Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
42 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.55% | — | Iswalle Getnote-mcpAI | 28/8/2026 | 31/8/2026 | A vulnerability was detected in iswalle getnote-mcp up to 1.5.0. The affected element is the function fs.readFileSync of the file src/index.ts of the component upload_image. Performing a manipulation of the argument image_path results in path traversal. The attack can be initiated remotely. The exploit is now public… | |
| Aplazada | Media (5.5) | 0.53% | — | Pratham-jaiswal Hotel Booking Management SystemAI | 17/4/2026 | 2/8/2026 | A vulnerability was detected in arnobt78 Hotel Booking Management System up to f8922d0e0f6ac1cc761974c7616f44c2bbc04bea. The impacted element is an unknown function of the file /api/health/detailed of the component Health Check Endpoint. Performing a manipulation results in information disclosure. Remote exploitation… | |
| Analizada | Baja (1.9) | 0.28% | — | Alokjaiswal Hotel-management-services-using-mysql-and-php | 7/12/2025 | 17/6/2026 | A vulnerability was found in alokjaiswal Hotel-Management-services-using-MYSQL-and-php up to 5f8b60a7aa6c06a5632de569d4e3f6a8cd82f76f. Affected by this vulnerability is an unknown functionality of the file /dishsub.php. The manipulation of the argument item.name results in cross site scripting. It is possible to… | |
| Analizada | Baja (2) | 0.23% | — | Alokjaiswal Hotel-management-services-using-mysql-and-php | 7/12/2025 | 17/6/2026 | A vulnerability has been found in alokjaiswal Hotel-Management-services-using-MYSQL-and-php up to 5f8b60a7aa6c06a5632de569d4e3f6a8cd82f76f. Affected is an unknown function of the file /usersub.php of the component Request Pending Page. The manipulation leads to cross site scripting. It is possible to initiate the… | |
| Aplazada | Baja (2) | 0.29% | — | Seaswalker Spring-analysisAI | 23/6/2025 | 17/6/2026 | A vulnerability was found in seaswalker spring-analysis up to 4379cce848af96997a9d7ef91d594aa129be8d71. It has been declared as problematic. Affected by this vulnerability is the function echo of the file /src/main/java/controller/SimpleController.java. The manipulation of the argument Name leads to cross site… | |
| Aplazada | Media (5.4) | 0.29% | — | GT3 Soluciones SwalAI | 29/4/2024 | 17/6/2026 | A Cross-Site Scripting XSS vulnerability has been detected on GT3 Soluciones SWAL. This vulnerability consists in a reflected XSS in the Titular parameter inside Gestion 'Documental > Seguimiento de Expedientes > Alta de Expedientes'. | |
| Analizada | Crítica (9.8) | 0.78% | 💥 PoC | Pratham-jaiswal Hotel Booking Management System | 7/3/2024 | 17/6/2026 | Hotel Booking Management v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at update.php. | |
| Analizada | Alta (7.5) | 0.68% | 💥 PoC | Pratham-jaiswal Hotel Booking Management System | 7/3/2024 | 17/6/2026 | Hotel Booking Management v1.0 was discovered to contain a SQL injection vulnerability via the npss parameter at rooms.php. | |
| Modificada | Media (4.9) | 2.5% | — | Auerswald Compact 5500r IP FirmwareAuerswald Compact 5200r IP FirmwareAuerswald Compact 5000r IP FirmwareAuerswald Compact 4000 IP Firmware+6 | 13/12/2021 | 17/6/2026 | Auerswald COMpact 5500R devices before 8.2B allow Arbitrary File Disclosure. A sub-admin can read the cleartext Admin password via the fileName=../../etc/passwd substring. | |
| Modificada | Alta (8.8) | 2.1% | — | Auerswald Compact 5500r IP FirmwareAuerswald Compact 5200r IP FirmwareAuerswald Compact 5000r IP FirmwareAuerswald Compact 4000 IP Firmware+6 | 13/12/2021 | 17/6/2026 | Auerswald COMpact 5500R devices before 8.2B allow Privilege Escalation via the passwd=1 substring. | |
| Modificada | Alta (7.5) | 50% | 💥 Exploit | Auerswald Comfortel 3600 IP FirmwareAuerswald Comfortel 2600 IP FirmwareAuerswald Comfortel 1400 IP Firmware | 13/12/2021 | 17/6/2026 | Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/../ substring. | |
| Modificada | Crítica (9.8) | 72% | 💥 Exploit | Auerswald Compact 5500r Firmware | 7/12/2021 | 17/6/2026 | Backdoors were discovered in Auerswald COMpact 5500R 7.8A and 8.0B devices, that allow attackers with access to the web based management application full administrative access to the device. | |
