Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
183 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.2) | 0.18% | — | Loytec L-inxAILoytec L-gateAILoytec L-rocAILoytec L-iobAI+3 | 24/7/2026 | 27/7/2026 | Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an authenticated `larmapp` attacker to make `/etc/passwd` writable by the `larmapp` group (leading to root privilege escalation) via a symlink attack on… | |
| Aplazada | Alta (8.4) | 0.15% | — | Loytec Lip-me201cAILoytec L-inxAILoytec L-gateAILoytec L-rocAI+5 | 24/7/2026 | 27/7/2026 | Improper Privilege Management (CWE-269) in `/usr/bin/ltsudo` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a `superadmin`-group attacker to reset the password of any LARM user (including the `larmapp` service account) via the `set-passwd` subcommand. | |
| Aplazada | Alta (8.7) | 0.61% | — | Loytec Lip-me201cAILoytec L-inxAILoytec L-gateAILoytec L-rocAI+4 | 24/7/2026 | 27/7/2026 | Stored Cross-Site Scripting (CWE-79) in the OPC XML-DA server statistics in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an unauthenticated remote attacker to execute arbitrary JavaScript in an administrator's browser (session hijacking, credential theft,… | |
| Aplazada | Alta (7.5) | 0.24% | — | Seppmail Secure Email GatewayAISeppmail CloudAI | 17/7/2026 | 17/7/2026 | SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, as the session token is disclosed inside the URL and a HTTP header. | |
| Analizada | Alta (8.6) | 0.56% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Traffic ManagerWso2 Universal Gateway | 6/7/2026 | 9/7/2026 | The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of their structure and content. This allows an unauthenticated remote attacker to inject malicious JSON data that can lead to a persistent denial of service condition. Successful… | |
| Analizada | Media (6.1) | 0.25% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+4 | 6/7/2026 | 6/10/2026 | The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application. By leveraging this weakness, an attacker can cause the user's browser… | |
| Analizada | Alta (8.7) | 0.58% | — | Mbs-solutions Universal Gateway Firmware | 3/6/2026 | 22/7/2026 | A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system access as root. | |
| Analizada | Alta (8.7) | 0.58% | — | Mbs-solutions Universal Gateway Firmware | 3/6/2026 | 22/7/2026 | A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root. | |
| Analizada | Alta (8.7) | 0.58% | — | Mbs-solutions Universal Gateway Firmware | 3/6/2026 | 22/7/2026 | A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root. | |
| Analizada | Alta (8.7) | 0.68% | — | Mbs-solutions Universal Gateway Firmware | 3/6/2026 | 22/7/2026 | The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient validation of user-supplied input. | |
| Analizada | Alta (7.2) | 0.53% | — | Mbs-solutions Universal Gateway Firmware | 3/6/2026 | 22/7/2026 | The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input. | |
| Analizada | Alta (7.2) | 0.53% | — | Mbs-solutions Universal Gateway Firmware | 3/6/2026 | 22/7/2026 | The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. | |
| Analizada | Alta (7.2) | 0.53% | — | Mbs-solutions Universal Gateway Firmware | 3/6/2026 | 22/7/2026 | The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. | |
| Analizada | Alta (7.2) | 0.53% | — | Mbs-solutions Universal Gateway Firmware | 3/6/2026 | 22/7/2026 | The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. | |
| Analizada | Alta (7.2) | 0.53% | — | Mbs-solutions Universal Gateway Firmware | 3/6/2026 | 22/7/2026 | The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. | |
| Analizada | Alta (7.2) | 0.53% | — | Mbs-solutions Universal Gateway Firmware | 3/6/2026 | 22/7/2026 | The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. | |
| Analizada | Crítica (9.3) | 0.59% | — | Mbs-solutions Universal Gateway Firmware | 3/6/2026 | 22/7/2026 | An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices. | |
| Analizada | Alta (8.8) | 0.17% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Traffic ManagerWso2 Universal Gateway | 11/5/2026 | 17/6/2026 | The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/Everyone' role can invoke these APIs, bypassing intended permission checks. This same vulnerability also affects Internal Service APIs, potentially exposing them in WSO2 APIM 3.x versions. A malicious… | |
| Analizada | Alta (7.5) | 0.19% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Traffic ManagerWso2 Universal Gateway | 11/5/2026 | 17/6/2026 | In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient validation or sanitization, allowing these headers to be injected into HTTP responses. By exploiting this vulnerability, a malicious actor can inject or overwrite arbitrary HTTP response headers. This can… | |
| Aplazada | Media (6.9) | 0.54% | — | Seppmail Secure Email GatewayAI | 8/5/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.4 exposes server environment variables through an unauthenticated endpoint in the new GINA UI, allowing remote attackers to obtain sensitive system information. | |
| Aplazada | Alta (8.3) | 0.73% | — | Seppmail Secure Email GatewayAI | 8/5/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.4 contains a server-side template injection vulnerability in the new GINA UI because an endpoint accepts attacker-controlled template, allowing remote attackers to execute arbitrary template expressions and potentially achieve remote code execution depending on the… | |
| Aplazada | Crítica (9.3) | 0.73% | — | Seppmail Secure Email GatewayAI | 8/5/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.2.1 allows unauthenticated remote code execution in the new GINA UI because an endpoint passes attacker-controlled input from a parameter to Perl's eval. | |
| Aplazada | Alta (8.8) | 0.54% | — | Seppmail Secure Email GatewayAI | 8/5/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.4 contains an unauthenticated path traversal vulnerability in the identifier parameter of /api.app/attachment/preview that allows remote attackers to read arbitrary local files and trigger deletion of files in the targeted directory with the privileges of the api.app… | |
| Aplazada | Crítica (9.2) | 0.76% | — | Seppmail Secure Email GatewayAI | 8/5/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.4 insecurely deserializes untrusted data, which can be reached from the new GINA UI and may allow unauthenticated remote attackers to execute code via a crafted serialized object. | |
| Aplazada | Crítica (9.3) | 0.53% | — | Seppmail Secure Email GatewayAI | 8/5/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.4 fails to enforce authorization checks for multiple endpoints in the new GINA UI, allowing unauthenticated remote attackers to access functionality that should require a valid session. |