Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
–

3560 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.1)0.25%—Armiya Information Technologies LTD Access Control System GKSAI7/7/20267/7/2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows XSS Targeting HTML Attributes. This issue affects Access Control System (GKS): before Version 2.
AplazadaAlta (8.4)0.16%—BR Industrial Automation AprolAI6/7/20266/7/2026
Untrusted Search Path vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before R 4.4-01P5.
AplazadaCrítica (9.1)0.22%—B AND R Industrial Automation Gmbh AprolAI6/7/20266/7/2026
Improper certificate validation vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before R 4.4-01P5.
AplazadaMedia (5.4)0.23%—Divvydrive Information Technologies INC DivvydriveAI1/7/20261/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS. This issue affects DivvyDrive: from v.4.8.2.23 before v.4.8.3.1.
AplazadaMedia (6.4)0.25%—Divvydrive Information Technologies INC DivvydriveAI1/7/20261/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS. This issue affects DivvyDrive: from 4.8.2.23 before v.4.8.3.1.
AnalizadaAlta (7.5)0.45%—IBM Infosphere Information Server30/6/20262/7/2026
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerability.
AnalizadaCrítica (9.1)0.41%—IBM Business Automation Manager30/6/20262/7/2026
IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
AnalizadaMedia (6.5)0.33%—IBM Devops AutomationIBM Devops Loop30/6/20266/10/2026
IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow an authenticated user to impersonate another user on the system.
AplazadaAlta (7.5)0.66%—Mz-automation Lib60870AI29/6/20264/8/2026
A heap buffer overflow in the HighPriorityASDUQueue_hasUnconfirmedIMessages function of lib60870 v2.3.3 to v2.3.6 allows attackers to cause a Denial of Service (DoS) via a crafted payload.
AplazadaMedia (5.5)0.43%—Itsourcecode Baptism Information Management SystemAI29/6/202629/6/2026
A security vulnerability has been detected in itsourcecode Baptism Information Management System 1.0. This affects an unknown function of the file /editBaptism.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be…
AplazadaMedia (5.5)0.43%—Itsourcecode Baptism Information Management SystemAI29/6/202629/6/2026
A weakness has been identified in itsourcecode Baptism Information Management System 1.0. The impacted element is an unknown function of the file /delbaptism.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the…
AplazadaAlta (8.4)0.18%—Hornerautomation CscapeAI25/6/202625/6/2026
Horner Automation Cscape versions prior to 10.2 SP3 are vulnerable to an Out-of-Bounds Read vulnerability through parsing CSP files. Successful exploitation of this vulnerability could allow an attacker to disclose information and execute arbitrary code.
Pendiente de análisisMedia (6.3)0.45%—Rockwellautomation CompactlogixAI16/6/202617/6/2026
A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's web server exposes CIP Connection IDs on the diagnostics webpage, which are accessible to any unauthenticated user on the network. This information can be leveraged by an attacker to construct…
Pendiente de análisisAlta (8.8)0.43%—Rockwellautomation 1794-aentrAI16/6/202617/6/2026
An improper authentication security issue exists within the 1794-AENTR adapter's embedded web server. The vulnerability allows an unauthenticated attacker to change the device's web interface password by sending a crafted HTTP GET request to a specific endpoint, without any prior authentication being required. If…
Pendiente de análisisCrítica (9.2)0.29%—Rockwellautomation Factorytalk Historian Site EditionAI16/6/20267/10/2026
An authentication bypass security issue exists within FactoryTalk Historian Site Edition. By continually sending requests to the login endpoint, an attacker may obtain a valid authentication token.
AplazadaAlta (7.1)0.40%—Funnelkit AutomationsAI15/6/202617/6/2026
Subscriber Broken Authentication in FunnelKit Automations <= 3.7.3 versions.
ModificadaAlta (7.7)1.0%—AxiosRedhat Advanced Cluster Management FOR KubernetesRedhat Advanced Cluster SecurityRedhat Ansible Automation Platform+811/6/202611/9/2026
Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affected Axios versions…
AplazadaCrítica (9.9)0.34%—Basarsoft Information Technologies INC RotabanAI11/6/202617/6/2026
Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows Upload a Web Shell to a Web Server. This issue affects Rotaban: from V2026.06.002 before V2026.06.003.
ModificadaAlta (7.5)0.99%—Js-cookie Javascript CookieRedhat 3scale API ManagementRedhat Ansible Automation PlatformRedhat Openshift AI+210/6/20269/9/2026
JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal assign() helper copies properties with for...in + plain assignment. When the source object is produced by JSON.parse, the JSON object's "__proto__" member is an own enumerable property, so the for…in…
AplazadaMedia (6.4)0.15%—Animation Addons FOR ElementorAI10/6/202623/7/2026
The Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the multiple parameters in all versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible…
AplazadaCrítica (9.8)0.47%—Mosk Information Technologies LTD CBS PlatformAI9/6/202623/7/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in MOSK Information Technologies Ltd. CBS Platform allows SQL Injection. This issue affects CBS Platform: through 09062026. NOTE: The vendor was contacted and it was learned that the product is not supported.
AplazadaMedia (5.5)0.28%—Sourcecodester Barangay Resident Profiling AND Information Management SystemAI8/6/202623/7/2026
A vulnerability has been found in SourceCodester Barangay Resident Profiling and Information Management System 1.0. The impacted element is an unknown function of the file passsword_reset.php of the component Password Reset Handler. Such manipulation of the argument new_password with the input password123 leads to use…
AplazadaCrítica (9.8)0.50%—Akmer Informatics Automation Industry AND Trade TeknopassAI4/6/202622/7/2026
Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Automation Industry and Trade Ltd. Co. TeknoPass allows SQL Injection. This issue affects TeknoPass: from 20210501 through 20260429.
AplazadaAlta (7.8)1.2%—SysteminformationAI27/5/202628/8/2026
systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation is vulnerable to command injection in networkInterfaces() when an active NetworkManager connection profile name contains shell metacharacters. The vulnerable value is obtained internally from real…
AnalizadaMedia (4.3)0.22%—IBM Business Automation Workflow27/5/202617/6/2026
IBM Business Automation Workflow containers and traditional may leak information about its database structure in error messages.