Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

1305 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (3.1)0.27%—Hcltech Dfxanalytics16/7/202617/7/2026
HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to implement the HTTP Strict Transport Security (HSTS) policy within its responses, which could allow a remote attacker to downgrade the communication channel to an unencrypted connection (HTTP) and…
AnalizadaMedia (6.5)0.16%—Hcltech Dfxanalytics16/7/202617/7/2026
HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite" attribute on session cookies generated during authentication, which could allow a remote attacker to execute Cross-Site Request Forgery (CSRF) attacks if additional mitigations, such as Anti-CSRF…
AnalizadaAlta (8.2)0.32%—Hcltech Dfxanalytics16/7/202617/7/2026
HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP address details within its generated server responses, which could allow a remote attacker to gather sensitive network topology information and use it to map the internal infrastructure for further…
AnalizadaMedia (5.3)0.33%—Hcltech Dfxanalytics16/7/202617/7/2026
HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote attacker to intercept, delay, or fraudulently retransmit valid authentication data to achieve unauthorized access. To mitigate this risk, the application must implement a mechanism to include timestamps with every…
AnalizadaAlta (7.2)0.28%—Hcltech Dfxanalytics16/7/202617/7/2026
HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The application fails to set the "secure" attribute on session cookies generated during authentication, which could allow a remote attacker to intercept network traffic and capture sensitive cookies, session…
AplazadaAlta (8.7)0.44%—Joomla 4analyticsAI15/7/202623/7/2026
Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS. A specially crafted unauthenticated request may result in website takeover under some circumstances.
AplazadaAlta (8.6)0.44%—Joomla 4analyticsAI15/7/202623/7/2026
Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS in relation to the AI analysis feature.
AnalizadaMedia (5.4)0.23%—Ijsbrandy Siteimprove Analytics10/7/20266/8/2026
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Siteimprove Analytics allows Cross-Site Scripting (XSS). This issue affects Siteimprove Analytics versions: from 0.0.0 to 2.0.1.
AplazadaBaja (2.9)0.40%—Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI3/7/20266/7/2026
A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This issue affects some unknown processing. The manipulation results in session fixiation. The attack can be executed remotely. The attack requires a high level of complexity. The exploitability is assessed as…
AplazadaBaja (2.1)0.37%—Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI3/7/20267/7/2026
A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This vulnerability affects unknown code of the file /index.php?action=view_student of the component POST Handler. The manipulation of the argument ID leads to authorization bypass. Remote…
AplazadaMedia (4.3)0.15%—IO Technologies Plugin FOR Google AnalyticsAI30/6/202630/6/2026
The Plugin for Google Analytics by IO technologies plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on the Google Analytics settings page (ga.php). This makes it possible for unauthenticated attackers to update…
AplazadaMedia (6.9)0.28%—Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI17/6/202618/6/2026
A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. Affected is an unknown function of the file /index.php of the component Student Self-Registration Endpoint. The manipulation leads to improper access controls. Remote exploitation of the attack…
AplazadaAlta (8.5)0.36%—Wp-slimstat Slimstat AnalyticsAI17/6/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs Slimstat Analytics allows Blind SQL Injection. This issue affects Slimstat Analytics: from n/a through 5.4.11.
AplazadaMedia (6.5)0.27%—Wp-slimstat Slimstat AnalyticsAI17/6/202617/6/2026
Unauthenticated Deserialization of untrusted data in Slimstat Analytics < 5.4.0 versions.
AplazadaAlta (7.1)0.18%—Elis Wordcents Adsense Widget With AnalyticsAI15/6/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in Eli&#039;s WordCents adSense Widget with Analytics <= 1.3.03.27 versions.
AplazadaBaja (2.1)0.27%—Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI14/6/202623/7/2026
A vulnerability has been found in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. The impacted element is an unknown function of the file /index.php. The manipulation of the argument action leads to cross site scripting. The attack is possible to be carried out remotely. The exploit has…
AplazadaAlta (7.2)0.53%—Wp-slimstat Slimstat AnalyticsAI28/5/202617/6/2026
The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'User-Agent' header in all versions up to, and including, 5.4.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
AplazadaMedia (6.5)0.44%—Independent AnalyticsAI28/5/202617/6/2026
The Independent Analytics plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.14.9. This is due to a public tracking route at /wp-json/iawp/search that accepts attacker-controlled referrer_url values when the signature matches, combined with a scheduled favicon…
AnalizadaAlta (7.8)0.18%—IBM Operations Analytics LOG Analysis27/5/202617/6/2026
IBM Operations Analytics - Log Analysis and IBM SmartCloud Analytics - Log Analysis uses default passwords default passwords from the manufacturing process for use during the installation process, which could allow an attacker to bypass authentication.
AnalizadaAlta (8.2)0.31%—IBM Cognos AnalyticsIBM Cognos Transformer27/5/202617/6/2026
IBM Cognos Analytics 11.2.0, 11.2.4, 12.0, and 12.1.0 and IBM Cognos Transformer 11.2.4, 12.0, and 12.1.0 are vulnerable to cross-site scripting (XSS). This vulnerability allows a remote attacker to inject arbitrary JavaScript code into the web user interface, which may alter the intended functionality and could lead…
AnalizadaCrítica (9.8)0.36%—IBM Operations Analytics LOG Analysis27/5/202617/6/2026
IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 IBM SmartCloud Analytics - Log Analysis does not require that users should have strong passwords by default, which makes it easier for attackers to…
AnalizadaMedia (4.3)0.17%—Hitachi Vantara Pentaho Data Integration AND Analytics27/5/202624/7/2026
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Although the user should not see those explicitly, the defect is mitigated by the fact the user can already leverage those…
AnalizadaMedia (6.3)0.15%—Hitachi Vantara Pentaho Data Integration AND Analytics27/5/202624/7/2026
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, does not apply ACLs on certain API endpoints related to platform mail notfications.
AnalizadaAlta (7.7)0.20%—Hitachi Vantara Pentaho Data Integration AND Analytics27/5/202624/7/2026
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x and 8.3.x, does not prevent certain XML parsers from resolving external entities.
AplazadaBaja (2.1)0.42%—Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI26/5/202624/7/2026
A weakness has been identified in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This impacts an unknown function of the file /index.php of the component SQL Handler. Executing a manipulation can lead to information exposure through error message. The attack may be performed from remote.…