Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2586▼ 297 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.45% | — | Uniong Webitr | 28/11/2025 | 17/6/2026 | WebITR developed by Uniong has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files. | |
| Analizada | Alta (7.1) | 0.32% | — | Uniong Webitr | 28/11/2025 | 17/6/2026 | WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents. | |
| Analizada | Alta (7.1) | 0.32% | — | Uniong Webitr | 28/11/2025 | 17/6/2026 | WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents. | |
| Analizada | Alta (7.7) | 0.40% | — | Uniong Webitr | 28/11/2025 | 17/6/2026 | WebITR developed by Uniong has an Authentication Bypass vulnerability, allowing authenticated remote attackers to log into the system as any user by modifying a specific parameter. Attackers must first obtain a user ID to exploit this vulnerability. | |
| Analizada | Alta (7.1) | 0.55% | — | Uniong Webitr | 22/8/2025 | 17/6/2026 | WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files. | |
| Analizada | Alta (7.1) | 0.55% | — | Uniong Webitr | 22/8/2025 | 17/6/2026 | WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files. | |
| Analizada | Alta (7.1) | 0.55% | — | Uniong Webitr | 22/8/2025 | 17/6/2026 | WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files. | |
| Analizada | Alta (7.1) | 0.55% | — | Uniong Webitr | 22/8/2025 | 17/6/2026 | WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files. | |
| Analizada | Alta (8.7) | 0.52% | — | Uniong Webitr | 22/8/2025 | 17/6/2026 | WebITR developed by Uniong has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents. | |
| Analizada | Crítica (9.3) | 0.65% | — | Uniong Webitr | 22/8/2025 | 17/6/2026 | WebITR developed by Uniong has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to log into the system as arbitrary users by exploiting a specific functionality. | |
| Analizada | Media (6.1) | 0.38% | — | Uniong Webitr | 9/9/2024 | 17/6/2026 | WebITR from Uniong has an Open Redirect vulnerability, which allows unauthorized remote attackers to exploit this vulnerability to forge URLs. Users, believing they are accessing a trusted domain, can be redirected to another page, potentially leading to phishing attacks. | |
| Modificada | Media (6.5) | 0.71% | — | Kaifa Webitr Attendance System | 15/12/2023 | 17/6/2026 | Kaifa Technology WebITR is an online attendance system, it has insufficient validation for user input within a special function. A remote attacker with regular user privilege can exploit this vulnerability to inject arbitrary SQL commands to read database. | |
| Modificada | Alta (8.8) | 0.89% | — | Kaifa Webitr Attendance System | 15/12/2023 | 17/6/2026 | Kaifa Technology WebITR is an online attendance system, its file uploading function does not restrict upload of file with dangerous type. A remote attacker with regular user privilege can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service. | |
| Modificada | Media (4.3) | 0.57% | — | Kaifa Webitr Attendance System | 15/12/2023 | 17/6/2026 | Kaifa Technology WebITR is an online attendance system. A remote attacker with regular user privilege can obtain partial sensitive system information from error message. | |
| Modificada | Crítica (9.8) | 0.57% | — | Kaifa Webitr Attendance System | 15/12/2023 | 17/6/2026 | Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key. An unauthenticated remote attacker can generate valid token parameter and exploit this vulnerability to access system with arbitrary user account, including administrator’s account, to execute login… |