Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
1917 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.34% | — | Adobe Format Plugins | 28/7/2026 | 5/8/2026 | Format Plugins is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Aplazada | Media (6.1) | 0.25% | — | Polen Media Software AND Information Services Website TemplateAI | 24/7/2026 | 24/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Software and Information Services Website Template allows Reflected XSS. This issue affects Website Template: before v2. | |
| Analizada | Crítica (9.3) | 0.75% | — | Equifax Victim Information Notification Exchange | 23/7/2026 | 26/8/2026 | The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass the login page, access other users' credentials, take over other user accounts, access sensitive PII, and dump other information from the database. | |
| Aplazada | Media (4.3) | 0.36% | — | Bizimhesap Information Systems Industry AND Trade INC Online Pre-accounting SoftwareAI | 23/7/2026 | 23/7/2026 | Allocation of resources without limits or throttling vulnerability in BizimHesap Information Systems Industry and Trade Inc. Online Pre-Accounting Software allows Excessive Allocation. This issue affects Online Pre-Accounting Software: through 17072026. | |
| Aplazada | Crítica (9.8) | 0.47% | 💥 PoC | Xpoda Turkiye Informatics Technology INC NO Code PlatformAI | 22/7/2026 | 30/7/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Informatics Technology Inc. No Code Platform allows SQL Injection. This issue affects No Code Platform: from 4.1.3 before 4.1.4. | |
| Aplazada | Media (4.3) | 0.28% | — | Gobito Informatics Technologies Corporate Training Management SystemAI | 20/7/2026 | 21/7/2026 | Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies Engineering Industry and Trade Ltd. Co. Corporate Training Management System allows Input Data Manipulation. This issue affects Corporate Training Management System: before dd1a9df64. | |
| Analizada | Alta (8.7) | 3.6% | — | Systeminformation | 17/7/2026 | 29/7/2026 | systeminformation is a System and OS information library for node.js. Prior to 5.31.7, networkInterfaces() on Linux is vulnerable to OS command injection through the Debian/Ubuntu interfaces(5) source directive because lib/network.js checkLinuxDCHPInterfaces() reads /etc/network/interfaces, extracts a source <path>… | |
| Aplazada | Crítica (9.8) | 0.47% | — | GIS Informatics Engineering Consulting Laboratory Gislab Laboratory Management SystemAI | 17/7/2026 | 17/7/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management System allows SQL Injection. This issue affects GisLab Laboratory Management System: from 1.4.03 through… | |
| Aplazada | Media (6.5) | 0.36% | — | GIS Informatics Engineering Consulting Laboratory RND AND Software Services Gislab Laboratory Management SystemAI | 17/7/2026 | 17/7/2026 | Authorization bypass through User-Controlled key vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management System allows Exploitation of Trusted Identifiers. This issue affects GisLab Laboratory Management System: from 1.4.03 through 08072026. | |
| Pendiente de análisis | Media (5.9) | 0.33% | — | Drupal RAW FormatterAI | 10/7/2026 | 13/7/2026 | vulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . This issue affects Raw Formatter [Meta Tag Formatter] versions: *.*. | |
| Analizada | Crítica (9.8) | 0.56% | — | Zroger Formatter Field | 10/7/2026 | 6/8/2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. This issue affects Formatter Field versions: from 0.0.0 to 2.0.0. | |
| Aplazada | Crítica (9.8) | 0.58% | — | Semtek Informatics Software Consulting Trade LTD CO Sem-pmpAI | 10/7/2026 | 10/7/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics Software Consulting Trade Ltd. Co. SEM-PMP allows Command Line Execution through SQL Injection. This issue affects SEM-PMP: through 23042026. | |
| Aplazada | Media (5.4) | 0.23% | — | Twiser Informatics Technology Consulting Trade AND Education INC Okrs & GoalsAI | 9/7/2026 | 9/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Twiser Informatics Technology Consulting, Trade and Education Inc. OKRs & Goals allows Stored XSS. This issue affects OKRs & Goals: from 28220 before 28398. | |
| Aplazada | Media (6.5) | 0.38% | — | Nomysoft Informatics Education AND Consulting INC NomysemAI | 8/7/2026 | 8/7/2026 | Exposure of sensitive information due to incompatible policies vulnerability in NOMYSOFT Informatics Education and Consulting Inc. Nomysem allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Nomysem: through 08072026. NOTE: The vendor was contacted early about this disclosure but did… | |
| Aplazada | Alta (8.2) | 0.34% | — | Armiya Information Technologies LTD Access Control System GKSAI | 7/7/2026 | 7/7/2026 | Missing Authorization vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Collect Data from Common Resource Locations. This issue affects Access Control System (GKS): before Version 2. | |
| Aplazada | Media (5.4) | 0.23% | — | Armiya Information Technologies Access Control System GKSAI | 7/7/2026 | 7/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Reflected XSS. This issue affects Access Control System (GKS): before Version 2. | |
| Aplazada | Media (6.1) | 0.25% | — | Armiya Information Technologies LTD Access Control System GKSAI | 7/7/2026 | 7/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Stored XSS. This issue affects Access Control System (GKS): before Version 2. | |
| Aplazada | Media (6.1) | 0.25% | — | Armiya Information Technologies LTD Access Control System GKSAI | 7/7/2026 | 7/7/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows XSS Targeting HTML Attributes. This issue affects Access Control System (GKS): before Version 2. | |
| Aplazada | Media (5.4) | 0.23% | — | Divvydrive Information Technologies INC DivvydriveAI | 1/7/2026 | 1/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS. This issue affects DivvyDrive: from v.4.8.2.23 before v.4.8.3.1. | |
| Aplazada | Media (6.4) | 0.25% | — | Divvydrive Information Technologies INC DivvydriveAI | 1/7/2026 | 1/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS. This issue affects DivvyDrive: from 4.8.2.23 before v.4.8.3.1. | |
| Pendiente de análisis | Media (5.6) | 0.39% | — | Solarwinds Database Performance AnalyzerAI | 30/6/2026 | 2/7/2026 | SolarWinds Database Performance Analyzer was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution. | |
| Analizada | Alta (7.5) | 0.45% | — | IBM Infosphere Information Server | 30/6/2026 | 2/7/2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerability. | |
| Aplazada | Media (5.5) | 0.43% | — | Itsourcecode Baptism Information Management SystemAI | 29/6/2026 | 29/6/2026 | A security vulnerability has been detected in itsourcecode Baptism Information Management System 1.0. This affects an unknown function of the file /editBaptism.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be… | |
| Aplazada | Media (5.5) | 0.43% | — | Itsourcecode Baptism Information Management SystemAI | 29/6/2026 | 29/6/2026 | A weakness has been identified in itsourcecode Baptism Information Management System 1.0. The impacted element is an unknown function of the file /delbaptism.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the… | |
| Analizada | Crítica (9.1) | 0.45% | 💥 PoC | Oracle Application Performance Management | 17/6/2026 | 18/6/2026 | Vulnerability in the APM - Application Performance Management product of Oracle Enterprise Manager (component: JADM, JVM Diagnostics). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise APM - Application… |