Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
374 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.75% | — | Holest Engineering Spreadsheet Price Changer FOR Woocommerce AND WP E-commerce LightAI | 24/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light excel-like-price-change-for-woocommerce-and-wp-e-commerce-light allows PHP Local File Inclusion.This issue… | |
| Analizada | Media (6.5) | 0.19% | — | IBM Engineering Requirements Management Doors Next | 3/3/2025 | 17/6/2026 | IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a user to download a malicious file without verifying the integrity of the code. | |
| Analizada | Alta (7.5) | 0.48% | — | IBM Engineering Requirements Management Doors Next | 3/3/2025 | 17/6/2026 | IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose application logic or other sensitive information. | |
| Analizada | Alta (7.5) | 0.48% | — | IBM Engineering Requirements Management Doors Next | 3/3/2025 | 17/6/2026 | IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose application logic or other sensitive information. | |
| Aplazada | Crítica (9.5) | 0.86% | — | IBL Software Engineering Visual WeatherAIIBL Software Engineering NamisAIIBL Software Engineering Aero WeatherAIIBL Software Engineering Satellite WeatherAI | 7/2/2025 | 17/6/2026 | A security vulnerability has been identified in the IBL Software Engineering Visual Weather and derived products (NAMIS, Aero Weather, Satellite Weather). The vulnerability is present in the Product Delivery Service (PDS) component in specific server configurations where the PDS pipeline utilizes the IPDS pipeline… | |
| Analizada | Media (6.5) | 0.41% | — | IBM Engineering Lifecycle Optimization Publishing | 4/1/2025 | 17/6/2026 | IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to cause an unhandled SSL exception which could leave the connection in an unexpected or insecure state. | |
| Analizada | Alta (7.3) | 0.31% | — | IBM Engineering Lifecycle Optimization Publishing | 4/1/2025 | 17/6/2026 | IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | |
| Analizada | Alta (7.5) | 0.48% | — | IBM Engineering Lifecycle Optimization Publishing | 4/1/2025 | 17/6/2026 | IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to cause a denial of service using a complex regular expression. | |
| Analizada | Media (6.5) | 0.60% | — | IBM Engineering Lifecycle Optimization Publishing | 4/1/2025 | 17/6/2026 | IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. | |
| Analizada | Alta (7.5) | 0.20% | — | IBM Engineering Lifecycle Optimization Publishing | 4/1/2025 | 17/6/2026 | IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | |
| Analizada | Crítica (9.8) | 0.34% | — | IBM Engineering Lifecycle Optimization - Engineering Insights | 25/12/2024 | 17/6/2026 | IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or perform unauthorized actions on the victims’ web browser. | |
| Analizada | Media (5.3) | 0.38% | — | IBM Engineering Lifecycle Optimization - Engineering Insights | 25/12/2024 | 17/6/2026 | IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | |
| Analizada | Alta (8.1) | 0.83% | — | IBM Engineering Systems Design Rhapsody | 22/11/2024 | 17/6/2026 | IBM Engineering Systems Design Rhapsody - Model Manager 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race condition. By sending a specially crafted request, an attacker could exploit this vulnerability to remotely execute code. | |
| Analizada | Alta (8.2) | 0.70% | — | IBM Engineering Lifecycle Optimization - Engineering Insights | 15/11/2024 | 17/6/2026 | IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | |
| Aplazada | Alta (7.5) | 0.52% | — | PCS Engineering Preston CinemaAI | 14/10/2024 | 17/6/2026 | An issue in PCS Engineering Preston Cinema (com.prestoncinema.app) 0.2.0 allows a remote attacker to obtain sensitive information via the firmware update process. | |
