Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

1917 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.35%—Global IT Informatics Services INC WeollAI12/6/202617/6/2026
Unrestricted upload of file with dangerous type vulnerability in Global IT Informatics Services Inc. WEOLL allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WEOLL: from 2.0.9 before 3.2.45.33.
AplazadaCrítica (9.9)0.34%—Basarsoft Information Technologies INC RotabanAI11/6/202617/6/2026
Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows Upload a Web Shell to a Web Server. This issue affects Rotaban: from V2026.06.002 before V2026.06.003.
AplazadaCrítica (9.8)0.45%💥 PoCSoagen Informatics Technologies Software AND Consulting ApinizerAI11/6/202617/6/2026
Improper neutralization of special elements used in an expression language statement ('expression language injection') vulnerability in Soagen Informatics Technologies Software and Consulting Inc. Apinizer allows Code Injection. This issue affects Apinizer: from 2026.04.0 before 2026.04.6.
AnalizadaAlta (7.8)0.34%—Adobe Format Plugins9/6/202628/8/2026
Format Plugins versions 1.1.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AnalizadaAlta (7.8)0.34%—Adobe Format Plugins9/6/202628/8/2026
Format Plugins versions 1.1.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AplazadaCrítica (9.8)0.47%—Mosk Information Technologies LTD CBS PlatformAI9/6/202623/7/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in MOSK Information Technologies Ltd. CBS Platform allows SQL Injection. This issue affects CBS Platform: through 09062026. NOTE: The vendor was contacted and it was learned that the product is not supported.
AplazadaMedia (5.5)0.28%—Sourcecodester Barangay Resident Profiling AND Information Management SystemAI8/6/202623/7/2026
A vulnerability has been found in SourceCodester Barangay Resident Profiling and Information Management System 1.0. The impacted element is an unknown function of the file passsword_reset.php of the component Password Reset Handler. Such manipulation of the argument new_password with the input password123 leads to use…
AplazadaCrítica (9.8)0.50%—Akmer Informatics Automation Industry AND Trade TeknopassAI4/6/202622/7/2026
Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Automation Industry and Trade Ltd. Co. TeknoPass allows SQL Injection. This issue affects TeknoPass: from 20210501 through 20260429.
AplazadaAlta (7.8)1.2%—SysteminformationAI27/5/202628/8/2026
systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation is vulnerable to command injection in networkInterfaces() when an active NetworkManager connection profile name contains shell metacharacters. The vulnerable value is obtained internally from real…
AnalizadaMedia (6.5)0.42%—IBM Cloud Application Performance Managemen27/5/202617/6/2026
IBM Cloud APM, Base Private 8.1.4 and IBM Cloud APM, Advanced Private 8.1.4 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in the data query logic of the Fenced environment.
AnalizadaAlta (7.8)0.16%—IBM Netezza Performance Server Replication Services27/5/202617/6/2026
IBM Netezza Performance Server Replication Services 3.0.2.0 through 3.0.5.0 allows an attacker with low‑privileged access to escalate their privileges to root. By exploiting this flaw, the attacker can execute root‑level commands, obtain a root shell, and change the root user’s password. Successful exploitation also…
AnalizadaAlta (8.8)0.46%—IBM Qradar Security Information AND Event Manager27/5/202617/6/2026
IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 002 could allow a privileged user to upload a malicious backup archive that could be restored and used to gain access to the underlying operating system.
AplazadaAlta (8)0.17%—Sitemio Information Technologies Trade WisecpAI20/5/202624/7/2026
Cross-Site request forgery (CSRF) vulnerability in Sitemio Information Technologies Trade Ltd. Co. WISECP allows Cross Site Request Forgery. This issue affects WISECP: through 20022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
AplazadaAlta (8.8)0.45%—Basamak Information Technology Consulting AND Organization Trade DernekwebAI18/5/202617/6/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Basamak Information Technology Consulting and Organization Trade Ltd. Co. DernekWeb allows Stored XSS. This issue affects DernekWeb: through 30122025.
AplazadaMedia (6.8)0.40%—IM Park Information Technology Electronics Press Publishing AND Advertising Education LTD CO DijidemiAI14/5/202617/6/2026
Authorization bypass through User-Controlled key vulnerability in Im Park Information Technology, Electronics, Press, Publishing and Advertising, Education Ltd. Co. DijiDemi allows Privilege Abuse. This issue affects DijiDemi: from v4.5.12.1 before v4.5.13.0.
AplazadaAlta (8.8)0.24%—Appyap Technology AND Information INC Yaay Social Media APPAI14/5/20267/10/2026
Authorization bypass through User-Controlled key vulnerability in APPYAP Technology and Information Inc. Yaay Social Media App allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Yaay Social Media App: from 3.8.0 through 24102025.
AnalizadaMedia (5.4)0.09%—Intel Connectivity Performance Suite12/5/202621/7/2026
Uncontrolled search path for some Intel(R) Connectivity Performance Suite software installers before version 50.25.1121.193 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of…
AplazadaCrítica (9.6)0.40%—Divvydrive Information Technologies INC DivvydriveAI7/5/202617/6/2026
URL redirection to untrusted site ('open redirect') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Parameter Injection. This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2.
AplazadaAlta (8.8)0.45%—Divvydrive Information Technologies INC DivvydriveAI7/5/202617/6/2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross-Site Scripting (XSS). This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2.
AplazadaMedia (6.5)0.17%—Divvydrive Information Technologies INC DivvydriveAI7/5/202617/6/2026
Cross-Site request forgery (CSRF) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross Site Request Forgery. This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2.
AplazadaAlta (8.8)0.45%—Divvydrive Information Technologies INC DivvydriveAI7/5/202617/6/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS. This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2.
AplazadaAlta (8.3)0.22%—Divvydrive Information Technologies INC DivvydriveAI7/5/20265/10/2026
Improperly controlled modification of Dynamically-Determined object attributes, Allocation of resources without limits or throttling vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Excessive Allocation, Flooding. This issue affects DivvyDrive: from 4.8.2.19 before 4.8.3.2.
AplazadaMedia (5.3)0.39%—ILM Informatique JopenddocumentAI4/5/202617/6/2026
Improper restriction of XML external entity reference vulnerability in ILM Informatique jOpenDocument allows Data Serialization External Entities Blowup. This issue affects jOpenDocument: 1.5.
AplazadaMedia (4.8)0.14%—ILM Informatique OpenconcertoAI4/5/202617/6/2026
Plaintext storage of a password vulnerability in ILM Informatique OpenConcerto allows Retrieve Embedded Sensitive Data. This issue affects OpenConcerto: 1.7.5.
AplazadaBaja (2.4)0.14%—ILM Informatique OpenconcertoAI4/5/202617/6/2026
Incorrect Permission Assignment for Critical Resource vulnerability in ILM Informatique OpenConcerto allows Replace Binaries. This issue affects OpenConcerto: 1.7.5.