Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

1917 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.34%—Adobe Format Plugins28/7/20265/8/2026
Format Plugins is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AplazadaMedia (6.1)0.25%—Polen Media Software AND Information Services Website TemplateAI24/7/202624/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Software and Information Services Website Template allows Reflected XSS. This issue affects Website Template: before v2.
AnalizadaCrítica (9.3)0.75%—Equifax Victim Information Notification Exchange23/7/202626/8/2026
The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass the login page, access other users' credentials, take over other user accounts, access sensitive PII, and dump other information from the database.
AplazadaMedia (4.3)0.36%—Bizimhesap Information Systems Industry AND Trade INC Online Pre-accounting SoftwareAI23/7/202623/7/2026
Allocation of resources without limits or throttling vulnerability in BizimHesap Information Systems Industry and Trade Inc. Online Pre-Accounting Software allows Excessive Allocation. This issue affects Online Pre-Accounting Software: through 17072026.
AplazadaCrítica (9.8)0.47%💥 PoCXpoda Turkiye Informatics Technology INC NO Code PlatformAI22/7/202630/7/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Informatics Technology Inc. No Code Platform allows SQL Injection. This issue affects No Code Platform: from 4.1.3 before 4.1.4.
AplazadaMedia (4.3)0.28%—Gobito Informatics Technologies Corporate Training Management SystemAI20/7/202621/7/2026
Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies Engineering Industry and Trade Ltd. Co. Corporate Training Management System allows Input Data Manipulation. This issue affects Corporate Training Management System: before dd1a9df64.
AnalizadaAlta (8.7)3.6%—Systeminformation17/7/202629/7/2026
systeminformation is a System and OS information library for node.js. Prior to 5.31.7, networkInterfaces() on Linux is vulnerable to OS command injection through the Debian/Ubuntu interfaces(5) source directive because lib/network.js checkLinuxDCHPInterfaces() reads /etc/network/interfaces, extracts a source <path>…
AplazadaCrítica (9.8)0.47%—GIS Informatics Engineering Consulting Laboratory Gislab Laboratory Management SystemAI17/7/202617/7/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management System allows SQL Injection. This issue affects GisLab Laboratory Management System: from 1.4.03 through…
AplazadaMedia (6.5)0.36%—GIS Informatics Engineering Consulting Laboratory RND AND Software Services Gislab Laboratory Management SystemAI17/7/202617/7/2026
Authorization bypass through User-Controlled key vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management System allows Exploitation of Trusted Identifiers. This issue affects GisLab Laboratory Management System: from 1.4.03 through 08072026.
Pendiente de análisisMedia (5.9)0.33%—Drupal RAW FormatterAI10/7/202613/7/2026
vulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . This issue affects Raw Formatter [Meta Tag Formatter] versions: *.*.
AnalizadaCrítica (9.8)0.56%—Zroger Formatter Field10/7/20266/8/2026
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. This issue affects Formatter Field versions: from 0.0.0 to 2.0.0.
AplazadaCrítica (9.8)0.58%—Semtek Informatics Software Consulting Trade LTD CO Sem-pmpAI10/7/202610/7/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics Software Consulting Trade Ltd. Co. SEM-PMP allows Command Line Execution through SQL Injection. This issue affects SEM-PMP: through 23042026.
AplazadaMedia (5.4)0.23%—Twiser Informatics Technology Consulting Trade AND Education INC Okrs & GoalsAI9/7/20269/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Twiser Informatics Technology Consulting, Trade and Education Inc. OKRs & Goals allows Stored XSS. This issue affects OKRs & Goals: from 28220 before 28398.
AplazadaMedia (6.5)0.38%—Nomysoft Informatics Education AND Consulting INC NomysemAI8/7/20268/7/2026
Exposure of sensitive information due to incompatible policies vulnerability in NOMYSOFT Informatics Education and Consulting Inc. Nomysem allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Nomysem: through 08072026. NOTE: The vendor was contacted early about this disclosure but did…
AplazadaAlta (8.2)0.34%—Armiya Information Technologies LTD Access Control System GKSAI7/7/20267/7/2026
Missing Authorization vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Collect Data from Common Resource Locations. This issue affects Access Control System (GKS): before Version 2.
AplazadaMedia (5.4)0.23%—Armiya Information Technologies Access Control System GKSAI7/7/20267/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Reflected XSS. This issue affects Access Control System (GKS): before Version 2.
AplazadaMedia (6.1)0.25%—Armiya Information Technologies LTD Access Control System GKSAI7/7/20267/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Stored XSS. This issue affects Access Control System (GKS): before Version 2.
AplazadaMedia (6.1)0.25%—Armiya Information Technologies LTD Access Control System GKSAI7/7/20267/7/2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows XSS Targeting HTML Attributes. This issue affects Access Control System (GKS): before Version 2.
AplazadaMedia (5.4)0.23%—Divvydrive Information Technologies INC DivvydriveAI1/7/20261/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS. This issue affects DivvyDrive: from v.4.8.2.23 before v.4.8.3.1.
AplazadaMedia (6.4)0.25%—Divvydrive Information Technologies INC DivvydriveAI1/7/20261/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS. This issue affects DivvyDrive: from 4.8.2.23 before v.4.8.3.1.
Pendiente de análisisMedia (5.6)0.39%—Solarwinds Database Performance AnalyzerAI30/6/20262/7/2026
SolarWinds Database Performance Analyzer was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution.
AnalizadaAlta (7.5)0.45%—IBM Infosphere Information Server30/6/20262/7/2026
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerability.
AplazadaMedia (5.5)0.43%—Itsourcecode Baptism Information Management SystemAI29/6/202629/6/2026
A security vulnerability has been detected in itsourcecode Baptism Information Management System 1.0. This affects an unknown function of the file /editBaptism.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be…
AplazadaMedia (5.5)0.43%—Itsourcecode Baptism Information Management SystemAI29/6/202629/6/2026
A weakness has been identified in itsourcecode Baptism Information Management System 1.0. The impacted element is an unknown function of the file /delbaptism.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the…
AnalizadaCrítica (9.1)0.45%💥 PoCOracle Application Performance Management17/6/202618/6/2026
Vulnerability in the APM - Application Performance Management product of Oracle Enterprise Manager (component: JADM, JVM Diagnostics). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise APM - Application…
Orbitaley — Vulnerabilidades