Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2782▼ 316 respecto a la semana anterior
Críticas / altas1289▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

8468 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.6)0.58%—Ragic Enterprise Cloud DatabaseAI13/10/20258/10/2026
La Base de datos en la nube empresarial desarrollada por Ragic tiene una vulnerabilidad de carga de archivos arbitraria, lo que permite a atacantes remotos privilegiados cargar y ejecutar puertas traseras web shell, posibilitando así la ejecución de código arbitrario en el servidor.
AplazadaCrítica (9.3)0.67%—Netsarang Xmanager EnterpriseAINetsarang XmanagerAINetsarang XshellAINetsarang XftpAI+19/10/202517/6/2026
NetSarang Xmanager Enterprise 5.0 Build 1232, Xmanager 5.0 Build 1045, Xshell 5.0 Build 1322, Xftp 5.0 Build 1218, and Xlpd 5.0 Build 1220 contain a malicious nssock2.dll that implements a multi-stage, DNS-based backdoor. The dormant library contacts a C2 DNS server via a specially crafted TXT record for a…
AnalizadaCrítica (9.8)0.49%—Sick Baggage AnalyticsSick Enterprise AnalyticsSick Logistic Diagnostic AnalyticsSick Package Analytics+16/10/202517/6/2026
The application does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it possible for an attacker to guess user credentials.
AnalizadaMedia (5.3)0.36%—Sick Baggage AnalyticsSick Enterprise AnalyticsSick Logistic Diagnostic AnalyticsSick Package Analytics+16/10/202517/6/2026
For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one.
AnalizadaAlta (7.5)0.39%—Sick Baggage AnalyticsSick Enterprise AnalyticsSick Logistic Diagnostic AnalyticsSick Package Analytics+16/10/202517/6/2026
In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be stored in various systems such as server logs, browser histories or proxy servers. As a result, there is a high risk that this sensitive data will be disclosed unintentionally.
AnalizadaMedia (5.3)0.36%—Sick Enterprise Analytics6/10/202517/6/2026
The application provides access to a login protected H2 database for caching purposes. The username is prefilled.
AnalizadaAlta (7.5)0.55%—Sick Enterprise Analytics6/10/202517/6/2026
If a user tries to login but the provided credentials are incorrect a log is created. The data for this POST requests is not validated and it’s possible to send giant payloads which are then logged.
AnalizadaMedia (4.3)0.33%—Sick Enterprise Analytics6/10/202517/6/2026
When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other internal information. An attacker can thus obtain information about the technology used and the structure of the application.
AnalizadaMedia (5.3)0.36%—Sick Enterprise Analytics6/10/202517/6/2026
An API endpoint allows arbitrary log entries to be created via POST request. Without sufficient validation of the input data, an attacker can create manipulated log entries and thus falsify or dilute logs, for example.
AnalizadaMedia (5.3)0.40%—Sick Baggage AnalyticsSick Enterprise AnalyticsSick Logistic Diagnostic AnalyticsSick Package Analytics+16/10/202517/6/2026
Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint, making the application vulnerable for user enumeration.
AnalizadaMedia (4.3)0.32%—Sick Enterprise Analytics6/10/202517/6/2026
A user with the appropriate authorization can create any number of user accounts via an API endpoint using a POST request. There are no quotas, checking mechanisms or restrictions to limit the creation.
AplazadaAlta (8.7)0.30%—Markany Safepc EnterpriseAI2/10/202517/6/2026
An attacker can obtain server information using Path Traversal vulnerability to conduct SQL Injection, which possibly exploits Unrestricted Upload of File with Dangerous Type vulnerability in MarkAny SafePC Enterprise on Windows, Linux.This issue affects SafePC Enterprise: V7.0.* (V7.0.YYYY.MM.DD) before V7.0.1, and…
AnalizadaMedia (5.1)0.26%—Mieweb Enterprise Health29/9/202517/6/2026
Medical Informatics Engineering Enterprise Health has a reflected cross site scripting vulnerability in the 'portlet_user_id' URL parameter. A remote, unauthenticated attacker can craft a URL that can execute arbitrary JavaScript in the victim's browser. This issue is fixed as of 2025-03-14.
