Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.52%—Isdo Software WEB SoftwareAI19/12/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ISDO Software Web Software allows SQL Injection. This issue affects Web Software: before 3.6.
ModificadaMedia (5.5)0.26%—Samsung Account WEB Software Development KIT5/12/202317/6/2026
Implicit intent hijacking vulnerability in Samsung Account Web SDK prior to version 1.5.24 allows attacker to get sensitive information.
ModificadaMedia (6.1)1.2%—IBM Tivoli Access Manager FOR E-businessIBM Security Access Manager FOR WEB SoftwareIBM Security Access Manager FOR WEB ApplianceIBM Security Access Manager FOR WEB+229/8/201717/6/2026
IBM Security Access Manager 6.1, 7.0, 8.0, and 9.0 e-community configurations may be affected by a redirect vulnerability. ECSSO Master Authentication can redirect to a server not participating in an e-community domain. IBM X-Force ID: 128687.
ModificadaAlta (10)4.2%—IBM Security Access Manager FOR Mobile SoftwareIBM Security Access Manager FOR WEB SoftwareIBM Security Access Manager FOR Mobile ApplianceIBM Security Access Manager FOR WEB Appliance21/6/201417/6/2026
Unspecified vulnerability in IBM Security Access Manager (ISAM) for Mobile 8.0 and IBM Security Access Manager for Web 7.0 and 8.0 allows remote attackers to execute arbitrary code via unknown vectors.
ModificadaAlta (8)1.4%—IBM Security Access Manager FOR WEB 8.0 FirmwareIBM Security Access Manager FOR WEB ApplianceIBM Security Access Manager FOR Mobile SoftwareIBM Security Access Manager FOR WEB Software+121/6/201417/6/2026
The Local Management Interface (LMI) in IBM Security Access Manager (ISAM) for Mobile 8.0 with firmware 8.0.0.0 through 8.0.0.3 and IBM Security Access Manager for Web 7.0, and 8.0 with firmware 8.0.0.2 and 8.0.0.3, allows remote attackers to bypass authentication via a login action with invalid credentials.
ModificadaAlta (7.1)3.1%—IBM Security Access Manager FOR WEB SoftwareIBM Security Access Manager FOR WEB Appliance8/5/201417/6/2026
The Reverse Proxy feature in IBM Global Security Kit (aka GSKit) in IBM Security Access Manager (ISAM) for Web 7.0 before 7.0.0-ISS-SAM-IF0006 and 8.0 before 8.0.0.3-ISS-WGA-IF0002 allows remote attackers to cause a denial of service (infinite loop) via crafted SSL messages.
ModificadaAlta (7.5)1.0%—Active WEB Softwares Active Test23/1/200916/6/2026
Multiple SQL injection vulnerabilities in start.asp in Active Test 2.1 allow remote attackers to execute arbitrary SQL commands via the (1) useremail parameter (aka username field) or (2) password parameter (aka password field). NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)1.0%—Active WEB Softwares Active Auction House27/3/200716/6/2026
SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Auction Pro 7.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter.
ModificadaAlta (7.5)1.2%—Active WEB Softwares Active Newsletter27/3/200716/6/2026
SQL injection vulnerability in ViewNewspapers.asp in Active Newsletter 4.3 and earlier allows remote attackers to execute arbitrary SQL commands via the NewsPaperID parameter.
ModificadaAlta (7.5)1.2%—Active WEB Softwares Active Link Engine23/3/200716/6/2026
SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Link Engine allows remote attackers to execute arbitrary SQL commands via the catid parameter.
ModificadaAlta (7.5)1.0%—Active WEB Softwares Active Photo Gallery23/3/200716/6/2026
SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Photo Gallery allows remote attackers to execute arbitrary SQL commands via the catid parameter.
ModificadaMedia (4.3)0.96%—Active WEB Softwares Activebuyandsell29/6/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in ActiveBuyAndSell 6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Title parameter to sendpassword.asp or (2) Keyword field in search.asp.
ModificadaAlta (7.5)1.3%—Active WEB Softwares Activebuyandsell29/6/200516/6/2026
Multiple SQL injection vulnerabilities in ActiveBuyAndSell 6.2 allow remote attackers to execute arbitrary SQL commands via the catid parameter to (1) default.asp or (2) buyersend.asp, (3) Administrator ID field in admin.asp, E-mail field in (4) advertiserstart.asp or (5) buyer.asp, or Keyword field in search.asp.
ModificadaMedia (4.3)5.1%—Active WEB Softwares Active Auction House2/5/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Active Auction House allow remote attackers to inject arbitrary web script or HTML via the (1) ReturnURL, (2) password, (3) username parameter, (4) ReturnURL parameter to account.asp, (5) Table, (6) Title parameter to sendpassword.asp, or (7) itemid to…
ModificadaAlta (7.5)4.3%—Active WEB Softwares Active Auction House6/4/200516/6/2026
Multiple SQL injection vulnerabilities in Active Auction House allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) SortDir, or (3) Sortby parameter to default.asp, (4) itemID parameter to ItemInfo.asp, or (5) Email field to sendpassword.asp.