Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
5318 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.34% | 💥 PoC | Nextscripts Social Networks Auto PosterAI | 10/3/2026 | 17/6/2026 | The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[nxs_fbembed]` shortcode in all versions up to, and including, 4.4.6. This is due to insufficient input sanitization and output escaping on the `snapFB` post meta value. This makes it possible for… | |
| Aplazada | Alta (8.8) | 0.58% | — | Nextscripts Social-networks-auto-poster-facebook-twitter-gAI | 5/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in NextScripts NextScripts social-networks-auto-poster-facebook-twitter-g allows Object Injection.This issue affects NextScripts: from n/a through <= 4.4.7. | |
| Analizada | Media (4.2) | 0.15% | — | Arubanetworks Arubaos | 4/3/2026 | 17/6/2026 | A vulnerability has been identified where an attacker connecting to an access point as a standard wired or wireless client can impersonate a gateway by leveraging an address-based spoofing technique. Successful exploitation enables the redirection of data streams, allowing for the interception or modification of… | |
| Analizada | Baja (3.1) | 0.16% | — | Arubanetworks Arubaos | 4/3/2026 | 17/6/2026 | A vulnerability in the client isolation mechanism may allow an attacker to bypass Layer 2 (L2) communication restrictions between clients and redirect traffic at Layer 3 (L3). In addition to bypassing policy enforcement, successful exploitation - when combined with a port-stealing attack - may enable a bi-directional… | |
| Analizada | Baja (3.1) | 0.19% | — | Arubanetworks Arubaos | 4/3/2026 | 17/6/2026 | A vulnerability in the packet processing logic may allow an authenticated attacker to craft and transmit a malicious Wi-Fi frame that causes an Access Point (AP) to classify the frame as group-addressed traffic and re-encrypt it using the Group Temporal Key (GTK) associated with the victim's BSSID. Successful… | |
| Analizada | Alta (7.6) | 0.27% | — | Arubanetworks Arubaos | 4/3/2026 | 17/6/2026 | A technique has been identified that adapts a known port-stealing method to Wi-Fi environments that use multiple BSSIDs. By leveraging the relationship between BSSIDs and their associated virtual ports, an attacker could potentially bypass inter-BSSID isolation controls. Successful exploitation may enable an attacker… | |
| Analizada | Alta (8.1) | 0.28% | — | Arubanetworks Arubaos | 4/3/2026 | 17/6/2026 | A vulnerability has been identified in a standardized wireless roaming protocol that could enable a malicious actor to install an attacker-controlled Group Temporal Key (GTK) on a client device. Successful exploitation of this vulnerability could allow a remote malicious actor to perform unauthorized frame injection,… | |
| Analizada | Media (5.4) | 0.09% | — | Arubanetworks Arubaos | 4/3/2026 | 17/6/2026 | A vulnerability has been identified in the wireless encryption handling of Wi-Fi transmissions. A malicious actor can generate shared-key authenticated transmissions containing targeted payloads while impersonating the identity of a primary BSSID.Successful exploitation allows for the delivery of tampered data to… | |
| Analizada | Media (6.3) | 0.11% | — | Nozominetworks ARC | 4/3/2026 | 17/6/2026 | The server certificate was not verified when an Arc agent connected to a Guardian or CMC. A malicious actor could perform a man-in-the-middle attack and intercept the communication between the Arc agent and the Guardian or CMC. This could result in theft of the client token and sensitive information (such as assets… | |
| Analizada | Baja (2) | 0.18% | — | Nozominetworks CMC | 4/3/2026 | 17/6/2026 | A Stored HTML Injection vulnerability was discovered in the CMC's Sensor Map functionality due to improper validation on connected Guardians' properties. A malicious authenticated user with administrator privileges on a Guardian connected to a CMC can edit the Guardian's properties to inject HTML tags. If the Sensor… | |
| Modificada | Baja (2.1) | 0.17% | — | Nozominetworks CMCNozominetworks Guardian | 4/3/2026 | 17/6/2026 | A Stored HTML Injection vulnerability was discovered in the Alerted Nodes Dashboard functionality due to improper validation on an input parameter. A malicious authenticated user with the required privileges could edit a node label to inject HTML tags. If the system is configured to use the Alerted Nodes Dashboard,… | |
