Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2717▼ 139 respecto a la semana anterior
Críticas / altas1239▼ 297 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 202 respecto a la semana anterior
–

22.752 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (10)1.1%—Microsoft Azure Managed Instance FOR Apache Cassandra20/8/202625/8/2026
Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.
Pendiente de análisisAlta (7.7)0.53%—Redhat Advanced Cluster ManagementAIRedhat Multicloud Operators SubscriptionAI20/8/202628/8/2026
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A tenant with HelmRelease create permissions can exploit this vulnerability by manipulating the `secretRef.Namespace` field. This allows the `GetSecret()` function in the HelmRelease controller to fetch…
Pendiente de análisisAlta (7.1)0.51%—Amazon AthenaAIAmazon Athena Federated QueryAIAmazon Secrets ManagerAI20/8/202625/8/2026
Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Federated Query prior to v2026.17.1 could allow an authenticated remote user to read arbitrary AWS Secrets Manager secrets in the deploying account by pointing the connector's connection string at an unrelated secret and at…
Pendiente de análisisMedia (5.4)0.35%—Redhat Advanced Cluster Management FOR KubernetesAI20/8/20263/9/2026
A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability stems from insufficient validation of advertised IP addresses within EndpointSlice objects. A compromised spoke cluster can exploit this by creating EndpointSlices with attacker-controlled IP…
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI20/8/202624/8/2026
A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /viewappointmentpending.php. This manipulation of the argument delid causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and…
AplazadaMedia (5.5)0.43%—Codeastro Apartment Visitor Management SystemAI20/8/202624/8/2026
A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file password-recovery.php. The manipulation of the argument email leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly…
AplazadaMedia (5.5)0.43%—Codeastro Apartment Visitor Management SystemAI20/8/202625/8/2026
A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. Affected is an unknown function of the file /apartment-visitor/forgotpw.php. Executing a manipulation of the argument secode can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and…
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI20/8/202624/8/2026
A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /viewappointmentapproved.php. Performing a manipulation of the argument delid results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
AplazadaCrítica (9.8)0.64%💥 PoCBaylan Measuring Instruments Industry AND Trade INC Baylan Smart Meter Management ApplicationAI20/8/202626/8/2026
Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Baylan Smart Meter Management Application (BMS) allows Authentication Bypass. This issue affects Baylan Smart Meter Management Application (BMS): before v1.1.10.142.
AplazadaMedia (4.8)0.24%—HCL Intelliops Event ManagementAI20/8/202628/8/2026
HCL IntelliOps Event Management (IEM) is affected by missing or insecure Cross-Origin Security headers. This issue makes the application's environment and resources susceptible to unauthorized external interaction and potential exploitation.
AplazadaMedia (5)0.28%—HCL Intelliops Event ManagementAI20/8/202629/9/2026
HCL IntelliOps Event Management (IEM) se ve afectado por la omisión de información. La falta de información rompe la auditabilidad y observabilidad de un flujo de trabajo. Si un atacante obtuviera acceso a la aplicación, el registro insuficiente podría dificultar la respuesta a incidentes.
AplazadaMedia (5.9)0.23%—HCL Intelliops Event ManagementAI20/8/202629/9/2026
HCL IntelliOps Event Management (IEM) está afectado por una condición de carrera. Puede ocurrir una 'ventana de tiempo' donde un atacante puede modificar el recurso causando un comportamiento impredecible.
AplazadaMedia (6.6)0.26%—HCL Intelliops Event ManagementAI20/8/202629/9/2026
HCL IntelliOps Event Management (IEM) se ve afectado por una violación de privilegios mínimos que podría permitir a un atacante acceder al recurso con el privilegio elevado al que no se podría acceder con los privilegios originales del atacante.
AplazadaMedia (5.4)0.25%—HCL Intelliops Event ManagementAI20/8/202629/9/2026
HCL IntelliOps Event Management (IEM) se ve afectado por un registro insuficiente. El registro insuficiente debilita la rendición de cuentas, oscurece la detección de ataques y permite el sondeo de privilegios.
