Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.43% | — | Ankara Hosting Site Management PanelAI | 31/8/2026 | 1/9/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Ankara Hosting Site Management Panel allows SQL Injection. This issue affects Site Management Panel: through 15062026. | |
| Aplazada | Alta (8.2) | 0.44% | — | FTC Software IT Services FTC E-commerce Management PanelAI | 30/7/2026 | 30/7/2026 | Missing authentication for critical function vulnerability in FTC Software IT Services FTC E-Commerce Management Panel allows Authentication Bypass. This issue affects FTC E-Commerce Management Panel: before 1.0.2. | |
| Aplazada | Alta (8.3) | 0.28% | — | Kenik Camera Management PanelAIKenik Kg-5260xxxx-il- G 2AI | 25/5/2026 | 23/7/2026 | Kenik Camera management Panel is vulnerable to Path Traversal vulnerability. An unauthenticated attacker can send GET request with arbitrary file path and read corresponding files located on the server. The issue was fixed in version 2026-04-23 of the KG-5260xxxx-IL-(G)2 cameras. Rest of the products were fixed in… | |
| Modificada | Crítica (9.8) | 0.53% | — | Ween Management Panel | 29/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ween Software Admin Panel allows SQL Injection. This issue affects Admin Panel: through 20231229. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Modificada | Media (4.3) | 0.71% | — | Techno - Portfolio Management Panel Project Techno - Portfolio Management Panel | 15/12/2017 | 17/6/2026 | Techno - Portfolio Management Panel through 2017-11-16 allows full path disclosure via an invalid s parameter to panel/search.php. | |
| Modificada | Alta (8.8) | 0.96% | — | Techno - Portfolio Management Panel Project Techno - Portfolio Management Panel | 15/12/2017 | 17/6/2026 | Techno - Portfolio Management Panel through 2017-11-16 allows SQL Injection via the panel/search.php s parameter. | |
| Modificada | Media (5.4) | 0.51% | — | Techno - Portfolio Management Panel Project Techno - Portfolio Management Panel | 15/12/2017 | 17/6/2026 | Techno - Portfolio Management Panel through 2017-11-16 allows XSS via the panel/search.php s parameter. | |
| Modificada | Media (4.3) | 0.55% | — | Techno - Portfolio Management Panel Project Techno - Portfolio Management Panel | 15/12/2017 | 17/6/2026 | Techno - Portfolio Management Panel through 2017-11-16 does not check authorization for panel/portfolio.php?action=delete requests that remove feedback. | |
| Modificada | Crítica (9.8) | 8.6% | 💥 Exploit | Techno - Portfolio Management Panel Project Techno - Portfolio Management Panel | 11/12/2017 | 17/6/2026 | Techno Portfolio Management Panel 1.0 allows an attacker to inject SQL commands via a single.php?id= request. |