Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2586▼ 297 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.1)0.45%—Uniong Webitr28/11/202517/6/2026
WebITR developed by Uniong has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.
AnalizadaAlta (7.1)0.32%—Uniong Webitr28/11/202517/6/2026
WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.
AnalizadaAlta (7.1)0.32%—Uniong Webitr28/11/202517/6/2026
WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.
AnalizadaAlta (7.7)0.40%—Uniong Webitr28/11/202517/6/2026
WebITR developed by Uniong has an Authentication Bypass vulnerability, allowing authenticated remote attackers to log into the system as any user by modifying a specific parameter. Attackers must first obtain a user ID to exploit this vulnerability.
AnalizadaAlta (7.1)0.55%—Uniong Webitr22/8/202517/6/2026
WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files.
AnalizadaAlta (7.1)0.55%—Uniong Webitr22/8/202517/6/2026
WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files.
AnalizadaAlta (7.1)0.55%—Uniong Webitr22/8/202517/6/2026
WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files.
AnalizadaAlta (7.1)0.55%—Uniong Webitr22/8/202517/6/2026
WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files.
AnalizadaAlta (8.7)0.52%—Uniong Webitr22/8/202517/6/2026
WebITR developed by Uniong has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.
AnalizadaCrítica (9.3)0.65%—Uniong Webitr22/8/202517/6/2026
WebITR developed by Uniong has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to log into the system as arbitrary users by exploiting a specific functionality.
AnalizadaMedia (6.1)0.38%—Uniong Webitr9/9/202417/6/2026
WebITR from Uniong has an Open Redirect vulnerability, which allows unauthorized remote attackers to exploit this vulnerability to forge URLs. Users, believing they are accessing a trusted domain, can be redirected to another page, potentially leading to phishing attacks.
ModificadaMedia (6.5)0.71%—Kaifa Webitr Attendance System15/12/202317/6/2026
Kaifa Technology WebITR is an online attendance system, it has insufficient validation for user input within a special function. A remote attacker with regular user privilege can exploit this vulnerability to inject arbitrary SQL commands to read database.
ModificadaAlta (8.8)0.89%—Kaifa Webitr Attendance System15/12/202317/6/2026
Kaifa Technology WebITR is an online attendance system, its file uploading function does not restrict upload of file with dangerous type. A remote attacker with regular user privilege can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service.
ModificadaMedia (4.3)0.57%—Kaifa Webitr Attendance System15/12/202317/6/2026
Kaifa Technology WebITR is an online attendance system. A remote attacker with regular user privilege can obtain partial sensitive system information from error message.
ModificadaCrítica (9.8)0.57%—Kaifa Webitr Attendance System15/12/202317/6/2026
Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key. An unauthenticated remote attacker can generate valid token parameter and exploit this vulnerability to access system with arbitrary user account, including administrator’s account, to execute login…