Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
5089 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.30% | — | Glen Scott Plugin Security ScannerAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Glen Scott Plugin Security Scanner plugin-security-scanner allows Stored XSS.This issue affects Plugin Security Scanner: from n/a through <= 2.0.2. | |
| Analizada | Media (6.1) | 1.9% | ⚠ Explotación activa | Libraesva Email Security Gateway | 19/9/2025 | 17/6/2026 | Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. For ESG 5.1 a fix has been released in 5.1.20. For ESG 5.2 a fix has been released in 5.2.31. For ESG 5.4 a fix has been released in 5.4.8. For ESG 5.5. a fix has… | |
| Aplazada | Alta (7.5) | 0.46% | — | Vmware FrameworkAIVmware SecurityAI | 16/9/2025 | 17/6/2026 | The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions. Your application may be affected by this if you are using… | |
| Aplazada | Alta (7.5) | 0.43% | — | Vmware Spring SecurityAI | 16/9/2025 | 17/6/2026 | The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue when using @PreAuthorize and other method security annotations, resulting in an authorization bypass. Your… | |
| Analizada | Baja (2.3) | 0.12% | — | IBM Qradar Security Information AND Event Manager | 14/9/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5 Update Pack 13 Independent Fix 01 could allow a local privileged user to perform unauthorized actions on configuration files due to improper permission assignment. | |
| Aplazada | Alta (8.8) | 0.63% | — | Daikin Security GatewayAI | 11/9/2025 | 17/6/2026 | Daikin Europe N.V Security Gateway is vulnerable to an authorization bypass through a user-controlled key vulnerability that could allow an attacker to bypass authentication. An unauthorized attacker could access the system without prior credentials. | |
| Analizada | Media (6.8) | 0.21% | — | IBM Security Verify Information Queue | 10/9/2025 | 17/6/2026 | IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 could allow a privileged user to escalate their privileges and attack surface on the host due to the containers running with unnecessary privileges. | |
| Analizada | Alta (7.5) | 0.19% | — | IBM Security Verify Information Queue | 10/9/2025 | 17/6/2026 | IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | |
| Analizada | Media (6.5) | 0.37% | — | IBM Security Verify Information Queue | 10/9/2025 | 17/6/2026 | IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 could allow a remote user to cause a denial of service due to improper handling of special characters that could lead to uncontrolled resource consumption. | |
| Aplazada | Alta (7.2) | 0.54% | 💥 PoC | K7 Security Anti-malwareAIK7 Rkscan.sysAI | 9/9/2025 | 17/6/2026 | K7RKScan.sys 23.0.0.10, part of the K7 Security Anti-Malware suite, allows an admin-privileged user to send crafted IOCTL requests to terminate processes that are protected through a third-party implementation. This is caused by insufficient caller validation in the driver's IOCTL handler, enabling unauthorized… | |
| Analizada | Media (6.5) | 0.60% | — | Opensecurity Mobile Security Framework | 2/9/2025 | 17/6/2026 | MobSF is a mobile application security testing tool used. In version 4.4.0, an authenticated user who uploaded a specially prepared one.a, can write arbitrary files to any directory writable by the user of the MobSF process. This issue has been patched in version 4.4.1. | |
| Analizada | Baja (1.3) | 0.78% | — | Opensecurity Mobile Security Framework | 2/9/2025 | 17/6/2026 | MobSF is a mobile application security testing tool used. In version 4.4.0, the GET /download/ route uses string path verification via os.path.commonprefix, which allows an authenticated user to download files outside the DWD_DIR download directory from "neighboring" directories whose absolute paths begin with the… | |
| Analizada | Alta (8.1) | 0.24% | — | Dieboldnixdorf Vynamic Security Suite | 29/8/2025 | 17/6/2026 | Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR01 does not validate file attributes or the contents of /root during integrity validation. This allows code execution, recovery of TPM Disk Encryption keys, decryption of the Windows system partition, and full control of the Windows OS, e.g., through ~/.profile… | |
| Analizada | Alta (8.1) | 0.37% | — | Dieboldnixdorf Vynamic Security Suite | 29/8/2025 | 17/6/2026 | Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical system files before the filesystem is properly mounted (e.g., leveraging a delete call in /etc/rc.d/init.d/mountfs to remove the /etc/fstab file). This can allow code execution and, in some versions,… | |
| Analizada | Media (5.3) | 0.34% | — | IBM Security Verify Governance | 28/8/2025 | 17/6/2026 | IBM Security Verify Governance Identity Manager 10.0.2 could allow a remote attacker to obtain sensitive information when detailed technical error messages are returned. This information could be used in further attacks against the system. | |
| Aplazada | Alta (8.5) | 0.30% | — | Opentext Enterprise Security ManagerAI | 25/8/2025 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Enterprise Security Manager. The vulnerability could be remotely exploited. | |
| Aplazada | Media (5.7) | 0.29% | — | Opentext Enterprise Security ManagerAI | 25/8/2025 | 17/6/2026 | An Information Exposure vulnerability has been identified in OpenText Enterprise Security Manager. The vulnerability could be remotely exploited. | |
| Analizada | Media (5.4) | 0.18% | — | IBM Qradar Incident ForensicsIBM Qradar Security Information AND Event Manager | 22/8/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5.0 Dashboard is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Alta (7.8) | 0.15% | — | IBM Qradar Incident ForensicsIBM Qradar Security Information AND Event Manager | 22/8/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5.0 UP13 could allow an authenticated user to escalate their privileges via a misconfigured cronjob due to execution with unnecessary privileges. | |
| Aplazada | Crítica (9.1) | 0.56% | — | Titanhq Spamtitan Email Security GatewayAI | 21/8/2025 | 17/6/2026 | An issue was discovered in TitanHQ SpamTitan Email Security Gateway 8.00.x before 8.00.101 and 8.01.x before 8.01.14. The file quarantine.php within the SpamTitan interface allows unauthenticated users to trigger account-level actions using a crafted GET request. Notably, when a non-existent email address is provided… | |
| Modificada | Media (5.3) | 0.44% | 💥 PoC | Followmedarling Cookies AND Content Security Policy | 19/8/2025 | 5/7/2026 | Incorrect Access Control in the AJAX endpoint functionality in jonkastonka Cookies and Content Security Policy plugin through version 2.29 allows remote attackers to cause a denial of service (database server resource exhaustion) via unlimited database write operations to the wp_ajax_nopriv_cacsp_insert_consent_data… | |
| Aplazada | Alta (8.6) | 0.68% | — | Cisco Secure Firewall Adaptive Security ApplianceAICisco Secure Firewall Threat DefenseAI | 14/8/2025 | 17/6/2026 | This vulnerability is due to insufficient boundary checks for specific data that is provided to the web services interface of an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected system. A successful exploit could allow the attacker to cause a buffer… | |
| Aplazada | Media (5.8) | 0.43% | — | Cisco Secure Firewall Adaptive Security ApplianceAICisco Secure Firewall Threat DefenseAI | 14/8/2025 | 17/6/2026 | A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak, resulting in a denial of service (DoS) condition. This… | |
| Aplazada | Media (5.8) | 0.43% | — | Cisco Secure Firewall Adaptive Security ApplianceAICisco Secure Firewall Threat DefenseAI | 14/8/2025 | 17/6/2026 | A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak, resulting in a denial of service (DoS) condition. This… | |
| Aplazada | Alta (8.5) | 0.47% | — | Cisco Secure Firewall Adaptive Security ApplianceAICisco Secure Firewall Threat DefenseAI | 14/8/2025 | 17/6/2026 | A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to create or delete arbitrary files on the underlying operating system. If critical system… |