Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
349 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.9) | 0.14% | — | Genshin Albedo CAT House APPAI | 21/7/2025 | 17/6/2026 | A vulnerability was found in Genshin Albedo Cat House App 1.0.2 on Android. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.house.auscat. The manipulation leads to improper export of android application components.… | |
| Aplazada | Crítica (10) | 80% | 💥 Exploit | Sawtooth Software Lighthouse StudioAI | 16/7/2025 | 17/6/2026 | A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the ciwweb.pl http://ciwweb.pl/ Perl web application. Exploitation allows an unauthenticated attacker can execute arbitrary commands. | |
| Aplazada | Media (6.1) | 0.24% | — | SAP Business WarehouseAI | 8/7/2025 | 17/6/2026 | SAP Business Warehouse (Business Explorer Web) allows an attacker to create a malicious link. If an authenticated user clicks on this link, the injected script gets executed within the scope of victim�s browser. This potentially leads to an impact on confidentiality and integrity. Availability is not impacted. | |
| Aplazada | Media (4.3) | 0.22% | — | SAP Business WarehouseAISAP Bw/4hanaAI | 8/7/2025 | 17/6/2026 | SAP Business Warehouse and SAP BW/4HANA BEx Tools allow an authenticated attacker to gain higher access levels than intended by exploiting improper authorization checks. This could potentially impact data integrity by allowing deletion of user table entries.�It has no impact on the confidentiality and availability of… | |
| Aplazada | Baja (2.7) | 0.43% | — | SAP Netweaver Business WarehouseAISAP CcawAI | 8/7/2025 | 17/6/2026 | SAP NetWeaver Business Warehouse CCAW application allows a privileged attacker to cause a high CPU load by executing a RFC enabled function modules without any input parameters, which results in reduced performance or interrupted operation of the affected resource. This leads to low impact on availability of the… | |
| Aplazada | Alta (7.7) | 0.41% | — | SAP Business WarehouseAISAP Plug-in BasisAI | 8/7/2025 | 17/6/2026 | SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to add fields to arbitrary SAP database tables and/or structures, potentially rendering the system unusable. On successful exploitation, an attacker can render the system unusable by triggering short dumps on login. This could cause a high… | |
| Aplazada | Alta (8.5) | 0.31% | — | SAP Business WarehouseAISAP Plug-in BasisAI | 10/6/2025 | 17/6/2026 | SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to drop arbitrary SAP database tables, potentially resulting in a loss of data or rendering the system unusable. On successful exploitation, an attacker can completely delete database entries but is not able to read any data. | |
| Analizada | Media (6.9) | 0.54% | — | Yangshare Warehouse Management System | 26/5/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in yangshare 技术杨工 warehouseManager 仓库管理系统 1.0. This affects an unknown part. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was… | |
| Aplazada | Crítica (9.8) | 0.59% | — | Ancorathemes Fish HouseAI | 23/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in AncoraThemes Fish House fish-house allows Object Injection.This issue affects Fish House: from n/a through <= 1.2.7. | |
| Analizada | Alta (8.2) | 0.88% | — | Clickhouse | 21/5/2025 | 17/6/2026 | Stack overflow leading to DoS can be triggered by a malicious authenticated client in Clickhouse before 19.14.3.3. | |
| Analizada | Media (5.9) | 0.38% | — | Clickhouse CH | 11/4/2025 | 17/6/2026 | When using the ch-go library, under a specific condition when the query includes a large, uncompressed malicious external data, it is possible for an attacker in control of such data to smuggle another query packet into the connection stream. | |
| Aplazada | Alta (7.5) | 0.47% | — | ClickhouseAI | 20/3/2025 | 17/6/2026 | When the library bridge feature is enabled, the clickhouse-library-bridge exposes an HTTP API on localhost. This allows clickhouse-server to dynamically load a library from a specified path and execute it in an isolated process. Combined with the ClickHouse table engine functionality that permits file uploads to… | |
