Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
4193 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.6) | 0.77% | — | UI Unifi OS ServerUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO FirmwareUI Unifi Dream Machine Special Edition Firmware+28 | 2/7/2026 | 10/7/2026 | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to bypass authentication of such UniFi OS devices or instances. | |
| Analizada | Alta (8.8) | 1.8% | — | UI Unifi OS ServerUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO FirmwareUI Unifi Dream Machine Special Edition Firmware+28 | 2/7/2026 | 10/7/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device. | |
| Analizada | Alta (8.8) | 0.43% | — | UI Unifi OS ServerUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO FirmwareUI Unifi Dream Machine Special Edition Firmware+28 | 2/7/2026 | 10/7/2026 | A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges within such UniFi OS devices or instances. | |
| Aplazada | Media (4.3) | 0.23% | — | Stormshield Network SecurityAI | 2/7/2026 | 2/7/2026 | A vulnerability was discovered on StormShield Network Security 4.3.0 to 4.3.41 (included), 4.8.0 to 4.8.15 (included) , 5.0.0 to 5.0.5 (included) There is a possible leak of secret information if administration commands have been passed with the CLI command line tool. Someone with SSH access to the firewall (if SSH… | |
| Pendiente de análisis | Media (4.3) | 0.13% | — | Stormshield Network SecurityAI | 1/7/2026 | 1/7/2026 | A vulnerability was discovered on Stormshield Network Security 4.3.0 to 4.3.41 (included), 4.4.0 to 4.8.15 (included) , 5.0.2 EA to 5.0.5 (included) A revoked client certificate can still be used to authenticate to the captive‑admin portal, allowing an attacker who possesses the revoked certificate to gain… | |
| Aplazada | Media (6.4) | 0.07% | — | Catonetworks Cato ClientAI | 1/7/2026 | 2/7/2026 | Improper certificate validation and a time-of-check time-of-use (TOCTOU) race condition in the PrivilegedHelperTool XPC service in Cato Client before v.5.13.1 on macOS allows a local authenticated attacker to escalate privileges to root via a self-signed certificate that bypasses the XPC caller verification and a… | |
| Pendiente de análisis | Alta (7.1) | 0.31% | — | Trellix Network Security CMAITrellix Network Security NXAI | 26/6/2026 | 29/9/2026 | A Code Injection vulnerability existed in Trellix Network Security CM and NX. A locally authenticated admin user can execute arbitrary code using the web interface and Alert artifact details. | |
| Aplazada | Alta (8.5) | 0.18% | — | Network Inventory AdvisorAI | 19/6/2026 | 29/9/2026 | Network Inventory Advisor 5.0.26.0 installs the niaservice service with an unquoted binary path that allows local attackers to escalate privileges by placing malicious executables in intermediate directories. Attackers can exploit the unquoted path in the service configuration to execute arbitrary code with… | |
| Analizada | Alta (7.5) | 0.46% | — | Inhandnetworks Ir915l-fq39-s FirmwareInhandnetworks Ir912l-fq58 Firmware | 18/6/2026 | 22/6/2026 | InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a buffer overflow vulnerability in the device registration function. This vulnerability could allow an attacker to cause a denial of service attack on the remote target device. | |
| Analizada | Crítica (9.8) | 2.3% | — | Inhandnetworks Ir915l-fq39-s FirmwareInhandnetworks Ir912l-fq58 Firmware | 18/6/2026 | 22/6/2026 | InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the file upload function. The vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input. | |
| Analizada | Crítica (9.8) | 2.3% | — | Inhandnetworks Ir915l-fq39-s FirmwareInhandnetworks Ir912l-fq58 Firmware | 18/6/2026 | 22/6/2026 | InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the Python application export function. This vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input. | |
| Analizada | Crítica (9.8) | 2.3% | — | Inhandnetworks Ir915l-fq39-s FirmwareInhandnetworks Ir912l-fq58 Firmware | 18/6/2026 | 22/6/2026 | InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the log viewing function. This vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input. | |
| Analizada | Crítica (9.8) | 2.3% | — | Inhandnetworks Ir915l-fq39-s FirmwareInhandnetworks Ir912l-fq58 Firmware | 18/6/2026 | 22/6/2026 | InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the Python configuration function. This vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input. | |
| Aplazada | Crítica (9.1) | 0.52% | — | Network-aiAI | 17/6/2026 | 23/6/2026 | Network-AI is a TypeScript/Node.js multi-agent orchestrator. In versions 5.7.1 and earlier, the MCP SSE server allows unauthenticated cross-origin MCP tool invocation due to an empty default secret. This issue was partially addressed by CVE-2026-46701 in version 5.4.5 by closing the CORS flaw (with… | |
| Analizada | Media (6.3) | 0.25% | — | Cisco Crosswork Network Controller | 17/6/2026 | 22/6/2026 | A vulnerability in the web-based management interface of Cisco Crosswork Network Controller could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. | |
| Analizada | Alta (7.1) | 0.46% | — | Canon EOS Network Setting Tool | 16/6/2026 | 18/6/2026 | Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier | |
| Analizada | Alta (7.6) | 0.32% | — | Canon EOS Network Setting Tool | 16/6/2026 | 18/6/2026 | Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier | |
| Analizada | Media (6.9) | 0.42% | — | Canon EOS Network Setting Tool | 16/6/2026 | 18/6/2026 | Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier | |
| Analizada | Alta (7.1) | 0.34% | — | Canon EOS Network Setting Tool | 16/6/2026 | 18/6/2026 | Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier | |
| Analizada | Alta (7.1) | 0.50% | — | Canon EOS Network Setting Tool | 16/6/2026 | 18/6/2026 | Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier | |
| Analizada | Alta (8.7) | 0.63% | — | Paloaltonetworks Idira Privileged Access Manager Vault | 12/6/2026 | 7/7/2026 | Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an unexpected service termination, resulting in a localized… | |
| Modificada | Alta (7.5) | 0.17% | — | Paloaltonetworks Idira Privilege Cloud Connector | 12/6/2026 | 23/6/2026 | Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validation may not be fully enforced. CyberArk Security Bulletin: CA26-17 | |
| Analizada | Alta (8.5) | 0.17% | — | Paloaltonetworks Idira Endpoint Privilege Manager | 11/6/2026 | 22/6/2026 | Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5 allow a local attacker to potentially compromise the agent daemon initialization. CyberArk Security Bulletin: CA26-19 | |
| Analizada | Alta (8.4) | 0.21% | — | Paloaltonetworks Idira Identity Browser Extension | 11/6/2026 | 22/6/2026 | Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validation flaw within its internal web-page verification routines. If an authenticated user navigates to a specially crafted webpage, this interaction could potentially allow a remote attacker to trigger… | |
| Analizada | Alta (8.7) | 0.81% | — | Paloaltonetworks Idira Privileged Session Manager FOR SSH | 11/6/2026 | 23/6/2026 | Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3, 14.2.5, and 14.0.6, an authenticated, low-privileged user could potentially execute arbitrary commands on the PSMP host. CyberArk Security Bulletins: CA26-17 and CA26-18 |