Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.47% | — | Brilliance Golden Link Secondary System | 19/6/2025 | 17/6/2026 | A vulnerability classified as critical has been found in Brilliance Golden Link Secondary System up to 20250609. This affects an unknown part of the file /storagework/custTakeInfoPage.htm. The manipulation of the argument custTradeName leads to sql injection. It is possible to initiate the attack remotely. The exploit… | |
| Analizada | Baja (2.1) | 0.47% | — | Brilliance Golden Link Secondary System | 19/6/2025 | 17/6/2026 | A vulnerability was found in Brilliance Golden Link Secondary System up to 20250609. It has been rated as critical. Affected by this issue is some unknown functionality of the file /storagework/rentTakeInfoPage.htm. The manipulation of the argument custTradeName leads to sql injection. The attack may be launched… | |
| Analizada | Media (5.3) | 0.37% | — | Brilliance Golden Link Secondary System | 5/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Brilliance Golden Link Secondary System up to 20250424. Affected is an unknown function of the file /sysframework/logSelect.htm. The manipulation of the argument nodename leads to sql injection. It is possible to launch the attack remotely. The exploit… | |
| Analizada | Media (5.3) | 0.37% | — | Brilliance Golden Link Secondary System | 5/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Brilliance Golden Link Secondary System up to 20250424. This issue affects some unknown processing of the file /reprotframework/tcCustDeferPosiQuery.htm. The manipulation of the argument custTradeId leads to sql injection. The attack may be initiated… | |
| Analizada | Media (5.3) | 0.37% | — | Brilliance Golden Link Secondary System | 5/6/2025 | 17/6/2026 | A vulnerability classified as critical was found in Brilliance Golden Link Secondary System up to 20250424. This vulnerability affects unknown code of the file /storagework/rentChangeCheckInfoPage.htm. The manipulation of the argument clientname leads to sql injection. The attack can be initiated remotely. The exploit… | |
| Analizada | Media (5.3) | 0.52% | — | Brilliance Golden Link Secondary System | 6/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Brilliance Golden Link Secondary System up to 20250424. Affected is an unknown function of the file /paraframework/queryTsDictionaryType.htm. The manipulation of the argument dictCn1 leads to sql injection. It is possible to launch the attack remotely.… | |
| Analizada | Media (5.3) | 0.52% | — | Brilliance Golden Link Secondary System | 6/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Brilliance Golden Link Secondary System up to 20250424. This issue affects some unknown processing of the file /reprotframework/tcEntrFlowSelect.htm. The manipulation of the argument custTradeId leads to sql injection. The attack may be initiated… | |
| Modificada | Alta (8.8) | 0.31% | — | Brandbrilliance Post State Tags | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in BRANDbrilliance Post State Tags plugin <= 2.0.6 versions. | |
| Modificada | Media (5.4) | 0.38% | — | Wpchill Brilliance | 22/6/2023 | 17/6/2026 | Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in WP Chill Brilliance theme <= 1.3.1 versions. | |
| Modificada | Media (6.5) | 0.97% | — | Colorlib ActivelloColorlib BonkersColorlib IlldyColorlib Newspaper X+11 | 7/6/2023 | 17/6/2026 | The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Activation/Deactivation. This is due to the 'activello_activate_plugin' and 'activello_deactivate_plugin' functions in the 'inc/welcome-screen/class-activello-welcome.php' file missing capability and… | |
| Modificada | Crítica (9.8) | 65% | — | Colorlib ActivelloColorlib BonkersColorlib IlldyColorlib Newspaper X+12 | 7/6/2023 | 17/6/2026 | The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, Pixova Lite <= 2.0.5, Brilliance <= 1.2.7, MedZone Lite <= 1.2.4, Regina Lite <= 2.0.4, Transcend <=… | |
| Modificada | Alta (8.7) | 0.40% | — | Philips Brilliance Firmware 64Philips Brilliance ICT SP FirmwarePhilips Brilliance ICT FirmwarePhilips Brilliance CT BIG Bore Firmware | 4/5/2018 | 17/6/2026 | Vulnerabilities within the Philips Brilliance CT kiosk environment (Brilliance 64 version 2.6.2 and prior, Brilliance iCT versions 4.1.6 and prior, Brillance iCT SP versions 3.2.4 and prior, and Brilliance CT Big Bore 2.3.5 and prior) could enable a limited-access kiosk user or an unauthorized attacker to break-out… | |
| Modificada | Alta (7.8) | 0.31% | — | Philips Brilliance Firmware 64Philips Brilliance ICT SP FirmwarePhilips Brilliance ICT FirmwarePhilips Brilliance CT BIG Bore Firmware | 4/5/2018 | 17/6/2026 | Philips Brilliance CT software (Brilliance 64 version 2.6.2 and prior, Brilliance iCT versions 4.1.6 and prior, Brillance iCT SP versions 3.2.4 and prior, and Brilliance CT Big Bore 2.3.5 and prior) contains fixed credentials, such as a password or cryptographic key, which it uses for its own inbound authentication,… | |
| Modificada | Alta (8.8) | 0.37% | — | Philips Brilliance Firmware 64Philips Brilliance ICT SP FirmwarePhilips Brilliance ICT FirmwarePhilips Brilliance CT BIG Bore Firmware | 4/5/2018 | 17/6/2026 | Philips Brilliance CT devices operate user functions from within a contained kiosk in a Microsoft Windows operating system. Windows boots by default with elevated Windows privileges, enabling a kiosk application, user, or an attacker to potentially attain unauthorized elevated privileges in Brilliance 64 version 2.6.2… |