| Modificada | Alta (8) | 4.0% | — | Auerswald Comfortel 1200 IP Firmware | 29/5/2019 | 17/6/2026 | A buffer overflow vulnerability in the DHCP and PPPOE configuration interface of the Auerswald COMfort 1200 IP phone 3.4.4.1-10589 allows a remote attacker (authenticated as simple user in the same network as the device) to trigger remote code execution via a POST request (ManufacturerName parameter) to the web server… | |
| Modificada | Alta (8) | 4.2% | — | Auerswald Comfortel 1200 IP Firmware | 29/5/2019 | 17/6/2026 | A command injection (missing input validation, escaping) in the ftp upgrade configuration interface on the Auerswald COMfort 1200 IP phone 3.4.4.1-10589 allows an authenticated remote attacker (simple user) -- in the same network as the device -- to trigger OS commands (like starting telnetd or opening a reverse… | |
| Modificada | Alta (8.1) | 1.7% | — | Intel Crosswalk | 1/8/2016 | 17/6/2026 | Intel Crosswalk before 19.49.514.5, 20.x before 20.50.533.11, 21.x before 21.51.546.0, and 22.x before 22.51.549.0 interprets a user's acceptance of one invalid X.509 certificate to mean that all invalid X.509 certificates should be accepted without prompting, which makes it easier for man-in-the-middle attackers to… | |
| Modificada | Media (4.3) | 1.7% | — | Derrick Oswald Html-parser | 29/10/2009 | 16/6/2026 | The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generation of an invalid UTF-8 character. | |
| Modificada | Alta (9.3) | 8.4% | — | Trend Micro Client-server-messaging Suite SMBTrend Micro Client-server Suite SMBTrend Micro Control ManagerTrend Micro Interscan Emanager+19 | 8/2/2007 | 16/6/2026 | Buffer overflow in the Trend Micro Scan Engine 8.000 and 8.300 before virus pattern file 4.245.00, as used in other products such as Cyber Clean Center (CCC) Cleaner, allows remote attackers to execute arbitrary code via a malformed UPX compressed executable. | |
| Modificada | Media (6.9) | 0.91% | 💥 Exploit | Trend Micro Viruswall | 30/1/2007 | 16/6/2026 | Buffer overflow in libvsapi.so in the VSAPI library in Trend Micro VirusWall 3.81 for Linux, as used by IScan.BASE/vscan, allows local users to gain privileges via a long command line argument, a different vulnerability than CVE-2005-0533. | |
| Modificada | Alta (7.5) | 4.4% | — | Trend Micro Client-server-messaging Suite SMBTrend Micro Client-server Suite SMBTrend Micro Control ManagerTrend Micro Interscan Emanager+11 | 2/5/2005 | 16/6/2026 | Heap-based buffer overflow in Trend Micro AntiVirus Library VSAPI before 7.510, as used in multiple Trend Micro products, allows remote attackers to execute arbitrary code via a crafted ARJ file with long header file names that modify pointers within a structure. | |
| Modificada | Media (5) | 8.4% | 💥 Exploit | Trend Micro Interscan Viruswall FOR Windows NT | 24/3/2004 | 16/6/2026 | Directory traversal vulnerability in Trend Micro Interscan Web Viruswall in InterScan VirusWall 3.5x allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. | |
| Modificada | Media (4.6) | 0.53% | — | Auerswald Comsuite CTI Controlcenter | 31/12/2003 | 16/6/2026 | Auerswald COMsuite CTI ControlCenter 3.1 creates a default "runasositron" user account with an easily guessable password, which allows local users or remote attackers to gain access. | |
| Modificada | Media (5) | 3.5% | — | Trend Micro Interscan Viruswall | 31/12/2002 | 16/6/2026 | InterScan VirusWall 3.6 for Linux and 3.52 for Windows allows remote attackers to bypass virus protection and possibly execute arbitrary code via HTTP 1.1 chunked transfer encoding. | |
| Modificada | Media (5) | 2.6% | — | Trend Micro Interscan Viruswall | 31/12/2002 | 16/6/2026 | InterScan VirusWall 3.52 for Windows allows remote attackers to bypass virus protection and possibly execute arbitrary code via HTTP 1.1 gzip content encoding. | |
| Modificada | Media (5) | 2.1% | — | Trend Micro Interscan Viruswall FOR Windows NT | 31/12/2002 | 16/6/2026 | Trend Micro InterScan VirusWall for Windows NT 3.52 does not record the sender's IP address in the headers for a mail message when it is passed from VirusWall to the MTA, which allows remote attackers to hide the origin of the message. | |
| Modificada | Alta (7.5) | 6.7% | — | GFI MailsecurityNetwork Associates Webshield SmtpRoaring Penguin CanitRoaring Penguin Mimedefang+1 | 24/9/2002 | 16/6/2026 | SMTP content filter engines, including (1) GFI MailSecurity for Exchange/SMTP before 7.2, (2) InterScan VirusWall before 3.52 build 1494, (3) the default configuration of MIMEDefang before 2.21, and possibly other products, do not detect fragmented emails as defined in RFC2046 ("Message Fragmentation and Reassembly")… |