Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1654 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.6) | 0.31% | — | Medivision Digital Signage Firmware | 10/12/2025 | 17/6/2026 | UBICOD Medivision Digital Signage 1.5.1 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without proper request validation. Attackers can craft a malicious web page that submits a form to the /query/user/itSet endpoint to add a new admin user with… | |
| Analizada | Alta (7.1) | 0.77% | — | Stvs Provision | 9/12/2025 | 17/6/2026 | STVS ProVision 5.9.10 contains a path traversal vulnerability that allows authenticated attackers to access arbitrary files by manipulating the files parameter in the archive download functionality. Attackers can send GET requests to /archive/download with directory traversal sequences to read sensitive system files… | |
| Analizada | Media (6.9) | 0.20% | — | Stvs Provision | 9/12/2025 | 17/6/2026 | STVS ProVision 5.9.10 contains a cross-site request forgery vulnerability that allows attackers to perform actions with administrative privileges by exploiting unvalidated HTTP requests. Attackers can visit malicious web sites to trigger the forge request, allowing them to create new admin users. | |
| Analizada | Crítica (9.8) | 0.54% | — | Millensys Vision Tools Workspace | 24/11/2025 | 17/6/2026 | MILLENSYS Vision Tools Workspace 6.5.0.2585 exposes a sensitive configuration endpoint (/MILLENSYS/settings) that is accessible without authentication. This page leaks plaintext database credentials, file share paths, internal license server configuration, and software update parameters. An unauthenticated attacker… | |
| Modificada | Media (4.3) | 0.20% | — | Apple IpadosApple Iphone OSApple MacosApple Visionos+1 | 21/11/2025 | 17/6/2026 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, tvOS 18.5, visionOS 2.5, watchOS 11.5. An attacker in physical proximity may be able to cause an out-of-bounds read in kernel… | |
| Aplazada | Media (5.3) | 0.21% | — | Cozyvision SMS Alert Order NotificationsAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SMS Alert Order Notifications: from n/a through <= 3.8.8. | |
| Modificada | Media (4) | 0.15% | — | Apple IpadosApple Iphone OSApple TvosApple Visionos+1 | 12/11/2025 | 17/6/2026 | An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to bypass ASLR. | |
| Aplazada | Crítica (9.3) | 0.46% | — | Survision LPR CameraAI | 4/11/2025 | 17/6/2026 | The Survision LPR Camera system does not enforce password protection by default. This allows access to the configuration wizard immediately without a login prompt or credentials check. | |
| Modificada | Alta (7.5) | 0.47% | — | Apple SafariApple IpadosApple Iphone OSApple Visionos | 4/11/2025 | 17/6/2026 | A privacy issue was addressed by removing sensitive data. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1. An app may be able to bypass certain Privacy preferences. | |
| Modificada | Alta (7.5) | 0.52% | — | Apple IpadosApple Iphone OSApple VisionosApple Watchos | 4/11/2025 | 17/6/2026 | A privacy issue was addressed with improved handling of user preferences. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. An app may be able to access sensitive user data. | |
| Modificada | Media (5.5) | 0.20% | — | Apple IpadosApple Iphone OSApple MacosApple Visionos | 4/11/2025 | 17/6/2026 | An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, visionOS 26.1. An app may be able to access sensitive user data. | |
| Modificada | Alta (7.5) | 0.52% | — | Apple IpadosApple Iphone OSApple MacosApple Visionos+1 | 4/11/2025 | 17/6/2026 | The issue was addressed by adding additional logic. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. Remote content may be loaded even when the 'Load Remote Images' setting is turned off. | |
| Modificada | Alta (8.1) | 0.49% | — | Apple SafariApple IpadosApple Iphone OSApple Tvos+2 | 4/11/2025 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious website may exfiltrate data cross-origin. | |
| Modificada | Alta (7.5) | 0.64% | — | Apple IpadosApple Iphone OSApple TvosApple Visionos+1 | 4/11/2025 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. An app may be able to cause unexpected system termination or corrupt kernel memory. | |
| Modificada | Media (6.5) | 0.61% | — | Apple SafariApple IpadosApple Iphone OSApple Visionos+1 | 4/11/2025 | 15/7/2026 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected Safari crash. | |
| Modificada | Media (5.5) | 0.26% | — | Apple IpadosApple Iphone OSApple VisionosApple Watchos | 4/11/2025 | 17/6/2026 | A privacy issue was addressed with improved checks. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. A malicious app may be able to take a screenshot of sensitive information in embedded views. | |
| Modificada | Media (5.5) | 0.19% | — | Apple IpadosApple Iphone OSApple VisionosApple Watchos | 4/11/2025 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. An app may be able to cause unexpected system termination or corrupt kernel memory. | |
| Modificada | Media (4.3) | 0.96% | — | Apple SafariApple IpadosApple Iphone OSApple Tvos+1 | 4/11/2025 | 14/8/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Media (6.5) | 0.51% | — | Apple SafariApple IpadosApple Iphone OSApple Tvos+2 | 4/11/2025 | 17/6/2026 | This issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Alta (7.5) | 0.58% | — | Apple IpadosApple Iphone OSApple TvosApple Visionos+1 | 4/11/2025 | 17/6/2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. An app may be able to enumerate a user's installed apps. | |
| Modificada | Media (4.3) | 0.75% | — | Apple SafariApple IpadosApple Iphone OSApple Tvos+2 | 4/11/2025 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Alta (8.8) | 1.2% | — | Apple SafariApple IpadosApple Iphone OSApple Tvos+2 | 4/11/2025 | 14/8/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to memory corruption. | |
| Modificada | Media (4.3) | 0.84% | — | Apple SafariApple IpadosApple Iphone OSApple Tvos+2 | 4/11/2025 | 17/6/2026 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Alta (8.8) | 0.85% | — | Apple SafariApple IpadosApple Iphone OSApple Tvos+2 | 4/11/2025 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to memory corruption. | |
| Modificada | Media (4.3) | 1.1% | — | Apple SafariApple IpadosApple Iphone OSApple Tvos+2 | 4/11/2025 | 17/6/2026 | This issue was addressed through improved state management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash. |