Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 331 respecto a la semana anterior
Críticas / altas1352▲ 94 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2) | 0.19% | — | Volotat AnagnorisisAI | 24/9/2026 | 24/9/2026 | A vulnerability was identified in volotat Anagnorisis up to 0.4.11. Affected by this issue is the function html of the file PlaylistManager.js of the component Media Filename Handler. Such manipulation of the argument file_path leads to cross site scripting. The attack can be launched remotely. The exploit is publicly… | |
| Aplazada | Baja (2.1) | 0.34% | — | Volotat AnagnorisisAI | 24/9/2026 | 24/9/2026 | A vulnerability was determined in volotat Anagnorisis up to 0.4.2. Affected by this vulnerability is the function get_file_content/save_file_content/move_files/start_streaming of the file page.html. This manipulation causes path traversal. The attack can be initiated remotely. The exploit has been publicly disclosed… | |
| Aplazada | Media (5.5) | 0.38% | — | Volotat AnagnorisisAI | 24/9/2026 | 29/9/2026 | A vulnerability was found in volotat Anagnorisis up to 0.3.1/0.4.0. Affected is an unknown function of the file app.py of the component Socket.IO Connect Interface. The manipulation results in missing authentication. It is possible to launch the attack remotely. The exploit has been made public and could be used. The… | |
| Aplazada | Alta (7.8) | 0.24% | — | Compugroup Medical CGM Isis MEDAI | 17/8/2026 | 31/8/2026 | An issue in CGM Germany - CompuGroup Medical CGM ISIS MED 2510.1.0.20 allows a remote attacker to execute arbtirary code via a crafted .dll file. | |
| Modificada | Media (5.3) | 1.4% | — | Apache Isis | 19/10/2022 | 17/6/2026 | When running in prototype mode, the h2 webconsole module (accessible from the Prototype menu) is automatically made available with the ability to directly query the database. It was felt that it is safer to require the developer to explicitly enable this capability. As of 2.0.0-M8, this can now be done using the… | |
| Modificada | Media (6.1) | 1.3% | — | Apache Isis | 19/10/2022 | 17/6/2026 | Prior to 2.0.0-M9, it was possible for an end-user to set the value of an editable string property of a domain object to a value that would be rendered unchanged when the value was saved. In particular, the end-user could enter javascript or similar and this would be executed. As of this release, the inputted strings… | |
| Modificada | Media (5) | 2.5% | — | Aspindir Kisisel Radyo Script | 2/11/2010 | 16/6/2026 | Kisisel Radyo Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for sevvo/eco23.mdb. | |
| Modificada | Alta (7.5) | 1.0% | — | Aspindir Kisisel Radyo Script | 2/11/2010 | 16/6/2026 | SQL injection vulnerability in radyo.asp in Kisisel Radyo Script allows remote attackers to execute arbitrary SQL commands via the Id parameter. | |
| Modificada | Alta (7.5) | 1.00% | — | Stormboards Aaronnemisis Stormboards | 26/12/2008 | 16/6/2026 | SQL injection vulnerability in thread.php in stormBoards 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (5) | 2.9% | — | Wwwisis | 16/10/2007 | 16/6/2026 | Directory traversal vulnerability in wxis.exe in WWWISIS 7.1 allows local users to read arbitrary files via a .. (dot dot) in the IsisScript parameter to iah. | |
| Modificada | Media (4.3) | 1.5% | — | Wwwisis | 14/10/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in wxis.exe in WWWISIS 7.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a call to the iah/iah.xis IsisScript code, possibly involving the lang or exprSearch parameter. | |
| Modificada | Media (6.8) | 4.7% | — | Lead Technologies Leadtools Raster Image SDKLead Technologies Leadtools Raster Isis Object | 1/6/2007 | 16/6/2026 | Heap-based buffer overflow in a certain ActiveX control in LEADTOOLS LEAD Raster ISIS Object (LTRIS14e.DLL) 14.5.0.44 allows remote attackers to cause a denial of service (Internet Explorer crash) or execute arbitrary code via a long DriverName property, a different ActiveX control than CVE-2007-2827. | |
| Modificada | Alta (9.3) | 6.4% | — | Lead Technologies Leadtools Isis Activex Control | 22/5/2007 | 16/6/2026 | Heap-based buffer overflow in LEAD Technologies LEADTOOLS ISIS ActiveX Control (ltisi14E.ocx) 14.5.0.44 and earlier allows remote attackers to execute arbitrary code via a long DriverName property. | |
| Modificada | Alta (7.5) | 1.1% | — | Kisisel Site 2007 Kisisel Site Forum.asp | 7/2/2007 | 16/6/2026 | SQL injection vulnerability in forum.asp in Kisisel Site 2007 allows remote attackers to execute arbitrary SQL commands via the forumid parameter. | |
| Modificada | Alta (10) | 5.4% | — | Wwwisis | 12/8/2002 | 16/6/2026 | wwwisis 3.45 and earlier allows remote attackers to execute arbitrary commands and read files via the parameters (1) prolog or (2) epilog. |