Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 306 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
71 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.41% | — | Raisecom Communication Command AND Dispatch Management PlatformAI | 14/8/2026 | 14/8/2026 | A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform up to 7.6.5. This affects an unknown part of the file /app/users/getpwd.php. Such manipulation of the argument sip leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might… | |
| Aplazada | Media (5.5) | 0.41% | — | Hanwang E-face General Management PlatformAI | 5/7/2026 | 6/7/2026 | A vulnerability was identified in Hanwang e-Face General Management Platform 6.3.5.4. This impacts an unknown function of the file /sysAuthStr/querySysAuthStr.do. The manipulation of the argument order leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might… | |
| Aplazada | Media (5.5) | 0.47% | — | Hanwang E-face General Management PlatformAI | 29/6/2026 | 29/6/2026 | A vulnerability was determined in Hanwang e-Face General Management Platform 6.3.5.4. This issue affects some unknown processing of the file /manage/resourceUpload/upload.do. Executing a manipulation of the argument File can lead to unrestricted upload. The attack may be launched remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.46% | — | Tiandy Easy7 Integrated Management PlatformAI | 25/5/2026 | 23/7/2026 | A vulnerability was determined in Tiandy Easy7 Integrated Management Platform 7.17.0. This issue affects some unknown processing of the file /rest/user/updateUserPassword of the component API Endpoint. Executing a manipulation can lead to weak password recovery. The attack can be executed remotely. The exploit has… | |
| Aplazada | Media (5.5) | 0.41% | — | Tiandy Easy7 Integrated Management PlatformAI | 25/5/2026 | 23/7/2026 | A vulnerability was found in Tiandy Easy7 Integrated Management Platform 7.17.0. This vulnerability affects unknown code of the file /Easy7/apps/WebService/GetDBDataEx.jsp. Performing a manipulation of the argument strTBName results in sql injection. Remote exploitation of the attack is possible. The exploit has been… | |
| Analizada | Media (5.3) | 0.21% | — | Verint Verba Collaboration Compliance AND Quality Management Platform | 14/5/2026 | 17/6/2026 | Verba is affected by a Stored Cross-Site Scripting (XSS) vulnerability within its login logging mechanism. When an unauthenticated remote attacker attempts to log in using an incorrect username and password combination, the supplied username value is recorded in the application logs. Due to lack of input sanitization,… | |
| Aplazada | Media (5.5) | 3.2% | — | Tiandy Easy7 Integrated Management PlatformAI | 3/5/2026 | 17/6/2026 | A vulnerability was identified in Tiandy Easy7 Integrated Management Platform 7.17.0. Affected by this vulnerability is an unknown functionality of the file /Easy7/rest/systemInfo/updateDbBackupInfo. Such manipulation of the argument week leads to os command injection. The attack can be executed remotely. The exploit… | |
| Aplazada | Alta (8.9) | 5.7% | — | Tiandy Easy7 Integrated Management PlatformAI | 23/3/2026 | 17/6/2026 | A vulnerability has been found in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This vulnerability affects unknown code of the file /Easy7/apps/WebService/ImportSystemConfiguration.jsp of the component Configuration Handler. The manipulation of the argument File leads to os command injection. The attack… | |
| Aplazada | Media (5.5) | 0.41% | — | Tiandy Easy7 Integrated Management PlatformAI | 17/3/2026 | 17/6/2026 | A security vulnerability has been detected in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This affects an unknown function of the file /rest/preSetTemplate/getRecByTemplateId. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed… | |
| Aplazada | Media (5.5) | 0.41% | — | Tiandy Easy7 Integrated Management PlatformAI | 17/3/2026 | 17/6/2026 | A weakness has been identified in Tiandy Easy7 Integrated Management Platform 7.17.0. The impacted element is an unknown function of the file /rest/devStatus/getDevDetailedInfo of the component Endpoint. Executing a manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The… | |
| Aplazada | Media (5.5) | 0.41% | — | Tiandy Easy7 Integrated Management PlatformAI | 17/3/2026 | 17/6/2026 | A security flaw has been discovered in Tiandy Easy7 Integrated Management Platform 7.17.0. The affected element is an unknown function of the file /rest/devStatus/queryResources of the component Endpoint. Performing a manipulation of the argument areaId results in sql injection. The attack can be initiated remotely.… | |
| Aplazada | Media (5.5) | 0.41% | — | Tiandy Integrated Management PlatformAI | 16/3/2026 | 17/6/2026 | A vulnerability was determined in Tiandy Integrated Management Platform 7.17.0. Affected by this issue is some unknown functionality of the file /rest/user/getAuthorityByUserId. Executing a manipulation of the argument userId can lead to sql injection. The attack may be launched remotely. The exploit has been publicly… | |
