Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
156 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 1.0% | — | NCR ITM WEB Terminal | 23/6/2025 | 17/6/2026 | An issue in NCR ITM Web terminal v.4.4.0 and v.4.4.4 allows a remote attacker to execute arbitrary code via a crafted script to the IP camera URL component. | |
| Analizada | Media (4.3) | 0.27% | — | NCR Terminal Handler | 23/6/2025 | 17/6/2026 | An issue in NCR Terminal Handler 1.5.1 allows a low-level privileged authenticated attacker to query the SOAP API endpoint to obtain information about all of the users of the application including their usernames, roles, security groups and account statuses. | |
| Analizada | Crítica (9.8) | 0.51% | — | NCR Terminal Handler | 23/6/2025 | 17/6/2026 | A settings manipulation vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands, including editing system security auditing configurations. | |
| Aplazada | Alta (7.1) | 0.29% | — | Terminal AfricaAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in terminalafrica Terminal Africa terminal-africa allows Reflected XSS.This issue affects Terminal Africa: from n/a through <= 1.13.24. | |
| Aplazada | Media (6.3) | 0.15% | — | Watchguard Terminal Services AgentAI | 28/3/2025 | 8/8/2026 | The WatchGuard Terminal Services Agent on Windows does not properly configure directory permissions when installed in a non-default directory. This could allow an authenticated local attacker to escalate to SYSTEM privileges on a vulnerable system. | |
| Aplazada | Alta (7.1) | 0.37% | — | Securesubmit Heartland Management TerminalAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SecureSubmit Heartland Management Terminal allows Reflected XSS. This issue affects Heartland Management Terminal: from n/a through 1.3.0. | |
| Aplazada | Media (6.6) | 1.2% | 💥 PoC | Warp TerminalAI | 14/10/2024 | 17/6/2026 | An issue was discovered in version of Warp Terminal prior to 2024.07.18 (v0.2024.07.16.08.02). A command injection vulnerability exists in the Docker integration functionality. An attacker can create a specially crafted hyperlink using the `warp://action/docker/open_subshell` intent that when clicked by the victim… | |
| Aplazada | Media (6.3) | 0.47% | — | TerminalfourAIXML JdbcAI | 15/8/2024 | 17/6/2026 | XML External Entity (XXE) vulnerability in Terminalfour 8.0.0001 through 8.3.18 and XML JDBC versions up to 1.0.4 allows authenticated users to submit malicious XML via unspecified features which could lead to various actions such as accessing the underlying server, remote code execution (RCE), or performing… | |
| Aplazada | Alta (8.8) | 0.72% | — | TerminalfourAIXML JdbcAI | 15/8/2024 | 17/6/2026 | XML External Entity (XXE) vulnerability in Terminalfour 8.0.0001 through 8.3.18 and XML JDBC versions up to 1.0.4 allows authenticated users to submit malicious XML via unspecified features which could lead to various actions such as accessing the underlying server, remote code execution (RCE), or performing… | |
| Modificada | Media (6.5) | 0.34% | — | Terminalfour | 15/8/2024 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability in Terminalfour before 8.3.19 allows authenticated users to use specific features to access internal services including sensitive information on the server that Terminalfour runs on. | |
| Modificada | Alta (8.3) | 0.19% | — | Siemens Omnivise T3000 Application ServerSiemens Omnivise T3000 Domain ControllerSiemens Omnivise T3000 Network Intrusion Detection SystemSiemens Omnivise T3000 Product Data Management+3 | 2/8/2024 | 17/6/2026 | A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Controller R9.2 (All versions), Omnivise T3000 Network Intrusion Detection System (NIDS) R9.2 (All versions), Omnivise T3000 Product Data Management (PDM) R9.2 (All versions), Omnivise T3000 R8.2 SP3… | |
