Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
2636 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.2) | 0.42% | — | Access Manager 92xxAI | 26/1/2026 | 17/6/2026 | The Access Manager 92xx in hardware revision K7 is based on Linux instead of Windows CE embedded in older hardware revisions. In this new hardware revision it was noticed that an SSH service is exposed on port 22. By analyzing the firmware of the devices, it was noticed that there are two users with hardcoded and weak… | |
| Aplazada | Media (6.9) | 0.38% | — | Access ManagerAI | 26/1/2026 | 17/6/2026 | The web server of the Access Manager offers a functionality to download a backup of the local database stored on the device. This database contains the whole configuration. This includes encrypted MIFARE keys, card data, user PINs and much more. The PINs are even stored unencrypted. Combined with the fact that an… | |
| Aplazada | Alta (8.7) | 0.41% | — | Dormakaba Access ManagerAI | 26/1/2026 | 17/6/2026 | The Access Manager is offering a trace functionality to debug errors and issues with the device. The trace functionality is implemented as a simple TCP socket. A tool called TraceClient.exe, provided by dormakaba via the Access Manager web interface, is used to connect to the socket and receive debug information. The… | |
| Aplazada | Media (5.9) | 0.17% | — | Ability INC WEB Accessibility With MAX AccessAI | 23/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ability, Inc Web Accessibility with Max Access accessibility-toolbar allows Stored XSS.This issue affects Web Accessibility with Max Access: from n/a through <= 2.1.0. | |
| Analizada | Media (4.6) | 0.14% | — | Absolute Secure Access | 17/1/2026 | 17/6/2026 | In Secure Access 12.70 and prior to 14.20, the logging subsystem may write an unredacted authentication token to logs under certain configurations. Any party with access to those logs could read the token and reuse it to access an integrated system. | |
| Analizada | Media (4.8) | 0.17% | — | Absolute Secure Access | 17/1/2026 | 17/6/2026 | CVE-2026-0518 is a cross-site scripting vulnerability in versions of Secure Access prior to 14.20. An attacker with administrative privileges can interfere with another administrator’s use of the console. | |
| Analizada | Media (6) | 0.31% | — | Absolute Secure Access | 17/1/2026 | 17/6/2026 | CVE-2026-0517 is a denial-of-service vulnerability in versions of Secure Access Server prior to 14.20. An attacker can send a specially crafted packet to a server and cause the server to crash | |
| Analizada | Media (6.6) | 0.75% | — | Paloaltonetworks Pan-osPaloaltonetworks Prisma Access | 15/1/2026 | 17/6/2026 | A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to cause a denial of service (DoS) to the firewall. Repeated attempts to trigger this issue results in the firewall entering into maintenance mode. | |
| Aplazada | Crítica (9.3) | 1.3% | — | Noaa Live Access ServerAINoaa PyferretAI | 15/1/2026 | 17/6/2026 | Sites running NOAA PMEL Live Access Server (LAS) are vulnerable to remote code execution via specially crafted requests that include PyFerret expressions. By leveraging a SPAWN command, a remote, unauthenticated attacker can execute arbitrary OS commands. Fixed in a version of… | |
| Aplazada | Alta (8.5) | 0.21% | — | Privateinternetaccess Private Internet AccessAI | 13/1/2026 | 17/6/2026 | Private Internet Access 3.3 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem permissions during… | |
| Aplazada | Alta (7.8) | 0.17% | — | HPE Aruba Networking Virtual Intranet AccessAI | 13/1/2026 | 17/6/2026 | A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking Virtual Intranet Access (VIA) client. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges. | |
| Aplazada | Alta (7.5) | 0.46% | — | HPE Networking Instant ON Access PointsAI | 13/1/2026 | 17/6/2026 | A vulnerability affecting HPE Networking Instant On Access Points has been identified where a device processing a specially crafted packet could enter a non-responsive state, in some cases requiring a hard reset to re-establish services. A malicious actor could leverage this vulnerability to conduct a… | |
| Aplazada | Alta (7.5) | 0.40% | — | HPE Instant ON Access PointsAI | 13/1/2026 | 17/6/2026 | A vulnerability in the router mode configuration of HPE Instant On Access Points exposed certain network configuration details to unintended interfaces. A malicious actor could gain knowledge of internal network configuration details through inspecting impacted packets. | |
