Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
251 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.18% | — | Pierre Lannoy SessionsAI | 22/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pierre Lannoy Sessions sessions allows Stored XSS.This issue affects Sessions: from n/a through <= 3.2.0. | |
| Aplazada | Media (5.9) | 0.22% | — | Inspectlet Heatmaps AND User Session RecordingAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in inspectlet Inspectlet – User Session Recording and Heatmaps inspectlet-heatmaps-and-user-session-recording allows Stored XSS.This issue affects Inspectlet – User Session Recording and Heatmaps: from n/a through <= 2.0. | |
| Aplazada | Media (6.5) | 0.26% | — | Catalyst Plugin SessionAI | 17/7/2025 | 17/6/2026 | Catalyst::Plugin::Session before version 0.44 for Perl generates session ids insecurely. The session id is generated from a (usually SHA-1) hash of a simple counter, the epoch time, the built-in rand function, the PID and the current Catalyst context. This information is of low entropy. The PID will come from a small… | |
| Aplazada | Alta (7.3) | 0.36% | — | Plack Middleware SessionAI | 16/7/2025 | 17/6/2026 | Plack-Middleware-Session before version 0.35 for Perl generates session ids insecurely. The default session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from… | |
| Aplazada | Media (4.2) | 0.34% | — | Rack-sessionAI | 8/5/2025 | 17/6/2026 | Rack::Session is a session management implementation for Rack. In versions starting from 2.0.0 to before 2.1.1, when using the Rack::Session::Pool middleware, and provided the attacker can acquire a session cookie (already a major issue), the session may be restored if the attacker can trigger a long running request… | |
| Aplazada | Alta (7.1) | 0.19% | — | Rafasashi User Session SynchronizerAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in rafasashi User Session Synchronizer user-session-synchronizer allows Stored XSS.This issue affects User Session Synchronizer: from n/a through <= 1.4.0. | |
| Aplazada | Alta (7) | 0.25% | — | AiohttpAIAiohttp SessionAIHome-assistant Home Assistant CoreAI | 18/2/2025 | 17/6/2026 | Home Assistant Core is an open source home automation that puts local control and privacy first. Affected versions are subject to a potential man-in-the-middle attacks due to missing SSL certificate verification in the project codebase and used third-party libraries. In the past, `aiohttp-session`/`request` had the… | |
| Analizada | Alta (7.5) | 0.16% | — | Audiocodes Mediant Session Border Controller | 7/2/2025 | 17/6/2026 | An issue was discovered in AudioCodes Mediant Session Border Controller (SBC) before 7.40A.501.841. Due to the use of weak password obfuscation/encryption, an attacker with access to configuration exports (INI) is able to decrypt the passwords. | |
| Aplazada | Alta (7.1) | 0.26% | — | Swit WP Sessions Time Monitoring Full AutomaticAI | 31/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in activity-log.com WP Sessions Time Monitoring Full Automatic activitytime allows Reflected XSS.This issue affects WP Sessions Time Monitoring Full Automatic: from n/a through <= 1.1.1. | |
| Aplazada | Media (6.1) | 0.50% | — | Cisco Unified Communications ManagerAICisco Unified Communications Manager Session Management EditionAICisco Unified Communications Manager IM AND Presence ServiceAICisco Unity ConnectionAI | 18/11/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an unauthenticated, remote attacker… | |
| Analizada | Media (5.1) | 15% | ⚠ Explotación activa | Citrix Session Recording | 12/11/2024 | 17/6/2026 | Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server | |
| Analizada | Media (5.1) | 3.5% | ⚠ Explotación activa | Citrix Session Recording | 12/11/2024 | 17/6/2026 | Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain | |
| Aplazada | Crítica (9.3) | 1.1% | — | Swit WP Sessions Time Monitoring Full AutomaticAI | 24/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in activity-log.com WP Sessions Time Monitoring Full Automatic activitytime allows SQL Injection.This issue affects WP Sessions Time Monitoring Full Automatic: from n/a through <= 1.0.9. | |
