Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▲ 36 respecto a la semana anterior
Críticas / altas1474▲ 366 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 464 respecto a la semana anterior
–

4635 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)——GG Soft Software Services PaperworkAI2/10/20262/10/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GG Soft Software Services Inc. Paperwork allows SQL Injection. This issue affects Paperwork: through 2026-09-09.
AplazadaAlta (7.2)0.49%—Document Merge ServiceAI1/10/20262/10/2026
Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Prior to version 9.1.0, a remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as…
Pendiente de análisisBaja (3.7)0.21%—HCL Bigfix Service ManagementAI1/10/20261/10/2026
HCL BigFix Service Management is affected by an Information Disclosure vulnerability the application returns sensitive information in error messages when invalid inputs are sent to certain API endpoints . This information could enable an attacker to facilitate further attacks.
Pendiente de análisisMedia (5.3)0.24%—HCL Bigfix Service ManagementAI1/10/20261/10/2026
HCL BigFix Service Management is affected by an Information Disclosure vulnerability because an exposed API endpoint exposes sensitive internal database information. This information could enable an attacker to facilitate targeted database attacks.
Pendiente de análisisMedia (4.3)0.16%—HCL Bigfix Service ManagementAI1/10/20261/10/2026
HCL BigFix Service Management is affected by an Improper Input Validation vulnerability, which could allow an attacker to inject unvalidated, malformed data into the application, enabling potential injection attacks or errors in downstream processing systems.
Pendiente de análisisMedia (5.3)0.24%—HCL Bigfix Service ManagementAI1/10/20261/10/2026
HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This information could enable an attacker to launch further, more serious attacks.
Pendiente de análisisAlta (7.4)0.15%—HCL Bigfix Service ManagementAI1/10/20261/10/2026
HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks.
Pendiente de análisisMedia (5.3)0.24%—HCL Bigfix Service ManagementAI1/10/20261/10/2026
HCL BigFix Service Management is affected by an Information Disclosure vulnerability, which could allow an unauthenticated attacker to analyze publicly accessible JavaScript files, enabling the discovery of hidden administrative API endpoints for further targeted exploitation.
Pendiente de análisisBaja (2.2)0.06%—HCL Bigfix Service ManagementAI1/10/20261/10/2026
HCL BigFix Service Management is affected by an Insecure Cookie Attribute Configuration vulnerability, which could allow an attacker to exploit missing security attributes such as SameSite, HttpOnly, Secure, and restrictive Paths, enabling Cross-Site Request Forgery (CSRF), session hijacking via Cross-Site Scripting…
Pendiente de análisisAlta (7.2)0.20%—HCL Bigfix Service ManagementAI1/10/20261/10/2026
HCL BigFix Service Management is affected by a Stored Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject and store malicious scripts within the application that execute when a victim views the affected page, enabling session hijacking and the theft of sensitive data.
Pendiente de análisisMedia (5.7)0.11%—Canonical WSL PRO ServiceAI29/9/202630/9/2026
In wsl-pro-service before 0.1.19ubuntu3, the service component which runs as root inside each WSL instance attaches the instance to Ubuntu Pro by executing the pro client with the Ubuntu Pro token passed as a command-line argument (pro attach <token>). On systems where /proc is mounted without process-hiding…
AplazadaAlta (8.8)0.24%—Iron Mountain Archiving Services EnvisionAI28/9/202628/9/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Iron Mountain Archiving Services Inc. EnVision allows SQL Injection. This issue affects enVision: before 260655.
AplazadaBaja (2.1)0.27%—Acrel Electric Unet WEB ServiceAI28/9/202628/9/2026
A vulnerability was determined in Acrel Electric Unet Web Service up to 20260814. This vulnerability affects unknown code of the file /exchange/attachment/upload of the component Upload Endpoint. This manipulation of the argument File causes unrestricted upload. The attack can be initiated remotely. The exploit has…
Pendiente de análisisCrítica (9.3)0.30%—Servicenow AI PlatformAI24/9/202625/9/2026
ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to extract instance data beyond what was intended, resulting in privilege escalation. ServiceNow deployed a security…
Pendiente de análisisAlta (8.7)0.29%—Servicenow AI PlatformAI24/9/202624/9/2026
ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an unauthenticated user to access data within the ServiceNow AI Platform that the user otherwise would not be entitled to access, potentially enabling…
Pendiente de análisisAlta (8.7)0.27%—Servicenow AI PlatformAI24/9/202624/9/2026
ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform. This security issue could enable an unauthenticated user, in certain circumstances, to create, modify, or delete instance data beyond what was intended. In August 2026, ServiceNow deployed a security…
Pendiente de análisisAlta (8.4)0.24%—Servicenow AI PlatformAI24/9/202625/9/2026
ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an authenticated user to access data within the ServiceNow AI Platform that the user otherwise would not be entitled to access, potentially enabling…
Pendiente de análisisCrítica (9.3)0.27%—Servicenow AI PlatformAI24/9/202624/9/2026
ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance's underlying database and gain access to, or modify, instance data…
AplazadaMedia (6.5)0.21%—Global IT Informatics Technology Services INC WeollAI23/9/202623/9/2026
Server-Side request forgery (SSRF) vulnerability in Global IT Informatics Technology Services Inc. Weoll allows Server Side Request Forgery. This issue affects Weoll: before 3.2.45.44.
Pendiente de análisisAlta (8.6)1.7%—Zohocorp Manageengine Adselfservice PlusAI22/9/202622/9/2026
Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass vulnerability in the REST API.
Pendiente de análisisCrítica (9.8)4.6%—Zohocorp Manageengine Adselfservice PlusAI22/9/202623/9/2026
Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client.
Pendiente de análisisMedia (6.1)0.20%—IBM Financial Transaction Manager FOR Swift Services FOR MultiplatformsAI18/9/202622/9/2026
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.16 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials…
En análisisBaja (3.1)0.15%—HCL Bigfix Service ManagementAI18/9/202618/9/2026
HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability. The application allows multiple simultaneous authenticated sessions for the same administrative account, which could enable an unauthorized attacker to predict or hijack valid session identifiers. Successful exploitation…
En análisisBaja (3.1)0.25%—HCL Bigfix Service ManagementAI18/9/202618/9/2026
HCL BigFix Service Management is affected by a Sensitive Information Leakage vulnerability, which could allow an unauthenticated attacker to extract internal IP addresses from the application's responses, enabling them to map the underlying network topology and identify potential internal targets.
En análisisBaja (3.1)0.24%—HCL Bigfix Service ManagementAI18/9/202618/9/2026
HCL BigFix Service Management is affected by a CORS Misconfiguration vulnerability due to improperly validated origin headers, which could allow an attacker to craft a malicious web page that interacts with the vulnerable application, enabling unauthorized access to protected resources and restricted APIs on behalf of…