| Analizada | Media (6) | 0.29% | — | Extremenetworks Extremecloud IQ Site Engine | 2/3/2026 | 17/6/2026 | In ExtremeCloud IQ – Site Engine (XIQ‑SE) before 26.2.10, a vulnerability in the NAC administration interface allows an authenticated NAC administrator to retrieve masked sensitive parameters from HTTP responses. Although credentials appear redacted in the user interface, the application returns the underlying… | |
| Analizada | Media (4.8) | 0.43% | — | Accellion Kiteworks | 27/2/2026 | 17/6/2026 | Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks Email Protection Gateway allows authenticated administrators to inject malicious scripts through a configuration interface. The stored script executes when users interact with the affected user interface. Version 9.2.0… | |
| Analizada | Media (6.5) | 0.54% | — | Accellion Kiteworks | 27/2/2026 | 17/6/2026 | Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration functionality allows bypassing of SSRF protections through DNS rebinding attacks. Malicious administrators could exploit this to access internal services that should be restricted. Version 9.2.0 contains a… | |
| Analizada | Alta (7.2) | 2.1% | — | Accellion Kiteworks | 27/2/2026 | 17/6/2026 | Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration allows uploading of arbitrary files without proper validation. Malicious administrators could exploit this to upload unauthorized file types to the system. Version 9.2.0 contains a patch for the issue. | |
| Aplazada | Baja (2.7) | 0.17% | — | Vmware WorkstationAI | 27/2/2026 | 17/6/2026 | Out-of-bound read vulnerability in VMware Workstation 25H1 and below on any platform allows an actor with non-administrative privileges on a guest VM to obtain limited information disclosure from the machine where VMware Workstation is installed. | |
| Aplazada | Media (5) | 0.16% | — | Vmware WorkstationAI | 27/2/2026 | 17/6/2026 | Out-of-bound write vulnerability in VMware Workstation 25H1 and below on any platform allows an actor with non-administrative privileges on a guest VM to terminate certain Workstation processes. | |
| Analizada | Media (5.4) | 0.14% | — | Soliton Securebrowser FOR OnegateSoliton Securebrowser IISoliton Secureworkspace | 27/2/2026 | 17/6/2026 | The installers for multiple products provided by Soliton Systems K.K. contain an issue with incorrect default permissions, which may allow arbitrary code to be executed with SYSTEM privileges. | |
| Analizada | Alta (8.8) | 3.0% | — | Accellion Kiteworks | 26/2/2026 | 17/6/2026 | Kiteworks is a private data network (PDN). Prior to version 9.2.0, avulnerability in Kiteworks command execution functionality allows authenticated users to redirect command output to arbitrary file locations. This could be exploited to overwrite critical system files and gain elevated access. Version 9.2.0 contains a… | |
| Aplazada | Media (5.9) | 0.21% | — | Vmware WorkstationAIVmware FusionAI | 26/2/2026 | 17/6/2026 | VMWare Workstation and Fusion contain a logic flaw in the management of network packets. Known attack vectors: A malicious actor with administrative privileges on a Guest VM may be able to interrupt or intercept network connections of other Guest VM's. Resolution: To remediate CVE-2026-22715 please upgrade to VMware… | |
| Analizada | Alta (8.8) | 0.30% | — | Bosch Rexroth Indraworks | 18/2/2026 | 17/6/2026 | A vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a manipulated file containing malicious serialized data. Exploitation requires user interaction, specifically opening a specially crafted file, which then causes the… | |
| Analizada | Alta (8.8) | 0.30% | — | Bosch Rexroth Indraworks | 18/2/2026 | 17/6/2026 | A vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a manipulated file containing malicious serialized data. Exploitation requires user interaction, specifically opening a specially crafted file, which then causes the… | |
| Analizada | Alta (8.8) | 0.39% | — | Bosch Rexroth IndraworksBosch Rexroth Ua.testclient | 18/2/2026 | 17/6/2026 | A vulnerability has been identified in the UA.Testclient utility, which is included in Rexroth IndraWorks. All versions prior to 15V24 are affected. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a manipulated file containing malicious serialized data. Exploitation requires user… | |
| Analizada | Alta (8.8) | 0.39% | — | Bosch Rexroth Indraworks | 18/2/2026 | 17/6/2026 | A vulnerability has been identified in the OPC.Testclient utility, which is included in Rexroth IndraWorks. All versions prior to 15V24 are affected. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a manipulated file containing malicious serialized data. Exploitation requires… | |
| Analizada | Alta (7.8) | 0.21% | — | 3DS Solidworks Edrawings | 16/2/2026 | 17/6/2026 | An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file. |