Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
2621 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.62% | — | Productivity SuiteAI | 23/10/2025 | 17/6/2026 | A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and read arbitrary files on the target machine. | |
| Aplazada | Alta (8.3) | 0.62% | — | Productivity SuiteAI | 23/10/2025 | 17/6/2026 | A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and write files with arbitrary data on the target machine. | |
| Aplazada | Alta (7.2) | 0.40% | — | Rymera Wholesale SuiteAI | 22/10/2025 | 8/10/2026 | Incorrect Privilege Assignment vulnerability in Josh Kohlbach Wholesale Suite woocommerce-wholesale-prices allows Privilege Escalation.This issue affects Wholesale Suite: from n/a through <= 2.2.4.2. | |
| Analizada | Alta (8.5) | 0.18% | — | NI Circuit Design Suite | 30/9/2025 | 17/6/2026 | There is a memory corruption vulnerability due to an out of bounds read in DefaultFontOptions() when using SymbolEditor in NI Circuit Design Suite. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted… | |
| Analizada | Alta (8.5) | 0.18% | — | NI Circuit Design Suite | 30/9/2025 | 17/6/2026 | There is a memory corruption vulnerability due to an out of bounds write in XML_Serialize() when using SymbolEditor in NI Circuit Design Suite. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted… | |
| Aplazada | Media (6) | 0.29% | — | Hitachienergy Asset SuiteAI | 30/9/2025 | 17/6/2026 | A vulnerability exists in Asset Suite for an authenticated user to manipulate the content of performance related log data or to inject crafted data in logfile for potentially carrying out further malicious attacks. Performance logging is typically enabled for troubleshooting purposes while resolving application… | |
| Analizada | Alta (7.5) | 0.37% | — | Dell Bsafe Micro-edition-suite | 25/9/2025 | 17/6/2026 | Dell BSAFE Micro Edition Suite, versions prior to 5.0.2.3 contain an Out-of-bounds Write vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service. | |
| Aplazada | Alta (7.8) | 0.11% | — | Smartvista SuiteAI | 18/9/2025 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability in Smartvista BackOffice SmartVista Suite 2.2.22 via crafted GET request. | |
| Aplazada | Media (4.3) | 0.34% | — | Patika Global Technologies HumansuiteAI | 16/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Encoding or Escaping of Output, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Patika Global Technologies HumanSuite allows Cross-Site Scripting… | |
| Aplazada | Media (6.5) | 0.29% | — | Patika Global Technologies HumansuiteAI | 16/9/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key, Externally Controlled Reference to a Resource in Another Sphere, Improper Authorization vulnerability in Patika Global Technologies HumanSuite allows Exploiting Trust in Client. This issue affects HumanSuite: before 53.21.0. | |
| Analizada | Alta (8.1) | 0.24% | — | Dieboldnixdorf Vynamic Security Suite | 29/8/2025 | 17/6/2026 | Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR01 does not validate file attributes or the contents of /root during integrity validation. This allows code execution, recovery of TPM Disk Encryption keys, decryption of the Windows system partition, and full control of the Windows OS, e.g., through ~/.profile… | |
| Analizada | Alta (8.1) | 0.37% | — | Dieboldnixdorf Vynamic Security Suite | 29/8/2025 | 17/6/2026 | Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical system files before the filesystem is properly mounted (e.g., leveraging a delete call in /etc/rc.d/init.d/mountfs to remove the /etc/fstab file). This can allow code execution and, in some versions,… | |
| Analizada | Media (6.5) | 0.31% | — | Talentneuron Hrforecast Suite | 19/8/2025 | 17/6/2026 | In the smartLibrary component of the HRForecast Suite 0.4.3, a SQL injection vulnerability was discovered in the valueKey parameter. This flaw enables any authenticated user to execute arbitrary SQL queries, via crafted payloads to valueKey to the api/smartlibrary/v2/en/dictionaries/options/lookup endpoint. | |
| Aplazada | Alta (7.3) | 0.13% | — | Intel Connectivity Performance SuiteAI | 12/8/2025 | 17/6/2026 | Time-of-check Time-of-use race condition for some Intel(R) Connectivity Performance Suite software installers before version 40.24.11210 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (8.6) | 0.17% | — | Siemens Simatic PCS NEOAISiemens Simatic S7-plcsimAISiemens Simatic Step 7AISiemens Simatic WinccAI+7 | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions < V6.0 SP1 Update 1), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 V17 (All versions < V17 Update 9), SIMATIC STEP 7 V18 (All versions), SIMATIC STEP 7 V19 (All… | |
| Analizada | Baja (3.7) | 0.23% | — | Salesagility Suitecrm | 7/8/2025 | 17/6/2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a vulnerability in SuiteCRM version 7.14.6 which allows unauthenticated downloads of any file from the upload-directory, as long as it is named by an ID (e.g. attachments). An unauthenticated attacker… | |
| Analizada | Alta (8.6) | 0.21% | — | Salesagility Suitecrm | 7/8/2025 | 17/6/2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a Cross Site Scripting (XSS) vulnerability in the email viewer in versions 7.14.0 through 7.14.6. An external attacker could send a prepared message to the inbox of the SuiteCRM-instance. By simply… | |
| Analizada | Media (5.1) | 0.21% | — | Salesagility Suitecrm | 7/8/2025 | 17/6/2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability. This vulnerability allows an attacker to execute JavaScript code by modifying the HTTP Referer header to include some arbitrary… | |
| Analizada | Alta (8.8) | 0.42% | — | Salesagility Suitecrm | 7/8/2025 | 17/6/2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions and below, the InboundEmail module allows the arbitrary execution of queries in the backend database, leading to SQL injection. This can have wide-reaching implications on confidentiality, integrity,… | |
| Analizada | Media (5.3) | 0.29% | — | Salesagility Suitecrm | 7/8/2025 | 17/6/2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, the broken authentication in the legacy iCal service allows unauthenticated access to meeting data. An unauthenticated actor can view any user's meeting (calendar event) data given… | |
| Analizada | Alta (8.8) | 0.38% | — | Salesagility Suitecrm | 7/8/2025 | 17/6/2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, user-supplied input is not validated/sanitized before it is passed to the unserialize function, which could lead to penetration, privilege escalation, sensitive data exposure, Denial… | |
| Modificada | Media (6.5) | 0.48% | — | Vedo Suite Project Vedo Suite | 6/8/2025 | 5/7/2026 | Bottinelli Informatical Vedo Suite 2024.17 is vulnerable to Server-side Request Forgery (SSRF) in the /api_vedo/video/preview endpoint, which allows remote authenticated attackers to trigger HTTP requests towards arbitrary remote paths via the "file" URL parameter. | |
| Modificada | Media (6.5) | 0.52% | — | Vedo Suite Project Vedo Suite | 6/8/2025 | 5/7/2026 | A local file inclusion (LFI) vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to read arbitrary filesystem files by exploiting an unsanitized 'readfile()' function call in '/api_vedo/video/preview'. | |
| Modificada | Alta (8.2) | 0.52% | — | Vedo Suite Project Vedo Suite | 6/8/2025 | 5/7/2026 | An unrestricted file upload vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to write to arbitrary filesystem paths by exploiting the insecure 'uploadPreviews()' custom function in '/api_vedo/colorways_preview', ultimately resulting in remote code execution (RCE). | |
| Modificada | Alta (8.6) | 0.30% | — | Vedo Suite Project Vedo Suite | 6/8/2025 | 5/7/2026 | Insecure Data Storage of credentials has been found in /api_vedo/configuration/config.yml file in Vedo Suite version 2024.17. This file contains clear-text credentials, secret keys, and database information. |