Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2557▼ 320 respecto a la semana anterior
Críticas / altas1342▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

27 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.1)0.33%—Aenrich A+hcmAI22/4/202617/6/2026
The a+HCM developed by aEnrich has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload arbitrary files to any path, including HTML documents, which may result in a XSS-like effect.
AplazadaAlta (7.1)0.43%—Aenrich A+hrdAI22/4/202617/6/2026
The a+HRD developed by aEnrich has a Missing Authorization vulnerability, allowing authenticated remote attackers to arbitrarily read database contents through a specific API method.
AplazadaAlta (7.1)0.46%—Aenrich A+hrdAI22/4/202617/6/2026
The a+HRD developed by aEnrich has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.
AplazadaMedia (5.1)0.20%—Aenrich A+hrdAIAenrich A+hcmAI12/11/202517/6/2026
The a+HRD and a+HCM developed by aEnrich has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to upload files containing malicious JavaScript code, which will execute on the client side when a user is tricked into visiting a specific URL.
AnalizadaCrítica (9.3)0.58%—Aenrich A+hrd12/11/202517/6/2026
The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to craft administrator access tokens and use them to access the system with elevated privileges.
AnalizadaCrítica (9.3)0.62%—Aenrich A+hrd12/11/202517/6/2026
The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to send crafted packets to obtain administrator access tokens and use them to access the system with elevated privileges.
AnalizadaMedia (4.8)0.21%—Aenrich A+hrd12/11/202517/6/2026
The a+HRD developed by aEnrich has a Stored Cross-Site Scripting vulnerability, allowing remote attackers with administrator privileges to inject persistent JavaScript codes that are executed in users' browsers upon page load.
AnalizadaAlta (7.5)0.42%—Snowplow Enrich3/4/202517/6/2026
An issue was discovered affecting Enrich 5.1.0 and below. It involves sending a maliciously crafted Snowplow event to the pipeline. Upon receiving this event and trying to validate it, Enrich crashes and attempts to restart indefinitely. As a result, event processing would be halted.
AnalizadaAlta (7.2)0.73%—Aenrich A+hrd20/1/202517/6/2026
The a+HRD from aEnrich Technology has an Insecure Deserialization vulnerability, allowing remote attackers with database modification privileges and regular system privileges to perform arbitrary code execution.
AnalizadaCrítica (9.8)0.74%—Aenrich A+hrd20/1/202517/6/2026
The a+HRD from aEnrich Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
AnalizadaMedia (5.3)0.52%—Aenrich A+hrd20/1/202517/6/2026
The a+HRD from aEnrich Technology has a Server-side Request Forgery, allowing unauthenticated remote attackers to exploit this vulnerability to probe internal network.
AnalizadaMedia (6.1)0.42%—Aenrich A+hrd20/1/202517/6/2026
The a+HRD from aEnrich Technology has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.
AplazadaMedia (6.5)0.27%—Copist Icons EnricherAI7/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in copist Icons Enricher icons-enricher allows Stored XSS.This issue affects Icons Enricher: from n/a through <= 1.0.8.
ModificadaMedia (6.5)0.32%—Serilog-contrib Serilog-enrichers-clientinfo29/8/202417/6/2026
Serilog before v2.1.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specifying an arbitrary IP as a value of X-Forwarded-For or Client-Ip headers while performing HTTP requests.
AnalizadaAlta (7.5)0.41%—Aenrich A+hrd15/4/202417/6/2026
aEnrich Technology a+HRD's functionality for downloading files using youtube-dl.exe does not properly restrict user input. This allows attackers to pass arbitrary arguments to youtube-dl.exe, leading to the download of partial unauthorized files.
AnalizadaMedia (5.3)0.36%—Aenrich A+hrd15/4/202417/6/2026
aEnrich Technology a+HRD's functionality for front-end retrieval of system configuration values lacks proper restrictions on a specific parameter, allowing attackers to modify this parameter to access certain sensitive system configuration values.
ModificadaCrítica (9.8)0.99%—Aenrich A+hrd27/4/202317/6/2026
aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ asynchronized message process. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perform arbitrary system operation or disrupt service.
ModificadaCrítica (9.8)0.99%—Aenrich A+hrd27/4/202317/6/2026
aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ interpreter. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perform arbitrary system operation or disrupt service.
ModificadaCrítica (9.8)1.5%—Aenrich A+hrd3/1/202317/6/2026
aEnrich a+HRD has improper validation for login function. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access API function to perform arbitrary system command or disrupt service.
ModificadaCrítica (9.8)1.2%—Aenrich A+hrd3/1/202317/6/2026
aEnrich a+HRD has insufficient user input validation for specific API parameter. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify and delete database.
ModificadaAlta (7.5)1.7%—Aenrich A+hrd3/1/202317/6/2026
aEnrich a+HRD log read function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.
ModificadaCrítica (9.8)1.0%—Aenrich A+hrd3/1/202317/6/2026
aEnrich’s a+HRD has inadequate filtering for specific URL parameter. An unauthenticated remote attacker can exploit this vulnerability to send arbitrary HTTP(s) request to launch Server-Side Request Forgery (SSRF) attack, to perform arbitrary system command or disrupt service.
ModificadaAlta (7.5)0.75%—Aenrich A+hrd9/9/202217/6/2026
aEnrich eHRD Learning Management Key Performance Indicator System 5+ has Improper Access Control. The web application does not validate user session when accessing many application pages. This can allow an attacker to gain unauthenticated access to sensitive functionalities in the application
ModificadaAlta (8.1)1.0%—Aenrich A+hrd9/9/202217/6/2026
aEnrich a+HRD 5.x Learning Management Key Performance Indicator System has a local file inclusion (LFI) vulnerability that occurs due to missing input validation in v5.x
ModificadaAlta (7.5)0.75%—Aenrich A+hrd9/9/202217/6/2026
aEnrich eHRD Learning Management Key Performance Indicator System 5+ exposes Sensitive Information to an Unauthorized Actor.