Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
473 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.50% | — | Thermofisher ION Torrent Onetouch 2 Firmware | 4/12/2025 | 17/6/2026 | An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. When they are powered on, an X11 display server is started. The display server listens on all network interfaces and is accessible over port 6000. The X11 access control list, by default, allows connections from 127.0.0.1 and… | |
| Analizada | Crítica (9.8) | 0.46% | — | Thermofisher ION Torrent Onetouch 2 Firmware | 4/12/2025 | 17/6/2026 | An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. They run an SSH server accessible over the default port 22. The root account has a weak default password of ionadmin, and a password change policy for the root account is not enforced. Thus, an attacker with network connectivity can… | |
| Analizada | Media (6.5) | 0.43% | — | Samsung Smart Touch Call | 2/12/2025 | 25/9/2026 | Improper verification of source of a communication channel in SmartTouchCall prior to version 1.0.1.1 allows remote attackers to access sensitive information. User interaction is required for triggering this vulnerability. | |
| Analizada | Alta (7.5) | 0.39% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux ARM SL+13 | 1/12/2025 | 17/6/2026 | An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition. | |
| Analizada | Media (6.5) | 0.21% | — | Perfood Couchauth | 20/11/2025 | 17/6/2026 | Session tokens and passwords in couch-auth 0.21.2 are stored in JavaScript objects and remain in memory without explicit clearing in src/user.ts lines 700-707. This creates a window of opportunity for sensitive data extraction through memory dumps, debugging tools, or other memory access techniques, potentially… | |
| Analizada | Alta (8.4) | 0.19% | — | Fujielectric Monitouch V-sft | 4/11/2025 | 17/6/2026 | Fuji Electric Monitouch V-SFT-6 is vulnerable to a stack-based buffer overflow while processing a specially crafted project file, which may allow an attacker to execute arbitrary code. | |
| Analizada | Alta (8.4) | 0.19% | — | Fujielectric Monitouch V-sft | 4/11/2025 | 17/6/2026 | A maliciously crafted project file may cause a heap-based buffer overflow in Fuji Electric Monitouch V-SFT-6, which may allow the attacker to execute arbitrary code. | |
| Aplazada | Alta (7.3) | 0.24% | — | UI Unifi Talk TouchAIUI Unifi Talk Touch MAXAIUI Unifi Talk G3AI | 31/10/2025 | 17/6/2026 | A vulnerability was identified in certain UniFi Talk devices where internal debugging functionality remained unintentionally enabled. This issue could allow an attacker with access to the UniFi Talk management network to invoke internal debug operations through the device API. Affected Products: UniFi Talk Touch… | |
| Analizada | Alta (8.4) | 0.17% | — | Fujielectric Monitouch V-sft | 10/10/2025 | 17/6/2026 | A use after free vulnerability exists in VS6ComFile!load_link_inf of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.17% | — | Fujielectric Monitouch V-sft | 10/10/2025 | 17/6/2026 | An out-of-bounds read vulnerability exists in VS6ComFile!CSaveData::delete_mem of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.17% | — | Fujielectric Monitouch V-sft | 10/10/2025 | 17/6/2026 | An out-of-bounds read vulnerability exists in VS6ComFile!get_ovlp_element_size of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.17% | — | Fujielectric Monitouch V-sft | 10/10/2025 | 17/6/2026 | An out-of-bounds read vulnerability exists in VS6ComFile!load_link_inf of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.18% | — | Fujielectric Monitouch V-sft | 10/10/2025 | 17/6/2026 | An out-of-bounds read vulnerability exists in VS6MemInIF!set_temp_type_default of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.18% | — | Fujielectric Monitouch V-sft | 10/10/2025 | 17/6/2026 | An out-of-bounds write vulnerability exists in VS6ComFile!CItemDraw::is_motion_tween of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.18% | — | Fujielectric Monitouch V-sft | 10/10/2025 | 17/6/2026 | An out-of-bounds write vulnerability exists in VS6ComFile!set_AnimationItem of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.18% | — | Fujielectric Monitouch V-sft | 10/10/2025 | 17/6/2026 | An out-of-bounds write vulnerability exists in VS6ComFile!CItemExChange::WinFontDynStrCheck of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.20% | — | Fujielectric Monitouch V-sft | 10/10/2025 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in VS6ComFile!CV7BaseMap::WriteV7DataToRom of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution. | |
| Analizada | Media (6.5) | 0.33% | 💥 PoC | Agasta Easy Touch Plus Firmware | 2/10/2025 | 17/6/2026 | An insecure permission vulnerability exists in the Agasta Easytouch+ version 9.3.97 The device allows unauthorized mobile applications to connect via Bluetooth Low Energy (BLE) without authentication. Once an unauthorized connection is established, legitimate applications are unable to connect, causing a denial of… | |
| Aplazada | Media (5.9) | 0.22% | — | VoucherpressAI | 22/9/2025 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chris Taylor VoucherPress voucherpress allows Stored XSS.This issue affects VoucherPress: from n/a through <= 1.5.7. | |
| Aplazada | Media (6.8) | 0.46% | — | Crestron Touchscreens X70AI | 9/9/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CRESTRON TOUCHSCREENS x70 allows Relative Path Traversal.This issue affects TOUCHSCREENS x70: from 3.000.0110.001 before 3.001.0031.001. Confirmed Affected Hardware: TSW-760, TSW-1060 Confirmed Affected Firmware: 3.002.1061… | |
| Aplazada | Alta (8.6) | 0.37% | — | Crestron Touchscreens X70AICrestron Tsw-x70AICrestron Tsw-x60AICrestron Tst-1080AI+9 | 3/9/2025 | 17/6/2026 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in CRESTRON TOUCHSCREENS x70 allows Argument Injection.This issue affects TOUCHSCREENS x70: from 3.001.0031.001 through 3.001.0034.001. A specially crafted SCP command sent via SSH login string can lead a valid… | |
| Aplazada | Alta (8.8) | 0.36% | — | Touch Lebanon Mobile APPAI | 20/8/2025 | 17/6/2026 | A vulnerability in the password reset workflow of the Touch Lebanon Mobile App 2.20.2 allows an attacker to bypass the OTP reset password mechanism. By manipulating the reset process, an unauthorized user may be able to reset the password and gain access to the account without needing to provide a legitimate… | |
| Analizada | Alta (7.3) | 0.19% | — | Couchbase Sync Gateway | 29/7/2025 | 17/6/2026 | An issue was discovered in Couchbase Sync Gateway before 3.2.6. In sgcollect_info_options.log and sync_gateway.log, there are cleartext passwords in redacted and unredacted output. | |
| Analizada | Media (4.9) | 0.23% | — | Couchbase .net SDK | 18/6/2025 | 17/6/2026 | The Couchbase .NET SDK (client library) before 3.7.1 does not properly enable hostname verification for TLS certificates. In fact, the SDK was also using IP addresses instead of hostnames due to a configuration option that was incorrectly enabled by default. | |
| Aplazada | Media (5.9) | 0.26% | — | Bravenewcode WptouchAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPtouch WPtouch wptouch allows Stored XSS.This issue affects WPtouch: from n/a through <= 4.3.60. |