Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3089▲ 499 respecto a la semana anterior
Críticas / altas1463▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

22.764 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI20/7/202620/7/2026
A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /prescriptionorderreport.php. Such manipulation of the argument delid leads to sql injection. The attack may be launched remotely. The exploit has been…
AnalizadaMedia (6.1)0.25%—Wso2 API Control PlaneWso2 API ManagerWso2 Identity Server20/7/202619/8/2026
The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encoding before rendering it within the response. This condition allows for the injection of malicious JavaScript payloads. An attacker can leverage this vulnerability to cause the user's browser to…
AplazadaBaja (2.1)0.47%—Itsourcecode Courier Management SystemAI19/7/202621/7/2026
A flaw has been found in itsourcecode Courier Management System up to 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php. Executing a manipulation of the argument page can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and…
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI18/7/202621/7/2026
A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /prescriptionrecord.php. This manipulation of the argument delid causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could…
AnalizadaAlta (7.5)0.55%—IBM Engineering Lifecycle Management17/7/202611/8/2026
IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ) Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 DOORS could allow a remote attacker to cause a denial of service due to improper handling of XML entity expansion.
AplazadaCrítica (9.8)0.47%—GIS Informatics Engineering Consulting Laboratory Gislab Laboratory Management SystemAI17/7/202617/7/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management System allows SQL Injection. This issue affects GisLab Laboratory Management System: from 1.4.03 through…
AplazadaMedia (6.5)0.36%—GIS Informatics Engineering Consulting Laboratory RND AND Software Services Gislab Laboratory Management SystemAI17/7/202617/7/2026
Authorization bypass through User-Controlled key vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management System allows Exploitation of Trusted Identifiers. This issue affects GisLab Laboratory Management System: from 1.4.03 through 08072026.
AplazadaAlta (7.2)0.39%—Proxmox Virtual EnvironmentAIProxmox Pve-managerAIProxmox Qemu-serverAIProxmox Pve-containerAI17/7/202617/7/2026
A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment (PVE) 9.x pve-manager before 9.1.9 and 8.x before 8.4.19; qemu-server 9.x before 9.1.7 and 8.x before 8.4.7; and pve-container before 6.1.3 (PVE 9.x) and before 5.3.4 (PVE 8.x) allows an attacker with privileges to call…
AplazadaMedia (5.5)0.43%—Code-projects Hospital BED Management SystemAI17/7/202621/7/2026
A vulnerability was found in code-projects Hospital Bed Management System 1.0. This affects an unknown part of the component Login Form. Performing a manipulation of the argument Username results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
AnalizadaAlta (8.1)0.42%💥 PoCAhnlab EPP Management17/7/20265/10/2026
AhnLab EPP Management v1.0.14.32-6249 se descubrió que contenía una vulnerabilidad de inyección NoSQL a través del endpoint eventlog/agentEvent/list.
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI17/7/202617/7/2026
A vulnerability was detected in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /prescriptionorderdetail.php. The manipulation of the argument delid results in sql injection. The attack can be launched remotely. The exploit is now public and may be used.
AnalizadaAlta (7.3)0.11%—Linuxfoundation Cert-manager16/7/202630/7/2026
cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the process of obtaining, renewing and using those certificates. From 1.18.0 until 1.19.6 and 1.20.3, Challenge resources under acme.cert-manager.io can be created directly by namespace users without…
AplazadaMedia (5.3)0.26%—Perfect Support Ticketing & Document Management SystemAI16/7/202616/7/2026
Perfect Support Ticketing & Document Management System through 1.7 contains a broken access control vulnerability that allows authenticated attackers with Agent-level privileges to manipulate the Support Agent assignment field of tickets by bypassing intended authorization checks. Attackers can add or remove any user,…
AplazadaMedia (5.1)0.24%—Perfect Support Ticketing AND Document Management SystemAI16/7/202618/7/2026
Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scripting vulnerability that allows authenticated attackers with Agent-level privileges to inject malicious payloads into the Notes field of assigned support tickets. Attackers can store malicious scripts that execute in…
AplazadaMedia (6.1)0.38%—Webappick Product Feed Manager FOR WoocommerceAI16/7/202616/7/2026
The Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 's' Search Parameter in all versions up to, and including, 7.6.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
Pendiente de análisisBaja (2.1)0.34%—NodejsAIOpenjsf Node Version ManagerAI15/7/202616/7/2026
Node Version Manager (nvm) is a POSIX-compliant shell function for managing multiple node.js versions. In versions 0.32.1 through 0.40.5, `nvm ls-remote` (and other commands that refresh remote LTS aliases, such as `nvm install --lts`) parse the node.js mirror's `index.tab` and use each release's LTS codename field as…
AnalizadaAlta (8.8)0.53%—F5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance ManagerF5 Nginx Open Source+215/7/202611/8/2026
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process,…
AnalizadaMedia (5.3)0.30%—F5 Nginx AgentF5 Nginx Instance Manager15/7/20266/8/2026
The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files outside of the designated secure directory. The config_dirs directive required for this issue can also be configured through NGINX Instance Manager. A successful exploit may allow an attacker to cross…
AplazadaMedia (5.6)0.14%—Asus System Control Interface V3AIAsus System Control InterfaceAIAsus Business ManagerAI15/7/202617/9/2026
Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read memory regions beyond the intended firmware boundary by supplying a crafted IOCTL request that bypasses the validation. Refer to the ' Security Update for ASUS System…
AplazadaAlta (8.4)0.17%—Asus System Control Interface V3AIAsus System Control InterfaceAIAsus Business ManagerAI15/7/202617/9/2026
Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL requests to the driver, bypassing OS-enforced memory protections. Refer to the '…
AplazadaAlta (8.2)0.16%💥 PoCAsus System Control InterfaceAIAsus Business ManagerAI15/7/202617/9/2026
Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive information via crafted IOCTL requests, which, in severe cases, may lead to a…
Pendiente de análisisCrítica (9.8)0.66%—Ciena Navigator Network Control SuiteAICiena Manage Control PlanAICiena Blue PlanetAI14/7/202615/7/2026
An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue Planet products. The issue is caused by improper handling of HTTP request paths and headers, which allows an unauthenticated attacker to manipulate requests in a manner…
Pendiente de análisisCrítica (9.8)0.48%—Ciena Navigator Network Control SuiteAICiena Manage Control PlanAI14/7/202615/7/2026
In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used for internal software operations. Some of these accounts have default passwords that may be predictable. While these accounts have very limited permissions on their own, an attacker could combine an…
AplazadaCrítica (9.8)1.1%—Openasset Digital Asset ManagementAI14/7/202615/7/2026
An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote attacker to execute arbitrary code via the name and description parameter of the Add/Update Project function
AnalizadaCrítica (9.6)1.0%—Adobe Experience Manager14/7/202628/8/2026
Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to read sensitive files, potentially gaining elevated…