Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.52% | — | Isdo Software WEB SoftwareAI | 19/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ISDO Software Web Software allows SQL Injection. This issue affects Web Software: before 3.6. | |
| Modificada | Media (5.5) | 0.26% | — | Samsung Account WEB Software Development KIT | 5/12/2023 | 17/6/2026 | Implicit intent hijacking vulnerability in Samsung Account Web SDK prior to version 1.5.24 allows attacker to get sensitive information. | |
| Modificada | Media (6.1) | 1.2% | — | IBM Tivoli Access Manager FOR E-businessIBM Security Access Manager FOR WEB SoftwareIBM Security Access Manager FOR WEB ApplianceIBM Security Access Manager FOR WEB+2 | 29/8/2017 | 17/6/2026 | IBM Security Access Manager 6.1, 7.0, 8.0, and 9.0 e-community configurations may be affected by a redirect vulnerability. ECSSO Master Authentication can redirect to a server not participating in an e-community domain. IBM X-Force ID: 128687. | |
| Modificada | Alta (10) | 4.2% | — | IBM Security Access Manager FOR Mobile SoftwareIBM Security Access Manager FOR WEB SoftwareIBM Security Access Manager FOR Mobile ApplianceIBM Security Access Manager FOR WEB Appliance | 21/6/2014 | 17/6/2026 | Unspecified vulnerability in IBM Security Access Manager (ISAM) for Mobile 8.0 and IBM Security Access Manager for Web 7.0 and 8.0 allows remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Alta (8) | 1.4% | — | IBM Security Access Manager FOR WEB 8.0 FirmwareIBM Security Access Manager FOR WEB ApplianceIBM Security Access Manager FOR Mobile SoftwareIBM Security Access Manager FOR WEB Software+1 | 21/6/2014 | 17/6/2026 | The Local Management Interface (LMI) in IBM Security Access Manager (ISAM) for Mobile 8.0 with firmware 8.0.0.0 through 8.0.0.3 and IBM Security Access Manager for Web 7.0, and 8.0 with firmware 8.0.0.2 and 8.0.0.3, allows remote attackers to bypass authentication via a login action with invalid credentials. | |
| Modificada | Alta (7.1) | 3.1% | — | IBM Security Access Manager FOR WEB SoftwareIBM Security Access Manager FOR WEB Appliance | 8/5/2014 | 17/6/2026 | The Reverse Proxy feature in IBM Global Security Kit (aka GSKit) in IBM Security Access Manager (ISAM) for Web 7.0 before 7.0.0-ISS-SAM-IF0006 and 8.0 before 8.0.0.3-ISS-WGA-IF0002 allows remote attackers to cause a denial of service (infinite loop) via crafted SSL messages. | |
| Modificada | Alta (7.5) | 1.0% | — | Active WEB Softwares Active Test | 23/1/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in start.asp in Active Test 2.1 allow remote attackers to execute arbitrary SQL commands via the (1) useremail parameter (aka username field) or (2) password parameter (aka password field). NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.0% | — | Active WEB Softwares Active Auction House | 27/3/2007 | 16/6/2026 | SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Auction Pro 7.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Active WEB Softwares Active Newsletter | 27/3/2007 | 16/6/2026 | SQL injection vulnerability in ViewNewspapers.asp in Active Newsletter 4.3 and earlier allows remote attackers to execute arbitrary SQL commands via the NewsPaperID parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Active WEB Softwares Active Link Engine | 23/3/2007 | 16/6/2026 | SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Link Engine allows remote attackers to execute arbitrary SQL commands via the catid parameter. | |
| Modificada | Alta (7.5) | 1.0% | — | Active WEB Softwares Active Photo Gallery | 23/3/2007 | 16/6/2026 | SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Photo Gallery allows remote attackers to execute arbitrary SQL commands via the catid parameter. | |
| Modificada | Media (4.3) | 0.96% | — | Active WEB Softwares Activebuyandsell | 29/6/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ActiveBuyAndSell 6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Title parameter to sendpassword.asp or (2) Keyword field in search.asp. | |
| Modificada | Alta (7.5) | 1.3% | — | Active WEB Softwares Activebuyandsell | 29/6/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in ActiveBuyAndSell 6.2 allow remote attackers to execute arbitrary SQL commands via the catid parameter to (1) default.asp or (2) buyersend.asp, (3) Administrator ID field in admin.asp, E-mail field in (4) advertiserstart.asp or (5) buyer.asp, or Keyword field in search.asp. | |
| Modificada | Media (4.3) | 5.1% | — | Active WEB Softwares Active Auction House | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Active Auction House allow remote attackers to inject arbitrary web script or HTML via the (1) ReturnURL, (2) password, (3) username parameter, (4) ReturnURL parameter to account.asp, (5) Table, (6) Title parameter to sendpassword.asp, or (7) itemid to… | |
| Modificada | Alta (7.5) | 4.3% | — | Active WEB Softwares Active Auction House | 6/4/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Active Auction House allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) SortDir, or (3) Sortby parameter to default.asp, (4) itemID parameter to ItemInfo.asp, or (5) Email field to sendpassword.asp. |