| Aplazada | Media (5.5) | 0.47% | — | Tiandy Easy7 Integrated Management PlatformAI | 16/3/2026 | 17/6/2026 | A vulnerability was found in Tiandy Easy7 Integrated Management Platform 7.17.0. This affects an unknown part of the file /rest/file/uploadLedImage of the component Endpoint. The manipulation of the argument File results in unrestricted upload. The attack may be launched remotely. The exploit has been made public and… | |
| Aplazada | Media (5.5) | 0.51% | — | Symantec Management PlatformAI | 16/3/2026 | 17/6/2026 | A vulnerability has been found in Technologies Integrated Management Platform 7.17.0. Affected by this issue is some unknown functionality of the file /SetWebpagePic.jsp. The manipulation of the argument targetPath/Suffix leads to unrestricted upload. The attack may be initiated remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.68% | — | Tiandy Easy7 Integrated Management PlatformAI | 16/3/2026 | 17/6/2026 | A vulnerability was identified in Tiandy Easy7 Integrated Management Platform 7.17.0. Impacted is an unknown function of the file /WebService/UpdateLocalDevInfo.jsp of the component Device Identifier Handler. Such manipulation of the argument username/password leads to missing authentication. The attack can be… | |
| Analizada | Media (5.5) | 0.74% | — | Shuoren Smart Heating Integrated Management Platform | 23/2/2026 | 17/6/2026 | A flaw has been found in ShuoRen Smart Heating Integrated Management Platform 1.0.0. Affected by this vulnerability is an unknown functionality of the file /MP/Service/Webservice/ExampleNodeService.asmx. Executing a manipulation of the argument File can lead to unrestricted upload. It is possible to launch the attack… | |
| Aplazada | Media (5.5) | 0.43% | — | Fujian Smart Integrated Management Platform SystemAI | 20/2/2026 | 17/6/2026 | A weakness has been identified in Fujian Smart Integrated Management Platform System up to 7.5. Impacted is an unknown function of the file /Module/CRXT/Controller/XCamera.ashx. This manipulation of the argument ChannelName causes sql injection. Remote exploitation of the attack is possible. The exploit has been made… | |
| Aplazada | Media (5.5) | 0.43% | — | Fujian Smart Integrated Management Platform SystemAI | 20/2/2026 | 17/6/2026 | A security flaw has been discovered in Fujian Smart Integrated Management Platform System up to 7.5. This issue affects some unknown processing of the file /Module/CRXT/Controller/XAccessPermissionPlus.ashx. The manipulation of the argument DeviceIDS results in sql injection. The attack may be launched remotely. The… | |
| Analizada | Media (6.5) | 0.27% | — | Summerpearlgroup Vacation Rental Management Platform | 31/10/2025 | 17/6/2026 | Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 does not properly invalidate active user sessions after a password change. This allows an attacker with a valid session token to maintain access to the account even after the legitimate user changes their password. | |
| Analizada | Media (6.3) | 0.20% | — | Summerpearlgroup Vacation Rental Management Platform | 31/10/2025 | 17/6/2026 | Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 suffers from insufficient server-side authorization. Authenticated attackers can call several endpoints and perform create/update/delete actions on resources owned by arbitrary users by manipulating request parameters (e.g., owner or resource id). | |
| Analizada | Alta (7.5) | 0.40% | — | Summerpearlgroup Vacation Rental Management Platform | 31/10/2025 | 17/6/2026 | Summer Pearl Group Vacation Rental Management Platform prior to 1.0.2 is susceptible to a Slowloris-style Denial-of-Service (DoS) condition in the HTTP connection handling layer, where an attacker that opens and maintains many slow or partially-completed HTTP connections can exhaust the server’s connection pool and… | |
| Aplazada | Crítica (9.8) | 0.53% | — | Aikaan IOT Management PlatformAI | 22/9/2025 | 17/6/2026 | Insufficient hardening of the proxyuser account in the AiKaan IoT management platform, combined with the use of a shared, hardcoded SSH private key, allows remote attackers to authenticate to the cloud controller, gain interactive shell access, and pivot into other connected IoT devices. This can lead to remote code… | |
| Aplazada | Baja (2) | 0.26% | — | Weaver E-mobile Mobile Management PlatformAI | 28/8/2025 | 25/9/2026 | A vulnerability was identified in Weaver E-Mobile Mobile Management Platform up to 20250813. Affected by this vulnerability is an unknown functionality. The manipulation of the argument gohome leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and might be used. The… | |
| Aplazada | Crítica (10) | 0.81% | — | Dahua Smart Park Integrated Management PlatformAI | 27/8/2025 | 3/9/2026 | A path traversal vulnerability exists in the Dahua Smart Park Integrated Management Platform (also referred to as the Dahua Smart Campus Integrated Management Platform), affecting the SOAP-based GIS bitmap upload interface. The flaw allows unauthenticated remote attackers to upload arbitrary files to the server via… | |
| Aplazada | Crítica (9.8) | 0.57% | — | Aikaan IOT Management PlatformAI | 21/8/2025 | 17/6/2026 | Aikaan IoT management platform v3.25.0325-5-g2e9c59796 provides a configuration to disable user sign-up in distributed deployments by hiding the sign-up option on the login page UI. However, the sign-up API endpoint remains publicly accessible and functional, allowing unauthenticated users to register accounts via… |