM QRadar SIEM 7.4 y 7.5 copia los archivos de claves de certificado utilizados para SSL/TLS en la interfaz de usuario web de QRadar en hosts gestionados en el despliegue que no requieren esa clave. ID de IBM X-Force: 244356.
ModificadaAlta (7.1)0.37%—Hitachienergy Lumada Asset Performance Management12/1/202317/6/2026
Existe una vulnerabilidad en las versiones afectadas de la función User Asset Group de Lumada APM debido a un fallo en la implementación del mecanismo de control de acceso en el “Limited Engineer” rol, otorgándole acceso a la característica de informes integrados de Power BI. Un atacante que logre explotar la…
ModificadaMedia (6.1)0.51%—Simplesamlphp Information Cards Module9/1/202316/6/2026
Se ha encontrado una vulnerabilidad en Information Cards Module en simpleSAMLphp y ha sido clasificada como problemática. Este problema afecta algún procesamiento desconocido. La manipulación conduce a cross-site scripting. El ataque puede iniciarse de forma remota. La actualización a la versión 1.0 puede solucionar…
Orbitaley — Vulnerabilidades