Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1917 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.8) | 0.51% | 💥 PoC | Openmicroscopy Bio-formats | 7/1/2026 | 17/6/2026 | Bio-Formats versions up to and including 8.3.0 perform unsafe Java deserialization of attacker-controlled memoization cache files (.bfmemo) during image processing. The loci.formats.Memoizer class automatically loads and deserializes memo files associated with images without validation, integrity checks, or trust… | |
| Modificada | Media (4.6) | 0.17% | — | Openmicroscopy Bio-formats | 7/1/2026 | 17/6/2026 | Bio-Formats versions up to and including 8.3.0 contain an XML External Entity (XXE) vulnerability in the Leica Microsystems metadata parsing component (e.g., XLEF). The parser uses an insecurely configured DocumentBuilderFactory when processing Leica XML-based metadata files, allowing external entity expansion and… | |
| Analizada | Media (6.5) | 0.43% | — | Apache Spatial Information System | 5/1/2026 | 7/10/2026 | Improper Restriction of XML External Entity Reference vulnerability in Apache SIS. It is possible to write XML files in such a way that, when parsed by Apache SIS, an XML file reveals to the attacker the content of a local file on the server running Apache SIS. This vulnerability impacts the following SIS services:… | |
| Aplazada | Media (5.1) | 0.24% | — | Netvision Information IsoinsightAI | 30/12/2025 | 7/10/2026 | ISOinsight developed by NetVision Information has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks. | |
| Aplazada | Alta (8.6) | 0.05% | — | Kings Information & Network Kess EnterpriseAI | 29/12/2025 | 7/10/2026 | Exposure of Sensitive Information to an Unauthorized Actor, Missing Encryption of Sensitive Data, Files or Directories Accessible to External Parties vulnerability in Kings Information & Network Co. KESS Enterprise on Windows allows Privilege Escalation, Modify Existing Service, Modify Shared File.This issue affects… | |
| Analizada | Media (5.5) | 0.18% | — | Terrainformatica Sciter | 26/12/2025 | 17/6/2026 | An issue in Terra Informatica Software, Inc Sciter v.4.4.7.0 allows a local attacker to obtain sensitive information via the adopt component of the Sciter video rendering function. | |
| Aplazada | Alta (7.6) | 0.33% | — | Verisay Communication AND Information Technology Industry AND Trade TrizbiAI | 25/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Communication and Information Technology Industry and Trade Ltd. Co. Trizbi allows Cross-Site Scripting (XSS). This issue affects Trizbi: before 2.144.4. | |
| Aplazada | Alta (7.6) | 0.31% | — | Verisay Communication AND Information Technology Industry AND Trade TitarusAI | 25/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Communication and Information Technology Industry and Trade Ltd. Co. Titarus allows Cross-Site Scripting (XSS). This issue affects Titarus: before 2.144.4. | |
| Aplazada | Alta (7.6) | 0.31% | — | Verisay Communication AND Information Technology Industry AND Trade LTD CO AidangoAI | 25/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Communication and Information Technology Industry and Trade Ltd. Co. Aidango allows Cross-Site Scripting (XSS). This issue affects Aidango: before 2.144.4. | |
| Analizada | Media (5.5) | 0.38% | — | Fabian Student Information System | 24/12/2025 | 17/6/2026 | A flaw has been found in code-projects Student Information System 1.0. This issue affects some unknown processing of the file /searchresults.php. Executing manipulation of the argument searchbox can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. | |
| Analizada | Baja (2) | 0.26% | — | Fabian Student Information System | 24/12/2025 | 17/6/2026 | A vulnerability was detected in code-projects Student Information System 1.0. This vulnerability affects unknown code of the file /profile.php. Performing manipulation of the argument firstname/lastname results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and… | |
| Aplazada | Media (6.3) | 0.21% | — | Proliz Software LTD OBS Student Affairs Information SystemAI | 17/12/2025 | 28/9/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Software Ltd. OBS (Student Affairs Information System)0 allows Reflected XSS. This issue affects OBS (Student Affairs Information System)0: before 26.5009. | |
