Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

60 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)8.9%💥 ExploitDivido23/5/201817/6/2026
In the Divido plugin for OpenCart, there is SQL injection. Attackers can use SQL injection to get some confidential information.
ModificadaAlta (7.8)1.0%—J-lis THE Public Certification Service FOR Individuals8/12/201717/6/2026
Untrusted search path vulnerability in The Public Certification Service for Individuals "The JPKI user's software" Ver3.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaMedia (5.5)3.7%💥 ExploitDivinglog Diving LOG8/9/201717/6/2026
XXE in Diving Log 6.0 allows attackers to remotely view local files through a crafted dive.xml file that is mishandled during a Subsurface import.
ModificadaAlta (7.8)1.8%—Jpki THE Public Certification Service FOR IndividualsJpki THE Public Certification Service FOR Individuals FOR Windows 7Jpki THE Public Certification Service FOR Individuals FOR Windows Vista9/6/201717/6/2026
Untrusted search path vulnerability in The Public Certification Service for Individuals "The JPKI user's software (for Windows 7 and later)" Ver3.0.1 and earlier, The Public Certification Service for Individuals "The JPKI user's software (for Windows Vista)" Ver3.0.1 and earlier and The Public Certification Service…
ModificadaAlta (7.3)0.51%—Jpki THE Public Certification Service FOR Individuals12/5/201717/6/2026
Untrusted search path vulnerability in installers for The Public Certification Service for Individuals "The JPKI user's software (for Windows 7 and later)" Ver3.1 and earlier, The Public Certification Service for Individuals "The JPKI user's software (for Windows Vista)", The Public Certification Service for…
ModificadaMedia (5)21%💥 ExploitElegantthemes Divi11/2/201517/6/2026
Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter in a revslider_show_image action to wp-admin/admin-ajax.php. NOTE: this vulnerability may be a duplicate of CVE-2014-9734.
ModificadaAlta (7.5)0.97%💥 ExploitSoftdivision Maxtrade AOI25/6/200816/6/2026
SQL injection vulnerability in the Trade module in Maxtrade AIO 1.3.23 allows remote attackers to execute arbitrary SQL commands via the categori parameter in a pocategorisell action to modules.php.
ModificadaAlta (7.5)2.4%💥 ExploitDivideconcept VHD WEB Pack6/2/200816/6/2026
Directory traversal vulnerability in index.php in DivideConcept VHD Web Pack 2.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.
ModificadaAlta (7.5)2.5%💥 ExploitPhpselect WEB Development Division3/10/200616/6/2026
PHP remote file inclusion vulnerability in index.php3 in the PDD package for PHPSelect Web Development Division allows remote attackers to execute arbitrary PHP code via a URL in the Application_Root parameter.
ModificadaAlta (7.5)43%—Allume Systems Division Stuffit ExpanderIBM Lotus NotesVerity Keyview Viewing SDKWinzip+310/10/200216/6/2026
Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code via ZIP files containing entries with long filenames, including (1) Microsoft Windows 98 with Plus! Pack, (2) Windows XP, (3) Windows ME, (4) Lotus Notes R4 through R6 (pre-gold),…
Orbitaley — Vulnerabilidades