Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
349 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.78% | — | Dormakabagroup Dormakaba Access Manager 9200-k7 FirmwareDormakabagroup Dormakaba Access Manager 9230-k7 FirmwareDormakabagroup Dormakaba Access Manager 9290-k7 FirmwareDormakabagroup Dormakaba Access Manager 9200-k5 Firmware+2 | 26/1/2026 | 17/6/2026 | The binary serving the web server and executing basically all actions launched from the Web UI is running with root privileges. This is against the least privilege principle. If an attacker is able to execute code on the system via other vulnerabilities it is possible to directly execute commands with highest… | |
| Aplazada | Crítica (9.2) | 0.42% | — | Access Manager 92xxAI | 26/1/2026 | 17/6/2026 | The Access Manager 92xx in hardware revision K7 is based on Linux instead of Windows CE embedded in older hardware revisions. In this new hardware revision it was noticed that an SSH service is exposed on port 22. By analyzing the firmware of the devices, it was noticed that there are two users with hardcoded and weak… | |
| Aplazada | Media (6.9) | 0.38% | — | Access ManagerAI | 26/1/2026 | 17/6/2026 | The web server of the Access Manager offers a functionality to download a backup of the local database stored on the device. This database contains the whole configuration. This includes encrypted MIFARE keys, card data, user PINs and much more. The PINs are even stored unencrypted. Combined with the fact that an… | |
| Aplazada | Alta (8.7) | 0.41% | — | Dormakaba Access ManagerAI | 26/1/2026 | 17/6/2026 | The Access Manager is offering a trace functionality to debug errors and issues with the device. The trace functionality is implemented as a simple TCP socket. A tool called TraceClient.exe, provided by dormakaba via the Access Manager web interface, is used to connect to the socket and receive debug information. The… | |
| Analizada | Alta (8.1) | 0.80% | — | Zohocorp Manageengine Pam360Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Password Manager PRO | 13/1/2026 | 17/6/2026 | Zohocorp ManageEngine PAM360 versions before 8202; Password Manager Pro versions before 13221; Access Manager Plus versions prior to 4401 are vulnerable to an authorization issue in the initiate remote session functionality. | |
| Aplazada | Media (6.2) | 0.10% | — | Fortra Core Privileged Access ManagerAIFortra Boks Server AgentAI | 16/12/2025 | 17/6/2026 | Insecure defaults in the Server Agent component of Fortra's Core Privileged Access Manager (BoKS) can result in the selection of weak password hash algorithms. This issue affects BoKS Server Agent 9.0 instances that support yescrypt and are running in a BoKS 8.1 domain. | |
| Aplazada | Media (5.5) | 0.14% | — | Fortra Core Privileged Access ManagerAI | 17/6/2025 | 17/6/2026 | A binary in the BoKS Server Agent component of Fortra's Core Privileged Access Manager (BoKS) on versions 7.2.0 (up to 7.2.0.17), 8.1.0 (up to 8.1.0.22), 8.1.1 (up to 8.1.1.7), 9.0.0 (up to 9.0.0.1) and also legacy tar installs of BoKS 7.2 without hotfix #0474 on Linux, AIX, and Solaris allows low privilege local… | |
| Aplazada | Media (4.2) | 0.23% | — | Cyberark Privileged Access ManagerAI | 3/2/2025 | 17/6/2026 | PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 has potentially elevated privileges in LDAP mapping. | |
| Analizada | Media (6.1) | 0.16% | — | Cyberark Privileged Access Manager | 3/2/2025 | 17/6/2026 | PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 does not properly address environment issues that can contribute to Host header injection. | |
| Analizada | Media (6.1) | 0.23% | — | Seling Visual Access Manager | 13/1/2025 | 17/6/2026 | Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via /common/autocomplete.php. | |
| Analizada | Media (6.1) | 0.23% | — | Seling Visual Access Manager | 13/1/2025 | 17/6/2026 | Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via vam/vam_visits.php. | |
| Analizada | Media (6.5) | 0.36% | — | Seling Visual Access Manager | 13/1/2025 | 17/6/2026 | An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can write arbitrary files by manipulating POST parameters of the page "common/vam_Sql.php". | |
| Analizada | Media (6.1) | 0.23% | — | Seling Visual Access Manager | 13/1/2025 | 17/6/2026 | Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via monitor/s_monitor_map.php. | |
| Analizada | Media (6.1) | 0.23% | — | Seling Visual Access Manager | 13/1/2025 | 17/6/2026 | Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via /vam/vam_ep.php. | |
| Analizada | Media (6.1) | 0.23% | — | Seling Visual Access Manager | 13/1/2025 | 17/6/2026 | Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via monitor/s_scheduledfile.php. | |
| Analizada | Alta (8.8) | 0.38% | — | Seling Visual Access Manager | 13/1/2025 | 17/6/2026 | An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_visits.php. | |
| Analizada | Media (5.4) | 0.24% | — | Seling Visual Access Manager | 13/1/2025 | 17/6/2026 | In Selesta Visual Access Manager < 4.42.2, an authenticated user can access the administrative page /common/vam_Sql.php, which allows for arbitrary SQL queries. | |
| Analizada | Baja (3.8) | 0.32% | — | Seling Visual Access Manager | 13/1/2025 | 17/6/2026 | An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in a GET parameter of /monitor/s_terminal.php. | |
| Analizada | Baja (3.8) | 0.24% | — | Seling Visual Access Manager | 13/1/2025 | 17/6/2026 | An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_anagraphic.php. | |
| Analizada | Baja (3.8) | 0.24% | — | Seling Visual Access Manager | 13/1/2025 | 17/6/2026 | An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /monitor/s_scheduledfile.php. | |
| Analizada | Baja (3.8) | 0.32% | — | Seling Visual Access Manager | 13/1/2025 | 17/6/2026 | An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_ep.php. | |
| Analizada | Baja (3.8) | 0.32% | — | Seling Visual Access Manager | 13/1/2025 | 17/6/2026 | An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_eps.php. | |
| Analizada | Baja (3.8) | 0.24% | — | Seling Visual Access Manager | 13/1/2025 | 17/6/2026 | An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple GET parameters of /vam/vam_i_command.php. | |
| Analizada | Baja (3.8) | 0.32% | — | Seling Visual Access Manager | 13/1/2025 | 17/6/2026 | An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in a GET parameter of /common/ajaxfunction.php. | |
| Analizada | Baja (3.8) | 0.32% | — | Seling Visual Access Manager | 13/1/2025 | 17/6/2026 | An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple parameters of /monitor/s_normalizedtrans.php. |