Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
237 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.59% | — | Newgensoft OmnidocsAI | 23/1/2026 | 17/6/2026 | An unauthenticated information disclosure vulnerability exists in Newgen OmniDocs due to missing authentication and access control on the /omnidocs/GetListofCabinet API endpoint. A remote attacker can access this endpoint without valid credentials to retrieve sensitive internal configuration information, including… | |
| Aplazada | Alta (7.1) | 0.21% | — | Codisto Omnichannel FOR WoocommerceAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codisto Omnichannel for WooCommerce codistoconnect allows Stored XSS.This issue affects Omnichannel for WooCommerce: from n/a through <= 1.3.65. | |
| Aplazada | Crítica (9.3) | 0.72% | — | Omni Secure FilesAI | 16/1/2026 | 16/6/2026 | Omni Secure Files plugin versions prior to 0.1.14 contain an arbitrary file upload vulnerability in the bundled plupload example endpoint. The /wp-content/plugins/omni-secure-files/plupload/examples/upload.php handler allows unauthenticated uploads without enforcing safe file type restrictions, enabling an attacker to… | |
| Analizada | Alta (8.2) | 0.30% | 💥 PoC | Newgensoft Omnidocs | 15/12/2025 | 17/6/2026 | An unauthenticated Broken Function Level Authorization (BFLA) vulnerability in Newgen OmniDocs v11.0 allows attackers to obtain sensitive information and execute a full account takeover via a crafted API request. | |
| Aplazada | Media (6.4) | 0.36% | 💥 PoC | Omnipressteam OmnipressAI | 5/12/2025 | 25/9/2026 | The Omnipress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web… | |
| Aplazada | Alta (7.2) | 0.29% | — | Codisto Omnichannel FOR WoocommerceAI | 4/12/2025 | 17/6/2026 | The Omnichannel for WooCommerce: Google, Amazon, eBay & Walmart Integration – Powered by Codisto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sync() function in all versions up to, and including, 1.3.65 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Analizada | Crítica (9.8) | 0.49% | — | Microsoft Dynamics Omnichannel SDK Storage Containers | 20/11/2025 | 17/6/2026 | Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Media (5.1) | 0.31% | — | Xcally OmnichannelAI | 13/11/2025 | 17/6/2026 | Cross-site Scripting (XSS) vulnerability reflected in xCally's Omnichannel v3.30.1. This vulnerability allowsan attacker to executed JavaScript code in the victim's browser by sending them a malicious URL using the 'failureMessage' parameter in '/login'. This vulnerability can be exploited to steal sentitive user… | |
| Aplazada | Media (5.3) | 0.24% | — | Omnissa Workspace ONE UEMAI | 12/11/2025 | 17/6/2026 | Omnissa Workspace ONE UEM contains an observable response discrepancy vulnerability. A malicious actor may be able to enumerate sensitive information such as tenant ID and user accounts that could facilitate brute-force, password-spraying or credential-stuffing attacks. | |
| Aplazada | Crítica (9.8) | 0.66% | — | Iib0011 Omni-toolsAI | 30/10/2025 | 17/6/2026 | iib0011 omni-tools v0.4.0 is vulnerable to remote code execution via unsafe JSON deserialization. | |
| Analizada | Alta (7.5) | 0.31% | — | Siderolabs Omni | 13/10/2025 | 17/6/2026 | Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.1.5 and 1.0.2, Omni might leak sensitive information via an API. | |
| Analizada | Alta (7.5) | 0.58% | — | Siderolabs Omni | 13/10/2025 | 17/6/2026 | Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.1.5 and 1.0.2, there is a nil pointer dereference vulnerability in the Omni Resource Service allows unauthenticated users to cause a server panic and denial of service by sending empty create/update resource requests through the API… | |
| Aplazada | Alta (7.5) | 0.31% | — | Oracle Sunos OmniosAI | 29/9/2025 | 17/6/2026 | An issue in SunOS Omnios v5.11 allows attackers to cause a Denial of Service (DoS) via repeatedly sending crafted TCP packets. | |
