Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

1833 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (5)0.21%—SAP Solution Tools Plug-inAI10/3/202617/6/2026
SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks for authenticated users, allowing system information to be disclosed. This vulnerability has a low impact on confidentiality and does not affect integrity or availability.
AnalizadaMedia (6.8)0.69%—Psd-tools Project Psd-tools26/2/202617/6/2026
psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.12.2, when a PSD file contains malformed RLE-compressed image data (e.g. a literal run that extends past the expected row size), decode_rle() raises ValueError which propagated all the way to the user, crashing psd.composite()…
AnalizadaMedia (6.5)0.14%—Fofolee Utools-quickcommand23/2/202617/6/2026
An issue pertaining to CWE-295: Improper Certificate Validation was discovered in fofolee uTools-quickcommand 5.0.3.
AplazadaAlta (7.2)0.38%—Smartertools SmartermailAI16/2/202617/6/2026
SmarterTools SmarterMail before 9526 allows XSS via MAPI requests.
AplazadaMedia (6.4)0.16%—Citations ToolsAI14/2/202617/6/2026
The Citations tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'code' parameter in the 'ctdoi' shortcode in all versions up to, and including, 0.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…
AplazadaMedia (4.9)0.37%—BFG Tools Extension ZipperAI14/2/202617/6/2026
The BFG Tools – Extension Zipper plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.7. This is due to insufficient input validation on the user-supplied `first_file` parameter in the `zip()` function. This makes it possible for authenticated attackers, with…
AplazadaMedia (6.7)0.32%—Inettools FOR IOSAI12/2/202617/6/2026
iNetTools for iOS 8.20 contains a denial of service vulnerability in the Whois feature that allows attackers to crash the application by manipulating input. Attackers can paste a specially crafted 98-character buffer into the Domain Name field to trigger an application crash.
AplazadaCrítica (9.2)0.29%—Element Server Suite Community EditionAIMatrix-toolsAIElement ESS Community Helm ChartAI12/2/202617/6/2026
Element Server Suite Community Edition (ESS Community) deploys a Matrix stack using the provided Helm charts and Kubernetes distribution. The ESS Community Helm Chart secrets initialization hook (using matrix-tools container before 0.5.7) is using an insecure Matrix server key generation method, allowing network…
AnalizadaAlta (7.7)0.22%—SAP Solution Tools Plug-in10/2/202617/6/2026
SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks for authenticated users, allowing sensitive information to be disclosed. This vulnerability has a high impact on confidentiality and does not affect integrity or availability.
AnalizadaMedia (4.3)0.18%—SAP Solution Tools Plug-in10/2/202617/6/2026
Due to missing authorization check in a function module in SAP Support Tools Plug-In, an authenticated attacker could invoke specific function modules to retrieve information about the system and its configuration. This disclosure of the system information could assist the attacker to plan subsequent attacks. This…
AnalizadaMedia (4.3)0.18%—SAP Solution Tools Plug-in10/2/202617/6/2026
In ABAP based SAP systems a remote enabled function module does not perform necessary authorization checks for an authenticated user resulting in disclosure of system information.This has low impact on confidentiality. Integrity and availability are not impacted.
AnalizadaAlta (7.8)0.20%—Tanium Endpoint Configuration Toolset SolutionTanium Patch Endpoint Tools10/2/202617/6/2026
Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.
AnalizadaAlta (7.8)0.20%—Tanium Patch Endpoint Tools9/2/202617/6/2026
Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.
AnalizadaAlta (7.1)0.18%—Yokogawa Fast/tools9/2/202617/6/2026
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product supports old SSL/TLS versions, potentially allowing an attacker to decrypt communications with the web server. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES,…
AnalizadaAlta (8.8)0.19%—Yokogawa Fast/tools9/2/202617/6/2026
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product supports weak cryptographic algorithms, potentially allowing an attacker to decrypt communications with the web server. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB,…
AnalizadaMedia (6.9)0.18%—Yokogawa Fast/tools9/2/202617/6/2026
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly validate request headers. When an attacker inserts an invalid host header, users could be redirected to malicious sites. The affected products and versions are as follows: FAST/TOOLS (Packages:…
AnalizadaMedia (6.3)0.11%—Yokogawa Fast/tools9/2/202617/6/2026
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product is vulnerable to Cross-Site Request Forgery (CSRF). When a user accesses a link crafted by an attacker, the user’s account could be compromised. The affected products and versions are as follows: FAST/TOOLS (Packages:…
AnalizadaMedia (6.9)0.24%—Yokogawa Fast/tools9/2/202617/6/2026
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. Detailed messages are displayed on the error page. This information could be exploited by an attacker for other attacks. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES,…
AnalizadaAlta (8.7)0.45%—Yokogawa Fast/tools9/2/202617/6/2026
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly validate URLs. An attacker could send specially crafted requests to steal files from the web server. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB,…
AnalizadaMedia (6.3)0.20%—Yokogawa Fast/tools9/2/202617/6/2026
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The response header contains an insecure setting. Users could be redirected to malicious sites by an attacker. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to…
AnalizadaBaja (2.1)0.26%—Yokogawa Fast/tools9/2/202617/6/2026
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly encode URLs. An attacker could tamper with web pages or execute malicious scripts. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01…
AnalizadaBaja (2.1)0.20%—Yokogawa Fast/tools9/2/202617/6/2026
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. Since there are input fields on this webpage with the autocomplete attribute enabled, the input content could be saved in the browser the user is using. The affected products and versions are as follows: FAST/TOOLS (Packages:…
AnalizadaBaja (2.1)0.14%—Yokogawa Fast/tools9/2/202617/6/2026
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The library version could be displayed on the web page. This information could be exploited by an attacker for other attacks. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES,…
AnalizadaBaja (2.1)0.30%—Yokogawa Fast/tools9/2/202617/6/2026
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The web server accepts the OPTIONS method. An attacker could potentially use this information to carry out other attacks. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES,…
AnalizadaMedia (6.9)0.35%—Yokogawa Fast/tools9/2/202617/6/2026
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The web server accepts access by IP address. When a worm that randomly searches for IP addresses intrudes into the network, it could potentially be attacked by the worm. The affected products and versions are as follows: FAST/TOOLS…
Orbitaley — Vulnerabilidades