Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2683▼ 54 respecto a la semana anterior
Críticas / altas1442▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
232 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2) | 0.25% | — | Phpgurukul Online Security Guards Hiring System | 18/7/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Online Security Guards Hiring System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/search.php. The manipulation of the argument searchdata leads to cross site scripting. The attack can be initiated remotely. The exploit has… | |
| Analizada | Media (6.5) | 0.40% | — | IBM Security Guardium | 28/5/2025 | 17/6/2026 | IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of input. | |
| Analizada | Media (4.3) | 0.28% | — | IBM Security Guardium | 28/5/2025 | 17/6/2026 | IBM Security Guardium 12.0 could allow an authenticated user to obtain sensitive information due to an incorrect authentication check. | |
| Analizada | Media (5.3) | 0.35% | — | IBM Security Guardium | 28/5/2025 | 17/6/2026 | IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | |
| Analizada | Media (5.5) | 0.24% | — | IBM Security Guardium | 15/5/2025 | 17/6/2026 | IBM Security Guardium 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (4.9) | 0.35% | — | IBM Security Guardium | 9/4/2025 | 17/6/2026 | IBM Security Guardium 11.4 and 12.1 could allow a privileged user to read any file on the system due to incorrect privilege assignment. | |
| Analizada | Media (6.9) | 0.64% | — | Phpgurukul Online Security Guards Hiring System | 3/4/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Online Security Guards Hiring System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/edit-guard-detail.php. The manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The… | |
| Analizada | Media (6.9) | 0.56% | — | Phpgurukul Online Security Guards Hiring System | 3/4/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in PHPGurukul Online Security Guards Hiring System 1.0. Affected is an unknown function of the file /admin/changeimage.php. The manipulation of the argument editid leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.53% | — | Phpgurukul Online Security Guards Hiring System | 23/3/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Online Security Guards Hiring System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/bwdates-reports-details.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to initiate the attack remotely. The… | |
| Analizada | Media (6.9) | 0.53% | — | Phpgurukul Online Security Guards Hiring System | 23/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in PHPGurukul Online Security Guards Hiring System 1.0. Affected by this issue is some unknown functionality of the file /search-request.php. The manipulation of the argument searchdata leads to sql injection. The attack may be launched remotely. The… | |
| Analizada | Media (5.4) | 0.22% | — | IBM Security Guardium | 19/12/2024 | 17/6/2026 | IBM Security Guardium 11.5 and 12.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Analizada | Baja (3.7) | 0.25% | — | IBM Security Guardium KEY Lifecycle Manager | 17/12/2024 | 17/6/2026 | IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle… | |
| Analizada | Alta (7.5) | 0.26% | — | IBM Security Guardium KEY Lifecycle Manager | 17/12/2024 | 17/6/2026 | IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information in cleartext in a communication channel that can be sniffed by unauthorized actors. | |
| Analizada | Media (4.3) | 0.47% | — | IBM Security Guardium KEY Lifecycle Manager | 17/12/2024 | 17/6/2026 | IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | |
| Analizada | Media (4.4) | 0.19% | — | IBM Security Guardium KEY Lifecycle Manager | 17/12/2024 | 17/6/2026 | IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores user credentials in configuration files which can be read by a local privileged user. | |
| Analizada | Media (4.4) | 0.35% | — | IBM Security Guardium KEY Lifecycle Manager | 17/12/2024 | 17/6/2026 | IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores potentially sensitive information in log files that could be read by a local privileged user. | |
| Analizada | Media (5.4) | 0.25% | — | IBM Security Guardium | 24/5/2024 | 17/6/2026 | IBM Security Guardium 11.4, 11.5, and 12.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 271525. | |
| Analizada | Media (4.4) | 0.17% | — | IBM Security Guardium | 16/5/2024 | 17/6/2026 | IBM Security Guardium 12.0 could allow a privileged user to perform unauthorized actions that could lead to a denial of service. IBM X-Force ID: 271690. | |
| Analizada | Alta (7.8) | 0.19% | — | IBM Security Guardium | 14/5/2024 | 17/6/2026 | IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privileges on the system due to improper permissions control. IBM X-Force ID: 271527. | |
| Analizada | Media (6.5) | 0.68% | — | IBM Security Guardium | 14/5/2024 | 17/6/2026 | IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow an authenticated user to upload files that would cause a denial of service. IBM X-Force ID: 271526. | |
| Analizada | Alta (8.8) | 1.0% | — | IBM Security Guardium | 14/5/2024 | 17/6/2026 | IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 271524. | |
| Analizada | Alta (8.2) | 1.4% | — | IBM Security Guardium KEY Lifecycle Manager | 29/2/2024 | 17/6/2026 | IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 247599. | |
| Analizada | Alta (8.8) | 1.1% | — | IBM Security Guardium KEY Lifecycle Manager | 29/2/2024 | 17/6/2026 | IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 247620. | |
| Analizada | Alta (8.8) | 1.4% | — | IBM Security Guardium KEY Lifecycle Manager | 28/2/2024 | 17/6/2026 | IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 247632. | |
| Analizada | Alta (8.8) | 0.56% | — | IBM Security Guardium KEY Lifecycle Manager | 28/2/2024 | 17/6/2026 | IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 247621. |