Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2556▼ 352 respecto a la semana anterior
Críticas / altas1335▲ 66 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
195 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.49% | — | Document Merge ServiceAI | 1/10/2026 | 2/10/2026 | Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Prior to version 9.1.0, a remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as… | |
| Aplazada | Alta (7.5) | 0.30% | — | Wellav WES Emergency Broadcast TerminalAI | 25/9/2026 | 30/9/2026 | An issue in Wellav Technologies Co., Ltd Wellav WES Emergency Broadcast Terminal WES100, WES270, WES280, and WES290 before 08-08-2023 allows a remote attacker to obtain sensitive information via the global API request wrapper function | |
| Pendiente de análisis | Media (6.8) | 0.17% | — | Araxis MergeAI | 24/9/2026 | 26/9/2026 | Araxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for remote servers in the Windows registry and does not apply sufficient cryptographic protection. An authenticated, non-administrative attacker could retrieve and unencrypt all credentials the target user has stored in Merge. | |
| Aplazada | Alta (8.7) | 0.51% | — | DeepmergeAI | 18/9/2026 | 23/9/2026 | deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to inject attacker-controlled properties into the returned object's prototype,… | |
| Aplazada | Alta (8.2) | 0.52% | — | Deepmerge-tsAI | 20/8/2026 | 18/9/2026 | deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. Prior to 8.0.0, the deepmerge, deepmergeCustom, deepmergeInto, and deepmergeIntoCustom APIs do not track visited objects or object pairs when recursively merging records. When two input values contain self-references at… | |
| Aplazada | Media (5.5) | 0.51% | — | Ts-deepmergeAI | 19/6/2026 | 23/6/2026 | Versions of the package ts-deepmerge before 8.0.0 are vulnerable to Uncaught Exception due to the improper handling of built-in Object.prototype methods (such as toString, valueOf). When user-controlled input contains these keys with non-function values, the resulting merged object becomes broken — any string context… | |
| Aplazada | Media (4.3) | 0.13% | — | Andy Moyle Emergency Password ResetAI | 17/6/2026 | 1/10/2026 | Cross-Site request forgery (CSRF) vulnerability in Andy Moyle Emergency Password Reset allows Cross Site Request Forgery. This issue affects Emergency Password Reset: from n/a through 8.0. | |
| Aplazada | Media (4.3) | 0.19% | — | EmergencywpAI | 3/6/2026 | 22/7/2026 | The EmergencyWP – Dead Man's switch & legacy deliverance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing or incorrect nonce validation on the form_settings_ui (settings save handler, procedural include scope) function. This makes it… | |
| Pendiente de análisis | Media (6.9) | 0.14% | — | Merge PacsAI | 29/4/2026 | 17/6/2026 | Merge PACS 7.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms targeting the merge-viewer endpoint. Attackers can submit POST requests to /servlet/actions/merge-viewer/summary with login credentials to hijack user sessions and… | |
| Pendiente de análisis | Crítica (9.3) | 0.67% | — | Intrado 911 Emergency GatewayAI | 23/4/2026 | 17/6/2026 | Intrado 911 Emergency Gateway (EGW) 5.x, 6.x, and 7.x contain a path traversal vulnerability in the download_debuglog_file.php endpoint used for Debug Logs downloads. An unauthenticated attacker can manipulate the name parameter to read arbitrary files outside the intended directory. | |
| Aplazada | Media (6.9) | 0.56% | — | Brikcss MergeAI | 20/4/2026 | 17/6/2026 | A vulnerability was determined in brikcss merge up to 1.3.0. This affects an unknown part. Executing a manipulation of the argument __proto__/constructor.prototype/prototype can lead to improperly controlled modification of object prototype attributes. The attack may be performed from remote. The vendor was contacted… | |
| Aplazada | Alta (8.5) | 0.15% | — | SPY EmergencyAI | 4/4/2026 | 21/7/2026 | Spy Emergency build 23.0.205 contains an unquoted service path vulnerability in the SpyEmrgHealth and SpyEmrgSrv services that allows local attackers to escalate privileges by inserting malicious executables. Attackers can place executable files in the unquoted service path and trigger service restart or system reboot… | |