| Aplazada | Media (5.3) | 0.15% | — | Oneidentity Safeguard FOR Privileged SessionsAI | 24/10/2024 | 17/6/2026 | An authentication-bypass issue in the RDP component of One Identity Safeguard for Privileged Sessions (SPS) On Premise before 7.5.1 (and LTS before 7.0.5.1) allows man-in-the-middle attackers to obtain access to privileged sessions on target resources by intercepting cleartext RDP protocol information. | |
| Aplazada | Crítica (10) | 1.1% | — | Juniper Networks Session Smart RouterAIJuniper Networks Session Smart ConductorAIJuniper Networks WAN Assurance RouterAI | 27/6/2024 | 17/6/2026 | An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router or conductor running with a redundant peer allows a network based attacker to bypass authentication and take full control of the device. Only routers or conductors that are running in high-availability… | |
| Aplazada | Alta (7.4) | 0.45% | — | Fastify SessionAI | 21/5/2024 | 17/6/2026 | @fastify/session is a session plugin for fastify. Requires the @fastify/cookie plugin. When restoring the cookie from the session store, the `expires` field is overriden if the `maxAge` field was set. This means a cookie is never correctly detected as expired and thus expired sessions are not destroyed. This… | |
| Aplazada | Alta (7.4) | 0.62% | — | Festify Secure-sessionAI | 10/4/2024 | 17/6/2026 | @festify/secure-session creates a secure stateless cookie session for Fastify. At the end of the request handling, it will encrypt all data in the session with a secret key and attach the ciphertext as a cookie value with the defined cookie name. After that, the session on the server side is destroyed. When an… | |
| Modificada | Media (5.5) | 0.33% | — | Opft Session | 1/3/2024 | 17/6/2026 | Session version 1.17.5 allows obtaining internal application files and public files from the user's device without the user's consent. This is possible because the application is vulnerable to Local File Read via chat attachments. | |
| Modificada | Alta (7.5) | 2.2% | — | Swit WP Sessions Time Monitoring Full Automatic | 26/12/2023 | 17/6/2026 | The WP Sessions Time Monitoring Full Automatic WordPress plugin before 1.0.9 does not sanitize the request URL or query parameters before using them in an SQL query, allowing unauthenticated attackers to extract sensitive data from the database via blind time based SQL injection techniques, or in some cases an… | |
| Modificada | Crítica (9.8) | 1.9% | — | Atos Unify Openscape BCFAtos Unify Openscape BranchAtos Unify Openscape Session Border Controller | 5/12/2023 | 17/6/2026 | An argument injection vulnerability has been identified in the administrative web interface of the Atos Unify OpenScape products "Session Border Controller" (SBC) and "Branch", before version V10 R3.4.0, and OpenScape "BCF" before versions V10R10.12.00 and V10R11.05.02. This allows an unauthenticated attacker to gain… | |
| Modificada | Media (4.3) | 0.41% | — | Oracle Enterprise Session Border Controller | 17/10/2023 | 17/6/2026 | Vulnerability in the Oracle Enterprise Session Border Controller product of Oracle Communications (component: Web UI). Supported versions that are affected are 9.0-9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Session Border… | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Crítica (9.8) | 3.9% | — | Unify Session Border Controller | 4/10/2023 | 17/6/2026 | Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of administrative scripts by unauthenticated users. | |
| Modificada | Alta (8.8) | 3.8% | — | Unify Session Border Controller | 4/10/2023 | 17/6/2026 | Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of OS commands as root user by low-privileged authenticated users. | |
| Modificada | Alta (7.2) | 0.96% | — | Atos Unify Openscape BCFAtos Unify Openscape BranchAtos Unify Openscape Session Border Controller | 14/4/2023 | 17/6/2026 | Atos Unify OpenScape SBC 10 before 10R3.1.3, OpenScape Branch 10 before 10R3.1.2, and OpenScape BCF 10 before 10R10.7.0 allow remote authenticated admins to inject commands. |