Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▲ 24 respecto a la semana anterior
Críticas / altas1467▲ 357 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.42% | — | Myworks WOO Sync FOR Quickbooks OnlineAI | 11/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MyWorks MyWorks WooCommerce Sync for QuickBooks Online myworks-woo-sync-for-quickbooks-online allows Reflected XSS.This issue affects MyWorks WooCommerce Sync for QuickBooks Online: from n/a through <= 2.9.1. | |
| Analizada | Alta (8.6) | 31% | ⚠ Explotación activa | Trimble Cityworks | 6/2/2025 | 17/6/2026 | Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer’s Microsoft Internet Information Services (IIS) web server. | |
| Aplazada | Alta (8.2) | 0.47% | — | Realtyworkstation Realty WorkstationAI | 21/1/2025 | 17/6/2026 | Missing Authorization vulnerability in realtyworkstation Realty Workstation realty-workstation allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Realty Workstation: from n/a through <= 1.0.45. | |
| Modificada | Crítica (9.8) | 0.53% | — | Realtyworkstation Realty Workstation | 28/10/2024 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in realtyworkstation Realty Workstation realty-workstation allows Authentication Bypass.This issue affects Realty Workstation: from n/a through <= 1.0.45. | |
| Modificada | Alta (8.8) | 0.42% | — | Gerryntabuhashe Gerryworks Post BY Mail | 20/10/2024 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in gerryworks GERRYWORKS Post by Mail gerryworks-post-by-mail allows Privilege Escalation.This issue affects GERRYWORKS Post by Mail: from n/a through <= 1.0. | |
| Modificada | Media (6.1) | 0.32% | — | Livelyworks Articart | 16/7/2023 | 17/6/2026 | A vulnerability was found in LivelyWorks Articart 2.0.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /change-language/de_DE of the component Base64 Encoding Handler. The manipulation of the argument redirectTo leads to open redirect. The attack may be launched… | |
| Modificada | Media (5.4) | 0.36% | — | Livelyworks Articart | 16/7/2023 | 17/6/2026 | A vulnerability has been found in LivelyWorks Articart 2.0.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /items/search. The manipulation of the argument search_term leads to cross site scripting. The attack can be launched remotely. The identifier VDB-234229… | |
| Modificada | Media (4.9) | 0.99% | — | Realtyworkstation Realty Workstation | 8/6/2022 | 17/6/2026 | The Realty Workstation WordPress plugin before 1.0.15 does not sanitise and escape the trans_edit parameter before using it in a SQL statement when an agent edit a transaction, leading to an SQL injection | |
| Modificada | Alta (8.8) | 0.50% | — | Accops Hyworks Windows Client | 7/12/2021 | 17/6/2026 | An Integer Overflow vulnerability exists in Accops HyWorks Windows Client prior to v 3.2.8.200. The IOCTL Handler 0x22005B in the Accops HyWorks Windows Client prior to v 3.2.8.200 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially… | |
| Modificada | Alta (8.8) | 0.48% | — | Accops Hyworks Windows Client | 7/12/2021 | 17/6/2026 | A Buffer Overflow vulnerability exists in Accops HyWorks Windows Client prior to v 3.2.8.200. The IOCTL Handler 0x22005B allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet. | |
| Modificada | Alta (8.8) | 0.50% | — | Accops Hyworks Windows Client | 7/12/2021 | 17/6/2026 | An Integer Overflow exists in Accops HyWorks Windows Client prior to v 3.2.8.200. The IOCTL Handler 0x22001B in the Accops HyWorks Windows Client prior to v 3.2.8.200 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O… | |
| Modificada | Alta (8.8) | 0.48% | — | Accops Hyworks DVM Tools | 7/12/2021 | 17/6/2026 | An Integer Overflow vulnerability exists in Accops HyWorks DVM Tools prior to v3.3.1.105 . The IOCTL Handler 0x22005B in the Accops HyWorks DVM Tools prior to v3.3.1.105 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted… | |
| Modificada | Alta (8.8) | 0.48% | — | Accops Hyworks Windows Client | 7/12/2021 | 17/6/2026 | A Buffer Overflow vulnerability exists in Accops HyWorks Windows Client prior to v 3.2.8.200. The IOCTL Handler 0x22001B allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet. | |
| Modificada | Alta (8.8) | 0.48% | — | Accops Hyworks DVM Tools | 7/12/2021 | 17/6/2026 | An Integer Overflow vulnerability exists in Accops HyWorks DVM Tools prior to v3.3.1.105 .The IOCTL Handler 0x22001B allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet. | |
| Modificada | Alta (8.8) | 0.48% | — | Accops Hyworks DVM Tools | 7/12/2021 | 17/6/2026 | A Buffer Overflow vulnerability exists in Accops HyWorks DVM Tools prior to v3.3.1.105. The IOCTL Handler 0x22001B allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet. | |
| Modificada | Crítica (9.8) | 2.4% | — | Yworks YED | 17/9/2020 | 17/6/2026 | yWorks yEd Desktop before 3.20.1 allows code execution via an XSL Transformation when using an XML file in conjunction with a custom stylesheet. | |
| Modificada | Crítica (9.8) | 1.2% | — | Yworks YED | 17/9/2020 | 17/6/2026 | yWorks yEd Desktop before 3.20.1 allows XXE attacks via an XML or GraphML document. | |
| Modificada | Crítica (9.8) | 1.4% | — | Cognito Moneyworks | 26/6/2017 | 17/6/2026 | Password exposure in Cognito Software Moneyworks 8.0.3 and earlier allows attackers to gain administrator access to all data, because verbose logging writes the administrator password to a world-readable file. | |
| Modificada | Baja (2.1) | 0.39% | — | Syworks Safenet | 12/6/2006 | 16/6/2026 | Syworks SafeNET allows local users to bypass restrictions on network resource consumption by editing the policy.dat file. |