Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
1917 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.35% | — | Global IT Informatics Services INC WeollAI | 12/6/2026 | 17/6/2026 | Unrestricted upload of file with dangerous type vulnerability in Global IT Informatics Services Inc. WEOLL allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WEOLL: from 2.0.9 before 3.2.45.33. | |
| Aplazada | Crítica (9.9) | 0.34% | — | Basarsoft Information Technologies INC RotabanAI | 11/6/2026 | 17/6/2026 | Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows Upload a Web Shell to a Web Server. This issue affects Rotaban: from V2026.06.002 before V2026.06.003. | |
| Aplazada | Crítica (9.8) | 0.45% | 💥 PoC | Soagen Informatics Technologies Software AND Consulting ApinizerAI | 11/6/2026 | 17/6/2026 | Improper neutralization of special elements used in an expression language statement ('expression language injection') vulnerability in Soagen Informatics Technologies Software and Consulting Inc. Apinizer allows Code Injection. This issue affects Apinizer: from 2026.04.0 before 2026.04.6. | |
| Analizada | Alta (7.8) | 0.34% | — | Adobe Format Plugins | 9/6/2026 | 28/8/2026 | Format Plugins versions 1.1.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.34% | — | Adobe Format Plugins | 9/6/2026 | 28/8/2026 | Format Plugins versions 1.1.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Aplazada | Crítica (9.8) | 0.47% | — | Mosk Information Technologies LTD CBS PlatformAI | 9/6/2026 | 23/7/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in MOSK Information Technologies Ltd. CBS Platform allows SQL Injection. This issue affects CBS Platform: through 09062026. NOTE: The vendor was contacted and it was learned that the product is not supported. | |
| Aplazada | Media (5.5) | 0.28% | — | Sourcecodester Barangay Resident Profiling AND Information Management SystemAI | 8/6/2026 | 23/7/2026 | A vulnerability has been found in SourceCodester Barangay Resident Profiling and Information Management System 1.0. The impacted element is an unknown function of the file passsword_reset.php of the component Password Reset Handler. Such manipulation of the argument new_password with the input password123 leads to use… | |
| Aplazada | Crítica (9.8) | 0.50% | — | Akmer Informatics Automation Industry AND Trade TeknopassAI | 4/6/2026 | 22/7/2026 | Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Automation Industry and Trade Ltd. Co. TeknoPass allows SQL Injection. This issue affects TeknoPass: from 20210501 through 20260429. | |
| Aplazada | Alta (7.8) | 1.2% | — | SysteminformationAI | 27/5/2026 | 28/8/2026 | systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation is vulnerable to command injection in networkInterfaces() when an active NetworkManager connection profile name contains shell metacharacters. The vulnerable value is obtained internally from real… | |
| Analizada | Media (6.5) | 0.42% | — | IBM Cloud Application Performance Managemen | 27/5/2026 | 17/6/2026 | IBM Cloud APM, Base Private 8.1.4 and IBM Cloud APM, Advanced Private 8.1.4 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in the data query logic of the Fenced environment. | |
| Analizada | Alta (7.8) | 0.16% | — | IBM Netezza Performance Server Replication Services | 27/5/2026 | 17/6/2026 | IBM Netezza Performance Server Replication Services 3.0.2.0 through 3.0.5.0 allows an attacker with low‑privileged access to escalate their privileges to root. By exploiting this flaw, the attacker can execute root‑level commands, obtain a root shell, and change the root user’s password. Successful exploitation also… | |
| Analizada | Alta (8.8) | 0.46% | — | IBM Qradar Security Information AND Event Manager | 27/5/2026 | 17/6/2026 | IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 002 could allow a privileged user to upload a malicious backup archive that could be restored and used to gain access to the underlying operating system. | |
