Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2509▼ 448 respecto a la semana anterior
Críticas / altas1286▼ 7 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 464 respecto a la semana anterior
–

87 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (4.8)0.29%—Cisco Integrated Management ControllerAI5/8/20266/8/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could…
AplazadaMedia (5.5)0.46%—Tiandy Easy7 Integrated Management PlatformAI25/5/202623/7/2026
A vulnerability was determined in Tiandy Easy7 Integrated Management Platform 7.17.0. This issue affects some unknown processing of the file /rest/user/updateUserPassword of the component API Endpoint. Executing a manipulation can lead to weak password recovery. The attack can be executed remotely. The exploit has…
AplazadaMedia (5.5)0.41%—Tiandy Easy7 Integrated Management PlatformAI25/5/202623/7/2026
A vulnerability was found in Tiandy Easy7 Integrated Management Platform 7.17.0. This vulnerability affects unknown code of the file /Easy7/apps/WebService/GetDBDataEx.jsp. Performing a manipulation of the argument strTBName results in sql injection. Remote exploitation of the attack is possible. The exploit has been…
AplazadaMedia (5.5)3.2%—Tiandy Easy7 Integrated Management PlatformAI3/5/202617/6/2026
A vulnerability was identified in Tiandy Easy7 Integrated Management Platform 7.17.0. Affected by this vulnerability is an unknown functionality of the file /Easy7/rest/systemInfo/updateDbBackupInfo. Such manipulation of the argument week leads to os command injection. The attack can be executed remotely. The exploit…
Pendiente de análisisCrítica (9.8)0.99%—Cisco Integrated Management ControllerAI1/4/202617/6/2026
A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as Admin. This vulnerability is due to incorrect handling of password change requests. An attacker could…
AplazadaAlta (8.9)5.7%—Tiandy Easy7 Integrated Management PlatformAI23/3/202617/6/2026
A vulnerability has been found in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This vulnerability affects unknown code of the file /Easy7/apps/WebService/ImportSystemConfiguration.jsp of the component Configuration Handler. The manipulation of the argument File leads to os command injection. The attack…
AplazadaMedia (5.5)0.41%—Tiandy Easy7 Integrated Management PlatformAI17/3/202617/6/2026
A security vulnerability has been detected in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This affects an unknown function of the file /rest/preSetTemplate/getRecByTemplateId. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed…
AplazadaMedia (5.5)0.41%—Tiandy Easy7 Integrated Management PlatformAI17/3/202617/6/2026
A weakness has been identified in Tiandy Easy7 Integrated Management Platform 7.17.0. The impacted element is an unknown function of the file /rest/devStatus/getDevDetailedInfo of the component Endpoint. Executing a manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The…
AplazadaMedia (5.5)0.41%—Tiandy Easy7 Integrated Management PlatformAI17/3/202617/6/2026
A security flaw has been discovered in Tiandy Easy7 Integrated Management Platform 7.17.0. The affected element is an unknown function of the file /rest/devStatus/queryResources of the component Endpoint. Performing a manipulation of the argument areaId results in sql injection. The attack can be initiated remotely.…
AplazadaMedia (5.5)0.41%—Tiandy Integrated Management PlatformAI16/3/202617/6/2026
A vulnerability was determined in Tiandy Integrated Management Platform 7.17.0. Affected by this issue is some unknown functionality of the file /rest/user/getAuthorityByUserId. Executing a manipulation of the argument userId can lead to sql injection. The attack may be launched remotely. The exploit has been publicly…
AplazadaMedia (5.5)0.47%—Tiandy Easy7 Integrated Management PlatformAI16/3/202617/6/2026
A vulnerability was found in Tiandy Easy7 Integrated Management Platform 7.17.0. This affects an unknown part of the file /rest/file/uploadLedImage of the component Endpoint. The manipulation of the argument File results in unrestricted upload. The attack may be launched remotely. The exploit has been made public and…
AplazadaMedia (5.5)0.68%—Tiandy Easy7 Integrated Management PlatformAI16/3/202617/6/2026
A vulnerability was identified in Tiandy Easy7 Integrated Management Platform 7.17.0. Impacted is an unknown function of the file /WebService/UpdateLocalDevInfo.jsp of the component Device Identifier Handler. Such manipulation of the argument username/password leads to missing authentication. The attack can be…
AnalizadaMedia (5.5)0.74%—Shuoren Smart Heating Integrated Management Platform23/2/202617/6/2026
