Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
2525 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.9) | 0.29% | 💥 PoC | Samsung Internet | 16/5/2025 | 17/6/2026 | Samsung Internet for Galaxy Watch version 5.0.9, available up until Samsung Galaxy Watch 3, does not properly validate TLS certificates, allowing for an attacker to impersonate any and all websites visited by the user. This is a critical misconfiguration in the way the browser validates the identity of the server. It… | |
| Analizada | Media (5.3) | 0.37% | — | Wowjoy Internet Doctor Workstation System | 27/4/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in wowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstation System 1.0. This issue affects some unknown processing of the file /v1/prescription/details/. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has… | |
| Analizada | Media (5.3) | 5.5% | — | Wowjoy Internet Doctor Workstation System | 27/4/2025 | 17/6/2026 | A vulnerability classified as problematic was found in wowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstation System 1.0. This vulnerability affects unknown code of the file /v1/prescription/list. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Aplazada | Alta (7.1) | 0.29% | — | AT Internet SmarttagAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BenDlz AT Internet SmartTag at-internet allows Reflected XSS.This issue affects AT Internet SmartTag: from n/a through <= 0.2. | |
| Analizada | Media (6.1) | 0.30% | 💥 PoC | Codeastro Internet Banking System | 17/4/2025 | 17/6/2026 | Code Astro Internet Banking System 2.0.0 is vulnerable to Cross Site Scripting (XSS) via the name parameter in /admin/pages_account.php. | |
| Aplazada | Media (6.6) | 0.49% | 💥 PoC | Internet-formation Wp-advanced-searchAI | 16/4/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Mathieu Chartier WP-Advanced-Search wp-advanced-search allows Upload a Web Shell to a Web Server.This issue affects WP-Advanced-Search: from n/a through <= 3.3.9.4. | |
| Aplazada | Media (5.3) | 0.33% | — | Wowjoy Internet Doctor Workstation SystemAI | 14/4/2025 | 17/6/2026 | A vulnerability has been found in wowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstation System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /v1/pushConfig/detail/. The manipulation leads to improper authorization. The attack can be launched remotely. The exploit… | |
| Analizada | Alta (8.8) | 0.88% | 💥 PoC | Codeastro Internet Banking System | 10/4/2025 | 17/6/2026 | A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file upload validation in the profile_pic parameter within pages_view_client.php. | |
| Analizada | Media (4.8) | 0.27% | 💥 PoC | Codeastro Internet Banking System | 9/4/2025 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in the name parameter of pages_add_acc_type.php in Code Astro Internet Banking System 2.0.0. | |
| Aplazada | Media (5) | 0.18% | — | Plain Craft LauncherAIMicrosoft Internet ExplorerAIMicrosoft WPFAI | 6/4/2025 | 17/6/2026 | Plain Craft Launcher (PCL) is a launcher for Minecraft. PCL allows users to use homepages provided by third parties. If controls such as WebBrowser are used in the homepage, WPF will use Internet Explorer to load the specified webpage. If the user uses a malicious homepage, the attacker can use IE background to access… | |
| Analizada | Baja (3.5) | 0.32% | — | Internet-formation Wp-advanced-search | 25/3/2025 | 17/6/2026 | The WordPress WP-Advanced-Search WordPress plugin before 3.3.9.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (4.9) | 0.38% | — | SAP WEB DispatcherAISAP Internet Communication ManagerAI | 11/3/2025 | 17/6/2026 | SAP Web Dispatcher and Internet Communication Manager allow an attacker with administrative privileges to enable debugging trace mode with a specific parameter value. This exposes unencrypted passwords in the logs, causing a high impact on the confidentiality of the application. There is no impact on integrity or… | |
| Aplazada | Media (6.9) | 0.31% | — | Dario Health Internet-based Server InfrastructureAI | 28/2/2025 | 17/6/2026 | The Dario Health Internet-based server infrastructure is vulnerable due to exposure of development environment details, which could lead to unsafe functionality. | |
