Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2686▼ 84 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
1913 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | — | — | Softtr Informatics E-commerce PackAI | 2/10/2026 | 2/10/2026 | Observable discrepancy vulnerability in Softtr Informatics Trading Limited Company E-Commerce Pack allows Account Footprinting. This issue affects E-Commerce Pack: through 2026-10-02. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Pendiente de análisis | Alta (7.5) | 0.67% | — | Fasterxml Jackson-dataformats-binaryAI | 1/10/2026 | 2/10/2026 | The Smile parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this format. SmileParser._handleLongFieldName() grows its internal name buffer through an unconstrained… | |
| Pendiente de análisis | Alta (7.5) | 0.67% | — | Fasterxml Jackson Dataformats BinaryAI | 1/10/2026 | 2/10/2026 | The CBOR parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this format. CBORParser._decodeLongerName() decodes a definite-length property name with no length check, and… | |
| Aplazada | Alta (8.8) | 0.23% | — | Interprobe Information Technologies Qorela DCAI | 29/9/2026 | 29/9/2026 | Missing Authorization vulnerability in Interprobe Information Technologies Inc. Qorela DC allows Privilege Abuse. This issue affects Qorela DC: from 1.6.1-RC29 before v1.6.2. | |
| Aplazada | Media (6.1) | 0.15% | — | Rolantis Information Technologies AgentisAI | 28/9/2026 | 28/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Rolantis Information Technologies Tourism Industry and Trade Co. Ltd. Agentis allows XSS Targeting HTML Attributes. This issue affects Agentis: from 4.44 before 4.6. | |
| Aplazada | Baja (2.1) | 0.20% | — | Forma LMSAI | 24/9/2026 | 29/9/2026 | A vulnerability was determined in Forma LMS up to 4.1.43. This impacts the function UserselectorAdmController::getDataTask of the file /appCore/ajax.adm_server.php?r=adm/userselector/getData of the component Multi-User-Selector AJAX Endpoint. This manipulation of the argument Name causes sql injection. The attack may… | |
| Aplazada | Media (6.5) | 0.21% | — | Global IT Informatics Technology Services INC WeollAI | 23/9/2026 | 23/9/2026 | Server-Side request forgery (SSRF) vulnerability in Global IT Informatics Technology Services Inc. Weoll allows Server Side Request Forgery. This issue affects Weoll: before 3.2.45.44. | |
| Aplazada | Media (6.1) | 0.18% | — | KA Informatics Technologies LTD BAR Association WebsiteAI | 18/9/2026 | 18/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in KA Informatics Technologies Ltd. Co. Bar Association Website allows Reflected XSS. This issue affects Bar Association Website: through 18092026. NOTE: The vendor was contacted early about this disclosure but did not… | |
| Aplazada | Alta (7.5) | 0.50% | — | GIS Informatics Gislab Laboratory Management SystemAI | 10/9/2026 | 10/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GIS Informatics GisLab Laboratory Management System allows Path Traversal. This issue affects GisLab Laboratory Management System: from 1.4.03 before 1.5. | |
| Aplazada | Crítica (9.8) | 0.47% | — | GIS Informatics Gislab Laboratory Management SystemAI | 10/9/2026 | 10/9/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GIS Informatics GisLab Laboratory Management System allows SQL Injection. This issue affects GisLab Laboratory Management System: from 1.4.03 before 1.5. | |
| Aplazada | Crítica (9.3) | 0.36% | — | Armiya Information Technologies LTD Access Control SystemAI | 10/9/2026 | 10/9/2026 | URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows Fake the Source of Data. This issue affects Access Control System: before Versiyon 2. | |
| Aplazada | Crítica (9.8) | 0.47% | — | Armiya Information Technologies LTD Access Control SystemAI | 10/9/2026 | 10/9/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows SQL Injection. This issue affects Access Control System: before Versiyon 2. | |
| Aplazada | Media (6.1) | 0.24% | — | Yordam Informatics Technology Consulting Training AND Electronic Systems Industry AND Trade Library Information AND Document Automation ProgramAI | 9/9/2026 | 9/9/2026 | URL redirection to untrusted site ('open redirect') vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows Phishing. This issue affects Library Information and Document Automation Program: from v22.1… | |
| Aplazada | Media (5.3) | 0.19% | — | Yordam Informatics Technology Consulting Training AND Electronic Systems Industry AND Trade Library Information AND Document Automation ProgramAI | 9/9/2026 | 9/9/2026 | Server-Side request forgery (SSRF) vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows Server Side Request Forgery. This issue affects Library Information and Document Automation Program: before… | |
| Aplazada | Media (4.3) | 0.18% | — | Yordam Informatics Technology Consulting Training AND Electronic Systems Industry AND Trade INC Library Reservation SystemAI | 9/9/2026 | 9/9/2026 | Missing authentication for critical function vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Reservation System allows Input Data Manipulation. This issue affects Library Reservation System: before v22.2. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Next4biz Information Technologies INC CSMAI | 7/9/2026 | 9/9/2026 | Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection. This issue affects CSM (Customer Service Management): before 8.0.3. | |
| Aplazada | Alta (7.5) | 0.50% | — | Next4biz Information Technologies INC CSMAI | 7/9/2026 | 8/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Path Traversal. This issue affects CSM (Customer Service Management): from 6.8.9 before 8.0.3. | |
| Aplazada | Media (5.5) | 0.53% | — | Code-projects Hospital Information SystemAI | 7/9/2026 | 9/9/2026 | A vulnerability was found in code-projects Hospital Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /HIS/his.sql of the component SQL Database Backup File Handler. Performing a manipulation results in information disclosure. Remote exploitation of the attack is possible.… | |
| Aplazada | Baja (2) | 0.35% | — | Code-projects Hospital Information SystemAI | 7/9/2026 | 8/9/2026 | A vulnerability has been found in code-projects Hospital Information System 1.0. Affected is an unknown function of the file /HIS/src/patients/editPatient.php of the component Patient Management. Such manipulation of the argument ID leads to cross site scripting. The attack may be launched remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Information System Society Membership SystemAI | 7/9/2026 | 28/9/2026 | A security vulnerability has been detected in itsourcecode Information System Society Membership System 1.0. This issue affects some unknown processing of the file /society/check_student.php. The manipulation of the argument student_id leads to sql injection. Remote exploitation of the attack is possible. The exploit… | |
| Pendiente de análisis | Alta (8.5) | 0.18% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 8/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an information disclosure vulnerability in DirectIo64.sys that allows unauthenticated local attackers to dump complete physical memory contents by supplying a caller-controlled file path… | |
| Pendiente de análisis | Alta (8.4) | 0.17% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 10/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an unauthenticated physical memory disclosure in DirectIo64.sys, reachable by unprivileged local users through a single IOCTL with no caller-identity check. The handler writes a… | |
| Pendiente de análisis | Media (6.9) | 0.16% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 8/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to issue arbitrary IN and OUT instructions to any x86 I/O port due to missing allowlist or port validation on… | |
| Pendiente de análisis | Alta (8.5) | 0.17% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 8/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to modify hardware configuration by exploiting exposed IOCTLs with no validation on device selection,… | |
| Pendiente de análisis | Media (6.9) | 0.15% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 14/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation and denial-of-service vulnerability in DirectIo64.sys that allows local attackers to read arbitrary Model-Specific Registers or write zero to any MSR through exposed… |