A flaw has been found in ShuoRen Smart Heating Integrated Management Platform 1.0.0. Affected by this vulnerability is an unknown functionality of the file /MP/Service/Webservice/ExampleNodeService.asmx. Executing a manipulation of the argument File can lead to unrestricted upload. It is possible to launch the attack…
AplazadaMedia (5.5)0.43%—Fujian Smart Integrated Management Platform SystemAI20/2/202617/6/2026
A weakness has been identified in Fujian Smart Integrated Management Platform System up to 7.5. Impacted is an unknown function of the file /Module/CRXT/Controller/XCamera.ashx. This manipulation of the argument ChannelName causes sql injection. Remote exploitation of the attack is possible. The exploit has been made…
AplazadaMedia (5.5)0.43%—Fujian Smart Integrated Management Platform SystemAI20/2/202617/6/2026
A security flaw has been discovered in Fujian Smart Integrated Management Platform System up to 7.5. This issue affects some unknown processing of the file /Module/CRXT/Controller/XAccessPermissionPlus.ashx. The manipulation of the argument DeviceIDS results in sql injection. The attack may be launched remotely. The…
AplazadaCrítica (10)0.81%—Dahua Smart Park Integrated Management PlatformAI27/8/20253/9/2026
A path traversal vulnerability exists in the Dahua Smart Park Integrated Management Platform (also referred to as the Dahua Smart Campus Integrated Management Platform), affecting the SOAP-based GIS bitmap upload interface. The flaw allows unauthenticated remote attackers to upload arbitrary files to the server via…
AplazadaMedia (5.4)0.22%—Cisco Integrated Management ControllerAICisco UCS ManagerAI27/8/202517/6/2026
A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker with low privileges to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to…
AplazadaAlta (7.1)0.43%—Cisco Integrated Management ControllerAICisco UCS ManagerAI27/8/202517/6/2026
A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to redirect a user to a malicious website. This vulnerability is due to insufficient verification of vKVM endpoints. An attacker could exploit…
AplazadaAlta (8.8)0.46%—Cisco Integrated Management ControllerAICisco UCS B-series ServersAICisco UCS C-series ServersAICisco UCS S-series ServersAI+14/6/202517/6/2026
A vulnerability in the SSH connection handling of Cisco Integrated Management Controller (IMC) for Cisco UCS B-Series, UCS C-Series, UCS S-Series, and UCS X-Series Servers could allow an authenticated, remote attacker to access internal services with elevated privileges. This vulnerability is due to insufficient…
AnalizadaMedia (6.9)0.65%—Gosuncntech Group Audio-visual Integrated Management11/5/202517/6/2026
A vulnerability has been found in Gosuncn Technology Group Audio-Visual Integrated Management Platform 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /sysmgr/user/listByPage. The manipulation leads to information disclosure. The attack can be launched remotely.…
AnalizadaMedia (6.9)0.65%—Gosuncntech Group Audio-visual Integrated Management11/5/202517/6/2026
A vulnerability, which was classified as problematic, was found in Gosuncn Technology Group Audio-Visual Integrated Management Platform 4.0. Affected is an unknown function of the file /config/config.properties of the component Configuration File Handler. The manipulation leads to information disclosure. It is…
AnalizadaMedia (6.9)0.60%—Caishixiong Modern Farm Digital Integrated Management System10/3/202517/6/2026
A vulnerability was found in Beijing Zhide Intelligent Internet Technology Modern Farm Digital Integrated Management System 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to files or directories accessible. It is possible to launch the attack remotely. The exploit…
AplazadaAlta (7.3)0.25%—AMD Integrated Management TechnologyAI11/2/202517/6/2026
A DLL hijacking vulnerability in AMD Integrated Management Technology (AIM-T) Manageability Service could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
AplazadaAlta (7.3)0.22%—AMD Integrated Management TechnologyAI11/2/202517/6/2026
Incorrect default permissions in the AMD Integrated Management Technology (AIM-T) Manageability Service installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
AplazadaMedia (5.4)0.62%—Cisco Integrated Management ControllerAI18/11/202417/6/2026
A vulnerability in the API endpoints of Cisco Integrated Management Controller could allow an authenticated, remote attacker to bypass authorization and take actions on a vulnerable system without authorization. The vulnerability is due to improper authorization checks on API endpoints. An attacker could exploit…