Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
164 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.23% | — | Soca Access Control SystemAI | 24/12/2025 | 17/6/2026 | SOCA Access Control System 180612 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without proper request validation. Attackers can craft malicious web pages that submit forged requests to create admin accounts by tricking logged-in users into visiting a… | |
| Aplazada | Media (5.1) | 0.20% | — | Zucchetti Axess Cloki Access ControlAI | 23/12/2025 | 17/6/2026 | Zucchetti Axess CLOKI Access Control 1.64 contains a cross-site request forgery vulnerability that allows attackers to manipulate access control settings without user interaction. Attackers can craft malicious web pages with hidden forms to disable or modify access control parameters by tricking authenticated users… | |
| Aplazada | Alta (8.7) | 0.55% | — | Commax Biometric Access Control SystemAI | 9/12/2025 | 17/6/2026 | COMMAX Biometric Access Control System 1.0.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access sensitive information and circumvent physical controls in smart homes and buildings by exploiting cookie poisoning. Attackers can forge cookies to bypass authentication and… | |
| Analizada | Crítica (9.8) | 0.72% | — | Avigilon Access Control Manager | 8/9/2025 | 17/6/2026 | A CSV injection vulnerability in the /id_profiles endpoint of Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via suuplying a crafted Excel file. | |
| Analizada | Crítica (9.8) | 2.9% | — | Avigilon Access Control Manager | 8/9/2025 | 17/6/2026 | A Host Header Injection vulnerability in Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via supplying a crafted URL. | |
| Aplazada | Alta (7.1) | 0.37% | — | Davidcramer Userbase-access-controlAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Cramer Userbase Access Control userbase-access-control allows Reflected XSS.This issue affects Userbase Access Control: from n/a through <= 1.0. | |
| Modificada | Alta (8.6) | 0.37% | — | Dataprom Personnel Attendance Control Systems / Access Control Security Systems | 15/11/2024 | 17/6/2026 | Origin Validation Error vulnerability in Dataprom Informatics Personnel Attendance Control Systems (PACS) / Access Control Security Systems (ACSS) allows Traffic Injection. This issue affects Personnel Attendance Control Systems (PACS) / Access Control Security Systems (ACSS): before 2024. | |
| Analizada | Alta (8.7) | 0.25% | — | Kastle Access Control System Firmware | 19/9/2024 | 17/6/2026 | Kastle Systems firmware prior to May 1, 2024, stored machine credentials in cleartext, which may allow an attacker to access sensitive information. | |
| Analizada | Crítica (9.2) | 0.37% | — | Kastle Access Control System Firmware | 19/9/2024 | 17/6/2026 | Kastle Systems firmware prior to May 1, 2024, contained a hard-coded credential, which if accessed may allow an attacker to access sensitive information. | |
| Analizada | Crítica (9.8) | 0.83% | — | Secom Dr.id Access Control | 14/8/2024 | 17/6/2026 | Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents. | |
| Modificada | Media (5.3) | 0.52% | — | Brandonwamboldt Wordpress Access Control | 28/2/2024 | 17/6/2026 | The WordPress Access Control plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.13 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's "Make Website Members Only" feature (when unset) and view restricted page and post… | |
| Modificada | Media (4.8) | 0.35% | — | Properfraction Admin BAR & Dashboard Access Control | 6/11/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Proper Fraction LLC. Admin Bar & Dashboard Access Control plugin <= 1.2.8 versions. | |
| Modificada | Alta (8.8) | 0.94% | — | Cassianetworks Access Controller | 27/10/2023 | 17/6/2026 | An issue was discovered in Cassia Access Controller 2.1.1.2303271039. The Web SSH terminal endpoint (spawned console) can be accessed without authentication. Specifically, there is no session cookie validation on the Access Controller; instead, there is only Basic Authentication to the SSH console. | |
| Modificada | Alta (8.8) | 1.1% | — | Cassianetworks Access Controller | 27/9/2023 | 17/6/2026 | An issue was discovered in Cassia Access Controller 2.1.1.2303271039. Establishing a web SSH session to gateways is vulnerable to Cross Site Request Forgery (CSRF) attacks. | |
| Modificada | Media (4.8) | 0.37% | — | Antonioandrade WP Htaccess Control | 30/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP htaccess Control plugin <= 3.5.1 versions. | |
| Modificada | Media (5.3) | 1.1% | — | Cassianetworks Access Controller | 11/5/2023 | 17/6/2026 | Cassia Access controller before 2.1.1.2203171453, was discovered to have a unprivileged -information disclosure vulnerability that allows read-only users have the ability to enumerate all other users and discover e-mail addresses, phone numbers, and privileges of all other users. | |
| Modificada | Media (5.4) | 0.55% | — | Niceforyou Linear Emerge E3 Access Control Firmware | 3/1/2023 | 17/6/2026 | Nice (formerly Nortek) Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e devices are vulnerable to Stored Cross-Site Scripting (XSS). | |
| Modificada | Crítica (9.8) | 4.3% | — | Niceforyou Linear Emerge E3 Access Control Firmware | 3/1/2023 | 17/6/2026 | Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a SQL injection vulnerability via the idt parameter. | |
| Modificada | Media (6.1) | 1.8% | — | Niceforyou Linear Emerge E3 Access Control Firmware | 13/12/2022 | 17/6/2026 | Certain Linear eMerge E3-Series devices are vulnerable to XSS via the type parameter (e.g., to the badging/badge_template_v0.php component). This affects 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e. | |
| Modificada | Media (6.1) | 0.91% | — | Niceforyou Linear Emerge E3 Access Control Firmware | 13/12/2022 | 17/6/2026 | Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a cross-site scripting (XSS) vulnerability which is chained with a local session fixation. This vulnerability allows attackers to escalate privileges via unspecified vectors. | |
| Modificada | Alta (7.5) | 0.63% | — | Cassianetworks Access Controller | 14/10/2022 | 17/6/2026 | An attacker may be able to use minify route with a relative path to view any file on the Cassia Networks Access Controller prior to 2.0.1. | |
| Modificada | Media (4.3) | 0.57% | — | Nextcloud Files Access Control | 15/9/2022 | 17/6/2026 | Nextcloud files access control is a nextcloud app to manage access control for files. Users with limited access can see file names in certain cases where they do not have privilege to do so. This issue has been addressed and it is recommended that the Nextcloud Files Access Control app is upgraded to 1.12.2, 1.13.1 or… | |
| Modificada | Alta (7.5) | 0.71% | — | SAP Access Control | 13/9/2022 | 17/6/2026 | SAP GRC Access control Emergency Access Management allows an authenticated attacker to access a Firefighter session even after it is closed in Firefighter Logon Pad. This attack can be launched only within the firewall. On successful exploitation the attacker can gain access to admin session and completely compromise… | |
| Modificada | Media (5.5) | 0.10% | — | Sicunet Access Control | 11/6/2022 | 17/6/2026 | A vulnerability was found in SICUNET Access Controller 0.32-05z. It has been declared as problematic. This vulnerability affects unknown code of the component Password Storage. The manipulation leads to weak encryption. Attacking locally is a requirement. | |
| Modificada | Crítica (9.8) | 1.2% | — | Sicunet Access Control | 11/6/2022 | 17/6/2026 | A vulnerability was found in SICUNET Access Controller 0.32-05z. It has been classified as very critical. This affects an unknown part. The manipulation leads to weak authentication. It is possible to initiate the attack remotely. |