| Modificada | Alta (8.5) | 0.24% | — | Siemens Omnivise T3000 Application ServerSiemens Omnivise T3000 Domain ControllerSiemens Omnivise T3000 Product Data ManagementSiemens Omnivise T3000 Terminal Server+2 | 2/8/2024 | 17/6/2026 | A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Controller R9.2 (All versions), Omnivise T3000 Product Data Management (PDM) R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), Omnivise T3000 R8.2 SP4 (All versions), Omnivise T3000 Terminal… | |
| Analizada | Media (6.3) | 0.37% | — | Terminalfour FormbankTerminalfour | 21/2/2024 | 17/6/2026 | An issue was discovered in Terminalfour 7.4 through 7.4.0004 QP3 and 8 through 8.3.19, and Formbank through 2.1.10-FINAL. Unauthenticated Stored Cross-Site Scripting can occur, with resultant Admin Session Hijacking. The attack vectors are Form Builder and Form Preview. | |
| Modificada | Alta (8.8) | 0.35% | — | Ncratleos Terminal Handler | 8/2/2024 | 17/6/2026 | Multiple Cross-Site Request Forgery (CSRF) chaining in NCR Terminal Handler v.1.5.1 allows privileges to be escalated by an attacker through a crafted request involving user account creation and adding the user to an administrator group. This is exploited by an undisclosed function in the WSDL that lacks security… | |
| Modificada | Media (6.5) | 0.34% | — | NCR Terminal Handler | 6/2/2024 | 17/6/2026 | Insecure Direct Object Reference in NCR Terminal Handler v.1.5.1 allows an unprivileged user to edit the audit logs for any user and can lead to CSV injection. | |
| Modificada | Alta (8.8) | 0.25% | — | Ncratleos Terminal Handler | 20/1/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in NCR Terminal Handler v.1.5.1 leads to a one-click account takeover. This is achieved by exploiting multiple vulnerabilities, including an undisclosed function in the WSDL that has weak security controls and can accept custom content types. | |
| Modificada | Crítica (9.8) | 0.74% | — | Ejinshan Terminal Security System | 20/1/2024 | 17/6/2026 | File upload vulnerability in ejinshan v8+ terminal security system allows attackers to upload arbitrary files to arbitrary locations on the server. | |
| Modificada | Media (6.5) | 0.34% | — | Terminalfour | 16/10/2023 | 17/6/2026 | In Terminalfour before 8.3.16, misconfigured LDAP users are able to login with an invalid password. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Alta (7.8) | 0.60% | — | Schneider-electric Ecostruxure Operator Terminal ExpertSchneider-electric Pro-face Blue | 14/6/2023 | 17/6/2026 | A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause execution of malicious code when an unsuspicious user loads a project file from the local filesystem into the HMI. | |
| Modificada | Crítica (9.8) | 0.62% | — | Adampos Mobilmen EL Terminali Yazilimi | 23/5/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adam Retail Automation Systems Mobilmen Terminal Software allows SQL Injection. This issue affects Mobilmen Terminal Software: before 3. | |
| Modificada | Crítica (9.8) | 0.72% | — | Eskom EL Terminali (SU Okuma) Uygulamalarimiz | 14/4/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eskom Water Metering Software allows Command Line Execution through SQL Injection. This issue affects Water Metering Software: before 23.04.06. | |
| Modificada | Media (4.9) | 0.56% | — | Terminalfour | 12/4/2023 | 17/6/2026 | The Logback component in Terminalfour before 8.3.14.1 allows OS administrators to obtain sensitive information from application server logs when debug logging is enabled. The fixed versions are 8.2.18.7, 8.2.18.2.2, 8.3.11.1, and 8.3.14.1. | |
| Modificada | Media (6.3) | 0.31% | — | Eternal Terminal Project Eternal Terminal | 16/2/2023 | 17/6/2026 | In Eternal Terminal 6.2.1, TelemetryService uses fixed paths in /tmp. For example, a local attacker can create /tmp/.sentry-native-etserver with mode 0777 before the etserver process is started. The attacker can choose to read sensitive information from that file, or modify the information in that file. | |
| Modificada | Media (5.3) | 1.1% | — | Eternal Terminal Project Eternal Terminal | 13/1/2023 | 17/6/2026 | In Eternal Terminal 6.2.1, etserver and etclient have world-readable logfiles. |