Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

33 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.0%—Agilefleet FleetcommanderAgilefleet Fleetcommander Kiosk18/11/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Agile FleetCommander and FleetCommander Kiosk before 4.08 allow remote attackers to inject arbitrary web script or HTML via an arbitrary text field.
ModificadaAlta (7.5)1.2%—Agilefleet FleetcommanderAgilefleet Fleetcommander Kiosk18/11/201216/6/2026
Multiple SQL injection vulnerabilities in Agile FleetCommander and FleetCommander Kiosk before 4.08 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (6.8)2.4%💥 ExploitXkiosk WEB9/10/200716/6/2026
PHP remote file inclusion vulnerability in system/funcs/xkurl.php in xKiosk WEB 3.0.1i, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the PEARPATH parameter.
ModificadaBaja (1.7)0.32%—Sitekiosk14/12/200616/6/2026
An unspecified ActiveX control in SiteKiosk before 6.5.150 is installed "safe for scripting", which allows local users to bypass security protections and read arbitrary files via certain functions.
ModificadaMedia (4.1)0.29%—Sitekiosk14/12/200616/6/2026
Cross-site scripting (XSS) vulnerability in the skinning feature in SiteKiosk before 6.5.150 allows local users to bypass security protections and inject arbitrary web script or HTML via an ABOUT: URI, which is displayed in the title bar of the browser.
ModificadaMedia (4.6)0.33%—SPB Kiosk Engine30/12/200516/6/2026
Spb Kiosk Engine 1.0.0.1 allows local users to bypass restrictions on allowed applications via (1) removable media containing a program that will execute because of the autorun setting and (2) applications that are able to invoke other applications, as demonstrated by a file: URL specifying a .exe file.
ModificadaBaja (2.1)0.34%—SPB Kiosk Engine30/12/200516/6/2026
Spb Kiosk Engine 1.0.0.1 stores the administrator's passcode in the registry in plaintext, which allows local users to obtain the passcode.
ModificadaBaja (2.1)0.32%—Info Touch Surfnet KioskAI31/12/200416/6/2026
Info Touch Surfnet kiosk allows local users to access the underlying filesystem via a 'file://' URI.
Orbitaley — Vulnerabilidades