Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
2262 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Real State ServicesAI | 5/7/2026 | 7/7/2026 | A security vulnerability has been detected in code-projects Real State Services 1.0. This issue affects some unknown processing of the file /pay.php. Such manipulation of the argument Bankname leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Real State ServicesAI | 5/7/2026 | 6/7/2026 | A weakness has been identified in code-projects Real State Services 1.0. This vulnerability affects unknown code of the file /builderHome.php. This manipulation of the argument loc causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be… | |
| Aplazada | Media (6.9) | 0.43% | — | Code-projects Real State ServicesAI | 5/7/2026 | 6/7/2026 | A vulnerability was detected in code-projects Real State Services 1.0. Affected by this vulnerability is an unknown functionality of the file /addprojectsale.php. The manipulation of the argument amen results in sql injection. The attack can be launched remotely. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Real State ServicesAI | 5/7/2026 | 6/7/2026 | A security vulnerability has been detected in code-projects Real State Services 1.0. Affected is an unknown function of the file /addprojectrent.php. The manipulation of the argument amen leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Real State ServicesAI | 5/7/2026 | 6/7/2026 | A weakness has been identified in code-projects Real State Services 1.0. This impacts an unknown function of the file /single-list_rent.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Real State ServicesAI | 5/7/2026 | 7/7/2026 | A security flaw has been discovered in code-projects Real State Services 1.0. This affects an unknown function of the file /normalHomeRent.php. Performing a manipulation of the argument loc results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Real State ServicesAI | 5/7/2026 | 6/7/2026 | A vulnerability was identified in code-projects Real State Services 1.0. The impacted element is an unknown function of the file /normalHomeSale.php. Such manipulation of the argument loc leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Real State ServicesAI | 29/6/2026 | 29/6/2026 | A weakness has been identified in code-projects Real State Services 1.0. Impacted is an unknown function of the file /single-list_sale.php?action=add. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could… | |
| Aplazada | Alta (8.1) | 0.72% | 💥 PoC | Vmware CRMAIVmware Pivotal.core.common.dllAIVmware Pivotal.engine.client.services.conversion.dllAI | 23/6/2026 | 25/6/2026 | An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll and Pivotal.Engine.Client.Services.Conversion.dll components. | |
| Modificada | Alta (8.8) | 0.37% | — | IBM Watson Speech Services Cartridge | 22/6/2026 | 23/7/2026 | IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. A privileged user could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | |
| Aplazada | Media (6.4) | 0.21% | — | Services Section BlockAI | 18/6/2026 | 18/6/2026 | The Services Section Block – Showcase Service Details in Grid or Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'link' Block Attribute in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Analizada | Alta (7.5) | 0.50% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 17/6/2026 | 25/9/2026 | A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected… | |
| Analizada | Crítica (9.1) | 8.9% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 17/6/2026 | 25/9/2026 | A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of… | |
| Aplazada | Alta (8.7) | 0.35% | — | Global IT Informatics Services INC WeollAI | 12/6/2026 | 17/6/2026 | Unrestricted upload of file with dangerous type vulnerability in Global IT Informatics Services Inc. WEOLL allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WEOLL: from 2.0.9 before 3.2.45.33. | |
| Pendiente de análisis | Media (5.8) | 0.35% | — | Guzzlehttp Guzzle ServicesAI | 11/6/2026 | 17/6/2026 | Guzzle Services provides an implementation of the Guzzle Command library that uses Guzzle service descriptions to describe web services, serialize requests, and parse responses into easy to use model structures. Versions prior ro 1.5.4 do not safely serialize scalar XML element values containing the CDATA terminator… | |
| Analizada | Baja (3.7) | 0.26% | — | Broadcom Spring WEB Services | 11/6/2026 | 4/9/2026 | Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay of UsernameToken nonces and creation timestamps, Timestamp elements, and certain SAML one-time-use semantics could be ineffective even when… | |
| Analizada | Alta (8.6) | 0.43% | — | Broadcom Spring WEB Services | 11/6/2026 | 4/9/2026 | When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebServiceMessageSender instances to destinations taken directly from request headers without verifying that those destinations are safe to connect to. Affected versions: Spring… | |
| Analizada | Alta (8.2) | 0.39% | — | Broadcom Spring WEB Services | 11/6/2026 | 4/9/2026 | Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the JDK's default DocumentBuilderFactory behavior instead of Spring's hardened parser configuration. Applications that evaluate XPath against untrusted XML payloads could… | |
| En análisis | Media (5.3) | 0.46% | — | Broadcom Spring WEB Services | 11/6/2026 | 4/9/2026 | Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or disabled user semantics) to remote SOAP clients through exception messages or callback outcomes, instead of failing with generic authentication errors. That behavior assists remote attackers in… | |
| Analizada | Media (4.8) | 0.15% | — | Broadcom Spring WEB Services | 11/6/2026 | 4/9/2026 | Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for validation RequestData. Inbound WS-Security decryption could therefore accept RSA PKCS#1 v1.5 (rsa-1_5) encrypted key material unless operators explicitly reconfigured the flag. Affected versions:… | |
| Analizada | Media (5.4) | 0.18% | — | Broadcom Spring WEB Services | 11/6/2026 | 4/9/2026 | X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped to UserDetails, without applying Spring Security's standard account lifecycle checks (disabled, locked, expired, or credentials-expired accounts). Affected versions: Spring Web Services 5.0.0… | |
| Analizada | Alta (8.2) | 0.34% | — | Broadcom Spring WEB Services | 11/6/2026 | 4/9/2026 | Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement on RequestData. Services that validate WS-Security on the network could therefore accept messages that violate BSP rules, weakening protocol-level checks. Affected… | |
| Aplazada | Media (5.5) | 0.27% | — | Code-projects Real State ServicesAI | 1/6/2026 | 22/7/2026 | A vulnerability has been found in code-projects Real State Services 1.0. This impacts an unknown function of the file /loginuser.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (5.3) | 0.41% | — | Oracle Rest Data Services | 28/5/2026 | 21/7/2026 | Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability can result in… | |
| Analizada | Media (5.3) | 0.30% | — | Oracle Rest Data Services | 28/5/2026 | 21/7/2026 | Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability can result in… |