Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2838▼ 146 respecto a la semana anterior
Críticas / altas1377▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 268 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.24% | — | Itpison Omicard EDMAI | 4/6/2026 | 22/7/2026 | OMICARD EDM developed by ITPison has a Insecure Direct Object Reference vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to obtain user's email address. | |
| Aplazada | Media (5.3) | 0.45% | — | Itpison Omicard EDMAI | 15/5/2024 | 17/6/2026 | ITPison OMICARD EDM fails to properly filter specific URL parameter, allowing unauthenticated remote attackers to modify the parameters and conduct Server-Side Request Forgery (SSRF) attacks. This vulnerability enables attackers to probe internal network information. | |
| Modificada | Alta (7.5) | 1.3% | — | Itpison Omicard EDM | 15/12/2023 | 17/6/2026 | ITPison OMICARD EDM has a path traversal vulnerability within its parameter “FileName” in a specific function. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files. | |
| Modificada | Crítica (9.8) | 1.1% | — | Itpison Omicard EDM | 15/12/2023 | 17/6/2026 | ITPison OMICARD EDM 's SMS-related function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify and delete database. | |
| Modificada | Crítica (9.8) | 0.96% | — | Itpison Omicard EDM | 15/12/2023 | 17/6/2026 | ITPison OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system commands or disrupt service. | |
| Modificada | Crítica (9.8) | 0.93% | — | Itpison Omicard EDM | 16/6/2023 | 17/6/2026 | OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system commands or disrupt service. | |
| Modificada | Media (6.8) | 0.33% | — | Itpison Omicard EDM | 2/6/2023 | 17/6/2026 | OMICARD EDM backend system’s file uploading function does not restrict upload of file with dangerous type. A local area network attacker with administrator privileges can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system commands or disrupt service. | |
| Modificada | Alta (7.5) | 1.4% | — | Omicard EDM Project Omicard EDM | 4/8/2022 | 17/6/2026 | OMICARD EDM’s mail image relay function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to by-pass authentication and access arbitrary system files. | |
| Modificada | Crítica (9.8) | 1.5% | — | Omicard EDM Project Omicard EDM | 4/8/2022 | 17/6/2026 | OMICARD EDM has a hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to execute arbitrary code, manipulate system data and disrupt service. | |
| Modificada | Crítica (9.8) | 1.4% | — | Omicard EDM Project Omicard EDM | 4/8/2022 | 17/6/2026 | OMICARD EDM’s API function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL commands to access, modify, delete database or disrupt service. | |
| Modificada | Alta (7.5) | 1.4% | — | Omicard EDM Project Omicard EDM | 4/8/2022 | 17/6/2026 | OMICARD EDM’s mail file relay function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to by-pass authentication and access arbitrary system files. |