Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

4214 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.27%—Nsquared Simply Schedule AppointmentsAI13/7/202613/7/2026
Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.11.11.
AplazadaMedia (6.5)0.33%—Nsquared Simply Schedule AppointmentsAI13/7/202613/7/2026
Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.12.4.
AplazadaBaja (2)0.35%—Craterapp CraterAI6/7/20266/7/2026
A weakness has been identified in crater-invoice-inc crater up to 6.0.6. This affects the function getFormattedString of the file app/Http/Requests/InvoicesRequest.php of the component Invoice Note Handler. Executing a manipulation of the argument notes can lead to cross site scripting. The attack may be launched…
ModificadaCrítica (9.8)0.42%—IBM Websphere Application Server30/6/202629/7/2026
IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.
AnalizadaMedia (6.1)0.34%—IBM Websphere Application Server30/6/20262/7/2026
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console.
AnalizadaAlta (7.5)0.47%—IBM Websphere Application Server30/6/20262/7/2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary file read vulnerability with the restConnector-2.0 feature enabled.
ModificadaCrítica (9.8)0.36%—IBM Websphere Application Server30/6/20266/8/2026
IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.
AnalizadaCrítica (9.3)0.38%—IBM Websphere Application Server30/6/20262/7/2026
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system.
AnalizadaCrítica (9.3)0.38%—IBM Websphere Application Server30/6/20262/7/2026
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help system.
AnalizadaAlta (7.5)0.78%—IBM Websphere Application Server30/6/20262/7/2026
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information from the administrative console's integrated help system.
AnalizadaCrítica (9.8)0.40%—IBM Websphere Application Server30/6/20262/7/2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled.
ModificadaMedia (4.3)0.39%—Redhat Build OF KeycloakRedhat Jboss Enterprise Application Platform Expansion Pack30/6/20265/8/2026
A vulnerability was discovered in Keycloak's Admin UI extension that allows certain administrative users to bypass security restrictions. When Fine-Grained Admin Permissions (FGAPv2) are enabled, an administrator who should only be able to search for users (but not view their full details) can use a specific…
AplazadaAlta (7.1)0.23%—Simply Schedule AppointmentsAI26/6/202626/6/2026
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.2 versions.
AnalizadaAlta (7.5)0.56%—IBM Websphere Application Server22/6/202623/6/2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
AnalizadaAlta (7.5)0.62%—IBM Websphere Application Server22/6/202623/6/2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
AnalizadaCrítica (9.1)0.39%—IBM Websphere Application Server22/6/202624/6/2026
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure.
AnalizadaCrítica (9.1)0.59%—IBM Websphere Application Server22/6/202624/6/2026
IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server thereby allowing the attacker to bypass security controls, spoof…
AnalizadaAlta (7.3)0.47%—IBM Websphere Application Server22/6/202623/6/2026
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applications.
AplazadaCrítica (9.8)0.56%—Thrivethemes Thrive ApprenticeAI17/6/202617/6/2026
Unauthenticated PHP Object Injection in Thrive Apprentice < 10.8.10.2 versions.
AplazadaAlta (8.2)0.34%—Hippoo Mobile APP FOR WoocommerceAI15/6/202617/6/2026
Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions.
AplazadaAlta (7.5)0.42%—Simply Schedule AppointmentsAI15/6/202617/6/2026
Unauthenticated Sensitive Data Exposure in Simply Schedule Appointments < 1.6.11.2 versions.
AplazadaCrítica (9.3)0.40%—Simply Schedule AppointmentsAI15/6/202617/6/2026
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.9.27 versions.
AplazadaAlta (7.1)0.25%—Simply Schedule AppointmentsAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.10.6 versions.
AplazadaMedia (4.8)0.10%—Genspark AI Workspace APPAI14/6/202624/7/2026
A vulnerability has been found in Genspark AI Workspace App 2.8.4 on Android. This vulnerability affects unknown code of the component ai.mainfunc.genspark. The manipulation leads to improper authorization in handler for custom url scheme. The attack can only be performed from a local environment. The vendor was…
AplazadaCrítica (9.4)0.15%—PC Suite APPAI12/6/202617/6/2026
An unauthorized access vulnerability exists in the PcSuite APP. The vulnerability can be exploited by attackers to Unauthorized access to the victim’s device.