| Aplazada | Alta (8.8) | 0.66% | — | Takenaka Engineering Digital Video RecorderAI | 18/9/2024 | 17/6/2026 | Hidden functionality issue in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings. | |
| Aplazada | Alta (8.8) | 1.00% | — | Takenaka Engineering Digital Video RecorderAI | 18/9/2024 | 17/6/2026 | OS command injection vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings. | |
| Aplazada | Alta (8.8) | 0.51% | — | Takenaka Engineering Digital Video RecorderAI | 18/9/2024 | 17/6/2026 | Improper authentication vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings. | |
| Modificada | Alta (8.2) | 0.61% | — | IBM Engineering Requirements Management DoorsIBM Engineering Requirements Management Doors WEB Access | 18/7/2024 | 17/6/2026 | IBM Engineering Requirements Management DOORS Web Access 9.7.2.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 273335. | |
| Analizada | Crítica (9.8) | 0.65% | — | IBM Engineering Lifecycle Optimization Publishing | 9/6/2024 | 17/6/2026 | IBM Engineering Lifecycle Optimization Publishing 7.0.2 and 7.03 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions. By sending a specially crafted request, a remote attacker could exploit this vulnerability to upload a malicious file, which could allow the… | |
| Analizada | Media (5.4) | 0.33% | — | IBM Engineering Workflow Management | 28/5/2024 | 17/6/2026 | IBM Engineering Workflow Management 7.0.2 and 7.0.3 is vulnerable to stored cross-site scripting. Under certain configurations, this vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted… | |
| Aplazada | Media (6.5) | 0.46% | — | Schweitzer Engineering Laboratories Sel-700btAISchweitzer Engineering Laboratories Sel-700gAISchweitzer Engineering Laboratories Sel-710-5AISchweitzer Engineering Laboratories Sel-751AI+4 | 4/4/2024 | 17/6/2026 | Inclusion of undocumented features vulnerability accessible when logged on with a privileged access level on the following Schweitzer Engineering Laboratories relays could allow the relay to behave unpredictably: SEL-700BT Motor Bus Transfer Relay, SEL-700G Generator Protection Relay, SEL-710-5 Motor Protection Relay,… | |
| Aplazada | Alta (7.5) | 0.61% | — | ABB Symphony Plus S+ OperationsAIABB Symphony Plus S+ EngineeringAIABB Symphony Plus S+ AnalystAI | 3/4/2024 | 17/6/2026 | ABB has internally identified a vulnerability in the ABB VPNI feature of the S+ Control API component which may be used by several Symphony Plus products (e.g., S+ Operations, S+ Engineering and S+ Analyst) This issue affects Symphony Plus S+ Operations: from 3..0;0 through 3.3 SP1 RU4, from 2.1;0 through 2.1 SP2 RU3,… | |
| Aplazada | Alta (7.5) | 0.51% | — | Cerberus PRO EN Engineering ToolAICerberus PRO EN Fire Panel Fc72xAICerberus PRO EN X200 Cloud DistributionAICerberus PRO EN X300 Cloud DistributionAI+11 | 12/3/2024 | 17/6/2026 | A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions), Cerberus PRO EN Fire Panel FC72x IP6 (All versions), Cerberus PRO EN Fire Panel FC72x IP7 (All versions), Cerberus PRO EN Fire Panel FC72x IP8 (All versions < IP8 SR4), Cerberus PRO EN X200 Cloud Distribution IP7 (All versions),… | |
| Aplazada | Alta (7.5) | 0.83% | — | Cerberus PRO EN Engineering ToolAICerberus PRO EN Fire Panel Fc72xAICerberus PRO EN X200 Cloud DistributionAICerberus PRO EN X300 Cloud DistributionAI+11 | 12/3/2024 | 17/6/2026 | A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions), Cerberus PRO EN Fire Panel FC72x IP6 (All versions), Cerberus PRO EN Fire Panel FC72x IP7 (All versions), Cerberus PRO EN Fire Panel FC72x IP8 (All versions < IP8 SR4), Cerberus PRO EN X200 Cloud Distribution IP7 (All versions),… |