Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 237 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.7) | 0.38% | — | Atisoluciones Ciges ApplicationAI | 24/11/2025 | 17/6/2026 | A sensitive information disclosure vulnerability exists in the error handling component of ATISoluciones CIGES Application version 2.15.6 and earlier. When certain unexpected conditions trigger unhandled exceptions, the application returns detailed error messages and stack traces to the client. This may expose… | |
| Aplazada | Crítica (9.8) | 0.49% | — | Atisoluciones CigesAI | 27/2/2025 | 17/6/2026 | A SQL Injection vulnerability has been found in Ciges 2.15.5 from ATISoluciones. This vulnerability allows an attacker to retrieve, create, update and delete database via $idServicio parameter in /modules/ajaxBloqueaCita.php endpoint. | |
| Aplazada | Crítica (9.8) | 0.49% | — | Atisoluciones CigesAI | 26/8/2024 | 17/6/2026 | SQL injection vulnerability in ATISolutions CIGES affecting versions lower than 2.15.5. This vulnerability allows a remote attacker to send a specially crafted SQL query to the /modules/ajaxServiciosCentro.php point in the idCentro parameter and retrieve all the information stored in the database. | |
| Analizada | Media (5.5) | 0.16% | — | Atisoluciones Ciges | 22/3/2024 | 17/6/2026 | Information exposure vulnerability in the CIGESv2 system. This vulnerability could allow a local attacker to intercept traffic due to the lack of proper implementation of the TLS protocol. | |
| Analizada | Media (6.1) | 0.31% | — | Atisoluciones Ciges | 22/3/2024 | 17/6/2026 | HTML injection vulnerability affecting the CIGESv2 system, which allows an attacker to inject arbitrary code and modify elements of the website and email confirmation message. | |
| Analizada | Media (6.1) | 0.31% | — | Atisoluciones Ciges | 22/3/2024 | 17/6/2026 | Stored Cross-Site Scripting (Stored-XSS) vulnerability affecting the CIGESv2 system, allowing an attacker to execute and store malicious javascript code in the application form without prior registration. | |
| Analizada | Alta (7.5) | 0.62% | — | Atisoluciones Ciges | 22/3/2024 | 17/6/2026 | Information exposure vulnerability in the CIGESv2 system. A remote attacker might be able to access /vendor/composer/installed.json and retrieve all installed packages used by the application. | |
| Analizada | Alta (7.5) | 0.68% | — | Atisoluciones Ciges | 22/3/2024 | 17/6/2026 | SQL injection vulnerability in the CIGESv2 system, through /ajaxServiciosAtencion.php, in the 'idServicio' parameter. The exploitation of this vulnerability could allow a remote user to retrieve all data stored in the database by sending a specially crafted SQL query. | |
| Analizada | Alta (7.5) | 0.68% | — | Atisoluciones Ciges | 22/3/2024 | 17/6/2026 | SQL injection vulnerability in the CIGESv2 system, through /ajaxSubServicios.php, in the 'idServicio' parameter. The exploitation of this vulnerability could allow a remote user to retrieve all data stored in the database by sending a specially crafted SQL query. | |
| Analizada | Alta (7.5) | 0.68% | — | Atisoluciones Ciges | 22/3/2024 | 17/6/2026 | SQL injection vulnerability in the CIGESv2 system, through /ajaxConfigTotem.php, in the 'id' parameter. The exploitation of this vulnerability could allow a remote user to retrieve all data stored in the database by sending a specially crafted SQL query. |