Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

3711 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.07%—Dell Alienware Command Center11/3/202617/6/2026
Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service.
AnalizadaMedia (6.1)0.21%—Cisco Unified Contact Center Express11/3/20268/7/2026
A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability exists because the web-based management interface of an affected…
En análisisMedia (6.1)0.21%—Cisco FinesseAICisco Packaged Contact Center EnterpriseAICisco Unified Contact Center EnterpriseAICisco Unified Contact Center ExpressAI+111/3/202617/6/2026
A vulnerability in the web-based management interface of  Cisco Finesse, Cisco Packaged Contact Center Enterprise (Packaged CCE), Cisco Unified Contact Center Enterprise (Unified CCE), Cisco Unified Contact Center Express (Unified CCX), and Cisco Unified Intelligence Center could allow an unauthenticated, remote…
AnalizadaAlta (7.8)0.31%—Microsoft Windows Admin Center10/3/202617/6/2026
Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (8.8)1.1%—Microsoft System Center Operations Manager10/3/202617/6/2026
Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a network.
AplazadaAlta (8.8)0.24%—Data Center AuditAI6/3/202617/6/2026
Data Center Audit 2.6.2 contains an SQL injection vulnerability in the username parameter of dca_login.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can submit crafted SQL payloads through POST requests to extract sensitive database information including usernames, database…
AplazadaMedia (6.9)0.13%—Data Center AuditAI6/3/202617/6/2026
Data Center Audit 2.6.2 contains a cross-site request forgery vulnerability that allows attackers to reset administrator passwords without authentication by submitting crafted POST requests. Attackers can send requests to dca_resetpw.php with parameters updateuser, pass, pass2, and submit_reset to change the admin…
AplazadaAlta (7.1)0.26%—Quanticalabs Medicenter - Health Medical ClinicAI5/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs MediCenter - Health Medical Clinic medicenter allows Reflected XSS.This issue affects MediCenter - Health Medical Clinic: from n/a through <= 14.9.
AnalizadaCrítica (10)43%⚠ Explotación activa💥 PoCCisco Secure Firewall Management Center4/3/202617/6/2026
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root&nbsp;on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream.…
AnalizadaCrítica (10)88%⚠ Explotación activa💥 ExploitCisco Secure Firewall Management Center4/3/202616/9/2026
—
AnalizadaMedia (6)0.14%—Cisco Secure Firewall Management Center4/3/20262/9/2026
A vulnerability in the lockdown mechanism of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, local attacker to perform arbitrary commands as root. This vulnerability is due to insufficient restrictions on remediation modules while in lockdown mode. An attacker could exploit this…
Pendiente de análisisMedia (5.9)0.44%—Cisco Secure Firewall Management CenterAICisco Secure Firewall Threat DefenseAI4/3/202617/6/2026
A vulnerability in the sftunnel functionality of Cisco Secure Firewall Management Center (FMC) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker with administrative privileges to write arbitrary files as root on the underlying operating system. This…
AnalizadaMedia (4.9)0.29%—Cisco Secure Firewall Management Center4/3/202610/8/2026
A vulnerability in the REST API of Cisco Secure FMC Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to inadequate validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted requests to an…
AnalizadaAlta (8.1)0.35%—Cisco Secure Firewall Management Center4/3/202610/8/2026
A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to inadequate validation of user-supplied input. An attacker could exploit this vulnerability by sending…
AnalizadaAlta (7.5)0.16%—Hitachi Configuration ManagerHitachi OPS Center API Configuration Manager25/2/202617/6/2026
Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager.This issue affects Hitachi Ops Center API Configuration Manager: from 10.0.0-00 before 11.0.4-00; Hitachi Configuration Manager: from 8.6.1-00 before 11.0.5-00.
AnalizadaMedia (5.2)0.14%💥 PoCHitachi Configuration ManagerHitachi Device ManagerHitachi OPS Center API Configuration Manager25/2/202617/6/2026
Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager, Hitachi Device Manager allows Session Hijacking.This issue affects Hitachi Ops Center API Configuration Manager: from 10.0.0-00 before 11.0.5-00; Hitachi Configuration Manager: from 8.5.1-00 before…
AnalizadaMedia (5.7)0.37%—Tenable Security Center23/2/202617/6/2026
An improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope.
AnalizadaBaja (2.1)0.38%—Tenable Security Center23/2/202617/6/2026
An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner' parameter.
AplazadaAlta (8.4)0.20%—Control Center PROAI18/2/202617/6/2026
Control Center PRO 6.2.9 contains a stack-based buffer overflow vulnerability in the user creation module's username field that allows attackers to overwrite Structured Exception Handler (SEH). Attackers can craft a malicious payload exceeding 664 bytes to inject shellcode and potentially execute arbitrary code on…
AnalizadaAlta (8.8)0.83%💥 PoCMicrosoft Windows Admin Center17/2/202617/6/2026
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
AplazadaAlta (7.4)1.8%—Tenable Security CenterAI17/2/202617/6/2026
A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the underlying server where Tenable Security Center is hosted.
AnalizadaAlta (7.3)0.17%—Siemens Simcenter FemapSiemens Simcenter Nastran10/2/202617/6/2026
A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applications contains an out of bounds read vulnerability while parsing specially crafted NDB files. This could allow an attacker to execute code in the context of the current process.
AnalizadaAlta (7.3)0.14%—Siemens Simcenter FemapSiemens Simcenter Nastran10/2/202617/6/2026
A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted NDB files. This could allow an attacker to execute code in the context of the current process.
AnalizadaAlta (7.3)0.14%—Siemens Simcenter FemapSiemens Simcenter Nastran10/2/202617/6/2026
A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applications contains an out of bounds read vulnerability while parsing specially crafted NDB files. This could allow an attacker to execute code in the context of the current process.
AnalizadaAlta (7.3)0.14%—Siemens Simcenter FemapSiemens Simcenter Nastran10/2/202617/6/2026
A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applications contains an out of bounds read vulnerability while parsing specially crafted XDB files. This could allow an attacker to execute code in the context of the current process.