| Analizada | Media (5.3) | 0.77% | — | Zzskzy Warehouse Refinement Management System | 12/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in zzskzy Warehouse Refinement Management System 1.3. This affects the function ProcessRequest of the file /getAdyData.ashx. The manipulation of the argument showid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.77% | — | Zzskzy Warehouse Refinement Management System | 12/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in zzskzy Warehouse Refinement Management System 1.3. Affected by this issue is the function UploadCrash of the file /crash/log/SaveCrash.ashx. The manipulation of the argument file leads to unrestricted upload. The attack may be launched remotely. The… | |
| Aplazada | Media (5.7) | 0.21% | — | SAP Business WarehouseAI | 11/3/2025 | 17/6/2026 | SAP Business Warehouse (Process Chains) allows an attacker to manipulate the process execution due to missing authorization check. An attacker with display authorization for the process chain object could set one or all processes to be skipped. This means corresponding activities, such as data loading, activation, or… | |
| Analizada | Media (5.3) | 0.63% | — | Zzskzy Warehouse Refinement Management System | 9/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in zzskzy Warehouse Refinement Management System 3.1. Affected is the function ProcessRequest of the file /AcceptZip.ashx. The manipulation of the argument file leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been… | |
| Aplazada | Alta (7.1) | 0.39% | — | Thebloghouse ComparepressAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thebloghouse ComparePress comparepress allows Reflected XSS.This issue affects ComparePress: from n/a through <= 2.0.8. | |
| Aplazada | Alta (7.1) | 0.30% | — | Willshouse Tinymce-extended-configAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in willshouse TinyMCE Extended Config tinymce-extended-config allows Reflected XSS.This issue affects TinyMCE Extended Config: from n/a through <= 0.1.0. | |
| Analizada | Alta (7.8) | 0.28% | — | Trendmicro Housecall FOR Home Networks | 22/2/2025 | 17/6/2026 | Trend Micro HouseCall for Home Networks version 5.3.1302 and below contains an uncontrolled search patch element vulnerability that could allow an attacker with low user privileges to create a malicious DLL that could lead to escalated privileges. | |
| Aplazada | Media (4.8) | 0.16% | — | Apphousekitchen Aldente Charge LimiterAI | 6/2/2025 | 17/6/2026 | A vulnerability has been found in AppHouseKitchen AlDente Charge Limiter up to 1.29 on macOS and classified as critical. This vulnerability affects the function shouldAcceptNewConnection of the file com.apphousekitchen.aldente-pro.helper of the component XPC Service. The manipulation leads to improper authorization.… | |
| Analizada | Media (5.4) | 0.29% | — | Mayurik House Rental Management System | 14/1/2025 | 17/6/2026 | Sourcecodester House Rental Management system v1.0 is vulnerable to Cross Site Scripting (XSS) in rental/manage_categories.php. | |
| Aplazada | Media (5.1) | 0.32% | — | Yeqifu WarehouseAI | 12/1/2025 | 17/6/2026 | A vulnerability has been found in longpi1 warehouse 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /resources/..;/inport/updateInport of the component Backend. The manipulation of the argument remark leads to cross site scripting. The attack can be launched… | |
| Analizada | Media (5.3) | 0.40% | — | Singmr Houserent | 9/1/2025 | 17/6/2026 | A vulnerability classified as problematic was found in SingMR HouseRent 1.0. This vulnerability affects unknown code of the file /toAdminUpdateHousePage?hID=30. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (5.3) | 0.38% | — | Singmr Houserent | 9/1/2025 | 17/6/2026 | A vulnerability classified as critical has been found in SingMR HouseRent 1.0. This affects the function singleUpload/upload of the file src/main/java/com/house/wym/controller/AddHouseController.java. The manipulation of the argument file leads to unrestricted upload. It is possible to initiate the attack remotely.… | |
| Analizada | Media (5.3) | 0.38% | — | Singmr Houserent | 9/1/2025 | 17/6/2026 | A vulnerability was found in SingMR HouseRent 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file src/main/java/com/house/wym/controller/AdminController.java. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been… |