Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
46 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.57% | — | Inrove Software AND Internet Services Bieticaret CMSAI | 19/2/2026 | 17/6/2026 | Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Internet Services BiEticaret CMS allows Authentication Bypass, HTTP Response Splitting. This issue affects BiEticaret CMS: from 2.1.13 through 19022026. NOTE: The vendor was contacted early about this… | |
| Aplazada | Alta (8.5) | 0.24% | — | Iqonic KivicareAI | 3/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Blind SQL Injection.This issue affects KiviCare: from n/a through <= 3.6.16. | |
| Aplazada | Media (5.3) | 0.33% | — | Iqonic KivicareAI | 23/1/2026 | 17/6/2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization checks in the uploadMedicalReport() function in all versions up to, and including, 3.6.15. This makes it possible for unauthenticated attackers to upload text files and PDF… | |
| Aplazada | Crítica (9.8) | 0.46% | — | Boldthemes DenticareAI | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in BoldThemes DentiCare denticare allows Object Injection.This issue affects DentiCare: from n/a through < 1.4.3. | |
| Aplazada | Alta (8.5) | 0.24% | — | Iqonic KivicareAI | 21/11/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows SQL Injection.This issue affects KiviCare: from n/a through <= 3.6.13. | |
| Aplazada | Media (4.6) | 0.24% | — | Akilli Ticaret Software Technologies Smart Trade E-commerceAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akıllı Ticaret Software Technologies Ltd. Co. Smart Trade E-Commerce allows Reflected XSS. This issue affects Smart Trade E-Commerce: before 4.5.0.0.1. | |
| Aplazada | Crítica (9.8) | 0.59% | — | Boldthemes MedicareAI | 23/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in BoldThemes Medicare medicare allows Object Injection.This issue affects Medicare: from n/a through <= 2.1.0. | |
| Modificada | Alta (8.8) | 0.20% | — | Proticaret | 2/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Gosoft Software Proticaret E-Commerce allows Cross Site Request Forgery. This issue affects Proticaret E-Commerce: before v6.0 NOTE: According to the vendor, fixing process is still ongoing for v4.05. | |
| Analizada | Alta (8.8) | 0.53% | — | Iqonic Kivicare | 28/2/2025 | 17/6/2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the ‘u_id’ parameter in all versions up to, and including, 3.6.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Analizada | Media (6.5) | 0.41% | — | Iqonic Kivicare | 6/12/2024 | 17/6/2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'sort[]' parameter of the static_data_list AJAX action in all versions up to, and including, 3.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | |
| Analizada | Media (6.5) | 0.58% | — | Iqonic Kivicare | 6/12/2024 | 17/6/2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'service_list[0][service_id]' parameter of the get_widget_payment_options AJAX action in all versions up to, and including, 3.6.4 due to insufficient escaping on the user supplied parameter and lack of… | |
| Analizada | Alta (7.5) | 14% | — | Iqonic Kivicare | 6/12/2024 | 17/6/2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'visit_type[service_id]' parameter of the tax_calculated_data AJAX action in all versions up to, and including, 3.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient… | |
| Aplazada | Crítica (10) | 0.55% | — | Atos Eviden IcareAI | 30/9/2024 | 17/6/2026 | An issue was discovered in Atos Eviden iCare 2.7.1 through 2.7.11. The application exposes a web interface locally. In the worst-case scenario, if the application is remotely accessible, it allows an attacker to execute arbitrary commands with system privilege on the endpoint hosting the application, without any… | |
| Modificada | Alta (8.8) | 0.34% | — | Iqonic Kivicare | 8/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects KiviCare: from n/a through <= 3.6.6. | |
| Modificada | Alta (8.8) | 0.39% | — | Iqonic Kivicare | 27/6/2023 | 17/6/2026 | The KiviCare WordPress plugin before 3.2.1 does not have CSRF checks (either flawed or missing completely) in various AJAX actions, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks. This includes, but is not limited to: Delete arbitrary appointments/medical records/etc,… | |
| Modificada | Media (4.3) | 0.25% | — | Iqonic Kivicare | 27/6/2023 | 17/6/2026 | The KiviCare WordPress plugin before 3.2.1 does not have proper CSRF and authorisation checks in various AJAX actions, allowing any authenticated users, such as subscriber to call them. Attacks include but are not limited to: Add arbitrary Clinic Admin/Doctors/etc and update plugin's settings | |
| Modificada | Media (6.1) | 1.2% | — | Iqonic Kivicare | 27/6/2023 | 17/6/2026 | The KiviCare WordPress plugin before 3.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrator | |
| Modificada | Media (6.5) | 0.75% | — | Iqonic Kivicare | 27/6/2023 | 17/6/2026 | The KiviCare WordPress plugin before 3.2.1 does not restrict the information returned in a response and returns all user data, allowing low privilege users such as subscriber to retrieve sensitive information such as the user email and hashed password of other users | |
| Modificada | Alta (8.8) | 1.6% | — | Novastar Novaicare | 12/7/2022 | 17/6/2026 | An issue has been discovered in Novastar-VNNOX-iCare Novaicare 7.16.0 that gives attacker privilege escalation and allows attackers to view corporate information and SMTP server details, delete users, view roles, and other unspecified impacts. NOTE: As of April 2026, the vendor has officially decommissioned the… | |
| Modificada | Crítica (9.8) | 13% | — | Iqonic Kivicare | 13/6/2022 | 17/6/2026 | The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL statements via the ajax_post AJAX action with the get_doctor_details route, leading to SQL Injections exploitable by unauthenticated users | |
| Modificada | Alta (7.5) | 2.1% | — | Proticaret | 3/12/2014 | 17/6/2026 | SQL injection vulnerability in Proticaret E-Commerce 3.0 allows remote attackers to execute arbitrary SQL commands via a tem:Code element in a SOAP request. |