| Analizada | Alta (8.1) | 0.80% | — | Zohocorp Manageengine Pam360Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Password Manager PRO | 13/1/2026 | 17/6/2026 | Zohocorp ManageEngine PAM360 versions before 8202; Password Manager Pro versions before 13221; Access Manager Plus versions prior to 4401 are vulnerable to an authorization issue in the initiate remote session functionality. | |
| Aplazada | Crítica (9.3) | 0.76% | — | AccessallyAI | 9/1/2026 | 17/6/2026 | AccessAlly WordPress plugin versions prior to 3.3.2 contain an unauthenticated arbitrary PHP code execution vulnerability in the Login Widget. The plugin processes the login_error parameter as PHP code, allowing an attacker to supply and execute arbitrary PHP in the context of the WordPress web server process,… | |
| Modificada | Media (6.8) | 0.22% | — | IWT Facesentry Access Control System Firmware | 8/1/2026 | 17/6/2026 | FaceSentry Access Control System 6.4.8 contains a cleartext password storage vulnerability that allows attackers to access unencrypted credentials in the device's SQLite database. Attackers can directly read sensitive login information stored in /faceGuard/database/FaceSentryWeb.sqlite without additional… | |
| Modificada | Crítica (9.1) | 0.33% | — | IWT Facesentry Access Control System Firmware | 8/1/2026 | 17/6/2026 | FaceSentry Access Control System 6.4.8 contains a cleartext transmission vulnerability that allows remote attackers to intercept authentication credentials. Attackers can perform man-in-the-middle attacks to capture HTTP cookie authentication information during network communication. | |
| Analizada | Media (5.1) | 0.32% | — | IWT Facesentry Access Control System Firmware | 8/1/2026 | 17/6/2026 | FaceSentry Access Control System 6.4.8 contains a cross-site scripting vulnerability in the 'msg' parameter of pluginInstall.php that allows attackers to inject malicious scripts. Attackers can exploit the unvalidated input to execute arbitrary JavaScript in victim browsers, potentially stealing authentication… | |
| Aplazada | Media (5.1) | 0.24% | — | Soca Access Control SystemAI | 8/1/2026 | 17/6/2026 | SOCA Access Control System 180612 contains a cross-site scripting vulnerability in the 'senddata' POST parameter of logged_page.php that allows attackers to inject malicious scripts. Attackers can exploit this weakness by sending crafted POST requests to execute arbitrary HTML and script code in a victim's browser… | |
| Modificada | Crítica (9.8) | 0.67% | — | Blueaccesstech Cobalt X1 | 6/1/2026 | 5/7/2026 | Blue Access Cobalt v02.000.195 suffers from an authentication bypass vulnerability, which allows an attacker to selectively proxy requests in order to operate functionality on the web application without the need to authenticate with legitimate credentials. | |
| Aplazada | Media (5.1) | 0.28% | — | Commax Biometric Access Control SystemAI | 31/12/2025 | 17/6/2026 | COMMAX Biometric Access Control System 1.0.0 contains an unauthenticated reflected cross-site scripting vulnerability in cookie parameters 'CMX_ADMIN_NM' and 'CMX_COMPLEX_NM'. Attackers can inject malicious HTML and JavaScript code into these cookie values to execute arbitrary scripts in a victim's browser session. | |
| Aplazada | Media (5.9) | 0.18% | — | Ikaes Accessibility PressAI | 31/12/2025 | 23/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ikaes Accessibility Press ilogic-accessibility allows Stored XSS.This issue affects Accessibility Press: from n/a through <= 1.0.2. | |
| Aplazada | Media (4.3) | 0.18% | — | Skynet Technologies USA LLC ALL IN ONE AccessibilityAI | 31/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Skynet Technologies USA LLC All in One Accessibility all-in-one-accessibility allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects All in One Accessibility: from n/a through <= 1.15. | |
| Analizada | Alta (8.7) | 2.6% | — | IWT Facesentry Access Control System Firmware | 24/12/2025 | 17/6/2026 | FaceSentry 6.4.8 contains an authenticated remote command injection vulnerability in pingTest.php and tcpPortTest.php scripts. Attackers can exploit unsanitized input parameters to inject and execute arbitrary shell commands with root privileges by manipulating the 'strInIP' and 'strInPort' parameters. | |
| Analizada | Media (5.1) | 0.24% | — | IWT Facesentry Access Control System Firmware | 24/12/2025 | 17/6/2026 | FaceSentry Access Control System 6.4.8 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to change administrator passwords, add new admin users, or open access control doors by tricking authenticated… |