Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2766▲ 12 respecto a la semana anterior
Críticas / altas1276▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 227 respecto a la semana anterior
–

3560 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.68%—IBM Security Verify Information Queue31/8/202317/6/2026
IBM Security Verify Information Queue v10.0.4 y v10.0.5 podría permitir a un atacante remoto obtener información sensible que podría ayudar en futuros ataques contra el sistema. IBM X-force ID: 256014.
ModificadaBaja (3.3)0.13%—IBM Security Verify Information Queue31/8/202317/6/2026
IBM Security Verify Information Queue v10.0.4 y v10.0.5 almacena información confidencial en texto claro que puede ser leída por un usuario local. IBM X-Force ID: 256013.
ModificadaAlta (7.5)0.57%—IBM Infosphere Information Server28/8/202317/6/2026
IBM InfoSphere Information Systems v11.7 podría exponer información sobre el sistema host y la configuración del entorno. IBM X-Force ID: 246332.
ModificadaAlta (8.8)0.30%—IBM Infosphere Information Server28/8/202317/6/2026
IBM InfoSphere Information Server v11.7 es vulnerable a Cross-Site Request Forgery lo que podría permitir a un atacante ejecutar acciones maliciosas y no autorizadas transmitidas desde un usuario en el que confía el sitio web. IBM X-Force ID: 245400.
ModificadaAlta (8.8)0.66%—IBM Infosphere Information Server28/8/202317/6/2026
IBM InfoSphere Information Server v11.7 es potencialmente vulnerable a la inyección CSV. Un atacante remoto podría ejecutar comandos arbitrarios en el sistema, debido a una validación incorrecta del contenido de los archivos CSV. IBM X-Force ID: 244368.
ModificadaMedia (5.3)0.48%—IBM Robotic Process AutomationIBM Robotic Process Automation FOR Cloud PAK22/8/202317/6/2026
IBM Robotic Process Automation 21.0.0 through 21.0.7.1 runtime is vulnerable to information disclosure of script content if the remote REST request computer policy is enabled. IBM X-Force ID: 263470.
ModificadaCrítica (9.8)0.70%—IBM Robotic Process Automation22/8/202317/6/2026
IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 is vulnerable to incorrect privilege assignment when importing users from an LDAP directory. IBM X-Force ID: 262481.
ModificadaMedia (4.3)0.49%—IBM Robotic Process Automation22/8/202317/6/2026
IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 server could allow an authenticated user to view sensitive information from installation logs. IBM X-Force Id: 262293.
ModificadaMedia (4.3)0.53%—IBM Robotic Process AutomationIBM Robotic Process Automation FOR Cloud PAK22/8/202317/6/2026
El servidor IBM Robotic Process Automation v21.0.0 a v21.0.7 podría permitir a un usuario autenticado ver información confidencial de los registros de la aplicación. IBM X-Force ID: 262289.
ModificadaCrítica (9.8)72%—Rockwellautomation Thinmanager Thinserver17/8/202317/6/2026
The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability. Due to an improper input validation, a path traversal vulnerability exists, via the filename field, when the ThinManager processes a certain function. If exploited, an unauthenticated remote attacker can upload…
ModificadaCrítica (9.1)82%—Rockwellautomation Thinmanager Thinserver17/8/202317/6/2026
The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, Due to improper input validation, a path traversal vulnerability exists when the ThinManager software processes a certain function. If exploited, an unauthenticated remote threat actor can delete arbitrary files…
ModificadaAlta (7.5)40%—Rockwellautomation Thinmanager Thinserver17/8/202317/6/2026
The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, an integer overflow condition exists in the affected products. When the ThinManager processes incoming messages, a read access violation occurs and terminates the process. A malicious user could exploit this…
ModificadaMedia (4.8)0.64%—Code-projects Hospital Information System14/8/202317/6/2026
Code Projects Hospital Information System 1.0 is vulnerable to Cross Site Scripting (XSS)
ModificadaAlta (7.5)1.2%—Rockwellautomation Armor Powerflex Firmware8/8/202317/6/2026
A vulnerability was discovered in the Rockwell Automation Armor PowerFlex device when the product sends communications to the local event log. Threat actors could exploit this vulnerability by sending an influx of network commands, causing the product to generate an influx of event log traffic at a high rate. If…
ModificadaMedia (6.1)0.64%💥 PoCOretnom23 Lost AND Found Information System4/8/20239/7/2026
Cross Site Scripting (XSS) vulnerability in sourcecodester Lost and Found Information System 1.0 allows remote attackers to run arbitrary code via the First Name, Middle Name and Last Name fields on the Create User page.