| Aplazada | Alta (8) | 0.17% | — | Sitemio Information Technologies Trade WisecpAI | 20/5/2026 | 24/7/2026 | Cross-Site request forgery (CSRF) vulnerability in Sitemio Information Technologies Trade Ltd. Co. WISECP allows Cross Site Request Forgery. This issue affects WISECP: through 20022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Aplazada | Alta (8.8) | 0.45% | — | Basamak Information Technology Consulting AND Organization Trade DernekwebAI | 18/5/2026 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Basamak Information Technology Consulting and Organization Trade Ltd. Co. DernekWeb allows Stored XSS. This issue affects DernekWeb: through 30122025. | |
| Aplazada | Media (6.8) | 0.40% | — | IM Park Information Technology Electronics Press Publishing AND Advertising Education LTD CO DijidemiAI | 14/5/2026 | 17/6/2026 | Authorization bypass through User-Controlled key vulnerability in Im Park Information Technology, Electronics, Press, Publishing and Advertising, Education Ltd. Co. DijiDemi allows Privilege Abuse. This issue affects DijiDemi: from v4.5.12.1 before v4.5.13.0. | |
| Aplazada | Alta (8.8) | 0.24% | — | Appyap Technology AND Information INC Yaay Social Media APPAI | 14/5/2026 | 7/10/2026 | Authorization bypass through User-Controlled key vulnerability in APPYAP Technology and Information Inc. Yaay Social Media App allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Yaay Social Media App: from 3.8.0 through 24102025. | |
| Analizada | Media (5.4) | 0.09% | — | Intel Connectivity Performance Suite | 12/5/2026 | 21/7/2026 | Uncontrolled search path for some Intel(R) Connectivity Performance Suite software installers before version 50.25.1121.193 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of… | |
| Aplazada | Crítica (9.6) | 0.40% | — | Divvydrive Information Technologies INC DivvydriveAI | 7/5/2026 | 17/6/2026 | URL redirection to untrusted site ('open redirect') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Parameter Injection. This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2. | |
| Aplazada | Alta (8.8) | 0.45% | — | Divvydrive Information Technologies INC DivvydriveAI | 7/5/2026 | 17/6/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross-Site Scripting (XSS). This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2. | |
| Aplazada | Media (6.5) | 0.17% | — | Divvydrive Information Technologies INC DivvydriveAI | 7/5/2026 | 17/6/2026 | Cross-Site request forgery (CSRF) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross Site Request Forgery. This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2. | |
| Aplazada | Alta (8.8) | 0.45% | — | Divvydrive Information Technologies INC DivvydriveAI | 7/5/2026 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS. This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2. | |
| Aplazada | Alta (8.3) | 0.22% | — | Divvydrive Information Technologies INC DivvydriveAI | 7/5/2026 | 5/10/2026 | Improperly controlled modification of Dynamically-Determined object attributes, Allocation of resources without limits or throttling vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Excessive Allocation, Flooding. This issue affects DivvyDrive: from 4.8.2.19 before 4.8.3.2. | |
| Aplazada | Media (5.3) | 0.39% | — | ILM Informatique JopenddocumentAI | 4/5/2026 | 17/6/2026 | Improper restriction of XML external entity reference vulnerability in ILM Informatique jOpenDocument allows Data Serialization External Entities Blowup. This issue affects jOpenDocument: 1.5. | |
| Aplazada | Media (4.8) | 0.14% | — | ILM Informatique OpenconcertoAI | 4/5/2026 | 17/6/2026 | Plaintext storage of a password vulnerability in ILM Informatique OpenConcerto allows Retrieve Embedded Sensitive Data. This issue affects OpenConcerto: 1.7.5. | |
| Aplazada | Baja (2.4) | 0.14% | — | ILM Informatique OpenconcertoAI | 4/5/2026 | 17/6/2026 | Incorrect Permission Assignment for Critical Resource vulnerability in ILM Informatique OpenConcerto allows Replace Binaries. This issue affects OpenConcerto: 1.7.5. |