Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

1917 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.10%—IBM Qradar Security Information AND Event Manager19/3/202617/6/2026
IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 stores potentially sensitive information in configuration files that could be read by a local user.
AnalizadaMedia (5.4)0.14%—IBM Qradar Security Information AND Event Manager19/3/202617/6/2026
IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality.
AnalizadaMedia (5)0.18%—IBM Qradar Security Information AND Event Manager19/3/202617/6/2026
IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 could allow an attacker with access to one tenant to access hostname data from another tenant's account.
AnalizadaAlta (7.5)0.32%—IBM Infosphere Information Server3/3/202617/6/2026
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 An XML External Entity (XXE) vulnerability in IBM InfoSphere Information Server could allow attackers to retrieve sensitive information from the server.
AnalizadaMedia (5.3)0.20%—IBM Infosphere Information Server3/3/202617/6/2026
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to writing of sensitive Information in a log file.
AplazadaAlta (8.4)0.44%—Informatik.hu-berlin FlairAI26/2/202617/6/2026
Deserialization of untrusted data in the LanguageModel class of Flair from versions 0.4.1 to latest are vulnerable to arbitrary code execution when loading a malicious model.
AnalizadaMedia (5.3)0.38%💥 PoCFormalms19/2/202617/6/2026
A user enumeration vulnerability exists in FormaLMS 4.1.18 and below in the password recovery functionality accessible via the /lostpwd endpoint. The application returns different error messages for valid and invalid usernames allowing an unauthenticated attacker to determine which usernames are registered in the…
ModificadaAlta (8.8)1.3%—Systeminformation19/2/202615/7/2026
systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` output in `versions()`. Version 5.31.0 fixes the issue.
ModificadaAlta (7.8)1.5%—Systeminformation19/2/202615/7/2026
systeminformation is a System and OS information library for node.js. In versions prior to 5.30.8, a command injection vulnerability in the `wifiNetworks()` function allows an attacker to execute arbitrary OS commands via an unsanitized network interface parameter in the retry code path. In `lib/wifi.js`, the…
AplazadaAlta (7.3)0.22%—Mecode Informatics AND Engineering Services LTD EnvantyAI19/2/202617/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in MeCODE Informatics and Engineering Services Ltd. Envanty allows Parameter Injection. This issue affects Envanty: before 1.0.6. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. The vulnerability was learned to be…
AplazadaMedia (6.5)0.32%—EKA Software Computer Information Advertising Services LTD Real Estate ScriptAI17/2/202617/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EKA Software Computer Information Advertising Services Ltd. Real Estate Script V5 (With Doping Module – Store Module – New Language System) allows Cross-Site Scripting (XSS). This issue affects Real Estate…
AplazadaCrítica (9.8)0.41%—NTN Information Processing Services Computer Software Hardware Industry AND Trade Smart PanelAI12/2/202617/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in NTN Information Processing Services Computer Software Hardware Industry and Trade Ltd. Co. Smart Panel allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Smart Panel: before 20251215.
AplazadaAlta (8.3)0.12%—PAN Software & Information Technologies LTD Pancafe PROAI11/2/202617/6/2026
Cleartext Transmission of Sensitive Information vulnerability in Pan Software & Information Technologies Ltd. PanCafe Pro allows Flooding. This issue affects PanCafe Pro: from < 3.3.2 through 23092025.
AplazadaAlta (8.8)0.43%—Birtech Information Technologies Industry AND Trade SensawayAI9/2/202617/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Sensaway allows Upload a Web Shell to a Web Server. This issue affects Sensaway: through 09022026. NOTE: Because the product was developed using outdated technology, the manufacturer is unable…
AplazadaMedia (6.5)0.28%—Birtech Information Technologies Industry AND Trade SensewayAI9/2/202617/6/2026
Insecure Storage of Sensitive Information vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Senseway allows Retrieve Embedded Sensitive Data. This issue affects Senseway: through 09022026. NOTE: Because the product was developed using outdated technology, the manufacturer is unable to fix…
AplazadaCrítica (9.8)0.47%—Xpoda Turkiye Information Technology INC Password ModuleAI9/2/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpoda Türkiye Information Technology Inc. Password Module allows SQL Injection. This issue affects Password Module: through 11022026.
AplazadaAlta (7.3)0.33%—Birtech Information Technologies Industry AND Trade SensewayAI9/2/202617/6/2026
Improper Authentication vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Senseway allows Authentication Abuse. This issue affects Senseway: through 09022026. NOTE: Because the product was developed using outdated technology, the manufacturer is unable to fix the relevant vulnerabilities.…
AplazadaAlta (8.6)0.33%—Zirve Information Technologies INC E-taxpayer Accounting WebsiteAI9/2/202617/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zirve Information Technologies Inc. E-Taxpayer Accounting Website allows Reflected XSS. This issue affects e-Taxpayer Accounting Website: through 07082025.
AnalizadaMedia (6.5)0.35%—Tanium Performance5/2/202617/6/2026
Tanium addressed an incorrect default permissions vulnerability in Performance.
AplazadaCrítica (9.8)0.47%💥 PoCEmit Informatics AND Communication Technologies Digita Efficiency Management SystemAI3/2/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Emit Informatics and Communication Technologies Industry and Trade Ltd. Co. DIGITA Efficiency Management System allows SQL Injection. This issue affects DIGITA Efficiency Management System: through 03022026. NOTE: The…
AplazadaMedia (5.1)0.20%—Sistem Informasi Pengumuman Kelulusan OnlineAI30/1/202617/6/2026
Sistem Informasi Pengumuman Kelulusan Online 1.0 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized admin users through the tambahuser.php endpoint. Attackers can craft a malicious HTML form to submit admin credentials and create new administrative accounts without the…
AplazadaMedia (5.1)0.29%—Forma LMSAI30/1/202617/6/2026
Forma.lms The E-Learning Suite 2.3.0.2 contains a persistent cross-site scripting vulnerability in multiple course and profile parameters. Attackers can inject malicious scripts in course code, name, description fields, and email parameter to execute arbitrary JavaScript without proper input sanitization.
AplazadaMedia (5.1)0.23%—Forma LMSAI26/1/202617/6/2026
Forma LMS 2.3 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts into user profile first and last name fields. Attackers can craft scripts like '<script>alert(document.cookie)</script>' to execute arbitrary JavaScript when the profile is viewed by other users.
AplazadaMedia (6.8)0.14%—Lenovo VantageAILenovo SmartperformanceaddinAI14/1/202617/6/2026
An improper link following vulnerability was reported in the SmartPerformanceAddin for Lenovo Vantage that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges.
AplazadaCrítica (9.1)0.51%—SAP Landscape TransformationAI13/1/202617/6/2026
SAP Landscape Transformation allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code/OS commands into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor,…