Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
164 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.71% | — | Sicunet Access Control | 11/6/2022 | 17/6/2026 | A vulnerability was found in SICUNET Access Controller 0.32-05z and classified as critical. Affected by this issue is some unknown functionality of the file card_scan_decoder.php. The manipulation of the argument No/door leads to privilege escalation. The attack may be launched remotely. | |
| Modificada | Alta (8.8) | 0.62% | — | Sicunet Access Control | 11/6/2022 | 17/6/2026 | A vulnerability has been found in SICUNET Access Controller 0.32-05z and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument c leads to privilege escalation. The attack can be launched remotely. | |
| Modificada | Alta (7.5) | 1.6% | — | Integrated Dell Remote Access Controller 8 Firmware | 21/4/2022 | 17/6/2026 | Dell iDRAC8 versions prior to 2.83.83.83 contain a denial of service vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to cause resource exhaustion in the webserver, resulting in a denial of service condition. | |
| Modificada | Alta (7.3) | 0.98% | 💥 PoC | Secom Dr.id Access ControlSecom Dr.id Attendance System | 7/4/2022 | 17/6/2026 | Taiwan Secom Dr.ID Access Control system’s login page has a hard-coded credential in the source code. An unauthenticated remote attacker can use the hard-coded credential to acquire partial system information and modify system setting to cause partial disrupt of service. | |
| Modificada | Alta (8.1) | 1.1% | — | Integrated Dell Remote Access Controller 9 Firmware | 25/1/2022 | 17/6/2026 | iDRAC9 versions prior to 5.00.20.00 contain an input injection vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to cause information disclosure or denial of service by supplying specially crafted input data to iDRAC. | |
| Modificada | Alta (7.2) | 2.2% | — | Integrated Dell Remote Access Controller 8 FirmwareIntegrated Dell Remote Access Controller 9 Firmware | 25/1/2022 | 17/6/2026 | iDRAC9 versions prior to 5.00.20.00 and iDRAC8 versions prior to 2.82.82.82 contain a stack-based buffer overflow vulnerability. An authenticated remote attacker with high privileges could potentially exploit this vulnerability to control process execution and gain access to the iDRAC operating system. | |
| Modificada | Media (5.3) | 4.2% | — | Integrated Dell Remote Access Controller 8 Firmware | 25/1/2022 | 17/6/2026 | Dell iDRAC 8 prior to version 2.82.82.82 contain a denial of service vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to deny access to the iDRAC webserver. | |
| Modificada | Alta (8.8) | 0.80% | — | SAP Access Control | 14/12/2021 | 17/6/2026 | SAP GRC Access Control - versions V1100_700, V1100_731, V1200_750, does not perform necessary authorization checks for an authenticated user, which could lead to escalation of privileges. | |
| Modificada | Alta (8.8) | 1.6% | — | 3xlogic Infinias Access Control | 1/10/2021 | 17/6/2026 | An issue was discovered in 3xLogic Infinias Access Control through 6.7.10708.0, affecting physical security. Users with login credentials assigned to a specific zone can send modified HTTP GET and POST requests, allowing them to view user data such as personal information and Prox card credentials. Also, an authorized… | |
| Modificada | Alta (7.5) | 1.8% | — | Secom Door Access ControlSecom Personnel Attendance System | 16/7/2021 | 17/6/2026 | Specific page parameters in Dr. ID Door Access Control and Personnel Attendance Management system does not filter special characters. Remote attackers can apply Path Traversal means to download credential files from the system without permission. | |
| Modificada | Crítica (9.8) | 2.2% | — | Secom Dr.id Access Control | 16/7/2021 | 17/6/2026 | Dr. ID Door Access Control and Personnel Attendance Management system uses the hard-code admin default credentials that allows remote attackers to access the system through the default password and obtain the highest permission. | |
| Modificada | Alta (8.8) | 5.2% | — | IWT Facesentry Access Control System Firmware | 4/5/2021 | 17/6/2026 | iWT Ltd FaceSentry Access Control System 6.4.8 suffers from an authenticated OS command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user via the 'strInIP' POST parameter in pingTest PHP script. | |
