Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2684▼ 80 respecto a la semana anterior
Críticas / altas1442▲ 302 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

118 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.38%—Pamzey Patients Waiting Area Queue Management System16/11/202517/6/2026
A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0. The impacted element is an unknown function of the file /php/api_patient_schedule.php. This manipulation of the argument appointmentID causes sql injection. The attack can be initiated remotely. The exploit has been…
AnalizadaMedia (5.5)0.44%—Pamzey Patients Waiting Area Queue Management System13/11/202517/6/2026
A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. The affected element is the function getPatientAppointment of the file /php/api_patient_checkin.php. Performing manipulation of the argument appointmentID results in sql injection. It is possible to initiate the attack…
AnalizadaMedia (6.5)0.24%—Pamzey Patients Waiting Area Queue Management System7/11/202517/6/2026
A SQL injection vulnerability exists in the SourceCodester PQMS (Patient Queue Management System) 1.0 in the api_patient_schedule.php endpoint. The appointmentID parameter is not properly sanitized, allowing attackers to execute arbitrary SQL commands.
AplazadaBaja (1.3)0.24%—Realcetecnologia Queue Ticket KioskAI11/9/202517/6/2026
A flaw has been found in SEAT Queue Ticket Kiosk up to 20250827. This affects an unknown part of the component Java RMI Registry Handler. This manipulation causes deserialization. The attack can only be done within the local network. The attack is considered to have high complexity. It is indicated that the…
AnalizadaMedia (6.8)0.21%—IBM Security Verify Information Queue10/9/202517/6/2026
IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 could allow a privileged user to escalate their privileges and attack surface on the host due to the containers running with unnecessary privileges.
AnalizadaAlta (7.5)0.19%—IBM Security Verify Information Queue10/9/202517/6/2026
IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
AnalizadaMedia (6.5)0.37%—IBM Security Verify Information Queue10/9/202517/6/2026
IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 could allow a remote user to cause a denial of service due to improper handling of special characters that could lead to uncontrolled resource consumption.
AnalizadaMedia (6.1)0.28%—Oracle Universal Work Queue15/7/202517/6/2026
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Request handling). Supported versions that are affected are 12.2.5-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Universal Work Queue. Successful…
AnalizadaAlta (8.1)0.35%—Oracle Universal Work Queue15/7/202517/6/2026
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Administration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal Work Queue.…
AnalizadaMedia (4.8)0.34%—Realcetecnologia Queue Ticket Kiosk26/5/202517/6/2026
A vulnerability classified as problematic was found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. Affected by this vulnerability is an unknown functionality of the file /adm/index.php of the component Cadastro de Administrador Page. The manipulation of the argument Name/Usuário leads to cross site scripting.…
AnalizadaMedia (5.3)0.50%—Realcetecnologia Queue Ticket Kiosk26/5/202517/6/2026
A vulnerability classified as critical has been found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. Affected is an unknown function of the file /adm/ajax.php of the component Image File Handler. The manipulation of the argument files[] leads to unrestricted upload. It is possible to launch the attack…
AnalizadaMedia (5.3)0.57%—Realcetecnologia Queue Ticket Kiosk26/5/202517/6/2026
A vulnerability was found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. It has been rated as problematic. This issue affects some unknown processing of the file /adm/index.php of the component Admin Login Page. The manipulation of the argument Usuário leads to cross site scripting. The attack may be…
AnalizadaMedia (6.9)0.45%—Realcetecnologia Queue Ticket Kiosk26/5/202517/6/2026
A vulnerability was found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. It has been declared as critical. This vulnerability affects unknown code of the file /adm/index.php of the component Admin Login Page. The manipulation of the argument Usuário leads to sql injection. The attack can be initiated…
AnalizadaAlta (7.5)14%—Rsiqueue Management System20/5/202517/6/2026
An unauthenticated blind SQL injection vulnerability exists in RSI Queue Management System v3.0 within the TaskID parameter of the get request handler. Attackers can remotely inject time-delayed SQL payloads to induce server response delays, enabling time-based inference and iterative extraction of sensitive database…
AnalizadaMedia (4.3)0.25%—Jenkins Simple Queue2/4/202517/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Simple Queue Plugin 1.4.6 and earlier allows attackers to change and reset the build queue order.
AplazadaAlta (7.1)0.26%—Milan Petrovic Gd-mail-queueAI31/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Milan Petrovic GD Mail Queue gd-mail-queue allows Reflected XSS.This issue affects GD Mail Queue: from n/a through <= 4.3.
AnalizadaAlta (8.8)0.20%—Migrate Queue Importer Project Migrate Queue Importer9/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate queue importer allows Cross Site Request Forgery.This issue affects Migrate queue importer: from 0.0.0 before 2.1.1.
AnalizadaAlta (8)80%—Jenkins Simple Queue27/11/202417/6/2026
Jenkins Simple Queue Plugin 1.4.4 and earlier does not escape the view name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Create permission.
AnalizadaAlta (7.5)0.33%—Loway Queuemetrics8/9/202417/6/2026
Loway - CWE-204: Observable Response Discrepancy
AnalizadaMedia (4.3)0.28%—Loway Queuemetrics8/9/202417/6/2026
Loway - CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
AnalizadaMedia (6.1)0.24%—Loway Queuemetrics8/9/202417/6/2026
Loway - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
ModificadaAlta (7.5)0.75%—IBM Security Verify Information Queue31/8/202317/6/2026
IBM Security Verify Information Queue 10.0.4 and 10.0.5 could allow a remote attacker to obtain sensitive information that could aid in further attacks against the system. IBM X-Force ID: 256015.
ModificadaMedia (5.3)0.68%—IBM Security Verify Information Queue31/8/202317/6/2026
IBM Security Verify Information Queue 10.0.4 and 10.0.5 could allow a remote attacker to obtain sensitive information that could aid in further attacks against the system. IBM X-force ID: 256014.
ModificadaBaja (3.3)0.13%—IBM Security Verify Information Queue31/8/202317/6/2026
IBM Security Verify Information Queue 10.0.4 and 10.0.5 stores sensitive information in plain clear text which can be read by a local user. IBM X-Force ID: 256013.
ModificadaMedia (6.1)0.44%—Webdesignmunich Mail Queue12/7/202317/6/2026
The Mail Queue plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute…