Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2838▼ 146 respecto a la semana anterior
Críticas / altas1377▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 268 respecto a la semana anterior
–

244 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.2)0.12%—IBM Concert24/9/202628/9/2026
IBM Concert 1.0.0 through 3.0.0 allows recursive copying of directories without proper controls which can lead to unintentional inclusion of sensitive or unnecessary files and increased attack surface.
AnalizadaAlta (7.8)0.12%—IBM Concert23/9/202629/9/2026
IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path resolution. As a result, an attacker with local system access can manipulate the search path environment to execute untrusted or malicious code.
AnalizadaCrítica (9.8)0.45%—IBM Concert23/9/202629/9/2026
IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker who can influence program execution or input may exploit this condition to corrupt memory, cause application crashes, or execute arbitrary code.
AnalizadaMedia (5.3)0.33%—IBM Concert23/9/202628/9/2026
IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary files on the system.
AnalizadaAlta (7.8)0.11%—IBM Concert23/9/202628/9/2026
IBM Concert 1.0.0 through 3.0.0 has a double free vulnerability that exists due to incorrect memory management. A local attacker can exploit this flaw to corrupt heap memory and execute arbitrary code in the context of the affected process.
AnalizadaAlta (7.8)0.30%—IBM Concert23/9/202628/9/2026
IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.
AnalizadaCrítica (9.8)1.4%—IBM Concert23/9/202628/9/2026
IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially crafted input that is incorporated into OS commands, resulting in arbitrary command execution on the underlying system. Successful exploitation allows remote code execution with the privileges of the affected application.
AnalizadaMedia (6.2)0.10%—IBM Concert23/9/202628/9/2026
IBM Concert 1.0.0 through 3.0.0 is vulnerable to improper access control which allows unauthorized modification of application files.
AnalizadaMedia (4.3)0.17%—IBM Concert23/9/202628/9/2026
IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.
AnalizadaMedia (5.3)0.24%—IBM Concert23/9/202628/9/2026
IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Pendiente de análisisCrítica (9.6)0.30%—IBM ConcertAI22/9/202624/9/2026
IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to access or modify unauthorized resources due to the use of wildcards in RBAC permission definitions.
Pendiente de análisisMedia (6.5)0.28%—IBM ConcertAI22/9/202623/9/2026
IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper enforcement of storage limits.
Pendiente de análisisMedia (6.5)0.19%—IBM ConcertAI22/9/202623/9/2026
IBM Concert 1.0.0 through 3.0.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Pendiente de análisisMedia (6.2)0.12%—IBM ConcertAI22/9/202623/9/2026
IBM Concert 1.0.0 through 3.0.0 could allow a local attacker to obtain sensitive information due to recursive copying of build context directories into container images.
Pendiente de análisisMedia (5.9)0.16%—IBM ConcertAI22/9/202623/9/2026
IBM Concert 1.0.0 through 3.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Pendiente de análisisMedia (5.3)0.36%—IBM ConcertAI22/9/202623/9/2026
IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to cause a denial of service using a specially crafted regular expression that would cause excessive resource consumption.
AnalizadaCrítica (9.1)0.51%—IBM Concert28/8/20262/9/2026
IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
AnalizadaMedia (5.9)0.17%—IBM Concert28/8/20262/9/2026
IBM Concert 1.0.0 through 2.3.1 could allow a remote attacker to perform unauthorized actions using man in the middle techniques due to improper certificate validation.
AplazadaMedia (4.8)0.14%—ILM Informatique OpenconcertoAI4/5/202617/6/2026
Plaintext storage of a password vulnerability in ILM Informatique OpenConcerto allows Retrieve Embedded Sensitive Data. This issue affects OpenConcerto: 1.7.5.
AplazadaBaja (2.4)0.14%—ILM Informatique OpenconcertoAI4/5/202617/6/2026
Incorrect Permission Assignment for Critical Resource vulnerability in ILM Informatique OpenConcerto allows Replace Binaries. This issue affects OpenConcerto: 1.7.5.
AnalizadaMedia (6.2)0.14%—IBM Concert7/4/202624/7/2026
IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.
AplazadaMedia (5.5)0.41%—Code-projects Concert Ticket Reservation SystemAI5/4/202624/7/2026
A weakness has been identified in code-projects Concert Ticket Reservation System 1.0. This affects an unknown part of the file /ConcertTicketReservationSystem-master/login.php of the component Parameter Handler. Executing a manipulation of the argument Email can lead to sql injection. The attack may be launched…
AplazadaMedia (5.5)0.41%—Code-projects Concert Ticket Reservation SystemAI5/4/202624/7/2026
A security flaw has been discovered in code-projects Concert Ticket Reservation System 1.0. Affected by this issue is some unknown functionality of the file /ConcertTicketReservationSystem-master/process_search.php of the component Parameter Handler. Performing a manipulation of the argument searching results in sql…
AnalizadaMedia (5.9)0.19%—IBM Concert25/3/202617/6/2026
IBM Concert 1.0.0 through 2.2.0 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.
AnalizadaAlta (7.5)0.20%—IBM Concert25/3/202617/6/2026
IBM Concert 1.0.0 through 2.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information