| Analizada | Media (4.8) | 0.25% | — | Internet-formation Modal Portfolio | 28/2/2025 | 17/6/2026 | The Modal Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.7.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts… | |
| Aplazada | Media (5.1) | 0.31% | — | Internet WEB Solutions Sublime CRMAI | 16/2/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Internet Web Solutions Sublime CRM up to 20250207. Affected is an unknown function of the file /crm/inicio.php of the component HTTP POST Request Handler. The manipulation of the argument msg_to leads to cross site scripting. It is possible to launch… | |
| Aplazada | Media (5.3) | 0.13% | — | Kaspersky Anti-virus SDK FOR WindowsAIKaspersky Security FOR Virtualization Light AgentAIKaspersky Endpoint Security FOR WindowsAIKaspersky Small Office SecurityAI+9 | 6/2/2025 | 17/6/2026 | Kaspersky has fixed a security issue in Kaspersky Anti-Virus SDK for Windows, Kaspersky Security for Virtualization Light Agent, Kaspersky Endpoint Security for Windows, Kaspersky Small Office Security, Kaspersky for Windows (Standard, Plus, Premium), Kaspersky Free, Kaspersky Anti-Virus, Kaspersky Internet Security,… | |
| Analizada | Alta (7.3) | 0.45% | 💥 PoC | Codeastro Internet Banking System | 22/1/2025 | 17/6/2026 | A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to execute arbitrary JavaScript on the admin page (pages_account), potentially leading to unauthorized actions such as changing account settings or stealing sensitive user information. This… | |
| Aplazada | Crítica (9.8) | 0.43% | — | Synnefoims Internet Management SoftwareAI | 22/1/2025 | 17/6/2026 | A SQL injection vulnerability exists in Synnefo Internet Management Software (IMS) version 2023 and earlier. This vulnerability occurs due to improper input validation in a specific API endpoint parameter allowing an attacker to manipulate SQL queries via crafted input. Successful exploitation could lead to… | |
| Modificada | Alta (7.1) | 0.31% | — | Akamai Secure Internet Access Enterprise Threatavert | 4/11/2024 | 17/6/2026 | Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorrect authorization controls for the Admin functionality on the ThreatAvert Policy page. An authenticated user can… | |
| Analizada | Crítica (9.8) | 3.0% | 💥 Exploit | Internet-formation Wp-advanced-search | 10/10/2024 | 17/6/2026 | The WP-Advanced-Search WordPress plugin before 3.3.9.2 does not sanitize and escape the t parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks | |
| Analizada | Media (5.5) | 0.16% | — | Samsung Internet | 8/10/2024 | 17/6/2026 | Use of implicit intent for sensitive communication in translation혻in Samsung Internet prior to version 26.0.3.1 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability. | |
| Aplazada | Media (5.9) | 0.22% | — | Shanghai Zhouma Network Technology IMS Intelligent Manufacturing Collaborative Internet OF Things SystemAI | 4/10/2024 | 17/6/2026 | An issue in Shanghai Zhouma Network Technology CO., Ltd IMS Intelligent Manufacturing Collaborative Internet of Things System v.1.9.1 allows a remote attacker to escalate privileges via the open port. | |
| Analizada | Alta (7.8) | 0.12% | — | AVG Internet Security | 12/9/2024 | 17/6/2026 | Local Privilege Escalation in AVG Internet Security v24 on Windows allows a local unprivileged user to escalate privileges to SYSTEM via COM-Hijacking. | |
| Analizada | Alta (7.5) | 0.69% | — | Dfinity Canister Developer KIT FOR THE Internet Computer | 5/9/2024 | 17/6/2026 | When a canister method is called via ic_cdk::call* , a new Future CallFuture is created and can be awaited by the caller to get the execution result. Internally, the state of the Future is tracked and stored in a struct called CallFutureState. A bug in the polling implementation of the CallFuture allows multiple… | |
| Aplazada | Crítica (9.8) | 0.57% | — | Ezviz Internet PT Camera Cs-cv246AI | 23/8/2024 | 5/7/2026 | Ezviz Internet PT Camera CS-CV246 D15655150 allows an unauthenticated host to access its live video stream by crafting a set of RTSP packets with a specific set of URLs that can be used to redirect the camera feed. NOTE: the vendor's perspective is that the Anonymous120386 sample code can establish RTSP protocol… |