Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
3711 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.07% | — | Dell Alienware Command Center | 11/3/2026 | 17/6/2026 | Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service. | |
| Analizada | Media (6.1) | 0.21% | — | Cisco Unified Contact Center Express | 11/3/2026 | 8/7/2026 | A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability exists because the web-based management interface of an affected… | |
| En análisis | Media (6.1) | 0.21% | — | Cisco FinesseAICisco Packaged Contact Center EnterpriseAICisco Unified Contact Center EnterpriseAICisco Unified Contact Center ExpressAI+1 | 11/3/2026 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Finesse, Cisco Packaged Contact Center Enterprise (Packaged CCE), Cisco Unified Contact Center Enterprise (Unified CCE), Cisco Unified Contact Center Express (Unified CCX), and Cisco Unified Intelligence Center could allow an unauthenticated, remote… | |
| Analizada | Alta (7.8) | 0.31% | — | Microsoft Windows Admin Center | 10/3/2026 | 17/6/2026 | Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (8.8) | 1.1% | — | Microsoft System Center Operations Manager | 10/3/2026 | 17/6/2026 | Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Alta (8.8) | 0.24% | — | Data Center AuditAI | 6/3/2026 | 17/6/2026 | Data Center Audit 2.6.2 contains an SQL injection vulnerability in the username parameter of dca_login.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can submit crafted SQL payloads through POST requests to extract sensitive database information including usernames, database… | |
| Aplazada | Media (6.9) | 0.13% | — | Data Center AuditAI | 6/3/2026 | 17/6/2026 | Data Center Audit 2.6.2 contains a cross-site request forgery vulnerability that allows attackers to reset administrator passwords without authentication by submitting crafted POST requests. Attackers can send requests to dca_resetpw.php with parameters updateuser, pass, pass2, and submit_reset to change the admin… | |
| Aplazada | Alta (7.1) | 0.26% | — | Quanticalabs Medicenter - Health Medical ClinicAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs MediCenter - Health Medical Clinic medicenter allows Reflected XSS.This issue affects MediCenter - Health Medical Clinic: from n/a through <= 14.9. | |
| Analizada | Crítica (10) | 43% | ⚠ Explotación activa💥 PoC | Cisco Secure Firewall Management Center | 4/3/2026 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream.… | |
| Analizada | Crítica (10) | 88% | ⚠ Explotación activa💥 Exploit | Cisco Secure Firewall Management Center | 4/3/2026 | 16/9/2026 | — | |
| Analizada | Media (6) | 0.14% | — | Cisco Secure Firewall Management Center | 4/3/2026 | 2/9/2026 | A vulnerability in the lockdown mechanism of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, local attacker to perform arbitrary commands as root. This vulnerability is due to insufficient restrictions on remediation modules while in lockdown mode. An attacker could exploit this… | |
| Pendiente de análisis | Media (5.9) | 0.44% | — | Cisco Secure Firewall Management CenterAICisco Secure Firewall Threat DefenseAI | 4/3/2026 | 17/6/2026 | A vulnerability in the sftunnel functionality of Cisco Secure Firewall Management Center (FMC) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker with administrative privileges to write arbitrary files as root on the underlying operating system. This… | |
| Analizada | Media (4.9) | 0.29% | — | Cisco Secure Firewall Management Center | 4/3/2026 | 10/8/2026 | A vulnerability in the REST API of Cisco Secure FMC Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to inadequate validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted requests to an… | |
| Analizada | Alta (8.1) | 0.35% | — | Cisco Secure Firewall Management Center | 4/3/2026 | 10/8/2026 | A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to inadequate validation of user-supplied input. An attacker could exploit this vulnerability by sending… | |
| Analizada | Alta (7.5) | 0.16% | — | Hitachi Configuration ManagerHitachi OPS Center API Configuration Manager | 25/2/2026 | 17/6/2026 | Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager.This issue affects Hitachi Ops Center API Configuration Manager: from 10.0.0-00 before 11.0.4-00; Hitachi Configuration Manager: from 8.6.1-00 before 11.0.5-00. | |
| Analizada | Media (5.2) | 0.14% | 💥 PoC | Hitachi Configuration ManagerHitachi Device ManagerHitachi OPS Center API Configuration Manager | 25/2/2026 | 17/6/2026 | Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager, Hitachi Device Manager allows Session Hijacking.This issue affects Hitachi Ops Center API Configuration Manager: from 10.0.0-00 before 11.0.5-00; Hitachi Configuration Manager: from 8.5.1-00 before… | |
| Analizada | Media (5.7) | 0.37% | — | Tenable Security Center | 23/2/2026 | 17/6/2026 | An improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope. | |
| Analizada | Baja (2.1) | 0.38% | — | Tenable Security Center | 23/2/2026 | 17/6/2026 | An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner' parameter. | |
| Aplazada | Alta (8.4) | 0.20% | — | Control Center PROAI | 18/2/2026 | 17/6/2026 | Control Center PRO 6.2.9 contains a stack-based buffer overflow vulnerability in the user creation module's username field that allows attackers to overwrite Structured Exception Handler (SEH). Attackers can craft a malicious payload exceeding 664 bytes to inject shellcode and potentially execute arbitrary code on… | |
| Analizada | Alta (8.8) | 0.83% | 💥 PoC | Microsoft Windows Admin Center | 17/2/2026 | 17/6/2026 | Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Alta (7.4) | 1.8% | — | Tenable Security CenterAI | 17/2/2026 | 17/6/2026 | A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the underlying server where Tenable Security Center is hosted. | |
| Analizada | Alta (7.3) | 0.17% | — | Siemens Simcenter FemapSiemens Simcenter Nastran | 10/2/2026 | 17/6/2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applications contains an out of bounds read vulnerability while parsing specially crafted NDB files. This could allow an attacker to execute code in the context of the current process. | |
| Analizada | Alta (7.3) | 0.14% | — | Siemens Simcenter FemapSiemens Simcenter Nastran | 10/2/2026 | 17/6/2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted NDB files. This could allow an attacker to execute code in the context of the current process. | |
| Analizada | Alta (7.3) | 0.14% | — | Siemens Simcenter FemapSiemens Simcenter Nastran | 10/2/2026 | 17/6/2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applications contains an out of bounds read vulnerability while parsing specially crafted NDB files. This could allow an attacker to execute code in the context of the current process. | |
| Analizada | Alta (7.3) | 0.14% | — | Siemens Simcenter FemapSiemens Simcenter Nastran | 10/2/2026 | 17/6/2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applications contains an out of bounds read vulnerability while parsing specially crafted XDB files. This could allow an attacker to execute code in the context of the current process. |