AnalizadaMedia (6.3)0.24%—Mieweb Enterprise Health29/9/202517/6/2026
Medical Informatics Engineering Enterprise Health has a CSV injection vulnerability that allows a remote, authenticated attacker to inject macros in downloadable CSV files. This issue is fixed as of 2025-03-14.
AnalizadaMedia (6.2)0.25%—Mieweb Enterprise Health29/9/202517/6/2026
Medical Informatics Engineering Enterprise Health allows authenticated users to upload arbitrary files. The impact of this behavior depends on how files are accessed. This issue is fixed as of 2025-04-08.
AnalizadaMedia (4.6)0.14%—Mieweb Enterprise Health29/9/202517/6/2026
Medical Informatics Engineering Enterprise Health includes the user's current session token in debug output. An attacker could convince a user to send this output to the attacker, thus allowing the attacker to impersonate that user. This issue is fixed as of 2025-04-08.
AnalizadaAlta (8.6)0.20%—Mieweb Enterprise Health29/9/202517/6/2026
Medical Informatics Engineering Enterprise Health has a cross site request forgery vulnerability that allows an unauthenticated attacker to trick administrative users into clicking a crafted URL and perform actions on behalf of that administrative user. This issue is fixed as of 2025-04-08.
AnalizadaAlta (7.2)0.54%—Wso2 Enterprise IntegratorWso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking IAM26/9/202517/6/2026
An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user-supplied filenames in the BPEL uploader SOAP service endpoint. A malicious actor with administrative privileges can upload arbitrary files to a user-controlled location on the server. By leveraging this…
AplazadaMedia (6.9)0.19%—Puppet EnterpriseAI24/9/202525/9/2026
En las versiones 2025.4.0 y 2025.5 de Puppet Enterprise, la clave de cifrado utilizada para cifrar contenido en la base de datos de Infra Assistant no fue excluida de los archivos recopilados por la copia de seguridad de Puppet. La clave solo está presente en el sistema si el usuario tiene una licencia Puppet…
AplazadaMedia (4.3)0.34%—Tuleap Community EditionAITuleap Enterprise EditionAIEnalean TuleapAI18/9/202517/6/2026
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Backlog item representations do not verify the permissions of the child trackers. Users might see tracker names they should not have access to. This vulnerability is fixed in Tuleap Community Edition 16.11.99.1757427600…
AplazadaBaja (2.1)0.34%—Yida Ecms Consulting Enterprise Management SystemAI14/9/202517/6/2026
A vulnerability was found in Yida ECMS Consulting Enterprise Management System 1.0. This affects an unknown part of the file /login.do of the component POST Request Handler. The manipulation of the argument requestUrl results in cross site scripting. It is possible to launch the attack remotely. The exploit has been…
AnalizadaAlta (7.1)0.63%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Enterprise Server+29/9/202517/6/2026
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
AplazadaMedia (5.4)0.27%—Lingotek-translationAILingotek RAY Enterprise TranslationAI5/9/202517/6/2026
Missing Authorization vulnerability in Jiro Sasamoto Ray Enterprise Translation lingotek-translation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ray Enterprise Translation: from n/a through <= 1.7.2.
ModificadaAlta (7.5)2.3%💥 PoCRedhat Build OF Apache Camel FOR Spring BootRedhat FuseRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Expansion Pack+42/9/20256/10/2026
Se encontró una vulnerabilidad en Undertow donde solicitudes de cliente malformadas pueden desencadenar restablecimientos de flujo del lado del servidor sin activar contadores de abuso. Este problema, conocido como el ataque “MadeYouReset”, permite a clientes maliciosos inducir una carga de trabajo excesiva del…
AnalizadaMedia (5.5)0.11%—IBM APP Connect Enterprise Certified Containers OperandsIBM APP Connect Operator1/9/202517/6/2026
IBM App Connect Enterprise Certified Container CD: 9.2.0 through 11.6.0, 12.1.0 through 12.14.0, and 12.0 LTS: 12.0.0 through 12.0.14stores potentially sensitive information in log files during installation that could be read by a local user on the container.