| Analizada | Alta (8.1) | 13% | — | Systeminformation | 16/12/2025 | 30/9/2026 | systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` function in systeminformation is vulnerable to OS command injection on Windows systems. The optional `drive` parameter is directly concatenated into a PowerShell command without sanitization, allowing… | |
| Aplazada | Alta (7.6) | 0.25% | — | Netiket Information Technologies ApplylogicAI | 11/12/2025 | 7/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Netiket Information Technologies Ltd. Co. ApplyLogic allows Exploitation of Trusted Identifiers. This issue affects ApplyLogic: through 01.12.2025. | |
| Aplazada | Media (4.3) | 0.22% | — | IM Park Information Technology Electronics Press Publishing AND Advertising Education LTD CO DijidemiAI | 10/12/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Im Park Information Technology, Electronics, Press, Publishing and Advertising, Education Ltd. Co. DijiDemi allows Exploitation of Trusted Identifiers. This issue affects DijiDemi: through 28.11.2025. | |
| Aplazada | Baja (3.5) | 0.20% | — | TAC Information Services Internal AND External Trade INC GoldenhornAI | 10/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TAC Information Services Internal and External Trade Inc. GoldenHorn allows Cross-Site Scripting (XSS). This issue affects GoldenHorn: before 4.25.1121.1. | |
| Aplazada | Crítica (9.3) | 0.57% | — | GTT TAX Information SystemAI | 10/12/2025 | 17/6/2026 | Bypass vulnerability in the authentication method in the GTT Tax Information System application, related to the Active Directory (LDAP) login method. Authentication is performed through a local WebSocket, but the web application does not properly validate the authenticity or origin of the data received, allowing an… | |
| Aplazada | Alta (7.1) | 0.21% | — | Nomysoft Information Technology Training AND Consulting INC NomysemAI | 10/12/2025 | 17/6/2026 | Incorrect Use of Privileged APIs vulnerability in NomySoft Information Technology Training and Consulting Inc. Nomysem allows Privilege Escalation. This issue affects Nomysem: through May 2025. | |
| Analizada | Baja (2.7) | 0.29% | — | IBM Qradar Security Information AND Event Manager | 9/12/2025 | 1/10/2026 | IBM QRadar SIEM 7.5 - 7.5.0 UP14 IF01 is affected by an information disclosure vulnerability involving exposure of directory information. IBM has addressed this vulnerability in the latest update. | |
| Analizada | Media (4.3) | 0.16% | — | IBM Infosphere Information Server | 8/12/2025 | 7/10/2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Analizada | Baja (1.9) | 0.34% | — | Rareprob HD Video Player ALL Formats | 2/12/2025 | 17/6/2026 | A security vulnerability has been detected in Rareprob HD Video Player All Formats App 12.1.372 on Android. Impacted is an unknown function of the component com.rocks.music.videoplayer. The manipulation leads to path traversal. The attack needs to be performed locally. The exploit has been disclosed publicly and may… | |
| Analizada | Baja (2.1) | 0.31% | — | Facebook-julykringcadayona Student Information System | 24/11/2025 | 17/6/2026 | A vulnerability was identified in itsourcecode Student Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /schedule_edit1.php. Such manipulation of the argument schedule_id leads to sql injection. The attack may be launched remotely. The exploit is publicly available and… | |
| Aplazada | Media (4.3) | 0.19% | — | Merlot Digital TNC Toolbox WEB PerformanceAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in Merlot Digital (by TNC) TNC Toolbox: Web Performance tnc-toolbox allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TNC Toolbox: Web Performance: from n/a through <= 2.0.4. | |
| Analizada | Baja (2.1) | 0.31% | — | Facebook-julykringcadayona Student Information System | 18/11/2025 | 17/6/2026 | A vulnerability was determined in itsourcecode Student Information System 1.0. The affected element is an unknown function of the file /enrollment_edit1.php. Executing manipulation of the argument en_id can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may… | |
| Analizada | Baja (2) | 0.26% | — | Fabian Student Information System | 16/11/2025 | 17/6/2026 | A vulnerability was identified in code-projects Student Information System 2.0. The impacted element is an unknown function of the file /editprofile.php. Such manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used. |