Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2774▼ 317 respecto a la semana anterior
Críticas / altas1288▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
8556 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.56% | — | Wso2 API Control PlaneWso2 API ManagerWso2 API Manager AnalyticsWso2 Data Analytics Server+11 | 16/10/2025 | 25/9/2026 | Una vulnerabilidad de control de acceso inadecuado existe en múltiples productos WSO2 debido a una aplicación de permisos insuficiente en ciertos servicios SOAP Admin internos y API REST del sistema. Un usuario con bajos privilegios puede explotar esta falla para realizar operaciones no autorizadas, incluyendo el… | |
| Analizada | Alta (7.2) | 0.66% | — | Elastic Cloud Enterprise | 13/10/2025 | 8/10/2026 | La neutralización indebida de elementos especiales utilizados en un motor de plantillas en Elastic Cloud Enterprise (ECE) puede permitir que un actor malicioso con acceso de administrador exfiltre información sensible y emita comandos mediante una cadena especialmente diseñada donde se evalúan las variables de Jinjava. | |
| Aplazada | Alta (8.6) | 0.58% | — | Ragic Enterprise Cloud DatabaseAI | 13/10/2025 | 8/10/2026 | La Base de datos en la nube empresarial desarrollada por Ragic tiene una vulnerabilidad de carga de archivos arbitraria, lo que permite a atacantes remotos privilegiados cargar y ejecutar puertas traseras web shell, posibilitando así la ejecución de código arbitrario en el servidor. | |
| Modificada | Alta (8.1) | 1.1% | 💥 PoC | Fairsketch Rise Ultimate Project Manager | 10/10/2025 | 5/7/2026 | Stored HTML injection in RISE Ultimate Project Manager & CRM allows authenticated users to inject arbitrary HTML into invoices and messages. Injected content renders in emails, PDFs, and messaging/chat modules sent to clients or team members, enabling phishing, credential theft, and business email compromise.… | |
| Aplazada | Crítica (9.3) | 0.67% | — | Netsarang Xmanager EnterpriseAINetsarang XmanagerAINetsarang XshellAINetsarang XftpAI+1 | 9/10/2025 | 17/6/2026 | NetSarang Xmanager Enterprise 5.0 Build 1232, Xmanager 5.0 Build 1045, Xshell 5.0 Build 1322, Xftp 5.0 Build 1218, and Xlpd 5.0 Build 1220 contain a malicious nssock2.dll that implements a multi-stage, DNS-based backdoor. The dormant library contacts a C2 DNS server via a specially crafted TXT record for a… | |
| Analizada | Crítica (9.8) | 0.49% | — | Sick Baggage AnalyticsSick Enterprise AnalyticsSick Logistic Diagnostic AnalyticsSick Package Analytics+1 | 6/10/2025 | 17/6/2026 | The application does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it possible for an attacker to guess user credentials. | |
| Analizada | Media (5.3) | 0.36% | — | Sick Baggage AnalyticsSick Enterprise AnalyticsSick Logistic Diagnostic AnalyticsSick Package Analytics+1 | 6/10/2025 | 17/6/2026 | For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one. | |
| Analizada | Alta (7.5) | 0.39% | — | Sick Baggage AnalyticsSick Enterprise AnalyticsSick Logistic Diagnostic AnalyticsSick Package Analytics+1 | 6/10/2025 | 17/6/2026 | In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be stored in various systems such as server logs, browser histories or proxy servers. As a result, there is a high risk that this sensitive data will be disclosed unintentionally. | |
| Analizada | Media (5.3) | 0.36% | — | Sick Enterprise Analytics | 6/10/2025 | 17/6/2026 | The application provides access to a login protected H2 database for caching purposes. The username is prefilled. | |
| Analizada | Alta (7.5) | 0.55% | — | Sick Enterprise Analytics | 6/10/2025 | 17/6/2026 | If a user tries to login but the provided credentials are incorrect a log is created. The data for this POST requests is not validated and it’s possible to send giant payloads which are then logged. | |
| Analizada | Media (4.3) | 0.33% | — | Sick Enterprise Analytics | 6/10/2025 | 17/6/2026 | When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other internal information. An attacker can thus obtain information about the technology used and the structure of the application. | |
| Analizada | Media (5.3) | 0.36% | — | Sick Enterprise Analytics | 6/10/2025 | 17/6/2026 | An API endpoint allows arbitrary log entries to be created via POST request. Without sufficient validation of the input data, an attacker can create manipulated log entries and thus falsify or dilute logs, for example. | |
| Analizada | Media (5.3) | 0.40% | — | Sick Baggage AnalyticsSick Enterprise AnalyticsSick Logistic Diagnostic AnalyticsSick Package Analytics+1 | 6/10/2025 | 17/6/2026 | Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint, making the application vulnerable for user enumeration. | |