AplazadaBaja (2.1)0.33%—Amirsanni Mini-inventory-and-sales-management-systemAI20/8/202620/8/2026
A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System 0.1. Affected is the function Transaction::getAll of the file application/models/Transaction.php. Performing a manipulation of the argument orderBy/orderFormat results in sql injection. It is possible to initiate the attack…
AplazadaMedia (5.5)0.43%—Code-projects Employee Management SystemAI20/8/202621/8/2026
A flaw has been found in code-projects Employee Management System 1.0. The impacted element is an unknown function of the file /process/aprocess.php of the component Admin Login Endpoint. This manipulation of the argument mailuid causes sql injection. Remote exploitation of the attack is possible. The exploit has been…
AplazadaMedia (5.5)0.43%—Code-projects Assessment ManagementAI20/8/202625/8/2026
A vulnerability was detected in code-projects Assessment Management 1.0. The affected element is an unknown function of the file /welcome.php. The manipulation of the argument userid results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.
Pendiente de análisisMedia (4.3)0.21%—RSA Securid Authentication ManagerAISplunk SoarAI19/8/202620/8/2026
In versions below 1.0.5 of the RSA SecurID Authentication Manager app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive token serial by invoking either the enable token or revoke token action, because the action's token_serial parameter is not masked and is shown in…
Pendiente de análisisMedia (6.9)0.16%—Otto Fleet ManagerAI19/8/202628/8/2026
A security issue exists within OTTO® Fleet Manager. The vulnerability stems from the use of an insufficient work factor in the bcrypt password hashing implementation, which could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. If an attacker…
AnalizadaAlta (7.3)0.14%—IBM Power System S922 (9009-22g) FirmwareIBM Power System H922 (9223-22s) FirmwareIBM Power System S914 (9009-41g) FirmwareIBM Power System S924 (9009-42g) Firmware+619/8/202625/8/2026
IBM Power Systems Firmware FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulnerability in host firmware NVRAM parsing. An attacker with root access to a guest partition on an OpenPOWER system can write a specially crafted NVRAM image, causing the…
AnalizadaAlta (8.2)0.17%—IBM Power System S1122 (9824-22a) FirmwareIBM Power System S1124 (9824-42a) FirmwareIBM Power System S1122s (9824-22b) FirmwareIBM Power System S1114 (9824-41b) Firmware+2519/8/202625/8/2026
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 through OP940.81 (Power HMC) is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service…
AnalizadaAlta (8.1)0.15%—IBM Power System S1122 (9824-22a) FirmwareIBM Power System S1124 (9824-42a) FirmwareIBM Power System S1122s (9824-22b) FirmwareIBM Power System S1114 (9824-41b) Firmware+2519/8/202625/8/2026
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or…
AnalizadaAlta (8.2)0.17%—IBM Power System S1122 (9824-22a) FirmwareIBM Power System S1124 (9824-42a) FirmwareIBM Power System S1122s (9824-22b) FirmwareIBM Power System S1114 (9824-41b) Firmware+2519/8/202625/8/2026
Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1, and OP940.00 - OP940.81 is affected by a vulnerability in the service processor mailbox interface. An attacker with authenticated service-level access to the BMC/FSP can…
AnalizadaAlta (8.2)0.17%—IBM Power System S1122 (9824-22a) FirmwareIBM Power System S1124 (9824-42a) FirmwareIBM Power System S1122s (9824-22b) FirmwareIBM Power System S1114 (9824-41b) Firmware+2519/8/202625/8/2026
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulnerability in host firmware configuration parsing. An attacker with service-level access to the BMC/FSP…
Pendiente de análisisMedia (6.2)0.54%—Volsync Addon-controllerAIRedhat Openshift Lifecycle ManagerAI19/8/20268/9/2026
A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject malicious YAML (Yet Another Markup Language) code into the OpenShift Lifecycle Manager (OLM) Subscription resource. This is due to improper escaping of annotation values when they are rendered into YAML. Successful…