Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
2636 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.30% | — | Blueaccesstech Cobalt X1AI | 5/8/2025 | 17/6/2026 | An Authentication Bypass vulnerability in Blue Access' Cobalt X1 thru 02.000.187 allows an unauthorized attacker to log into the application as an administrator without valid credentials. | |
| Aplazada | Crítica (9.8) | 1.2% | — | UI Unifi Access Reader PROAIUI Unifi Access G2 Reader PROAIUI Unifi Access G3 Reader PROAIUI Unifi Access IntercomAI+2 | 4/8/2025 | 17/6/2026 | An Improper Input Validation in certain UniFi Access devices could allow a Command Injection by a malicious actor with access to UniFi Access management network. Affected Products: UniFi Access Reader Pro (Version 2.14.21 and earlier) UniFi Access G2 Reader Pro (Version 1.10.32 and earlier) UniFi Access G3 Reader Pro… | |
| Analizada | Media (6.9) | 0.49% | — | Opexustech Foiaxpress Public Access Link | 31/7/2025 | 17/6/2026 | OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows an unauthenticated, remote attacker to query the /App/CreateRequest.aspx endpoint to check for the existence of valid usernames. There are no rate-limiting mechanisms in place. | |
| Analizada | Media (6.9) | 0.54% | — | Opexustech Foiaxpress Public Access Link | 31/7/2025 | 17/6/2026 | OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows attackers to bypass account-lockout and CAPTCHA protections. Unauthenticated remote attackers can more easily brute force passwords. | |
| Analizada | Media (5.3) | 0.35% | — | Opexustech Foiaxpress Public Access Link | 31/7/2025 | 17/6/2026 | OPEXUS FOIAXpress Public Access Link (PAL), version v11.1.0, allows an authenticated user to add entries to the list of states and territories. | |
| Analizada | Media (5.1) | 0.20% | — | Absolute Secure Access | 31/7/2025 | 17/6/2026 | CVE-2025-54085 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access to the console and who have been assigned a certain set of permissions can bypass those permissions to improperly read or change other settings. The attack complexity is… | |
| Analizada | Media (5.3) | 0.31% | — | Absolute Secure Access | 31/7/2025 | 17/6/2026 | CVE-2025-49084 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access can overwrite policy rules without the requisite permissions. The attack complexity is low, attack requirements are present, privileges required are high and no user… | |
| Analizada | Alta (7) | 0.37% | — | Absolute Secure Access | 31/7/2025 | 17/6/2026 | CVE-2025-49083 is a vulnerability in the management console of Absolute Secure Access after version 12.00 and prior to version 13.56. Attackers with administrative access to the console can cause unsafe content to be deserialized and executed in the security context of the console. The attack complexity is low and… | |
| Analizada | Media (5.1) | 0.22% | — | Absolute Secure Access | 31/7/2025 | 17/6/2026 | CVE-2025-49082 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access to the console and who have been assigned a certain set of permissions can bypass those permissions to improperly read other settings. The attack complexity is low, there… | |
| Aplazada | Media (4.8) | 0.08% | — | Tsplus Remote AccessAI | 29/7/2025 | 17/6/2026 | Access to TSplus Remote Access Admin Tool is restricted to administrators (unless "Disable UAC" option is enabled) and requires a PIN code. In versions below v18.40.6.17 the PIN's hash is stored in a system registry accessible to regular users, making it possible to perform a brute-force attack using rainbow tables,… | |
| Aplazada | Alta (7) | 0.17% | — | Imprivata Enterprise Access ManagementAI | 23/7/2025 | 17/6/2026 | A vulnerability in Imprivata Enterprise Access Management (formerly Imprivata OneSign) allows bypassing the login screen of the shared kiosk workstation and allows unauthorized access to the underlying Windows system through the already logged-in autologon account due to insufficient handling of keyboard shortcuts.… | |
| Aplazada | Alta (8.1) | 0.29% | — | Restrict File AccessAI | 15/7/2025 | 17/6/2026 | The Restrict File Access plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the 'restrict-file-access' page. This makes it possible for unauthenticated attackers to to delete arbitrary files on the… | |
