Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2610▼ 308 respecto a la semana anterior
Críticas / altas1345▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.50% | — | Oasys SysoaAI | 4/9/2026 | 9/9/2026 | SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attacker to execute arbitrary code via the outtype parameter in the /outaddresspaging path | |
| Analizada | Media (5.3) | 0.29% | — | Misstt123 Oasys | 16/4/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in misstt123 oasys 1.0. Affected by this issue is some unknown functionality of the component Sticky Notes Handler. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.65% | — | Misstt123 Oasys | 16/4/2025 | 17/6/2026 | A vulnerability classified as problematic was found in misstt123 oasys 1.0. Affected by this vulnerability is the function image of the file /show. The manipulation leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use… | |
| Analizada | Alta (7.5) | 0.53% | — | Misstt123 Oasys | 1/11/2024 | 17/6/2026 | An issue in the component /logins of oasys v1.1 allows attackers to access sensitive information via a burst attack. | |
| Modificada | Media (6.5) | 1.1% | — | Oasys Project Oasys | 30/3/2022 | 17/6/2026 | An SQL Injection vulnerability exists in oasys oa_system as of 9/7/2021 in resources/mappers/notice-mapper.xml. | |
| Modificada | Alta (7.5) | 1.0% | — | Onlinetechtools.com Oasys Professional | 5/11/2010 | 16/6/2026 | SQL injection vulnerability in process.asp in OnlineTechTools Online Work Order System (OWOS) Professional Edition 2.10 allows remote attackers to execute arbitrary SQL commands via the password parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Baja (2.6) | 1.2% | — | Oasyssoft E-business Designer | 12/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in form_grupo.html in E-Business Designer (eBD) 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this issue might be resultant from SQL injection. | |
| Modificada | Media (5) | 1.4% | — | Oasyssoft E-business Designer | 12/5/2006 | 16/6/2026 | E-Business Designer (eBD) 3.1.4 and earlier allows remote attackers to obtain the full path of the web server via "'" characters, and possibly other invalid values, in (1) the id parameter to form_grupo.html, or requests to the (2) archivos/ and (3) files/ directories. NOTE: this issue might be resultant from SQL… | |
| Modificada | Media (6.8) | 8.7% | — | Oasyssoft E-business Designer | 12/5/2006 | 16/6/2026 | E-Business Designer (eBD) 3.1.4 and earlier allows remote attackers to upload or modify arbitrary files, and execute arbitrary code, via a direct request to (1) common/html_editor/image_browser.upload.html, (2) common/html_editor/image_browser.html, or (3) common/html_editor/html_editor.html. NOTE: this can also be… | |
| Modificada | Media (4.3) | 1.2% | — | Onlinetechtools.com Oasys Lite | 27/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.asp in Online Attendance System (OASYS) Lite 1.0 allows remote attackers to inject arbitrary web script or HTML via certain search parameters, possibly the keyword parameter. |