Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
4639 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.28% | — | Delinea Cloud SuiteAIDelinea Privileged Access ServiceAI | 18/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Delinea Inc. Cloud Suite and Privileged Access Service. Remediation: This issue is fixed in Cloud Suite: 25.1 | |
| Aplazada | Media (6.9) | 0.35% | — | Delinea Cloud SuiteAIDelinea Privileged Access ServiceAIDelinea Server SuiteAI | 18/2/2026 | 17/6/2026 | Improper Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in Delinea Inc. Cloud Suite and Privileged Access Service. If you're not using the latest Server Suite agents, this fix requires that you upgrade to Server Suite 2023.1 (agent 6.0.1) or later. * If you cannot upgrade to Release 2023.1… | |
| Aplazada | Crítica (9.5) | 0.35% | — | Opentext Directory ServicesAI | 18/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in OpenText™ Directory Services allows Object Injection. The vulnerability could lead to remote code execution, denial of service, or privilege escalation. This issue affects Directory Services: before 24.4.16, from 25.1 before 25.1.9, from 25.2 before 25.2.9, from 25.3… | |
| Aplazada | Media (6.1) | 0.18% | — | IBM Financial Transaction Manager FOR ACH ServicesAIIBM Financial Transaction Manager FOR Check ServicesAI | 17/2/2026 | 17/6/2026 | IBM Financial Transaction Manager for ACH Services and Check Services for Multi-Platform 3.0.0.0 through 3.0.5.4 Interim Fix 027 IBM Financial Transaction Manager for Check Services v3 (Multiplatforms) is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary… | |
| Aplazada | Media (6.5) | 0.32% | — | EKA Software Computer Information Advertising Services LTD Real Estate ScriptAI | 17/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EKA Software Computer Information Advertising Services Ltd. Real Estate Script V5 (With Doping Module – Store Module – New Language System) allows Cross-Site Scripting (XSS). This issue affects Real Estate… | |
| Aplazada | Media (5.5) | 2.9% | — | Tosei Self-service Washing MachineAI | 16/2/2026 | 17/6/2026 | A flaw has been found in Tosei Self-service Washing Machine 4.02. Impacted is an unknown function of the file /cgi-bin/tosei_datasend.php. Executing a manipulation of the argument adr_txt_1 can lead to command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The… | |
| Aplazada | Alta (8.5) | 0.14% | — | Realtek IIS Codec ServiceAI | 12/2/2026 | 17/6/2026 | Realtek IIS Codec Service 6.4.10041.133 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in the service configuration to inject malicious executables and escalate privileges on the system. | |
| Aplazada | Crítica (9.8) | 0.41% | — | NTN Information Processing Services Computer Software Hardware Industry AND Trade Smart PanelAI | 12/2/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in NTN Information Processing Services Computer Software Hardware Industry and Trade Ltd. Co. Smart Panel allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Smart Panel: before 20251215. | |
| Aplazada | Alta (7.8) | 0.10% | — | Dell Idrac Service ModuleAIDell Idrac Service Module FOR WindowsAIDell Idrac Service Module FOR LinuxAI | 12/2/2026 | 17/6/2026 | Dell iDRAC Service Module (iSM) for Windows, versions prior to 6.0.3.1, and Dell iDRAC Service Module (iSM) for Linux, versions prior to 5.4.1.1, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of… | |
| Aplazada | Crítica (9.4) | 0.39% | — | E-kalite Software Hardware Engineering Design AND Internet Services Industry AND Trade LTD CO TurboardAI | 11/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard allows Reflected XSS. This issue affects Turboard: from 2025.07 before 2026.02. NOTE: This CVE record… | |
| Aplazada | Alta (8.3) | 0.27% | — | Saastech Cleaning AND Internet Services INC TemizlikyoldaAI | 11/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saastech Cleaning and Internet Services Inc. TemizlikYolda allows Cross-Site Scripting (XSS). This issue affects TemizlikYolda: through 11022026. NOTE: The vendor was contacted early about this disclosure but… | |
