Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
56 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.8) | 0.20% | — | UI Unifi IOS APPAIUI Unifi Access PointAI | 9/7/2024 | 17/6/2026 | UniFi iOS app 10.15.0 introduces a misconfiguration on 2nd Generation UniFi Access Points configured as standalone (not using UniFi Network Application) that could cause the SSID name to change and/or the WiFi Password to be removed on the 5GHz Radio. This vulnerability is fixed in UniFi iOS app 10.15.2 and later. | |
| Modificada | Media (6.1) | 0.25% | — | Vantiva Mediaaccess Dga2232 Firmware | 16/6/2024 | 17/6/2026 | Vantiva - MediaAccess DGA2232 v19.4 - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Aplazada | Baja (2.2) | 0.44% | — | UI Unifi Connect EV StationAIUI Unifi Connect EV Station PROAIUI Unifi Access G2 Reader PROAIUI Unifi Access Reader PROAI+4 | 7/5/2024 | 17/6/2026 | An Improper Access Control could allow a malicious actor authenticated in the API to enable Android Debug Bridge (ADB) and make unsupported changes to the system. Affected Products: UniFi Connect EV Station (Version 1.1.18 and earlier) UniFi Connect EV Station Pro (Version 1.1.18 and earlier) UniFi Access G2 Reader… | |
| Aplazada | Alta (7.5) | 0.52% | — | UI Unifi Access PointsAIUI Unifi SwitchesAIUI Unifi LTE BackupAIUI Unifi ExpressAI | 20/2/2024 | 17/6/2026 | A malformed discovery packet sent by a malicious actor with preexisting access to the network could interrupt the functionality of device management and discovery. Affected Products: UniFi Access Points UniFi Switches UniFi LTE Backup UniFi Express (Only Mesh Mode, Router mode is not affected) Mitigation: Update UniFi… | |
| Modificada | Crítica (9.8) | 0.61% | — | Prestamonster Multi Accessories PRO | 9/2/2024 | 17/6/2026 | SQL injection vulnerability in Presta Monster "Multi Accessories Pro" (hsmultiaccessoriespro) module for PrestaShop versions 5.1.1 and before, allows remote attackers to escalate privileges and obtain sensitive information via the method HsAccessoriesGroupProductAbstract::getAccessoriesByIdProducts(). | |
| Modificada | Media (5.5) | 0.57% | 💥 Exploit | IBM I Access Client Solutions | 9/2/2024 | 17/6/2026 | IBM i Access Client Solutions (ACS) 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.4 is vulnerable to NT LAN Manager (NTLM) hash disclosure by an attacker modifying UNC capable paths within ACS configuration files to point to a hostile server. If NTLM is enabled, the Windows operating system will try to authenticate… | |
| Modificada | Alta (8.8) | 0.99% | 💥 PoC | IBM I Access Client Solutions | 14/12/2023 | 17/6/2026 | IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to execute remote code. Due to improper authority checks the attacker could perform operations on the PC under the user's authority. IBM X-Force ID: 268273. | |
| Modificada | Media (6.5) | 0.63% | 💥 PoC | IBM I Access Client Solutions | 14/12/2023 | 17/6/2026 | IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 is vulnerable to having its key for an encrypted password decoded. By somehow gaining access to the encrypted password, a local attacker could exploit this vulnerability to obtain the password to other systems. IBM X-Force ID: 268265. | |
| Modificada | Alta (7.5) | 1.6% | 💥 PoC | IBM I Access Client Solutions | 14/12/2023 | 17/6/2026 | IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to obtain a decryption key due to improper authority checks. IBM X-Force ID: 268270. | |
| Modificada | Media (5.3) | 0.37% | — | Zkteco Bioaccess IVS | 3/8/2023 | 9/7/2026 | An access control issue in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to arbitrarily close and open the doors managed by the platform remotely via sending a crafted web request. | |
| Modificada | Alta (7.5) | 0.73% | — | Zkteco Bioaccess IVS | 3/8/2023 | 9/7/2026 | A path traversal vulnerability in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. | |
