Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
2636 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6) | 0.26% | — | 2N Access Commander | 4/3/2026 | 17/6/2026 | 2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to remain active after logout in web application. | |
| Analizada | Media (5.3) | 0.19% | — | 2N Access Commander | 4/3/2026 | 17/6/2026 | Improper validation of API end-point in 2N Access Commander version 3.4.2 and prior allows attacker to bypass password policy for backup file encryption. This vulnerability can only be exploited after authenticating with administrator privileges. | |
| Analizada | Media (6.9) | 0.29% | — | 2N Access Commander | 4/3/2026 | 17/6/2026 | 2N Access Commander version 3.4.1 and prior is vulnerable to log pollution. Certain parameters sent over API may be included in the logs without prior validation or sanitisation. This vulnerability can only be exploited after authenticating with administrator privileges. | |
| Analizada | Alta (8.8) | 0.89% | — | 2N Access Commander | 4/3/2026 | 17/6/2026 | API endpoint for user synchronization in 2N Access Commander version 3.4.1 did not have a sufficient input validation allowing for OS command injection. This vulnerability can only be exploited after authenticating with administrator privileges. | |
| Analizada | Alta (7.8) | 1.3% | ⚠ Explotación activa💥 PoC | Qualcomm Sm7675p FirmwareQualcomm Sm8475p FirmwareQualcomm Sm8550p FirmwareQualcomm Sm8635 Firmware+233 | 2/3/2026 | 17/6/2026 | Memory corruption while using alignments for memory allocation. | |
| Analizada | Media (6.5) | 0.11% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+39 | 2/3/2026 | 17/6/2026 | Transient DOS when MAC configures config id greater than supported maximum value. | |
| Analizada | Alta (7.2) | 0.14% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem FirmwareQualcomm Apq8098 Firmware+202 | 2/3/2026 | 17/6/2026 | Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Sa8295p FirmwareQualcomm Sa8620p FirmwareQualcomm Sa8770p FirmwareQualcomm Sa9000p Firmware+174 | 2/3/2026 | 17/6/2026 | Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources. | |
| Analizada | Media (6.5) | 0.11% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+121 | 2/3/2026 | 17/6/2026 | Transient DOS when an LTE RLC packet with invalid TB is received by UE. | |
| Aplazada | Media (6.4) | 0.21% | — | WP AccessibilityAI | 27/2/2026 | 17/6/2026 | The WP Accessibility plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'alt' attribute of images processed by the "Long Description UI" feature in all versions up to, and including, 2.3.1. This is due to the plugin's JavaScript retrieving the alt attribute using getAttribute() and… | |
| Analizada | Baja (2.7) | 0.17% | — | Zscaler Internet Access Admin Portal | 23/2/2026 | 17/6/2026 | Improper neutralization of special elements in user-supplied input within the ZIA Admin UI could allow an authenticated administrator to access or retrieve unauthorized internal information in rare conditions. | |
| Analizada | Baja (2.7) | 0.20% | — | Zscaler Internet Access Admin Portal | 23/2/2026 | 17/6/2026 | Improper validation of user-supplied input in the ZIA Admin UI could allow an authenticated administrator to initiate backend functions through specific input fields in limited scenarios. | |
| Aplazada | Media (5.3) | 0.29% | — | Accessibe WEB AccessibilityAI | 19/2/2026 | 17/6/2026 | The Web Accessibility by accessiBe plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11. This is due to the `accessibe_render_js_in_footer()` function logging the complete plugin options array to the browser console on public pages, without restricting output… | |
| Aplazada | Media (5.3) | 0.28% | — | Delinea Cloud SuiteAIDelinea Privileged Access ServiceAI | 18/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Delinea Inc. Cloud Suite and Privileged Access Service. Remediation: This issue is fixed in Cloud Suite: 25.1 | |
| Aplazada | Media (6.9) | 0.35% | — | Delinea Cloud SuiteAIDelinea Privileged Access ServiceAIDelinea Server SuiteAI | 18/2/2026 | 17/6/2026 | Improper Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in Delinea Inc. Cloud Suite and Privileged Access Service. If you're not using the latest Server Suite agents, this fix requires that you upgrade to Server Suite 2023.1 (agent 6.0.1) or later. * If you cannot upgrade to Release 2023.1… | |
| Aplazada | Media (6.4) | 0.23% | — | Wpdataaccess WP Data AccessAI | 14/2/2026 | 17/6/2026 | The WP Data Access plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpda_app' shortcode in all versions up to, and including, 5.5.63 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Crítica (9.9) | 91% | ⚠ Explotación activa💥 Exploit | Beyondtrust Privileged Remote AccessBeyondtrust Remote Support | 6/2/2026 | 17/6/2026 | BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site… | |
| Analizada | Baja (2.3) | 0.18% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 4/2/2026 | 17/6/2026 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Baja (2) | 0.12% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Access Policy Manager Client | 4/2/2026 | 17/6/2026 | A vulnerability exists in BIG-IP Edge Client and browser VPN clients on Windows that may allow attackers to gain access to sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | |
| Analizada | Alta (7.8) | 0.16% | — | Native-instruments Native Access | 2/2/2026 | 17/6/2026 | It was found that the XPC service offered by the privileged helper of Native Access uses the PID of the connecting client to verify its code signature. This is considered insecure and can be exploited by PID reuse attacks. The connection handler function uses _xpc_connection_get_pid(arg2) as argument for the… | |
| Modificada | Alta (8.8) | 0.22% | — | Native-instruments Native Access | 2/2/2026 | 17/6/2026 | During the installation of the Native Access application, a privileged helper `com.native-instruments.NativeAccess.Helper2`, which is used by Native Access to trigger functions via XPC communication like copy-file, remove or set-permissions, is deployed as well. The communication with the XPC service of the privileged… | |
| Aplazada | Alta (7.2) | 0.91% | 💥 PoC | Hikvision Wireless Access PointAI | 30/1/2026 | 17/6/2026 | Some Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution. | |
| Aplazada | Alta (8.5) | 0.18% | — | Program Access ControllerAI | 28/1/2026 | 17/6/2026 | Program Access Controller 1.2.0.0 contains an unquoted service path vulnerability in PACService.exe that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path during system startup or reboot to inject and run malicious executables with LocalSystem permissions. | |
| Aplazada | Media (5.4) | 0.17% | — | Beat-accessAI | 27/1/2026 | 17/6/2026 | beat-access for Windows version 3.0.3 and prior contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with SYSTEM privileges. | |
| Analizada | Alta (8.8) | 0.78% | — | Dormakabagroup Dormakaba Access Manager 9200-k7 FirmwareDormakabagroup Dormakaba Access Manager 9230-k7 FirmwareDormakabagroup Dormakaba Access Manager 9290-k7 FirmwareDormakabagroup Dormakaba Access Manager 9200-k5 Firmware+2 | 26/1/2026 | 17/6/2026 | The binary serving the web server and executing basically all actions launched from the Web UI is running with root privileges. This is against the least privilege principle. If an attacker is able to execute code on the system via other vulnerabilities it is possible to directly execute commands with highest… |