Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▼ 88 respecto a la semana anterior
Críticas / altas1419▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)83▼ 429 respecto a la semana anterior
61 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.5) | 0.39% | — | SAP WEB DispatcherAISAP Internet Communication ManagerAISAP Content ServerAI | 8/9/2026 | 8/9/2026 | SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could… | |
| Aplazada | Media (5.5) | 0.41% | — | Raisecom Communication Command AND Dispatch Management PlatformAI | 14/8/2026 | 14/8/2026 | A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform up to 7.6.5. This affects an unknown part of the file /app/users/getpwd.php. Such manipulation of the argument sip leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might… | |
| Pendiente de análisis | Crítica (9.4) | 1.8% | — | GMS Dispatcher ServiceAI | 11/8/2026 | 28/8/2026 | An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests. | |
| Aplazada | Media (5.5) | 0.41% | — | Rongzhitong Visual Integrated Command AND Dispatch PlatformAI | 6/8/2026 | 12/8/2026 | A flaw has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. The affected element is an unknown function of the file /dm/dispatch/user/findAll. Executing a manipulation of the argument Name can lead to sql injection. It is possible to launch the attack remotely. The exploit has… | |
| Aplazada | Media (5.5) | 0.47% | — | Rongzhitong Visual Integrated Command AND Dispatch PlatformAI | 6/8/2026 | 12/8/2026 | A vulnerability was detected in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. Impacted is an unknown function of the file /dm/dispatch/userinfo/upload. Performing a manipulation of the argument File results in unrestricted upload. It is possible to initiate the attack remotely. The… | |
| Analizada | Media (5.5) | 0.67% | — | Rongzhitong Visual Integrated Command AND Dispatch Platform | 18/2/2026 | 17/6/2026 | A vulnerability was determined in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. This impacts an unknown function of the file /dm/dispatch/user/delete of the component User Handler. This manipulation of the argument ID causes improper access controls. Remote exploitation of the attack is… | |
| Analizada | Media (5.5) | 0.58% | — | Rongzhitong Visual Integrated Command AND Dispatch Platform | 18/2/2026 | 17/6/2026 | A vulnerability was found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. This affects an unknown function of the file /dm/dispatch/user/add of the component User Handler. The manipulation results in improper access controls. The attack may be launched remotely. The exploit has been made… | |
| Analizada | Media (5.5) | 0.64% | — | Rongzhitong Visual Integrated Command AND Dispatch Platform | 18/2/2026 | 17/6/2026 | A vulnerability has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. The impacted element is an unknown function of the file /dispatch/api?cmd=userinfo. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to… | |
| Aplazada | Alta (8.2) | 0.36% | — | SAP WEB DispatcherAISAP ICMAI | 9/12/2025 | 17/6/2026 | SAP Web Dispatcher and ICM may expose internal testing interfaces that are not intended for production. If enabled, unauthenticated attackers could exploit them to access diagnostics, send crafted requests, or disrupt services. This vulnerability has a high impact on confidentiality, availability and low impact on… | |
| Aplazada | Alta (7.5) | 0.54% | — | SAP WEB DispatcherAISAP Internet Communication ManagerAISAP Content ServerAI | 9/12/2025 | 17/6/2026 | SAP Web Dispatcher, Internet Communication Manager (ICM), and SAP Content Server allow an unauthenticated user to exploit logical errors that lead to a memory corruption vulnerability. This results in high impact on the availability with no impact on confidentiality or integrity of the application. | |
| Aplazada | Alta (7.5) | 0.51% | — | WP DispatcherAI | 3/10/2025 | 17/6/2026 | The WP Dispatcher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wp_dispatcher_process_upload() function in all versions up to, and including, 1.2.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary… | |
| Aplazada | Alta (8.8) | 0.34% | — | WP DispatcherAI | 3/10/2025 | 17/6/2026 | The WP Dispatcher plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.3) | 0.39% | — | Lenovo DispatcherAI | 11/9/2025 | 17/6/2026 | A potential insufficient access control vulnerability was reported in the Lenovo Dispatcher 3.0 and Dispatcher 3.1 drivers used by some Lenovo consumer notebooks that could allow an authenticated local user to execute code with elevated privileges. The Lenovo Dispatcher 3.2 driver is not affected. This vulnerability… | |
