Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2564▼ 301 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

13 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.1)0.27%—Eleveo Quality ManagementAI28/9/202629/9/2026
A security flaw has been discovered in Eleveo Quality Management 9.7.0. This issue affects the function UtilsService.createAndSaveAudit of the file /qm/cz.zoom.scorecard.webui.Scorecard/QMUtilsService of the component GWT RPC Handler. Performing a manipulation results in information disclosure. The attack is possible…
AplazadaBaja (2.1)0.36%—Eleveo Quality ManagementAI28/9/202629/9/2026
A vulnerability was found in Eleveo Quality Management 9.7.0. Affected by this issue is some unknown functionality of the file /qm/cz.zoom.scorecard.webui.Scorecard/cz.zoom.scorecard.webui.Scorecard/QMBODownload. The manipulation results in information disclosure. The attack may be launched remotely. The exploit has…
AplazadaBaja (2.1)0.34%—Eleveo Quality ManagementAI28/9/20261/10/2026
A vulnerability has been found in Eleveo Quality Management 9.7.0. Affected by this vulnerability is an unknown functionality of the file Scorecard.jsp of the component Questionnaire Audio Upload. The manipulation leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the…
AplazadaBaja (2.1)0.49%—Eleveo Quality ManagementAI4/9/20264/9/2026
A vulnerability was identified in Eleveo Quality Management 9.7.0. The affected element is the function QuestionnaireService.runDataExportNow of the component Questionnaire Service. Such manipulation of the argument file_name leads to path traversal. The attack may be performed from remote. The exploit is publicly…
AplazadaBaja (2.1)0.40%—Eleveo Quality ManagementAI4/9/202611/9/2026
A vulnerability was determined in Eleveo Quality Management 9.7.0. Impacted is an unknown function of the file /enc-fwk-data/api/v3/conversations/<ID>/events of the component Conversation Handler. This manipulation of the argument createdBy causes dynamically-determined object attributes. The attack is possible to be…
AplazadaBaja (2.1)0.47%—Eleveo Quality ManagementAI4/9/20264/9/2026
A vulnerability was found in Eleveo Quality Management 9.7.0. This issue affects some unknown processing of the file /enc-fwk-data/api/v3/conversations/<ID>/events of the component Conversation Handler. The manipulation of the argument labels results in denial of service. The attack can be executed remotely. The…
AplazadaBaja (2)0.33%—Eleveo Quality ManagementAI4/9/20268/9/2026
A vulnerability has been found in Eleveo Quality Management 9.7.0. This vulnerability affects unknown code of the component Conversation Review. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was…
AnalizadaMedia (5.3)0.21%—Verint Verba Collaboration Compliance AND Quality Management Platform14/5/202617/6/2026
Verba is affected by a Stored Cross-Site Scripting (XSS) vulnerability within its login logging mechanism. When an unauthenticated remote attacker attempts to log in using an incorrect username and password combination, the supplied username value is recorded in the application logs. Due to lack of input sanitization,…
AplazadaCrítica (9.8)0.59%—Mergentech Quality Management SystemAI25/3/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mergen Software Quality Management System allows SQL Injection. This issue affects Quality Management System: through 25032024.
ModificadaCrítica (9.8)0.53%—Mergentech Quality Management System18/1/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mergen Software Quality Management System allows SQL Injection. This issue affects Quality Management System: before v1.2.
ModificadaMedia (4.3)0.69%—SAP Quality Management13/11/201917/6/2026
An SQL Injection vulnerability in SAP Quality Management (corrected in S4CORE versions 1.0, 1.01, 1.02, 1.03) allows an attacker to carry out targeted database queries that can read individual fields of historical inspection results.
ModificadaAlta (8.8)2.2%—Verint Collaboration ComplianceVerint Quality Management Platform4/10/201817/6/2026
Verba Collaboration Compliance and Quality Management Platform before 9.2.1.5545 has Insecure Permissions.
ModificadaMedia (6.5)1.8%—Verint Verba Collaboration Compliance AND Quality Management Platform4/10/201817/6/2026
Verba Collaboration Compliance and Quality Management Platform before 9.2.1.5545 has Incorrect Access Control.