| Analizada | Media (4.3) | 0.32% | — | Sick Enterprise Analytics | 6/10/2025 | 17/6/2026 | A user with the appropriate authorization can create any number of user accounts via an API endpoint using a POST request. There are no quotas, checking mechanisms or restrictions to limit the creation. | |
| Aplazada | Alta (8.7) | 0.30% | — | Markany Safepc EnterpriseAI | 2/10/2025 | 17/6/2026 | An attacker can obtain server information using Path Traversal vulnerability to conduct SQL Injection, which possibly exploits Unrestricted Upload of File with Dangerous Type vulnerability in MarkAny SafePC Enterprise on Windows, Linux.This issue affects SafePC Enterprise: V7.0.* (V7.0.YYYY.MM.DD) before V7.0.1, and… | |
| Analizada | Media (5.1) | 0.26% | — | Mieweb Enterprise Health | 29/9/2025 | 17/6/2026 | Medical Informatics Engineering Enterprise Health has a reflected cross site scripting vulnerability in the 'portlet_user_id' URL parameter. A remote, unauthenticated attacker can craft a URL that can execute arbitrary JavaScript in the victim's browser. This issue is fixed as of 2025-03-14. | |
| Analizada | Media (6.3) | 0.24% | — | Mieweb Enterprise Health | 29/9/2025 | 17/6/2026 | Medical Informatics Engineering Enterprise Health has a CSV injection vulnerability that allows a remote, authenticated attacker to inject macros in downloadable CSV files. This issue is fixed as of 2025-03-14. | |
| Analizada | Media (6.2) | 0.25% | — | Mieweb Enterprise Health | 29/9/2025 | 17/6/2026 | Medical Informatics Engineering Enterprise Health allows authenticated users to upload arbitrary files. The impact of this behavior depends on how files are accessed. This issue is fixed as of 2025-04-08. | |
| Analizada | Media (4.6) | 0.14% | — | Mieweb Enterprise Health | 29/9/2025 | 17/6/2026 | Medical Informatics Engineering Enterprise Health includes the user's current session token in debug output. An attacker could convince a user to send this output to the attacker, thus allowing the attacker to impersonate that user. This issue is fixed as of 2025-04-08. | |
| Analizada | Alta (8.6) | 0.20% | — | Mieweb Enterprise Health | 29/9/2025 | 17/6/2026 | Medical Informatics Engineering Enterprise Health has a cross site request forgery vulnerability that allows an unauthenticated attacker to trick administrative users into clicking a crafted URL and perform actions on behalf of that administrative user. This issue is fixed as of 2025-04-08. | |
| Modificada | Media (6.1) | 0.23% | 💥 PoC | Fairsketch Rise Ultimate Project Manager | 29/9/2025 | 5/7/2026 | A cross-site scripting (XSS) vulnerability in FairSketch RISE Ultimate Project Manager & CRM 3.9.4 allows an administrator to store a JavaScript payload using the file explorer in the admin dashboard when creating new folders. | |
| Analizada | Alta (7.2) | 0.54% | — | Wso2 Enterprise IntegratorWso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking IAM | 26/9/2025 | 17/6/2026 | An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user-supplied filenames in the BPEL uploader SOAP service endpoint. A malicious actor with administrative privileges can upload arbitrary files to a user-controlled location on the server. By leveraging this… | |
| Aplazada | Media (6.9) | 0.19% | — | Puppet EnterpriseAI | 24/9/2025 | 25/9/2026 | En las versiones 2025.4.0 y 2025.5 de Puppet Enterprise, la clave de cifrado utilizada para cifrar contenido en la base de datos de Infra Assistant no fue excluida de los archivos recopilados por la copia de seguridad de Puppet. La clave solo está presente en el sistema si el usuario tiene una licencia Puppet… | |
| Aplazada | Media (4.3) | 0.34% | — | Tuleap Community EditionAITuleap Enterprise EditionAIEnalean TuleapAI | 18/9/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Backlog item representations do not verify the permissions of the child trackers. Users might see tracker names they should not have access to. This vulnerability is fixed in Tuleap Community Edition 16.11.99.1757427600… | |
| Aplazada | Baja (2.1) | 0.34% | — | Yida Ecms Consulting Enterprise Management SystemAI | 14/9/2025 | 17/6/2026 | A vulnerability was found in Yida ECMS Consulting Enterprise Management System 1.0. This affects an unknown part of the file /login.do of the component POST Request Handler. The manipulation of the argument requestUrl results in cross site scripting. It is possible to launch the attack remotely. The exploit has been… |