Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▲ 64 respecto a la semana anterior
Críticas / altas1484▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 448 respecto a la semana anterior
315 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.27% | — | Eleveo Quality ManagementAI | 28/9/2026 | 29/9/2026 | A security flaw has been discovered in Eleveo Quality Management 9.7.0. This issue affects the function UtilsService.createAndSaveAudit of the file /qm/cz.zoom.scorecard.webui.Scorecard/QMUtilsService of the component GWT RPC Handler. Performing a manipulation results in information disclosure. The attack is possible… | |
| Aplazada | Baja (2.1) | 0.36% | — | Eleveo Quality ManagementAI | 28/9/2026 | 29/9/2026 | A vulnerability was found in Eleveo Quality Management 9.7.0. Affected by this issue is some unknown functionality of the file /qm/cz.zoom.scorecard.webui.Scorecard/cz.zoom.scorecard.webui.Scorecard/QMBODownload. The manipulation results in information disclosure. The attack may be launched remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 0.34% | — | Eleveo Quality ManagementAI | 28/9/2026 | 1/10/2026 | A vulnerability has been found in Eleveo Quality Management 9.7.0. Affected by this vulnerability is an unknown functionality of the file Scorecard.jsp of the component Questionnaire Audio Upload. The manipulation leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Aplazada | Media (6.8) | 0.14% | — | Qualitysoft QNDAI | 16/9/2026 | 16/9/2026 | QND uses a hard-coded cryptographic key, which may allow a local attacker who is logged in to a Windows PC where the affected product's client is installed to obtain administrator credentials, including an ID and password. | |
| Aplazada | Alta (7.5) | 0.32% | — | Oracle E-business SuiteAIOracle QualityAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Quality. Successful attacks of this… | |
| Aplazada | Alta (7.1) | 0.29% | — | Oracle E-business SuiteAIOracle QualityAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Quality. Successful attacks of this… | |
| Aplazada | Baja (2.1) | 0.49% | — | Eleveo Quality ManagementAI | 4/9/2026 | 4/9/2026 | A vulnerability was identified in Eleveo Quality Management 9.7.0. The affected element is the function QuestionnaireService.runDataExportNow of the component Questionnaire Service. Such manipulation of the argument file_name leads to path traversal. The attack may be performed from remote. The exploit is publicly… | |
| Aplazada | Baja (2.1) | 0.40% | — | Eleveo Quality ManagementAI | 4/9/2026 | 11/9/2026 | A vulnerability was determined in Eleveo Quality Management 9.7.0. Impacted is an unknown function of the file /enc-fwk-data/api/v3/conversations/<ID>/events of the component Conversation Handler. This manipulation of the argument createdBy causes dynamically-determined object attributes. The attack is possible to be… | |
| Aplazada | Baja (2.1) | 0.47% | — | Eleveo Quality ManagementAI | 4/9/2026 | 4/9/2026 | A vulnerability was found in Eleveo Quality Management 9.7.0. This issue affects some unknown processing of the file /enc-fwk-data/api/v3/conversations/<ID>/events of the component Conversation Handler. The manipulation of the argument labels results in denial of service. The attack can be executed remotely. The… | |
| Aplazada | Baja (2) | 0.33% | — | Eleveo Quality ManagementAI | 4/9/2026 | 8/9/2026 | A vulnerability has been found in Eleveo Quality Management 9.7.0. This vulnerability affects unknown code of the component Conversation Review. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was… | |
| Analizada | Media (6.3) | 0.26% | — | Oracle Quality | 21/7/2026 | 17/8/2026 | Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Quality Workbench HTML system). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Quality. Successful attacks of… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Quality | 21/7/2026 | 30/7/2026 | Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Quality. Successful attacks of this… | |
| Analizada | Alta (8.2) | 0.36% | — | Oracle Quality | 21/7/2026 | 30/7/2026 | Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Quality. While the vulnerability is in… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Quality | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Quality. Successful attacks of this… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Quality | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Quality. Successful attacks of this… | |
| Analizada | Media (5.3) | 0.21% | — | Verint Verba Collaboration Compliance AND Quality Management Platform | 14/5/2026 | 17/6/2026 | Verba is affected by a Stored Cross-Site Scripting (XSS) vulnerability within its login logging mechanism. When an unauthenticated remote attacker attempts to log in using an incorrect username and password combination, the supplied username value is recorded in the application logs. Due to lack of input sanitization,… | |
| Aplazada | Media (5.3) | 0.31% | — | Code Quality Control ToolAI | 11/10/2025 | 17/6/2026 | The Code Quality Control Tool plugin for WordPress is vulnerable to Sensitive Information Exposure in version 2.1 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files. | |
| Aplazada | Crítica (9.3) | 0.63% | — | Bian QUE Feijiu Intelligent Emergency AND Quality Control SystemAI | 27/8/2025 | 25/9/2026 | An unauthenticated SQL injection vulnerability exists in the GetLyfsByParams endpoint of Bian Que Feijiu Intelligent Emergency and Quality Control System, accessible via the /AppService/BQMedical/WebServiceForFirstaidApp.asmx interface. The backend fails to properly sanitize user-supplied input in the strOpid… | |
| Analizada | Media (6.1) | 0.12% | — | Siemens Opcenter Quality | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < V2506), SOA Cockpit (All versions >= V13.2 < V2506). The affected application support insecure TLS 1.0 and 1.1 protocol. An attacker could achieve a man-in-the-middle… | |
| Analizada | Baja (2.1) | 0.17% | — | Siemens Opcenter Quality | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < V2506), SOA Cockpit (All versions >= V13.2 < V2506). The affected application does not expire the session without logout. This could allow an attacker to get unauthorized… | |
| Analizada | Baja (2.1) | 0.16% | — | Siemens Opcenter Quality | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < V2506), SOA Cockpit (All versions >= V13.2 < V2506). The affected application improperly handles error while accessing an inaccessible resource leading to exposing the… | |
| Analizada | Media (5.1) | 0.19% | — | Siemens Opcenter Quality | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < V2506), SOA Cockpit (All versions >= V13.2 < V2506). The affected application displays SQL statement in the error messages encountered during the generation of reports… | |
| Analizada | Media (5.9) | 0.08% | — | Siemens Opcenter Quality | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < V2506), SOA Cockpit (All versions >= V13.2 < V2506). The affected application does not have adequate encryption of sensitive information. This could allow an… | |
| Analizada | Baja (2) | 0.12% | — | Siemens Opcenter Quality | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < V2506), SOA Cockpit (All versions >= V13.2 < V2506). The affected application do not encrypt the communication in LDAP interface by default. This could allow an… | |
| Analizada | Alta (7.5) | 0.18% | — | Siemens Opcenter Quality | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < V2506), SOA Cockpit (All versions >= V13.2 < V2506). The affected application does not enforce mandatory authorization on some functionality level at server side. This… |