Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2724▼ 13 respecto a la semana anterior
Críticas / altas1452▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

10 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.27%—Aiopms Database SoftwareAI30/5/202622/7/2026
AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the director parameter. Attackers can send GET requests to director.php with crafted SQL payloads in the director parameter to extract sensitive…
AplazadaCrítica (9.8)0.36%—Database Software Training Consulting LTD Databank Accreditation SoftwareAI19/2/202625/6/2026
Authorization Bypass Through User-Controlled SQL Primary Key vulnerability in DATABASE Software Training Consulting Ltd. Databank Accreditation Software allows SQL Injection. This issue affects Databank Accreditation Software: before 2026/04.
ModificadaAlta (7.5)0.95%—ABB 800xaABB Base SoftwareABB Compact Product SuiteABB Control Builder Safe1/4/202217/6/2026
Improper Input Validation vulnerability in ABB 800xA, Control Software for AC 800M, Control Builder Safe, Compact Product Suite - Control and I/O, ABB Base Software for SoftControl allows an attacker to cause the denial of service.
ModificadaMedia (6.1)25%—Beyondtrust Appliance Base Software5/1/202217/6/2026
A cross-site scripting (XSS) vulnerability has been reported and confirmed for BeyondTrust Secure Remote Access Base Software version 6.0.1 and older, which allows the injection of unauthenticated, specially-crafted web requests without proper sanitization.
ModificadaCrítica (9.8)0.54%—ABB Base Software8/9/202117/6/2026
A vulnerability in Base Software for SoftControl allows an attacker to insert and run arbitrary code in a computer running the affected product. This issue affects: .
ModificadaBaja (3.3)0.34%—ABB MMS ServerABB OPC ServerABB Base Software29/4/202017/6/2026
Insufficient protection of the inter-process communication functions in ABB System 800xA products OPC Server for AC 800M, MMS Server for AC 800M and Base Software for SoftControl (all published versions) enables an attacker authenticated on the local system to inject data, affecting the online view of runtime data…
ModificadaAlta (7.8)0.28%—ABB Control Builder MABB MMS ServerABB OPC ServerABB Base Software29/4/202017/6/2026
Insufficient folder permissions used by system functions in ABB System 800xA products OPCServer for AC800M (versions 6.0 and earlier) and Control Builder M Professional, MMSServer for AC800M, Base Software for SoftControl (version 6.1 and earlier) allow low privileged users to read, modify, add and delete system and…
ModificadaAlta (7.5)0.97%—Knowledgebase-script Phpkb Knowledge Base Software14/11/200816/6/2026
Multiple SQL injection vulnerabilities in PHPKB Knowledge Base Software 1.5 Professional allow remote attackers to execute arbitrary SQL commands via the ID parameter to (1) email.php and (2) question.php, a different vector than CVE-2008-1909.
ModificadaAlta (7.5)1.2%—Altantisfaq Altantis Knowledge Base Software29/11/200516/6/2026
SQL injection vulnerability in search.php in AtlantisFAQ Knowledge Base Software 2.03 and earlier allows remote attackers to execute arbitrary SQL commands via the searchStr parameter.
ModificadaAlta (7.5)1.1%—Faqsystems Faqring Knowledge Base Software29/11/200516/6/2026
SQL injection vulnerability in answer.php in FAQSystems FAQRing Knowledge Base Software 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.