ModificadaMedia (6.5)0.49%—IBM Robotic Process AutomationIBM Robotic Process Automation FOR Cloud PAK2/8/202317/6/2026
IBM Robotic Process Automation v21.0.0 a 21.0.7.latest es vulnerable al acceso no autorizado a datos debido a una validación de autorización insuficiente en algunas rutas API. ID de IBM X-Force: 245425.
ModificadaMedia (5.9)0.54%—Br-automation Automation Runtime26/7/202317/6/2026
Improper initialization implementation in Portmapper used in B&R Industrial Automation Automation Runtime <G4.93 allows unauthenticated network-based attackers to cause permanent denial-of-service conditions.
ModificadaCrítica (9.8)0.49%—Oretnom23 Lost AND Found Information System23/7/202317/6/2026
A vulnerability has been found in SourceCodester Lost and Found Information System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=delete_category of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql…
ModificadaMedia (5.3)0.51%—IBM Robotic Process AutomationIBM Robotic Process Automation AS A ServiceIBM Robotic Process Automation FOR Cloud PAK19/7/202317/6/2026
IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.4 and 23.0.0 through 23.0.5 is vulnerable to disclosing server version information which may be used to determine software vulnerabilities at the operating system level. IBM X-Force ID: 259368.
ModificadaMedia (6.5)0.54%—IBM Infosphere Information Server19/7/202317/6/2026
IBM InfoSphere Information Server v11.7 podría permitir a un usuario autenticado obtener información confidencial debido a una configuración de seguridad insegura en "InfoSphere Data Flow Designer". IBM X-Force ID: 259352.
ModificadaMedia (4.4)1.7%—Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+218/7/202317/6/2026
Vulnerabilidad en el producto MySQL Server de Oracle MySQL (componente: Server: DDL). Las versiones afectadas son 8.0.33 y anteriores. Una vulnerabilidad difícil de explotar permite a un atacante con altos privilegios y acceso a la red a través de múltiples protocolos comprometer MySQL Server. Los ataques exitosos de…
ModificadaMedia (4.9)1.4%—Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+218/7/202317/6/2026
Vulnerabilidad en el producto MySQL Server de Oracle MySQL (componente: Server: Replication). Las versiones afectadas son 8.0.33 y anteriores. Una vulnerabilidad fácilmente explotable permite a un atacante con altos privilegios con acceso a la red a través de múltiples protocolos comprometer MySQL Server. Los ataques…
ModificadaMedia (4.9)1.8%—Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+218/7/202317/6/2026
Vulnerabilidad en el producto MySQL Server de Oracle MySQL (componente: Server: Optimizer). Las versiones afectadas son 8.0.33 y anteriores. Una vulnerabilidad fácilmente explotable permite a un atacante con altos privilegios con acceso a la red a través de múltiples protocolos comprometer MySQL Server. Los ataques…
ModificadaMedia (4.9)1.4%—Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+218/7/202317/6/2026
Vulnerabilidad en el producto MySQL Server de Oracle MySQL (componente: Server: Optimizer). Las versiones afectadas son 8.0.33 y anteriores. Una vulnerabilidad fácilmente explotable permite a un atacante con altos privilegios con acceso a la red a través de múltiples protocolos comprometer MySQL Server. Los ataques…
ModificadaMedia (5.9)1.3%—Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+218/7/202317/6/2026
Vulnerabilidad en el producto MySQL Server de Oracle MySQL (componente: Programas cliente). Las versiones afectadas son 5.7.42 y anteriores y 8.0.33 y anteriores. Una vulnerabilidad difícil de explotar permite a un atacante con pocos privilegios y acceso a la red a través de múltiples protocolos comprometer MySQL…