Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3020▼ 63 respecto a la semana anterior
Críticas / altas1413▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
119 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.1) | 0.33% | — | Pexip Infinity | 25/12/2025 | 30/9/2026 | Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange Tokens. This allows a remote attacker to read potentially sensitive data and excessively consume resources, leading to a denial of service. | |
| Analizada | Media (5.9) | 0.32% | — | Pexip Infinity | 25/12/2025 | 30/9/2026 | Pexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Teams SIP Guest Join, has Improper Input Validation in the OTJ service, allowing a remote attacker to trigger a software abort via a crafted calendar invite, leading to a denial of service. | |
| Analizada | Media (6.1) | 0.20% | — | Zucchetti Infinity ZmaintenanceInfinity Zucchetti | 4/11/2025 | 17/6/2026 | A reflected cross-site scripted (XSS) vulnerability in the /jsp/gsfr_feditorHTML.jsp endpoint of Zucchetti ZMaintenance Infinity and Infinity Zucchetti v4.1 and earlier allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into the pHtmlSource parameter. A… | |
| Analizada | Media (6.1) | 0.26% | — | Zucchetti AD HOC Infinity | 30/10/2025 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Zucchetti Ad Hoc Infinity 4.2 and earlier allows remote unauthenticated attackers to inject arbitrary JavaScript via the pHtmlSource parameter of the /ahi/jsp/gsfr_feditorHTML.jsp?pHtmlSource endpoint. | |
| Aplazada | Media (5) | 0.33% | — | Grafana InfinityAIGrafanaAI | 4/8/2025 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. The Infinity datasource plugin, maintained by Grafana Labs, allows visualizing data from JSON, CSV, XML, GraphQL, and HTML endpoints. If the plugin was configured to allow only certain URLs, an attacker could bypass this restriction using a specially… | |
| Analizada | Alta (7.5) | 0.53% | — | Pexip Infinity | 2/4/2025 | 17/6/2026 | Signalling in Pexip Infinity 29 through 36.2 before 37.0 has improper input validation that allows remote attackers to trigger a temporary denial of service (software abort). | |
| Aplazada | Crítica (9.1) | 0.54% | — | Pexip Infinity ConnectAI | 2/4/2025 | 17/6/2026 | Pexip Infinity Connect before 1.13.0 lacks sufficient authenticity checks during the loading of resources, and thus remote attackers can cause the application to run untrusted code. | |
| Analizada | Alta (7.5) | 0.50% | — | Pexip Infinity | 2/4/2025 | 17/6/2026 | Pexip Infinity before 35.0 has improper input validation that allows remote attackers to trigger a denial of service (software abort) via a crafted signalling message. | |
| Analizada | Media (5.4) | 0.38% | — | Zucchetti AD HOC Infinity | 11/3/2025 | 17/6/2026 | Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution via the /jsp/home.jsp, /jsp/gsfr_feditorHTML.jsp, /servlet/SPVisualZoom, /jsp/gsmd_container.jsp components | |
| Analizada | Alta (7.6) | 0.34% | — | Zucchetti AD HOC Infinity | 11/3/2025 | 17/6/2026 | In Zucchetti Ad Hoc Infinity 2.4, an improper check on the m_cURL parameter allows an attacker to redirect the victim to an attacker-controlled website after the authentication. | |
| Analizada | Media (5.4) | 0.38% | — | Zucchetti AD HOC Infinity | 11/3/2025 | 17/6/2026 | Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution via the /servlet/gsdm_fsave_htmltmp, /servlet/gsdm_btlk_openfile components | |
| Analizada | Alta (7.3) | 0.46% | — | Zucchetti AD HOC Infinity | 11/3/2025 | 17/6/2026 | A local file include vulnerability in the /servlet/Report of Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution by uploading a jsp web/reverse shell through /jsp/zimg_upload.jsp. | |
| Analizada | Media (4.8) | 0.21% | — | Pega Infinity | 5/12/2024 | 17/6/2026 | Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search. | |
| Analizada | Crítica (9.8) | 0.48% | — | Pega Infinity | 20/11/2024 | 17/6/2026 | Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code | |
| Analizada | Media (4.8) | 0.14% | — | Cybelesoft Thinfinity Workspace | 13/11/2024 | 17/6/2026 | Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain a hardcoded cryptographic key used for encryption. | |
| Analizada | Alta (7.3) | 0.28% | — | Cybelesoft Thinfinity Workspace | 13/11/2024 | 17/6/2026 | Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This vulnerability allows attackers to create arbitrary user profiles with elevated privileges. | |
| Analizada | Alta (7.5) | 0.39% | — | Cybelesoft Thinfinity Workspace | 13/11/2024 | 17/6/2026 | A full path disclosure in Cybele Software Thinfinity Workspace before v7.0.2.113 allows attackers to obtain the root path of the application via unspecified vectors. | |
| Analizada | Alta (8.1) | 0.45% | — | Cybelesoft Thinfinity Workspace | 13/11/2024 | 17/6/2026 | Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a secondary broker via a crafted request. | |
| Analizada | Crítica (9.8) | 0.46% | — | Cybelesoft Thinfinity Workspace | 13/11/2024 | 17/6/2026 | Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endpoint where Web Sockets connections are established. | |
| Analizada | Media (4.8) | 0.26% | — | Pega Infinity | 12/9/2024 | 17/6/2026 | Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage. | |
| Analizada | Media (4.8) | 0.26% | — | Pega Infinity | 12/9/2024 | 17/6/2026 | Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with case type. | |
| Analizada | Media (4.8) | 0.26% | — | Pega Infinity | 12/9/2024 | 17/6/2026 | Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with App name. | |
| Analizada | Media (4.3) | 0.21% | — | Pexip Infinity | 10/6/2024 | 17/6/2026 | Pexip Infinity before 34.1 has Improper Access Control for persons in a waiting room. They can see the conference roster list, and perform certain actions that should not be allowed before they are admitted to the meeting. | |
| Modificada | Media (6.1) | 0.31% | — | Pexip Infinity | 25/12/2023 | 17/6/2026 | Pexip Infinity before 32 allows Webapp1 XSS via preconfigured links. | |
| Modificada | Alta (7.5) | 0.61% | — | Pexip Infinity | 25/12/2023 | 17/6/2026 | Pexip Infinity before 31.2 has Improper Input Validation for RTCP, allowing remote attackers to trigger an abort. |