Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
56 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.35% | — | Eleveo Call Recording SoftwareAI | 10/7/2026 | 13/7/2026 | A flaw has been found in Eleveo Call Recording Software 9.7.0. This affects an unknown function of the file /callrec/roleAddAction.do of the component Group Interface. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been published and may be… | |
| Aplazada | Baja (2.1) | 0.35% | — | Eleveo Call Recording SoftwareAI | 10/7/2026 | 13/7/2026 | A vulnerability was detected in Eleveo Call Recording Software 9.7.0. The impacted element is an unknown function of the file /callrec/userAddAction.do. Performing a manipulation of the argument role results in improper authorization. It is possible to initiate the attack remotely. The exploit is now public and may be… | |
| Analizada | Alta (8.4) | 0.18% | — | Liveon Canonnwcamplugin.exeLiveon Canonnwcampluginforadmin.exeLiveon Downloader5installer.exeLiveon Downloader5installerforadmin.exe | 23/4/2026 | 17/6/2026 | The installers of LiveOn Meet Client for Windows (Downloader5Installer.exe and Downloader5InstallerForAdmin.exe) and the installers of Canon Network Camera Plugin (CanonNWCamPlugin.exe and CanonNWCamPluginForAdmin.exe) insecurely load Dynamic Link Libraries (DLLs). If a malicious DLL is placed at the same directory,… | |
| Aplazada | Alta (8.1) | 0.34% | — | Ancorathemes SaveoAI | 20/2/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Saveo saveo allows PHP Local File Inclusion.This issue affects Saveo: from n/a through <= 1.1.2. | |
| Aplazada | Alta (8.7) | 0.55% | — | Aerohive HiveosAI | 6/1/2026 | 17/6/2026 | Aerohive HiveOS contains a denial of service vulnerability in the NetConfig UI that allows unauthenticated attackers to render the web interface unusable. Attackers can send a crafted HTTP request to the action.php5 script with specific parameters to trigger a 5-minute service disruption. | |
| Analizada | Crítica (9.8) | 5.0% | — | Eveo Urve WEB Manager | 21/7/2025 | 17/6/2026 | An issue was discovered in Eveo URVE Web Manager 27.02.2025. The application exposes a /_internal/pc/vpro.php localhost endpoint to unauthenticated users that is vulnerable to OS Command Injection. The endpoint takes an input parameter that is passed directly into the shell_exec() function of PHP. NOTE: this can be… | |
| Analizada | Alta (8.6) | 1.6% | 💥 Exploit | Eveo Urve WEB Manager | 21/7/2025 | 17/6/2026 | An issue was discovered in Eveo URVE Web Manager 27.02.2025. The endpoint /_internal/redirect.php allows for Server-Side Request Forgery (SSRF). The endpoint takes a URL as input, sends a request to this address, and reflects the content in the response. This can be used to request endpoints only reachable by the… | |
| Aplazada | Alta (7.1) | 0.15% | — | Steveorevo Domain ThemeAI | 11/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Steveorevo Domain Theme domain-theme allows Stored XSS.This issue affects Domain Theme: from n/a through <= 1.3. | |
| Analizada | Media (5.4) | 0.45% | — | Ladybirdweb Faveo Helpdesk | 1/11/2024 | 17/6/2026 | An issue in Ladybird Web Solution Faveo Helpdesk & Servicedesk (On-Premise and Cloud) 9.2.0 allows a remote attacker to execute arbitrary code via the Subject and Identifier fields | |
| Aplazada | Alta (8.2) | 0.38% | — | Ladybird WEB Solution Faveo-helpdeskAI | 22/10/2024 | 17/6/2026 | An arbitrary file upload vulnerability in the Ticket Generation function of Ladybird Web Solution Faveo-Helpdesk v2.0.3 allows attackers to execute arbitrary code via uploading a crafted .html or .svg file. | |
| Aplazada | Alta (8.8) | 0.44% | — | Creativeon WhmpressAI | 19/8/2024 | 17/6/2026 | Missing Authorization vulnerability in creativeon WHMpress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WHMpress: from n/a through 6.2-revision-5. | |
| Aplazada | Alta (7.1) | 0.27% | — | Creativeon WhmpressAI | 18/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in creativeon WHMpress allows Reflected XSS.This issue affects WHMpress: from n/a through 6.2-revision-5. | |
| Aplazada | Media (5.7) | 0.23% | — | HiveosAI | 30/4/2024 | 17/6/2026 | HiveOS through 0.6-102@191212 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes trivial with Shodan.io. NOTE: as of 2019-09-26, the vendor indicated that they would consider fixing this. | |