| Analizada | Media (6.5) | 0.25% | — | IBM DB2 Merge Backup | 17/2/2026 | 17/6/2026 | IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an authenticated user to cause the program to crash due to a buffer being overwritten when it is allocated on the stack. | |
| Analizada | Media (6.5) | 0.25% | — | IBM DB2 Merge Backup | 17/2/2026 | 17/6/2026 | IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an authenticated user to cause the program to crash due to the incorrect calculation of a buffer size. | |
| Analizada | Alta (7.5) | 0.19% | — | IBM DB2 Merge Backup | 17/2/2026 | 17/6/2026 | IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an attacker to access sensitive information in memory due to the buffer not properly clearing resources. | |
| Aplazada | Media (5.4) | 0.11% | — | Launchinteractive Merge Minify RefreshAI | 22/1/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in launchinteractive Merge + Minify + Refresh merge-minify-refresh allows Cross Site Request Forgery.This issue affects Merge + Minify + Refresh: from n/a through <= 2.14. | |
| Aplazada | Alta (8.5) | 0.17% | — | SPY EmergencyAI | 16/1/2026 | 17/6/2026 | Spy Emergency 25.0.650 contains an unquoted service path vulnerability in its Windows service configurations that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted file paths in SpyEmergencyHealth.exe and SpyEmergencySrv.exe to inject malicious code during system… | |
| Analizada | Media (6.9) | 2.7% | — | Dontkry Willitmerge | 29/11/2025 | 17/6/2026 | willitmerge is a command line tool to check if pull requests are mergeable. In versions 0.2.1 and prior, there is a command Injection vulnerability in willitmerge. The vulnerability manifests in this package due to the use of insecure child process execution API (exec) to which it concatenates user input, whether… | |
| Aplazada | Crítica (9.8) | 0.35% | — | Callvision Healthcare Callvision Emergency CodeAI | 7/10/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Callvision Healthcare Callvision Emergency Code allows SQL Injection, Blind SQL Injection. This issue affects Callvision Emergency Code: before V3.0. | |
| Aplazada | Media (4.3) | 0.17% | — | Andy Moyle Emergency Password ResetAI | 22/9/2025 | 30/9/2026 | Cross-Site Request Forgery (CSRF) vulnerability in andy_moyle Emergency Password Reset emergency-password-reset allows Cross Site Request Forgery.This issue affects Emergency Password Reset: from n/a through <= 9.3. | |
| Aplazada | Baja (2.1) | 0.29% | — | Papermerge DMSAI | 10/9/2025 | 25/9/2026 | A security flaw has been discovered in Papermerge DMS up to 3.5.3. This issue affects some unknown processing of the component Authorization Token Handler. Performing manipulation results in improper authorization. The attack can be initiated remotely. The exploit has been released to the public and may be exploited.… | |
| Aplazada | Crítica (9.3) | 0.63% | — | Bian QUE Feijiu Intelligent Emergency AND Quality Control SystemAI | 27/8/2025 | 25/9/2026 | An unauthenticated SQL injection vulnerability exists in the GetLyfsByParams endpoint of Bian Que Feijiu Intelligent Emergency and Quality Control System, accessible via the /AppService/BQMedical/WebServiceForFirstaidApp.asmx interface. The backend fails to properly sanitize user-supplied input in the strOpid… | |
| Aplazada | Alta (7.5) | 0.56% | — | Gravitywp - Merge TagsAI | 14/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in GravityWP GravityWP - Merge Tags gravitywp-merge-tags allows PHP Local File Inclusion.This issue affects GravityWP - Merge Tags: from n/a through <= 1.4.4. | |
| Analizada | Media (5.5) | 0.48% | — | Phpgurukul Emergency Ambulance Hiring Portal | 20/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument Message leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Analizada | Baja (2.1) | 0.40% | — | Phpgurukul Emergency Ambulance Hiring Portal | 20/6/2025 | 17/6/2026 | A vulnerability classified as critical was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/add-ambulance.php. The manipulation of the argument ambregnum leads to sql injection. The attack can be launched remotely. The exploit has… |