Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

3711 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.3)0.14%—Siemens Simcenter FemapSiemens Simcenter Nastran10/2/202617/6/2026
A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applications contains an out of bounds read vulnerability while parsing specially crafted XDB files. This could allow an attacker to execute code in the context of the current process.
AnalizadaAlta (7.3)0.17%—Siemens Simcenter FemapSiemens Simcenter Nastran10/2/202617/6/2026
A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applications contains an out of bounds write vulnerability while parsing specially crafted XDB files. This could allow an attacker to execute code in the context of the current process.
AnalizadaMedia (5.5)0.47%—Bontrofftech Medical Center Portal Management System6/2/202617/6/2026
A vulnerability has been found in SourceCodester Medical Center Portal Management System 1.0. Affected is an unknown function of the file /emp_edit1.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.
AnalizadaMedia (5.5)0.38%—Bontrofftech Medical Center Portal Management System6/2/202617/6/2026
A vulnerability was detected in SourceCodester Medical Center Portal Management System 1.0. This affects an unknown function of the file /login.php. The manipulation of the argument User results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.
AplazadaMedia (4.8)0.20%—Cisco Packaged Contact Center EnterpriseAICisco Unified Contact Center EnterpriseAI21/1/202617/6/2026
These vulnerabilities exist because the web-based management interface does not properly validate user-supplied input. An attacker could exploit these vulnerabilities by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the…
AplazadaMedia (4.8)0.20%—Cisco Packaged Contact Center EnterpriseAICisco Unified Contact Center EnterpriseAI21/1/202617/6/2026
These vulnerabilities exist because the web-based management interface does not properly validate user-supplied input. An attacker could exploit these vulnerabilities by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the…
AnalizadaAlta (8.2)0.34%—Mitel CXMitel Micontact Center Business15/1/202617/6/2026
A vulnerability in the Multimedia Email component of Mitel MiContact Center Business through 10.2.0.10 and Mitel CX through 1.1.0.1 could allow an unauthenticated attacker to conduct a Cross-Site Scripting (XSS) attack due to insufficient input validation. A successful exploit requires user interaction where the email…
AnalizadaAlta (8.7)4.1%—Kyocera Command Center RX13/1/202617/6/2026
Kyocera Command Center RX ECOSYS M2035dn contains a directory traversal vulnerability that allows unauthenticated attackers to read sensitive system files by manipulating file paths under the /js/ path. Attackers can exploit the issue by sending requests like /js/../../../../.../etc/passwd%00.jpg (null-byte appended…
AnalizadaAlta (7.5)0.23%—Microsoft Windows Admin Center13/1/202617/6/2026
Improper verification of cryptographic signature in Windows Admin Center allows an authorized attacker to elevate privileges locally.
AplazadaMedia (5.1)0.52%—Fibaro System Home CenterAI6/1/202617/6/2026
FIBARO System Home Center 5.021 contains a remote file inclusion vulnerability in the undocumented proxy API that allows attackers to include arbitrary client-side scripts. Attackers can exploit the 'url' GET parameter to inject malicious JavaScript and potentially hijack user sessions or manipulate page content.
AnalizadaBaja (1.2)0.60%—Qnap License Center2/1/202617/6/2026
A buffer overflow vulnerability has been reported to affect License Center. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: License Center 2.0.36 and later
AnalizadaBaja (1.3)0.58%—Qnap License Center2/1/202617/6/2026
An out-of-bounds read vulnerability has been reported to affect License Center. If a remote attacker gains a user account, they can then exploit the vulnerability to obtain secret data. We have already fixed the vulnerability in the following version: License Center 2.0.36 and later
AnalizadaMedia (6.5)0.21%—IBM DB2 Intelligence Center26/12/20257/10/2026
IBM Db2 Intelligence Center 1.1.0, 1.1.1, 1.1.2 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms.
AplazadaAlta (8.8)0.34%—Echo Call Center Services Trade AND Industry INC Specto CMAI24/12/20257/10/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Echo Call Center Services Trade and Industry Inc. Specto CM allows Remote Code Inclusion. This issue affects Specto CM: before 17032025.
AplazadaMedia (5.4)0.17%—Echo Call Center Services Trade AND Industry INC Specto CMAI24/12/20257/10/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Echo Call Center Services Trade and Industry Inc. Specto CM allows Stored XSS. This issue affects Specto CM: before 17032025.
AplazadaAlta (7.1)0.22%—Hitachi Infrastructure Analytics AdvisorAIHitachi OPS Center AnalyzerAI24/12/202517/6/2026
Authorization bypass vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component) and Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component).This issue affects Hitachi Infrastructure Analytics Advisor:; Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.5-00.
AplazadaAlta (8.2)0.20%—Hitachi Infrastructure Analytics AdvisorAIHitachi OPS Center AnalyzerAI24/12/202517/6/2026
Cross-site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component) and Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component).This issue affects Hitachi Infrastructure Analytics Advisor:; Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.5-00.
AnalizadaCrítica (9.8)0.77%—Microsoft Partner Center18/12/202517/6/2026
Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.
AnalizadaAlta (7.3)0.20%—Siemens Simcenter Femap12/12/20257/10/2026
A vulnerability has been identified in Simcenter Femap (All versions < V2512). The affected applications contains an uninitialized memory vulnerability while parsing specially crafted SLDPRT files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-27146)
AnalizadaAlta (7.8)0.47%—Microsoft Windows Admin Center11/12/20257/10/2026
Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges locally.
AplazadaCrítica (9.2)0.26%—Siemens ComosAISiemens JT Bi-directional Translator FOR StepAISiemens NXAISiemens Simcenter 3DAI+59/12/20257/10/2026
A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), JT Bi-Directional Translator for STEP (All versions), NX V2412 (All versions < V2412.8900 with Cloud Entitlement (bundled as NX X)), NX V2506 (All versions < V2506.6000 with Cloud Entitlement (bundled as…
AplazadaCrítica (9.1)0.21%—Siemens ComosAISiemens NXAISiemens Simcenter 3DAISiemens Simcenter FemapAI+19/12/20257/10/2026
A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), NX V2412 (All versions < V2412.8700), NX V2506 (All versions < V2506.6000), Simcenter 3D (All versions < V2506.6000), Simcenter Femap (All versions < V2506.0002), Solid Edge SE2025 (All versions < V225.0…
AplazadaAlta (7.3)0.20%—Siemens PS Iges Parasolid Translator ComponentAISiemens Simcenter FemapAISiemens Solid EdgeAI17/11/202517/6/2026
A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions < V29.0.258), Simcenter Femap (All versions < V2512.0003), Solid Edge (All versions < V226.00 Update 03). The affected applications contains an out of bounds read vulnerability while parsing specially crafted IGS files. This…
AnalizadaMedia (5.5)0.11%—Dell Alienware Command Center13/11/202517/6/2026
Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain a Process Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure.
AnalizadaAlta (7.8)0.12%—Dell Alienware Command Center13/11/202517/6/2026
Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contains an Insecure Temporary File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.