Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
2621 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.41% | — | Vedo Suite Project Vedo Suite | 6/8/2025 | 5/7/2026 | Vedo Suite 2024.17 is vulnerable to Incorrect Access Control, which allows remote attackers to obtain a valid high privilege JWT token without prior authentication via sending an empty HTTP POST request to the /autologin/ API endpoint. | |
| Modificada | Media (6.1) | 0.42% | — | Vedo Suite Project Vedo Suite | 6/8/2025 | 5/7/2026 | A Cross-site scripting (XSS) vulnerability in /api_vedo/ in Vedo Suite version 2024.17 allows remote attackers to inject arbitrary Javascript or HTML code and potentially trigger code execution in victim's browser. | |
| Modificada | Media (6.5) | 0.45% | — | Vedo Suite Project Vedo Suite | 6/8/2025 | 5/7/2026 | A path traversal vulnerability in Vedo Suite 2024.17 allows remote authenticated attackers to read arbitrary filesystem files by exploiting an unsanitized 'file_get_contents()' function call in '/api_vedo/template'. | |
| Aplazada | Media (5.9) | 0.20% | — | Mitsubishielectric Genesis64AIMitsubishielectric Iconics SuiteAIMitsubishielectric MobilehmiAIMitsubishielectric Hyper HistorianAI+4 | 6/8/2025 | 17/6/2026 | Windows Shortcut Following (.LNK) vulnerability in multiple processes of Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric MobileHMI versions 10.97.3 and prior, Mitsubishi Electric Hyper Historian versions 10.97.3 and prior,… | |
| Aplazada | Media (6.7) | 0.15% | — | Asus AI Suite 3AI | 1/8/2025 | 17/6/2026 | A null pointer dereference vulnerability exists in the IOMap64.sys driver of ASUS AI Suite 3. The vulnerability can be triggered by a specially crafted input, which may lead to a system crash (BSOD). Refer to the ' Security Update for for AI Suite 3 ' section on the ASUS Security Advisory for more information. | |
| Analizada | Alta (8.4) | 0.30% | — | Nokia Wavesuite NOC | 21/7/2025 | 17/6/2026 | The web application allows user input to pass unfiltered to a command executed on the underlying operating system. An attacker with high privileged access (administrator) to the application has the potential execute commands on the operating system under the context of the webserver. The vulnerable component is bound… | |
| Analizada | Crítica (9) | 0.25% | — | Nokia Wavesuite NOC | 21/7/2025 | 17/6/2026 | File contents could be read from the local file system by an attacker. Additionally, malicious code could be inserted in the file, leading to a full compromise of the web application and the container it is running on. The vulnerable component is bound to the network stack and the set of possible attackers extends up… | |
| Analizada | Crítica (9) | 0.35% | — | Nokia Wavesuite NOC | 21/7/2025 | 17/6/2026 | The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The vulnerable component is bound to the network stack and the set of possible attackers extends up to and including the entire Internet. An attacker with low privileged access to the application has the… | |
| Aplazada | Alta (8.7) | 0.36% | — | Leviton AcquisuiteAILeviton Energy Monitoring HUBAI | 18/7/2025 | 17/6/2026 | Leviton AcquiSuite and Energy Monitoring Hub are susceptible to a cross-site scripting vulnerability, allowing an attacker to craft a malicious payload in URL parameters, which would execute in a client browser when accessed by a user, steal session tokens, and control the service. | |
| Analizada | Media (5.4) | 0.17% | — | Oracle E-business Suite | 15/7/2025 | 17/6/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.… | |
| Aplazada | Media (6.5) | 0.45% | — | Asna RegistrarAIAsna Datagate FOR SQL ServerAIAsna Datagate Component SuiteAIAsna Datagate MonitorAI+13 | 3/7/2025 | 17/6/2026 | ASNA Assist and ASNA Registrar before 2025-03-31 allow deserialization attacks against .NET remoting. These are Windows system services that support license key management and deprecated Windows network authentication. The services are implemented with .NET remoting and can be exploited via well-known deserialization… | |
| Aplazada | Alta (7.1) | 0.12% | — | Plumwd Twitch TV Embed SuiteAI | 27/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in plumwd Twitch TV Embed Suite twitch-tv-embed-suite allows Stored XSS.This issue affects Twitch TV Embed Suite: from n/a through <= 2.1.0. | |
| Analizada | Media (5.4) | 0.19% | — | Fl3r Accessibility Suite | 27/6/2025 | 17/6/2026 | The FL3R Accessibility Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fl3raccessibilitysuite shortcode in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Crítica (9.3) | 0.66% | — | 5vtechnologies Blue Angel Software Suite | 24/6/2025 | 17/6/2026 | A hardcoded credential vulnerability exists in the Blue Angel Software Suite deployed on embedded Linux systems. The application contains multiple known default and hardcoded user accounts that are not disclosed in public documentation. These accounts allow unauthenticated or low-privilege attackers to gain… | |
| Modificada | Alta (7.7) | 11% | 💥 Exploit | 5vtechnologies Blue Angel Software Suite | 24/6/2025 | 17/6/2026 | An OS command injection vulnerability exists in the Blue Angel Software Suite running on embedded Linux devices via the ping_addr parameter in the webctrl.cgi script. The application fails to properly sanitize input before passing it to the system-level ping command. An authenticated attacker can inject arbitrary… | |
| Analizada | Media (6.1) | 1.7% | ⚠ Explotación activa | Synacor Zimbra Collaboration Suite | 23/6/2025 | 17/6/2026 | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information. This issue arises… | |
| Aplazada | Media (6.5) | 0.23% | — | Wpengine Gutenberg Blocks ACF Blocks SuiteAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Engine Gutenberg Blocks – ACF Blocks Suite acf-blocks allows Stored XSS.This issue affects Gutenberg Blocks – ACF Blocks Suite: from n/a through <= 2.6.11. | |
| Analizada | Media (4.8) | 0.29% | — | Dell Wyse Management Suite | 10/6/2025 | 17/6/2026 | Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection | |
| Analizada | Media (6.8) | 0.30% | — | Dell Wyse Management Suite | 10/6/2025 | 17/6/2026 | Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Analizada | Media (6.1) | 0.39% | — | Dell Wyse Management Suite | 10/6/2025 | 17/6/2026 | Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection. | |
| Analizada | Baja (2.7) | 0.19% | — | Dell Wyse Management Suite | 10/6/2025 | 17/6/2026 | Dell Wyse Management Suite, versions prior to WMS 5.2, contain a Cross-Site Request Forgery (CSRF) vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery. | |
| Analizada | Alta (7.5) | 0.34% | — | Dell Wyse Management Suite | 10/6/2025 | 17/6/2026 | Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Exposure of Sensitive Information Through Data Queries vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Analizada | Alta (8.2) | 0.49% | — | Dell Wyse Management Suite | 10/6/2025 | 17/6/2026 | Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Absolute Path Traversal vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and Unauthorized access. | |
| Aplazada | Media (5.4) | 0.32% | — | Ability INC Accessibility SuiteAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Ability, Inc Accessibility Suite online-accessibility allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accessibility Suite: from n/a through <= 4.19. | |
| Analizada | Alta (8.8) | 0.32% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 3/6/2025 | 17/6/2026 | IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an unauthenticated user in the environment to obtain highly sensitive information in configuration files. |