Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3142▲ 563 respecto a la semana anterior
Críticas / altas1455▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
22.765 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.6) | 0.11% | — | BMC Control-m Enterprise ManagerAI | 1/7/2026 | 1/7/2026 | The Control-M/Enterprise Manager uses weak protections for stored hashes of account passwords, potentially allowing offline password recovery attacks if credential data is obtained by an attacker. This vulnerability affects Control-M/Enterprise Manager unsupported versions 9.0.20.x and potentially earlier unsupported… | |
| Pendiente de análisis | Alta (8.9) | 0.42% | — | BMC Control-m ServerAIBMC Control-m Enterprise ManagerAI | 1/7/2026 | 1/7/2026 | Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowed object types in the out of support Control-M/Server and Control-M/Enterprise Manager versions 9.0.20.x and potentially earlier. This issue may allow an authenticated attacker to trigger unintended… | |
| Analizada | Crítica (9.1) | 0.41% | — | IBM Business Automation Manager | 30/6/2026 | 2/7/2026 | IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | |
| Aplazada | Crítica (9.3) | 0.63% | — | Advantech Hospital Queuing ManagementAI | 30/6/2026 | 30/6/2026 | Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a specific URL to obtain API documentation. | |
| Aplazada | Alta (8.7) | 0.55% | — | Advantech Hospital Queuing ManagementAI | 30/6/2026 | 30/6/2026 | Hospital Quening Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a specific URL to obtain API documentation. | |
| Aplazada | Crítica (9.1) | 0.66% | 💥 PoC | Alexantr FilemanagerAI | 29/6/2026 | 30/6/2026 | An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the filemanager.php component | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Hospital Management SystemAI | 29/6/2026 | 29/6/2026 | A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /patientchangepassword.php. Executing a manipulation of the argument newpassword can lead to sql injection. The attack may be launched remotely. The exploit has been made… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Hospital Management SystemAI | 29/6/2026 | 29/6/2026 | A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /patientdetail.php. Performing a manipulation of the argument editid results in sql injection. The attack may be initiated remotely. The exploit has been released… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Hospital Management SystemAI | 29/6/2026 | 30/6/2026 | A vulnerability has been found in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /insertbillingrecord.php. The manipulation of the argument patientid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Aplazada | Baja (2) | 0.33% | — | Sourcecodester Inventory Management SystemAI | 29/6/2026 | 29/6/2026 | A vulnerability was detected in SourceCodester Inventory Management System 1.0. Impacted is an unknown function of the file /api/users_handler.php of the component User Registration Endpoint. Performing a manipulation of the argument full_name results in cross site scripting. The attack is possible to be carried out… | |
| Aplazada | Media (5.5) | 0.47% | — | Sourcecodester Inventory Management SystemAI | 29/6/2026 | 1/7/2026 | A weakness has been identified in SourceCodester Inventory Management System 1.0. This vulnerability affects unknown code of the file /api/users_handler.php of the component User Registration Endpoint. This manipulation of the argument role causes improper access controls. Remote exploitation of the attack is… | |
| Aplazada | Baja (2) | 0.35% | — | Codeagstro Complaint Management SystemAI | 29/6/2026 | 29/6/2026 | A security flaw has been discovered in CodeAstro Complaint Management System 1.0. This issue affects some unknown processing of the file /report/addreport of the component Report Handler. Performing a manipulation of the argument Report Title results in cross site scripting. Remote exploitation of the attack is… | |
| Aplazada | Baja (2.1) | 0.47% | — | Itsourcecode Online Hotel Management SystemAI | 29/6/2026 | 29/6/2026 | A vulnerability was identified in itsourcecode Online Hotel Management System 1.0. This vulnerability affects unknown code of the file /admin/mod_room/controller.php?action=add of the component POST Request Handler. Such manipulation of the argument Name leads to cross site scripting. The attack may be launched… | |
| Aplazada | Baja (2.1) | 0.47% | — | Itsourcecode Online Hotel Management SystemAI | 29/6/2026 | 1/7/2026 | A vulnerability was determined in itsourcecode Online Hotel Management System 1.0. This affects an unknown part of the file /admin/mod_users/controller.php?action=edit of the component POST Request Handler. This manipulation of the argument Name causes cross site scripting. The attack may be initiated remotely. The… | |
| Aplazada | Media (5.5) | 0.43% | — | Itsourcecode Online Hotel Management SystemAI | 29/6/2026 | 29/6/2026 | A vulnerability was found in itsourcecode Online Hotel Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/mod_users/controller.php?action=add. The manipulation of the argument Name results in sql injection. The attack can be launched remotely. The exploit has been made… | |
| Aplazada | Baja (2.1) | 0.47% | — | Itsourcecode Online Hotel Management SystemAI | 29/6/2026 | 30/6/2026 | A vulnerability has been found in itsourcecode Online Hotel Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/mod_amenities/controller.php?action=add of the component POST Request Handler. The manipulation of the argument Name leads to cross site scripting. The attack… | |
| Aplazada | Media (5.5) | 0.50% | — | Itsourcecode Online Hotel Management SystemAI | 29/6/2026 | 29/6/2026 | A flaw has been found in itsourcecode Online Hotel Management System 1.0. Affected is an unknown function of the file /admin/mod_amenities/controller.php?action=add. Executing a manipulation of the argument image can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.43% | — | Itsourcecode Online Hotel Management SystemAI | 29/6/2026 | 29/6/2026 | A vulnerability was detected in itsourcecode Online Hotel Management System 1.0. This impacts an unknown function of the file /admin/mod_amenities/controller.php?action=edit. Performing a manipulation of the argument amen_id results in sql injection. It is possible to initiate the attack remotely. The exploit is now… | |
| Aplazada | Media (5.5) | 0.43% | — | Itsourcecode Baptism Information Management SystemAI | 29/6/2026 | 29/6/2026 | A security vulnerability has been detected in itsourcecode Baptism Information Management System 1.0. This affects an unknown function of the file /editBaptism.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be… | |
| Aplazada | Media (5.5) | 0.43% | — | Itsourcecode Baptism Information Management SystemAI | 29/6/2026 | 29/6/2026 | A weakness has been identified in itsourcecode Baptism Information Management System 1.0. The impacted element is an unknown function of the file /delbaptism.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the… | |
| Aplazada | Baja (2.1) | 0.51% | — | Coderastro Complaint Management SystemAI | 29/6/2026 | 29/6/2026 | A security flaw has been discovered in CodeAstro Complaint Management System 1.0. The affected element is the function deletereport of the file application/controllers/Report.php of the component Report Endpoint. The manipulation results in authorization bypass. The attack can be executed remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Hospital Management SystemAI | 29/6/2026 | 30/6/2026 | A vulnerability was identified in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /doctortimings.php. The manipulation of the argument editid leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. | |
| Aplazada | Media (5.5) | 0.47% | — | Hanwang E-face General Management PlatformAI | 29/6/2026 | 29/6/2026 | A vulnerability was determined in Hanwang e-Face General Management Platform 6.3.5.4. This issue affects some unknown processing of the file /manage/resourceUpload/upload.do. Executing a manipulation of the argument File can lead to unrestricted upload. The attack may be launched remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Hospital Management SystemAI | 29/6/2026 | 30/6/2026 | A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /doctorprofile.php. The manipulation of the argument doctorname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Hospital Management SystemAI | 29/6/2026 | 29/6/2026 | A weakness has been identified in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /doctorchangepassword.php. Executing a manipulation of the argument newpassword can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the… |