| Modificada | Baja (3.3) | 0.10% | — | AMD Alveo U50 FirmwareAMD Alveo U200 FirmwareAMD Alveo U250 FirmwareAMD Alveo U280 Firmware+43 | 13/2/2024 | 17/6/2026 | Insufficient verification of data authenticity in the configuration state machine may allow a local attacker to potentially load arbitrary bitstreams. | |
| Modificada | Crítica (9.8) | 0.71% | — | Veom Service Tracking | 22/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Veon Computer Service Tracking Software allows SQL Injection. This issue affects Service Tracking Software: before crm 2.0. | |
| Modificada | Crítica (9.8) | 1.0% | 💥 PoC | Trispark NovuseduTrispark VEO Transportation | 29/8/2023 | 9/7/2026 | TripSpark VEO Transportation-2.2.x-XP_BB-20201123-184084 NovusEDU-2.2.x-XP_BB-20201123-184084 allows unsafe data inputs in POST body parameters from end users without sanitizing using server-side logic. It was possible to inject custom SQL commands into the "Student Busing Information" search queries. | |
| Modificada | Media (5.4) | 0.47% | — | Ladybirdweb Faveo Helpdesk | 24/6/2023 | 17/6/2026 | Faveo Helpdesk Enterprise version 6.0.1 allows an attacker with agent permissions to perform privilege escalation on the application. This occurs because the application is vulnerable to stored XSS. | |
| Modificada | Media (6.5) | 0.60% | — | Arista EOSArista Ceos-labArista CloudeosArista Veos-lab | 25/4/2023 | 17/6/2026 | On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a request allowing it to update arbitrary configurations in the switch. This situation occurs only when the Streaming Telemetry Agent (referred to as the TerminAttr agent) is enabled and gNMI access… | |
| Modificada | Alta (8.8) | 0.80% | — | Ladybirdweb Faveo Helpdesk | 24/3/2023 | 17/6/2026 | Faveo Helpdesk 1.0-1.11.1 is vulnerable to SQL Injection. When the user logs in through the login box, he has no judgment on the validity of the user's input data. The parameters passed from the front end to the back end are controllable, which will lead to SQL injection. | |
| Modificada | Media (6.5) | 1.1% | — | Ladybirdweb Faveo Servicedesk | 24/3/2023 | 17/6/2026 | Faveo 5.0.1 allows remote attackers to obtain sensitive information via a modified user ID in an Insecure Direct Object Reference (IDOR) attack. | |
| Modificada | Alta (8) | 1.1% | — | Eveo Urve WEB Manager | 15/7/2022 | 17/6/2026 | A vulnerability was found in URVE Web Manager. It has been rated as critical. This issue affects some unknown processing of the file _internal/uploader.php. The manipulation leads to unrestricted upload. The attack needs to be approached within the local network. The exploit has been disclosed to the public and may be… | |
| Modificada | Alta (8) | 13% | — | Eveo Urve WEB Manager | 15/7/2022 | 17/6/2026 | A vulnerability was found in URVE Web Manager. It has been declared as critical. This vulnerability affects unknown code of the file _internal/collector/upload.php. The manipulation leads to unrestricted upload. Access to the local network is required for this attack to succeed. The exploit has been disclosed to the… | |
| Modificada | Alta (8) | 1.1% | — | Eveo Urve WEB Manager | 15/7/2022 | 17/6/2026 | A vulnerability was found in URVE Web Manager. It has been classified as critical. This affects an unknown part of the file kreator.html5/img_upload.php. The manipulation leads to unrestricted upload. Access to the local network is required for this attack. The exploit has been disclosed to the public and may be used. | |
| Modificada | Crítica (10) | 5.1% | — | Eleveo Call Recording | 28/10/2021 | 17/6/2026 | Zoom Call Recording 6.3.1 from Eleveo is vulnerable to Java Deserialization attacks targeting the inbuilt RMI service. A remote unauthenticated attacker can exploit this vulnerability by sending crafted RMI requests to execute arbitrary code on the target host. | |
| Modificada | Media (6.1) | 0.84% | — | Faveohelpdesk Faveo | 1/10/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in dompdf/dompdf/www/demo.php infaveo-helpdesk v1.11.0 and below allow remote attackers to inject arbitrary web script or HTML via the $_SERVER["PHP_SELF"] parameter. |