| Aplazada | Crítica (9.8) | 1.1% | — | HPE Networking Instant ON Access PointsAI | 8/7/2025 | 17/6/2026 | Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device authentication. Successful exploitation could allow a remote attacker to gain administrative access to the system. | |
| Aplazada | Alta (7.2) | 1.5% | — | HPE Networking Instant ON Access PointsAI | 8/7/2025 | 17/6/2026 | An authenticated command injection vulnerability exists in the Command line interface of HPE Networking Instant On Access Points. A successful exploitation could allow a remote attacker with elevated privileges to execute arbitrary commands on the underlying operating system as a highly privileged user. | |
| Analizada | Media (5.9) | 0.33% | — | IBM Engineering Requirements Management DoorsIBM Engineering Requirements Management Doors WEB Access | 7/7/2025 | 17/6/2026 | IBM Engineering Requirements Management DOORS 9.7.2.9, under certain configurations, could allow a remote attacker to obtain password reset instructions of a legitimate user using man in the middle techniques. | |
| Analizada | Media (5.4) | 0.19% | — | Fl3r Accessibility Suite | 27/6/2025 | 17/6/2026 | The FL3R Accessibility Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fl3raccessibilitysuite shortcode in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (5.5) | 0.14% | — | Fortra Core Privileged Access ManagerAI | 17/6/2025 | 17/6/2026 | A binary in the BoKS Server Agent component of Fortra's Core Privileged Access Manager (BoKS) on versions 7.2.0 (up to 7.2.0.17), 8.1.0 (up to 8.1.0.22), 8.1.1 (up to 8.1.1.7), 9.0.0 (up to 9.0.0.1) and also legacy tar installs of BoKS 7.2 without hotfix #0474 on Linux, AIX, and Solaris allows low privilege local… | |
| Analizada | Alta (8.6) | 0.15% | — | Citrix Secure Access Client | 17/6/2025 | 17/6/2026 | Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Secure Access Client for Windows | |
| Analizada | Alta (8.6) | 0.95% | — | Beyondtrust Privileged Remote AccessBeyondtrust Remote Support | 16/6/2025 | 17/6/2026 | The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code execution. | |
| Aplazada | Media (6.5) | 0.62% | — | Restrict File AccessAI | 14/6/2025 | 17/6/2026 | The Restrict File Access plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.2 via the output() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain… | |
| Aplazada | Alta (8.1) | 0.84% | — | Zagg Electronics AccessoriesAI | 14/6/2025 | 17/6/2026 | The Zagg - Electronics & Accessories WooCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.1 via the load_view() function that is called via at least three AJAX actions: 'load_more_post', 'load_shop', and 'load_more_product. This makes it… | |
| Aplazada | Alta (7.2) | 1.4% | — | Hikvision Wireless Access PointAI | 13/6/2025 | 17/6/2026 | Some Hikvision Wireless Access Point are vulnerable to authenticated remote command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution. | |
| Aplazada | Media (5.1) | 0.19% | — | Paloaltonetworks Prisma Access BrowserAI | 12/6/2025 | 17/6/2026 | An insufficient implementation of cache vulnerability in Palo Alto Networks Prisma® Access Browser enables users to bypass certain data control policies. | |
| Analizada | Media (6.9) | 0.48% | — | Absolute Secure Access | 12/6/2025 | 17/6/2026 | There is an insufficient input validation vulnerability in the warehouse component of Absolute Secure Access prior to server version 13.55. Attackers with system administrator permissions can impair the availability of the Secure Access administrative UI by writing invalid data to the warehouse over the network. The… | |
| Analizada | Alta (8.7) | 0.37% | — | Absolute Secure Access | 12/6/2025 | 17/6/2026 | There is a memory management vulnerability in Absolute Secure Access server versions 9.0 to 13.54. Attackers with network access to the server can cause a Denial of Service by sending a specially crafted sequence of packets to the server. The attack complexity is low, there are no attack requirements, privileges, or… |