| Modificada | Alta (7.5) | 0.93% | — | Secom Dr.id Access ControlSecom Dr.id Attendance System | 11/2/2020 | 17/6/2026 | TAIWAN SECOM CO., LTD., a Door Access Control and Personnel Attendance Management system, stores users’ information by cleartext in the cookie, which divulges password to attackers. | |
| Modificada | Crítica (9.8) | 1.4% | — | Secom Dr.id Access ControlSecom Dr.id Attendance System | 11/2/2020 | 17/6/2026 | TAIWAN SECOM CO., LTD., a Door Access Control and Personnel Attendance Management system, contains a vulnerability of Pre-auth SQL Injection, allowing attackers to inject a specific SQL command. | |
| Modificada | Media (5.3) | 1.2% | — | Secom Dr.id Access ControlSecom Dr.id Attendance System | 11/2/2020 | 17/6/2026 | TAIWAN SECOM CO., LTD., a Door Access Control and Personnel Attendance Management system, allows attackers to enumerate and exam user account in the system. | |
| Modificada | Crítica (9.8) | 2.4% | — | HP Access Control | 9/1/2020 | 17/6/2026 | A potential security vulnerability has been identified in the software solution HP Access Control versions prior to 16.7. This vulnerability could potentially grant elevation of privilege. | |
| Modificada | Media (6.5) | 0.71% | — | 3xlogic Infinias Access Control Firmware | 14/11/2019 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in 3xLogic Infinias Access Control through 6.6.9586.0 allows remote attackers to execute malicious and unauthorized actions (e.g., delete application users) by sending a crafted HTML document or encoded URL to a user that the website trusts. The user needs to have an… | |
| Modificada | Media (5.7) | 1.8% | — | Cisco Secure Access Control Server Solution Engine | 5/10/2018 | 17/6/2026 | A vulnerability in the web-based UI of Cisco Secure Access Control Server could allow an authenticated, remote attacker to gain read access to certain information in an affected system. The vulnerability is due to improper handling of XML External Entities (XXEs) when parsing an XML file. An attacker could exploit… | |
| Modificada | Crítica (9.8) | 6.8% | — | Cisco Secure Access Control System | 2/5/2018 | 17/6/2026 | A vulnerability in the ACS Report component of Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected system. Commands executed by the attacker are processed at the targeted user's privilege level. The vulnerability is due to insufficient… | |
| Modificada | Baja (3.3) | 1.5% | — | Cisco Secure Access Control Server Solution Engine | 8/3/2018 | 17/6/2026 | A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could allow an unauthenticated, remote attacker to gain read access to certain information in the affected system. The vulnerability is due to improper handling of XML External Entities (XXEs) when parsing an… | |
| Modificada | Baja (3.3) | 1.5% | — | Cisco Secure Access Control Server Solution Engine | 8/3/2018 | 17/6/2026 | A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could allow an unauthenticated, remote attacker to gain read access to certain information in the affected system. The vulnerability is due to improper handling of XML External Entities (XXEs) when parsing an… | |
| Analizada | Crítica (9.8) | 18% | ⚠ Explotación activa | Cisco Secure Access Control System | 8/3/2018 | 17/6/2026 | A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected… | |
| Modificada | Media (5.3) | 2.2% | — | Cisco Secure Access Control System | 30/11/2017 | 17/6/2026 | A vulnerability in the web-based interface of Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to view sensitive information on an affected system. The vulnerability exists because the affected software does not sufficiently protect system software version information when the… | |
| Modificada | Media (5.4) | 0.89% | — | Cisco Secure Access Control System | 7/8/2017 | 17/6/2026 | A vulnerability in the web-based management interface of the Cisco Secure Access Control System (ACS) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of the affected system. More Information: CSCve70587. Known Affected Releases:… | |
| Modificada | Media (6.1) | 1.2% | — | Dell Integrated Remote Access Controller Firmware | 10/4/2017 | 17/6/2026 | Dell Integrated Remote Access Controller (iDRAC) 6 before 2.85 and 7/8 before 2.30.30.30 has XSS. |