| Aplazada | Media (4.6) | 0.29% | — | Hexagon Hxgn Oncall Dispatch Advantage WEBAIHexagon Hxgn Oncall Dispatch Advantage MobileAI | 25/6/2025 | 17/6/2026 | Hexagon HxGN OnCall Dispatch Advantage (Web) v10.2309.03.00264 and Hexagon HxGN OnCall Dispatch Advantage (Mobile) v10.2402 are vulnerable to Cross Site Scripting (XSS) which allows a remote authenticated attacker with access to the Broadcast (Person) functionality to execute arbitrary code. | |
| Aplazada | Media (4.9) | 0.38% | — | SAP WEB DispatcherAISAP Internet Communication ManagerAI | 11/3/2025 | 17/6/2026 | SAP Web Dispatcher and Internet Communication Manager allow an attacker with administrative privileges to enable debugging trace mode with a specific parameter value. This exposes unencrypted passwords in the logs, causing a high impact on the confidentiality of the application. There is no impact on integrity or… | |
| Aplazada | Media (4.3) | 0.38% | — | SAP Netweaver Application Server AbapAISAP WEB DispatcherAISAP GUI FOR HtmlAI | 12/11/2024 | 17/6/2026 | SAP NetWeaver Application Server ABAP allows an unauthenticated attacker with network access to read files from the server, which otherwise would be restricted.This attack is possible only if a Web Dispatcher or some sort of Proxy Server is in use and the file in question was previously opened or downloaded in an… | |
| Aplazada | Media (6.6) | 1.1% | — | Rubyonrails Action PackAIRubyonrails Action DispatchAI | 16/10/2024 | 17/6/2026 | Action Pack is a framework for handling and responding to web requests. Starting in version 3.1.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, and 7.2.1.1, there is a possible ReDoS vulnerability in the query parameter filtering routines of Action Dispatch. Carefully crafted query parameters can cause query… | |
| Aplazada | Crítica (9.8) | 0.42% | — | Fujian Kelixin Communication Command AND Dispatch PlatformAI | 8/10/2024 | 17/6/2026 | Fujian Kelixin Communication Command and Dispatch Platform <=7.6.6.4391 is vulnerable to SQL Injection via /client/get_gis_fence.php. | |
| Analizada | Media (6.3) | 0.21% | — | SAP Netweaver AbapSAP Netweaver JavaSAP Content ServerSAP WEB Dispatcher | 13/8/2024 | 17/6/2026 | Due to the missing authorization checks in the local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application Server (ABAP and Java), and SAP Content Server can impersonate other users and may perform some unintended actions. This could lead to a low impact on confidentiality and a high impact on the… | |
| Analizada | Crítica (9.8) | 0.55% | — | Kelixin Communication Command AND Dispatch Project Kelixin Communication Command AND Dispatch | 19/3/2024 | 17/6/2026 | A vulnerability was found in Fujian Kelixin Communication Command and Dispatch Platform up to 20240318. It has been classified as critical. This affects an unknown part of the file /api/client/editemedia.php. The manipulation of the argument number/enterprise_uuid leads to sql injection. It is possible to initiate the… | |
| Analizada | Crítica (9.8) | 1.9% | — | Kelixin Communication Command AND Dispatch Project Kelixin Communication Command AND Dispatch | 19/3/2024 | 17/6/2026 | A vulnerability was found in Fujian Kelixin Communication Command and Dispatch Platform up to 20240318 and classified as critical. Affected by this issue is some unknown functionality of the file api/client/user/pwd_update.php. The manipulation of the argument uuid leads to sql injection. The attack may be launched… | |
| Analizada | Crítica (9.8) | 0.56% | — | Kelixin Communication Command AND Dispatch Project Kelixin Communication Command AND Dispatch | 19/3/2024 | 17/6/2026 | A vulnerability has been found in Fujian Kelixin Communication Command and Dispatch Platform up to 20240318 and classified as critical. Affected by this vulnerability is an unknown functionality of the file api/client/down_file.php. The manipulation of the argument uuid leads to sql injection. The attack can be… | |
| Analizada | Crítica (9.8) | 0.62% | — | Kelixin Communication Command AND Dispatch Project Kelixin Communication Command AND Dispatch | 17/3/2024 | 17/6/2026 | A vulnerability was found in Fujian Kelixin Communication Command and Dispatch Platform up to 20240313. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file api/client/get_extension_yl.php. The manipulation of the argument imei leads to sql injection. The attack can… | |
| Modificada | Alta (8.8) | 1.3% | — | Fl3xx CrewFl3xx Dispatch | 20/9/2023 | 17/6/2026 | Unrestricted File Upload vulnerability in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to execute arbitrary code via the add attachment function in the New Expense component. | |
| Modificada | Media (6.5) | 0.78% | — | Fl3xx CrewFl3xx Dispatch | 20/9/2023 | 17/6/2026 | An Indirect Object Reference (IDOR) in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to escalate privileges via the user parameter. |