Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2556▼ 352 respecto a la semana anterior
Críticas / altas1335▲ 66 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
–

195 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.49%—Document Merge ServiceAI1/10/20262/10/2026
Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Prior to version 9.1.0, a remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as…
AplazadaAlta (7.5)0.30%—Wellav WES Emergency Broadcast TerminalAI25/9/202630/9/2026
An issue in Wellav Technologies Co., Ltd Wellav WES Emergency Broadcast Terminal WES100, WES270, WES280, and WES290 before 08-08-2023 allows a remote attacker to obtain sensitive information via the global API request wrapper function
Pendiente de análisisMedia (6.8)0.17%—Araxis MergeAI24/9/202626/9/2026
Araxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for remote servers in the Windows registry and does not apply sufficient cryptographic protection. An authenticated, non-administrative attacker could retrieve and unencrypt all credentials the target user has stored in Merge.
AplazadaAlta (8.7)0.51%—DeepmergeAI18/9/202623/9/2026
deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to inject attacker-controlled properties into the returned object's prototype,…
AplazadaAlta (8.2)0.52%—Deepmerge-tsAI20/8/202618/9/2026
deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. Prior to 8.0.0, the deepmerge, deepmergeCustom, deepmergeInto, and deepmergeIntoCustom APIs do not track visited objects or object pairs when recursively merging records. When two input values contain self-references at…
AplazadaMedia (5.5)0.51%—Ts-deepmergeAI19/6/202623/6/2026
Versions of the package ts-deepmerge before 8.0.0 are vulnerable to Uncaught Exception due to the improper handling of built-in Object.prototype methods (such as toString, valueOf). When user-controlled input contains these keys with non-function values, the resulting merged object becomes broken — any string context…
AplazadaMedia (4.3)0.13%—Andy Moyle Emergency Password ResetAI17/6/20261/10/2026
Cross-Site request forgery (CSRF) vulnerability in Andy Moyle Emergency Password Reset allows Cross Site Request Forgery. This issue affects Emergency Password Reset: from n/a through 8.0.
AplazadaMedia (4.3)0.19%—EmergencywpAI3/6/202622/7/2026
The EmergencyWP – Dead Man's switch & legacy deliverance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing or incorrect nonce validation on the form_settings_ui (settings save handler, procedural include scope) function. This makes it…
Pendiente de análisisMedia (6.9)0.14%—Merge PacsAI29/4/202617/6/2026
Merge PACS 7.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms targeting the merge-viewer endpoint. Attackers can submit POST requests to /servlet/actions/merge-viewer/summary with login credentials to hijack user sessions and…
Pendiente de análisisCrítica (9.3)0.67%—Intrado 911 Emergency GatewayAI23/4/202617/6/2026
Intrado 911 Emergency Gateway (EGW) 5.x, 6.x, and 7.x contain a path traversal vulnerability in the download_debuglog_file.php endpoint used for Debug Logs downloads. An unauthenticated attacker can manipulate the name parameter to read arbitrary files outside the intended directory.
AplazadaMedia (6.9)0.56%—Brikcss MergeAI20/4/202617/6/2026
A vulnerability was determined in brikcss merge up to 1.3.0. This affects an unknown part. Executing a manipulation of the argument __proto__/constructor.prototype/prototype can lead to improperly controlled modification of object prototype attributes. The attack may be performed from remote. The vendor was contacted…
AplazadaAlta (8.5)0.15%—SPY EmergencyAI4/4/202621/7/2026
Spy Emergency build 23.0.205 contains an unquoted service path vulnerability in the SpyEmrgHealth and SpyEmrgSrv services that allows local attackers to escalate privileges by inserting malicious executables. Attackers can place executable files in the unquoted service path and trigger service restart or system reboot…
AnalizadaMedia (6.5)0.25%—IBM DB2 Merge Backup17/2/202617/6/2026
IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an authenticated user to cause the program to crash due to a buffer being overwritten when it is allocated on the stack.
AnalizadaMedia (6.5)0.25%—IBM DB2 Merge Backup17/2/202617/6/2026
IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an authenticated user to cause the program to crash due to the incorrect calculation of a buffer size.
AnalizadaAlta (7.5)0.19%—IBM DB2 Merge Backup17/2/202617/6/2026
IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an attacker to access sensitive information in memory due to the buffer not properly clearing resources.
AplazadaMedia (5.4)0.11%—Launchinteractive Merge Minify RefreshAI22/1/202617/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in launchinteractive Merge + Minify + Refresh merge-minify-refresh allows Cross Site Request Forgery.This issue affects Merge + Minify + Refresh: from n/a through <= 2.14.
AplazadaAlta (8.5)0.17%—SPY EmergencyAI16/1/202617/6/2026
Spy Emergency 25.0.650 contains an unquoted service path vulnerability in its Windows service configurations that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted file paths in SpyEmergencyHealth.exe and SpyEmergencySrv.exe to inject malicious code during system…
AnalizadaMedia (6.9)2.7%—Dontkry Willitmerge29/11/202517/6/2026
willitmerge is a command line tool to check if pull requests are mergeable. In versions 0.2.1 and prior, there is a command Injection vulnerability in willitmerge. The vulnerability manifests in this package due to the use of insecure child process execution API (exec) to which it concatenates user input, whether…
AplazadaCrítica (9.8)0.35%—Callvision Healthcare Callvision Emergency CodeAI7/10/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Callvision Healthcare Callvision Emergency Code allows SQL Injection, Blind SQL Injection. This issue affects Callvision Emergency Code: before V3.0.
AplazadaMedia (4.3)0.17%—Andy Moyle Emergency Password ResetAI22/9/202530/9/2026
Cross-Site Request Forgery (CSRF) vulnerability in andy_moyle Emergency Password Reset emergency-password-reset allows Cross Site Request Forgery.This issue affects Emergency Password Reset: from n/a through <= 9.3.
AplazadaBaja (2.1)0.29%—Papermerge DMSAI10/9/202525/9/2026
A security flaw has been discovered in Papermerge DMS up to 3.5.3. This issue affects some unknown processing of the component Authorization Token Handler. Performing manipulation results in improper authorization. The attack can be initiated remotely. The exploit has been released to the public and may be exploited.…
AplazadaCrítica (9.3)0.63%—Bian QUE Feijiu Intelligent Emergency AND Quality Control SystemAI27/8/202525/9/2026
An unauthenticated SQL injection vulnerability exists in the GetLyfsByParams endpoint of Bian Que Feijiu Intelligent Emergency and Quality Control System, accessible via the /AppService/BQMedical/WebServiceForFirstaidApp.asmx interface. The backend fails to properly sanitize user-supplied input in the strOpid…
AplazadaAlta (7.5)0.56%—Gravitywp - Merge TagsAI14/8/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in GravityWP GravityWP - Merge Tags gravitywp-merge-tags allows PHP Local File Inclusion.This issue affects GravityWP - Merge Tags: from n/a through <= 1.4.4.
AnalizadaMedia (5.5)0.48%—Phpgurukul Emergency Ambulance Hiring Portal20/6/202517/6/2026
A vulnerability, which was classified as critical, has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument Message leads to sql injection. The attack may be launched remotely. The exploit has been…
AnalizadaBaja (2.1)0.40%—Phpgurukul Emergency Ambulance Hiring Portal20/6/202517/6/2026
A vulnerability classified as critical was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/add-ambulance.php. The manipulation of the argument ambregnum leads to sql injection. The attack can be launched remotely. The exploit has…