Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.7) | 0.28% | — | Suprema Biostar XAISupremainc Biostar 2AI | 14/9/2026 | 22/9/2026 | An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET request. | |
| Aplazada | Alta (8.7) | 0.54% | — | Supremainc Biostar 2AI | 29/5/2026 | 21/7/2026 | An unhandled exception in Suprema BioStar 2 (Server), versions 2.9.8, 2.9.10, and 2.9.11, that allows an unauthenticated remote attacker to cause a denial of service (DoS) by sending HTTP POST requests to the ‘/api/migration’ endpoint. This request triggers a failure that halts critical processes, leaving the system… | |
| Aplazada | Crítica (10) | 0.55% | — | Supremainc Biostar 2AI | 29/5/2026 | 21/7/2026 | Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) that allow backup files to be publicly exposed when the administrator configures their path within the NGINX webroot. This vulnerability allows an attacker with network access to directly download backup ZIP files… | |
| Pendiente de análisis | Media (4.8) | 0.25% | — | Supremainc Biostar 2AI | 4/3/2026 | 17/6/2026 | Suprema’s BioStar 2 in version 2.9.11.6 allows users to set new password without providing the current one. Exploiting this flaw combined with other vulnerabilities can lead to unauthorized account access and potential system compromise. | |
| Modificada | Alta (8.8) | 0.60% | — | Supremainc Biostar 2 | 3/8/2023 | 17/6/2026 | A SQL injection vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows authenticated users to inject arbitrary SQL directives into an SQL statement and execute arbitrary SQL commands. | |
| Modificada | Alta (7.5) | 0.73% | — | Supremainc Biostar 2 | 3/8/2023 | 17/6/2026 | A path traversal vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated attackers to fetch arbitrary files from the server's web server. | |
| Modificada | Alta (8.8) | 1.6% | — | Supremainc Biostar 2 | 3/8/2023 | 17/6/2026 | An OS Command injection vulnerability exists in Suprema BioStar 2 before V2.9.1, which allows authenticated users to execute arbitrary OS commands on the BioStar 2 server. | |
| Modificada | Alta (7.5) | 0.56% | — | Supremainc Biostar 2 | 3/8/2023 | 17/6/2026 | An authentication bypass vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated users to access some functionality on BioStar 2 servers. | |
| Modificada | Alta (8.8) | 0.86% | — | Supremainc Biostar 2 | 22/5/2023 | 17/6/2026 | Suprema BioStar 2 before 2022 Q4, v2.9.1 has Insecure Permissions. A vulnerability in the web application allows an authenticated attacker with "User Operator" privileges to create a highly privileged user account. The vulnerability is caused by missing server-side validation, which can be exploited to gain full… | |
| Modificada | Media (6.5) | 7.6% | — | Supremainc Biostar 2 | 29/3/2023 | 9/7/2026 | Suprema BioStar 2 v2.8.16 was discovered to contain a SQL injection vulnerability via the values parameter at /users/absence?search_month=1. | |
| Modificada | Alta (8.8) | 1.1% | — | Supremainc Biostar 2 | 19/9/2022 | 17/6/2026 | A vulnerability in Suprema BioStar (aka Bio Star) 2 v2.8.16 allows attackers to escalate privileges to System Administrator via a crafted PUT request to the update profile page. | |
| Modificada | Alta (7.5) | 51% | — | Supremainc Biostar 2 | 13/7/2020 | 17/6/2026 | An issue was discovered in the Video Extension in Suprema BioStar 2 before 2.8.2. Remote attackers can read arbitrary files from the server via Directory Traversal. |