Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2693▼ 77 respecto a la semana anterior
Críticas / altas1446▲ 303 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2) | 0.33% | — | Campcodes Division Regional Athletic Meet Game Result Matrix SystemAI | 12/3/2026 | 17/6/2026 | A weakness has been identified in Campcodes Division Regional Athletic Meet Game Result Matrix System 2.1. This vulnerability affects unknown code of the file save_up_athlete.php. This manipulation of the argument a_name causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been… | |
| Aplazada | Baja (2) | 0.33% | — | Campcodes Division Regional Athletic Meet Game Result Matrix SystemAI | 12/3/2026 | 17/6/2026 | A security flaw has been discovered in Campcodes Division Regional Athletic Meet Game Result Matrix System 2.1. This affects an unknown part of the file save-games.php. The manipulation of the argument game_name results in cross site scripting. The attack may be performed from remote. The exploit has been released to… | |
| Aplazada | Media (5.4) | 0.33% | — | Aiphone IX SystemAIAiphone IXG SystemAIAiphone System Support SoftwareAI | 22/11/2024 | 17/6/2026 | Use of hard-coded cryptographic key issue exists in AIPHONE IX SYSTEM, IXG SYSTEM, and System Support Software. A network-adjacent unauthenticated attacker may log in to SFTP service and obtain and/or manipulate unauthorized files. | |
| Aplazada | Media (6.5) | 0.37% | — | Aiphone IX SystemAIAiphone IXG SystemAI | 22/11/2024 | 17/6/2026 | Insufficiently protected credentials issue exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent unauthenticated attacker may obtain sensitive information such as a username and its password in the address book. | |
| Aplazada | Alta (8) | 1.1% | — | Aiphone IX SystemAIAiphone IXG SystemAI | 22/11/2024 | 17/6/2026 | OS command injection vulnerability exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent authenticated attacker may execute an arbitrary OS command with root privileges by sending a specially crafted request. | |
| Modificada | Crítica (9.8) | 0.76% | — | Game Result Matrix System Project Game Result Matrix System | 23/6/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Game Result Matrix System 1.0. This affects an unknown part of the file /dipam/athlete-profile.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack… | |
| Modificada | Media (6.1) | 0.57% | — | Game Result Matrix System Project Game Result Matrix System | 23/6/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in SourceCodester Game Result Matrix System 1.0. Affected by this issue is some unknown functionality of the file /dipam/save-delegates.php of the component GET Parameter Handler. The manipulation of the argument del_name leads to cross site… | |
| Modificada | Alta (8.1) | 12% | — | Libssh2Debian LinuxFedoraproject FedoraNetapp Cloud Backup+3 | 16/7/2019 | 17/6/2026 | In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to an out-of-bounds read in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to disclose sensitive information or cause a denial of… | |
| Modificada | Alta (7.5) | 74% | — | Redhat VirtualizationRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+34 | 6/8/2018 | 17/6/2026 | Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service. | |
| Modificada | Alta (7.5) | 2.5% | — | Invisionix Systems Invisionix Roaming System Remote | 21/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in pageheaderdefault.inc.php in Invisionix Roaming System Remote (IRSR) 0.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _sysSessionPath parameter. |