| Analizada | Baja (0.5) | 0.20% | — | Siderolabs Omni | 24/9/2025 | 17/6/2026 | Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to version 0.48.0, Omni Wireguard SideroLink has the potential to escape. Omni and each Talos machine establish a peer-to-peer (P2P) SideroLink connection using WireGuard to mutually authenticate and authorize access. The WireGuard interface… | |
| Analizada | Alta (7.3) | 0.37% | — | Microsoft Omniparser | 24/9/2025 | 17/6/2026 | Binding to an unrestricted ip address in GitHub allows an unauthorized attacker to execute code over a network. | |
| Analizada | Baja (2.3) | 0.14% | — | Ecovacs Deebot X1S PRO FirmwareEcovacs Deebot X1 PRO Omni FirmwareEcovacs Deebot X1 Omni FirmwareEcovacs Deebot X1 Turbo Firmware+9 | 5/9/2025 | 17/6/2026 | ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic AES encryption key, which can be easily derived. | |
| Analizada | Alta (7.5) | 0.29% | — | Ecovacs Deebot X1S PRO FirmwareEcovacs Deebot X1 PRO Omni FirmwareEcovacs Deebot X1 Omni FirmwareEcovacs Deebot X1 Turbo Firmware+9 | 5/9/2025 | 17/6/2026 | ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be sent to base station via insecure connection between robot and base station. | |
| Analizada | Baja (2.3) | 0.22% | — | Ecovacs Deebot X1S PRO FirmwareEcovacs Deebot X1 PRO Omni FirmwareEcovacs Deebot X1 Omni FirmwareEcovacs Deebot X1 Turbo Firmware+9 | 5/9/2025 | 17/6/2026 | ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easily derived. | |
| Aplazada | Alta (8.6) | 0.30% | — | Omnissa Secure Email GatewayAI | 11/8/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) in Omnissa Secure Email Gateway (SEG) in SEG prior to 2.32 running on Windows and SEG prior to 2503 running on UAG allows routing of network traffic such as HTTP requests to internal networks. | |
| Aplazada | Media (5.4) | 0.19% | — | Omnissa Workspace ONE UEMAI | 11/8/2025 | 17/6/2026 | Omnissa Workspace ONE UEM contains a Server-Side Request Forgery (SSRF) Vulnerability. A malicious actor with user privileges may be able to access restricted internal system information, potentially enabling enumeration of internal network resources. | |
| Aplazada | Alta (7.5) | 22% | 💥 Exploit | Omnissa Workspace ONE UEMAI | 11/8/2025 | 17/6/2026 | Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to gain access to sensitive information by sending crafted GET requests (read-only) to restricted API endpoints. | |
| Aplazada | Media (5.5) | 0.13% | — | Nvidia Omniverse LauncherAI | 31/7/2025 | 17/6/2026 | NVIDIA Omniverse Launcher for Windows and Linux contains a vulnerability in the launcher logs, where a user could cause sensitive information to be written to the log files through proxy servers. A successful exploit of this vulnerability might lead to information disclosure. | |
| Aplazada | Media (5.3) | 0.26% | — | OmnishopAI | 23/7/2025 | 17/6/2026 | The Omnishop plugin for WordPress is vulnerable to Unauthenticated Registration Bypass in all versions up to, and including, 1.0.9. Its /users/register endpoint is exposed to the public (permission_callback always returns true) and invokes wp_create_user() unconditionally, ignoring the site’s users_can_register option… | |
| Aplazada | Media (6.5) | 0.16% | — | OmnishopAI | 23/7/2025 | 17/6/2026 | The Omnishop plugin for WordPress is vulnerable to Cross-Site Request Forgery on its /users/delete REST route in all versions up to, and including, 1.0.9. The route’s permission_callback only verifies that the requester is logged in, but fails to require any nonce or other proof of intent. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.23% | — | Omnipressteam OmnipressAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in omnipressteam Omnipress omnipress allows DOM-Based XSS.This issue affects Omnipress: from n/a through <= 1.6.4. |