Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2774▲ 9 respecto a la semana anterior
Críticas / altas1289▼ 242 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
2202 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.17% | — | IBM Planning Analytics Local | 13/8/2026 | 17/8/2026 | IBM Planning Analytics 2.0, and 2.1 Local is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. | |
| Aplazada | Alta (8.5) | 0.36% | — | Visitor Traffic Real Time Statistics PROAI | 13/8/2026 | 14/8/2026 | Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Visitor Traffic Real Time Statistics PROAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Visitors Traffic Real Time StatisticsAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Visitors Traffic Real Time Statistics <= 8.11 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Arraytics BookticsAI | 13/8/2026 | 14/8/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arraytics Booktics allows Blind SQL Injection. This issue affects Booktics: from n/a through 1.0.22. | |
| Aplazada | Crítica (10) | 0.86% | — | Quarka QA AnalyticsAI | 13/8/2026 | 14/8/2026 | Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions. | |
| Pendiente de análisis | Alta (8.6) | 0.52% | — | Opensearch Security AnalyticsAI | 12/8/2026 | 21/8/2026 | Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter to the threat intel source configuration endpoint. | |
| Aplazada | Media (6.5) | 0.37% | — | Wp-statistics WP StatisticsAI | 8/8/2026 | 26/8/2026 | The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics AJAX handlers, relying only on a nonce that every authenticated user holds, allowing users with Subscriber-level access and above to disclose the site's visitor analytics data. | |
| Pendiente de análisis | Media (6.5) | 0.44% | — | Datadog Android ApplicationAIGoogle Firebase CrashlyticsAI | 7/8/2026 | 3/9/2026 | In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datadog UUID, with no user-facing opt-out. Impact: The Datadog user UUID and crash data are visible within Firebase Crashlytics. This UUID is not identifying outside Datadog's own systems. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Loca Software Informatics Technology LTD CMSAI | 6/8/2026 | 26/8/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. CMS allows SQL Injection. This issue affects CMS: through 06082026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Aplazada | Alta (7.2) | 0.40% | — | Independent AnalyticsAI | 5/8/2026 | 12/8/2026 | The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 404 not_found_url tracking parameter in versions up to, and including, 2.15.0. This is due to the get_cell_content() function applying urldecode() after esc_url() when rendering the URL column for 404 entries — a… | |
| Aplazada | Alta (8.1) | 0.27% | — | Search Analytics FOR WPAI | 5/8/2026 | 12/8/2026 | The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.16. This is due to missing or incorrect nonce validation on the `process_bulk_action()` function of `MWTSA_Stats_Table`. This makes it possible for unauthenticated attackers to delete… | |
| Analizada | Alta (7.6) | 0.15% | — | Qualcomm Sm6225p FirmwareQualcomm Sm6450p FirmwareQualcomm Sm6475p FirmwareQualcomm Sm6475q Firmware+207 | 4/8/2026 | 6/8/2026 | Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration. | |
| Analizada | Alta (8.1) | 0.21% | — | Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+139 | 4/8/2026 | 6/8/2026 | Cryptographic Issue while processing registration requests with malformed or missing authentication parameters. | |
| Analizada | Media (6.5) | 0.17% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+143 | 4/8/2026 | 6/8/2026 | Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling. | |
| Analizada | Media (6.5) | 0.17% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+140 | 4/8/2026 | 6/8/2026 | Information Disclosure when processing wireless network channel switch information with improperly formatted length fields. | |
| Aplazada | Crítica (9.8) | 0.29% | — | Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI | 4/8/2026 | 26/8/2026 | Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. | |
| Aplazada | Alta (7.4) | 0.34% | — | Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI | 4/8/2026 | 26/8/2026 | Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Session Hijacking. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. | |
| Aplazada | Crítica (9.1) | 0.40% | — | Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI | 4/8/2026 | 26/8/2026 | Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. | |
| Aplazada | Media (6.5) | 0.35% | — | Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI | 4/8/2026 | 26/8/2026 | Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Reusing Session IDs (aka Session Replay). This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. | |
| Aplazada | Media (5.4) | 0.21% | — | Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI | 4/8/2026 | 26/8/2026 | URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Phishing. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. | |
| Aplazada | Media (5.3) | 0.33% | — | Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI | 4/8/2026 | 26/8/2026 | Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Account Footprinting. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. | |
| Aplazada | Media (6.5) | 0.44% | — | Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI | 4/8/2026 | 26/8/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Path Traversal. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. | |
| Aplazada | Media (5.4) | 0.23% | — | Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI | 4/8/2026 | 26/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Stored XSS. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. | |
| Aplazada | Crítica (9.8) | 0.52% | — | Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI | 4/8/2026 | 26/8/2026 | Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. |