| Aplazada | Media (5.4) | 0.21% | — | Saastech Cleaning AND Internet Services INC TemizlikyoldaAI | 11/2/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Saastech Cleaning and Internet Services Inc. TemizlikYolda allows Manipulating User-Controlled Variables. This issue affects TemizlikYolda: through 11022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Aplazada | Alta (8.7) | 0.48% | — | Sarman Soft Software AND Technology Services Industry AND Trade CMSAI | 10/2/2026 | 17/6/2026 | Execution After Redirect (EAR) vulnerability in Sarman Soft Software and Technology Services Industry and Trade Ltd. Co. CMS allows JSON Hijacking (aka JavaScript Hijacking), Authentication Bypass. This issue affects CMS: through 10022026. NOTE: The vendor was contacted early about this disclosure but did not respond… | |
| Aplazada | Crítica (9.9) | 0.58% | — | Gitlab AI GatewayAIGitlab DUO Workflow ServiceAI | 9/2/2026 | 17/6/2026 | GitLab has remediated a vulnerability in the Duo Workflow Service component of GitLab AI Gateway affecting all versions of the AI Gateway from 18.1.6, 18.2.6, 18.3.1 to 18.6.1, 18.7.0, and 18.8.0 in which AI Gateway was vulnerable to insecure template expansion of user supplied data via crafted Duo Agent Platform Flow… | |
| Aplazada | Alta (8.5) | 0.18% | — | Alps HID Monitor ServiceAI | 6/2/2026 | 17/6/2026 | Alps HID Monitor Service 8.1.0.10 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files\Apoint2K\HidMonitorSvc.exe to inject malicious executables and gain system-level… | |
| Aplazada | Alta (8.5) | 0.15% | — | Wondershare Application Framework ServiceAI | 6/2/2026 | 17/6/2026 | Wondershare Application Framework Service 2.4.3.231 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted service path by placing malicious executables in specific directory locations to hijack the… | |
| Aplazada | Alta (8.5) | 0.18% | — | Wacom WtabletserviceAI | 5/2/2026 | 17/6/2026 | Wacom WTabletService 6.6.7-3 contains an unquoted service path vulnerability that allows local attackers to execute malicious code with elevated privileges. Attackers can insert an executable file in the service path to run unauthorized code when the service restarts or the system reboots. | |
| Aplazada | Alta (8.5) | 0.21% | — | Rockwell Factorytalk Activation ServiceAIRockwellautomation Studio 5000 Logix DesignerAI | 5/2/2026 | 17/6/2026 | Studio 5000 Logix Designer 30.01.00 contains an unquoted service path vulnerability in the FactoryTalk Activation Service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Rockwell Software\FactoryTalk Activation\ to inject… | |
| Analizada | Baja (3.5) | 0.23% | — | IBM Jazz Reporting Service | 4/2/2026 | 17/6/2026 | IBM Jazz Reporting Service could allow an authenticated user on the network to affect the system's performance using complicated queries due to insufficient resource pooling. | |
| Analizada | Baja (3.5) | 0.22% | — | IBM Jazz Reporting Service | 4/2/2026 | 17/6/2026 | IBM Jazz Reporting Service could allow an authenticated user on the host network to obtain sensitive information about other projects that reside on the server. | |
| Analizada | Baja (3.5) | 0.23% | — | IBM Jazz Reporting Service | 4/2/2026 | 17/6/2026 | IBM Jazz Reporting Service could allow an authenticated user on the host network to cause a denial of service using specially crafted SQL query that consumes excess memory resources. | |
| Analizada | Media (6.9) | 0.36% | — | F5 Big-ip Container Ingress Services | 4/2/2026 | 17/6/2026 | A vulnerability exists in F5 BIG-IP Container Ingress Services that may allow excessive permissions to read cluster secrets. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Baja (2.3) | 0.18% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 4/2/2026 | 17/6/2026 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Aplazada | Alta (8.5) | 0.17% | — | Iskysoft Application Framework ServiceAI | 1/2/2026 | 17/6/2026 | Iskysoft Application Framework Service 2.4.3.241 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that would be run with the… | |
| Aplazada | Alta (8.5) | 0.14% | — | Andrea ST Filters ServiceAI | 30/1/2026 | 17/6/2026 | Andrea ST Filters Service 1.0.64.7 contains an unquoted service path vulnerability in its Windows service configuration. Local attackers can exploit the unquoted path to inject malicious code that will execute with elevated LocalSystem privileges during service startup. |