Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
2262 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.36% | — | F5 Big-ip Container Ingress Services | 4/2/2026 | 17/6/2026 | A vulnerability exists in F5 BIG-IP Container Ingress Services that may allow excessive permissions to read cluster secrets. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Baja (2.3) | 0.18% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 4/2/2026 | 17/6/2026 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Aplazada | Media (5.4) | 0.24% | — | Smartdatasoft Pool ServicesAI | 22/1/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Pool Services pool-services allows Server Side Request Forgery.This issue affects Pool Services: from n/a through <= 3.3. | |
| Aplazada | Alta (8.1) | 0.36% | — | Solvera Software Services Trade INC TeknoeraAI | 22/1/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Solvera Software Services Trade Inc. Teknoera allows File Content Injection. This issue affects Teknoera: through 01102025. | |
| Aplazada | Alta (7.5) | 0.42% | — | Solvera Software Services Trade TeknoeraAI | 22/1/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Solvera Software Services Trade Inc. Teknoera allows Exploitation of Trusted Identifiers. This issue affects Teknoera: through 01102025. | |
| Aplazada | Media (6.5) | 0.49% | — | Keycloak-servicesAI | 21/1/2026 | 17/6/2026 | A flaw was found in the keycloak-services component of Keycloak. This vulnerability allows the issuance of access and refresh tokens for disabled users, leading to unauthorized use of previously revoked privileges, via a business logic vulnerability in the Token Exchange implementation when a privileged client invokes… | |
| Analizada | Media (4.8) | 0.27% | — | Cisco Identity Services Engine | 15/1/2026 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based… | |
| Analizada | Media (4.8) | 0.27% | — | Cisco Identity Services Engine | 15/1/2026 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient… | |
| Analizada | Baja (2.9) | 0.46% | — | Redhat Hardened ImagesRedhat Jboss Core ServicesRedhat Openshift Container PlatformRedhat Enterprise Linux+3 | 15/1/2026 | 1/9/2026 | A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly… | |
| Analizada | Media (5.9) | 0.97% | — | Redhat Hardened ImagesRedhat Jboss Core ServicesRedhat Openshift Container PlatformRedhat Enterprise Linux+3 | 15/1/2026 | 1/9/2026 | A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML… | |
| Analizada | Baja (3.7) | 0.54% | — | Xmlsoft Libxml2Redhat Hardened ImagesRedhat Jboss Core ServicesRedhat Openshift Container Platform+3 | 15/1/2026 | 1/9/2026 | A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to… | |
| Aplazada | Media (4.9) | 6.2% | — | Cisco Identity Services EngineAICisco Identity Services Engine Passive Identity ConnectorAI | 7/1/2026 | 17/6/2026 | This vulnerability is due to improper parsing of XML that is processed by the web-based management interface of Cisco ISE and Cisco ISE-PIC. An attacker could exploit this vulnerability by uploading a malicious file to the application. A successful exploit could allow the attacker to read arbitrary files from the… | |
| Aplazada | Alta (8.8) | 0.34% | — | Echo Call Center Services Trade AND Industry INC Specto CMAI | 24/12/2025 | 7/10/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Echo Call Center Services Trade and Industry Inc. Specto CM allows Remote Code Inclusion. This issue affects Specto CM: before 17032025. | |
| Aplazada | Media (5.4) | 0.17% | — | Echo Call Center Services Trade AND Industry INC Specto CMAI | 24/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Echo Call Center Services Trade and Industry Inc. Specto CM allows Stored XSS. This issue affects Specto CM: before 17032025. | |
| Aplazada | Alta (7.3) | 0.45% | 💥 Exploit | Netbt Consulting Services INC E-faturaAI | 22/12/2025 | 17/6/2026 | Unquoted Search Path or Element vulnerability in NetBT Consulting Services Inc. E-Fatura allows Leveraging/Manipulating Configuration File Search Paths, Redirect Access to Libraries. This issue affects e-Fatura: before 1.2.15. | |
| Aplazada | Media (6.5) | 0.12% | — | Identity Agent FOR Terminal ServicesAI | 22/12/2025 | 17/6/2026 | An authenticated local user can obtain information that allows claiming security policy rules of another user due to sensitive information being printed in plaintext in Identity Agent for Terminal Services debug files. | |
| Aplazada | Alta (8.8) | 0.36% | — | Jthemes Sale Immigration LAW Visa Services Support Migration Agent ConsultingAI | 18/12/2025 | 5/10/2026 | Incorrect Privilege Assignment vulnerability in Jthemes Sale! Immigration law, Visa services support, Migration Agent Consulting immiex allows Privilege Escalation.This issue affects Sale! Immigration law, Visa services support, Migration Agent Consulting: from n/a through <= 1.5.8. | |
| Aplazada | Alta (7.1) | 0.23% | — | GG Soft Software Services INC PaperworkAI | 17/12/2025 | 28/9/2026 | Authorization Bypass Through User-Controlled Key vulnerability in GG Soft Software Services Inc. PaperWork allows Exploitation of Trusted Identifiers. This issue affects PaperWork: from 5.2.0.9427 before 6.0. | |
| Aplazada | Alta (7.6) | 0.24% | — | Aksis Computer Services AND Consulting INC AxonboardAI | 11/12/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Aksis Computer Services and Consulting Inc. AxOnboard allows Exploitation of Trusted Identifiers. This issue affects AxOnboard: from 3.2.0 before 3.3.0. | |
| Aplazada | Baja (3.5) | 0.20% | — | TAC Information Services Internal AND External Trade INC GoldenhornAI | 10/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TAC Information Services Internal and External Trade Inc. GoldenHorn allows Cross-Site Scripting (XSS). This issue affects GoldenHorn: before 4.25.1121.1. | |
| Analizada | Baja (1.9) | 0.28% | — | Alokjaiswal Hotel-management-services-using-mysql-and-php | 7/12/2025 | 17/6/2026 | A vulnerability was found in alokjaiswal Hotel-Management-services-using-MYSQL-and-php up to 5f8b60a7aa6c06a5632de569d4e3f6a8cd82f76f. Affected by this vulnerability is an unknown functionality of the file /dishsub.php. The manipulation of the argument item.name results in cross site scripting. It is possible to… | |
| Analizada | Baja (2) | 0.23% | — | Alokjaiswal Hotel-management-services-using-mysql-and-php | 7/12/2025 | 17/6/2026 | A vulnerability has been found in alokjaiswal Hotel-Management-services-using-MYSQL-and-php up to 5f8b60a7aa6c06a5632de569d4e3f6a8cd82f76f. Affected is an unknown function of the file /usersub.php of the component Request Pending Page. The manipulation leads to cross site scripting. It is possible to initiate the… | |
| Aplazada | Alta (8.8) | 0.30% | — | GG Soft Software Services INC PaperworkAIHibernateAI | 7/11/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 564 - SQL Injection: Hibernate vulnerability in GG Soft Software Services Inc. PaperWork allows Blind SQL Injection, SQL Injection. This issue affects PaperWork: from 6.1.0.9390 before 6.1.0.9398. | |
| Analizada | Alta (7.5) | 0.71% | 💥 PoC | Cisco Identity Services Engine | 5/11/2025 | 17/6/2026 | A vulnerability in the RADIUS setting Reject RADIUS requests from clients with repeated failures on Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause Cisco ISE to restart unexpectedly. This vulnerability is due to a logic error when processing a RADIUS access request for a… | |
| Analizada | Media (4.9) | 0.30% | — | Cisco Identity Services Engine | 5/11/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability exists because certain files lack proper data protection mechanisms. An attacker with read-only Administrator privileges could… |