| Modificada | Alta (7.5) | 0.60% | — | Zkteco Bioaccess IVS | 3/8/2023 | 9/7/2026 | ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to obtain sensitive information about all managed devices, including their IP addresses and device names. | |
| Modificada | Crítica (9.8) | 0.61% | — | Zkteco Bioaccess IVS | 3/8/2023 | 9/7/2026 | ZKTeco BioAccess IVS v3.3.1 was discovered to contain a SQL injection vulnerability. | |
| Modificada | Media (6.7) | 0.35% | — | IBM I Access Client Solutions | 21/11/2022 | 17/6/2026 | IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability. By placing a specially crafted file in a compromised folder, an attacker could exploit this vulnerability to… | |
| Modificada | Alta (7.5) | 11% | 💥 Exploit | Genieaccess Wip3bvaf Firmware | 17/6/2019 | 17/6/2026 | Genie Access WIP3BVAF WISH IP 3MP IR Auto Focus Bullet Camera devices through 3.x are vulnerable to directory traversal via the web interface, as demonstrated by reading /etc/shadow. NOTE: this product is discontinued, and its final firmware version has this vulnerability (4.x versions exist only for other Genie… | |
| Modificada | Alta (7.8) | 1.2% | — | IBM I Access | 4/1/2019 | 17/6/2026 | An untrusted search path vulnerability in IBM i Access for Windows versions 7.1 and earlier on Windows can allow arbitrary code execution via a Trojan horse DLL in the current working directory, related to use of the LoadLibrary function. IBM X-Force ID: 152079. | |
| Modificada | Media (6.1) | 1.2% | — | IBM Tivoli Access Manager FOR E-businessIBM Security Access Manager FOR WEB SoftwareIBM Security Access Manager FOR WEB ApplianceIBM Security Access Manager FOR WEB+2 | 29/8/2017 | 17/6/2026 | IBM Security Access Manager 6.1, 7.0, 8.0, and 9.0 e-community configurations may be affected by a redirect vulnerability. ECSSO Master Authentication can redirect to a server not participating in an e-community domain. IBM X-Force ID: 128687. | |
| Modificada | Alta (7.8) | 0.36% | — | IBM I Access FOR Windows | 28/8/2017 | 17/6/2026 | Stack-based buffer overflow in IBM V5R4, and IBM i Access for Windows 6.1 and 7.1. | |
| Modificada | Alta (7.8) | 0.36% | — | IBM I Access | 8/7/2016 | 17/6/2026 | IBM i Access 7.1 on Windows allows local users to discover registry passwords via unspecified vectors. | |
| Modificada | Media (5.5) | 0.77% | 💥 Exploit | IBM I Access | 2/1/2016 | 17/6/2026 | Buffer overflow in IBM i Access 7.1 on Windows allows local users to cause a denial of service (application crash) via unspecified vectors. | |
| Modificada | Media (4) | 0.51% | — | IBM I Access | 2/1/2016 | 17/6/2026 | AFP Workbench Viewer in IBM i Access 7.1 on Windows allows remote attackers to cause a denial of service (viewer crash) via a crafted workbench file. | |
| Modificada | Alta (8.8) | 1.5% | 💥 Exploit | IBM I Access | 2/1/2016 | 17/6/2026 | Buffer overflow in IBM i Access 7.1 on Windows allows local users to gain privileges via unspecified vectors. | |
| Modificada | Alta (7.2) | 0.38% | — | IBM I Access | 28/1/2015 | 17/6/2026 | Buffer overflow in the Data Transfer Program in IBM i Access 5770-XE1 5R4, 6.1, and 7.1 on Windows allows local users to gain privileges via unspecified vectors. | |
| Modificada | Media (5) | 2.1% | — | IBM Tivoli Access Manager FOR E-business | 19/1/2011 | 16/6/2026 | Directory traversal vulnerability in WebSEAL in IBM Tivoli Access Manager for e-business 5.1 before 5.1.0.39-TIV-AWS-IF0040, 6.0 before 6.0.0.25-TIV-AWS-IF0026, 6.1.0 before 6.1.0.5-TIV-AWS-IF0006, and 6.1.1 before 6.1.1-TIV-AWS-FP0001 has unspecified impact and attack vectors. NOTE: this might overlap CVE-2010-4622. | |
| Modificada | Media (4) | 1.1% | — | IBM Tivoli Access Manager FOR E-business | 30/12/2010 | 16/6/2026 | WebSEAL in IBM Tivoli Access Manager for e-business 6.1.1 before 6.1.1-TIV-AWS-FP0001 allows remote authenticated users to cause a denial of service (worker thread consumption) via shift-reload actions. |