Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
97 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.1) | 0.56% | — | Fleetdm Fleet | 26/2/2026 | 17/6/2026 | Fleet is open source device management software. A SQL injection vulnerability in versions prior to 4.80.1 allowed authenticated users to inject arbitrary SQL expressions via the `order_key` query parameter. Due to unsafe use of `goqu.I()` when constructing the `ORDER BY` clause, specially crafted input could escape… | |
| Analizada | Crítica (9.3) | 0.26% | — | Fleetdm Fleet | 21/1/2026 | 17/6/2026 | Fleet is open source device management software. In versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, a vulnerability in Fleet's Windows MDM enrollment flow could allow an attacker to submit forged authentication tokens that are not properly validated. Because JWT signatures were not verified, Fleet could… | |
| Analizada | Media (6.3) | 0.29% | — | Fleetdm Fleet | 21/1/2026 | 17/6/2026 | Fleet is open source device management software. A broken access control issue in versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3 allowed authenticated users to access debug and profiling endpoints regardless of role. As a result, low-privilege users could view internal server diagnostics and trigger… | |
| Analizada | Media (5.5) | 0.25% | — | Fleetdm Fleet | 21/1/2026 | 17/6/2026 | fleetdm/fleet is open source device management software. Prior to versions 4.78.2, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, if Windows MDM is enabled, an unauthenticated attacker can exploit this XSS vulnerability to steal a Fleet administrator's authentication token (FLEET::auth_token) from localStorage. This could allow… | |
| Aplazada | Media (6.1) | 0.24% | — | Mobile-industrial-robots MIR RobotAIMobile-industrial-robots MIR FleetAI | 1/12/2025 | 17/6/2026 | Open redirect in the web server component of MiR Robot and Fleet software allows a remote attacker to redirect users to arbitrary external websites via a crafted parameter, facilitating phishing or social engineering attacks. | |
| Aplazada | Media (4.4) | 0.22% | — | Fleet ManagerAI | 11/11/2025 | 30/9/2026 | The Fleet Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary… | |
| Aplazada | Media (5.5) | 0.26% | — | MIR SoftwareAIMIR FleetAI | 20/8/2025 | 17/6/2026 | Stored cross-site scripting (XSS) in the web interface of MiR software versions prior to 3.0.0 on MiR Robots and MiR Fleet allows execution of arbitrary JavaScript code in a victim’s browser | |
| Aplazada | Media (6.4) | 0.24% | — | FleetwireAI | 23/7/2025 | 17/6/2026 | The Fleetwire Fleet Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fleetwire_list shortcode in all versions up to, and including, 1.0.19 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (5.3) | 0.55% | — | Oracle Fleet Patching AND Provisioning | 15/4/2025 | 17/6/2026 | Vulnerability in the Fleet Patching and amp; Provisioning component of Oracle Database Server. Supported versions that are affected are 19.3-19.26. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Fleet Patching and amp; Provisioning. Successful attacks of… | |
| Aplazada | Crítica (9.3) | 0.67% | — | Fleetdm FleetAILinuxfoundation OsqueryAI | 6/3/2025 | 17/6/2026 | fleetdm/fleet is an open source device management, built on osquery. In vulnerable versions of Fleet, an attacker could craft a specially-formed SAML response to forge authentication assertions, provision a new administrative user account if Just-In-Time (JIT) provisioning is enabled, or create new accounts tied to… | |
| Aplazada | Crítica (9) | 0.27% | — | Elastic Fleet ServerAI | 23/1/2025 | 17/6/2026 | An issue was identified in Fleet Server where Fleet policies that could contain sensitive information were logged on INFO and ERROR log levels. The nature of the sensitive information largely depends on the integrations enabled. | |
| Aplazada | Media (6.9) | 19% | — | Envaysoft FleetcartAI | 23/5/2024 | 17/6/2026 | A vulnerability has been found in EnvaySoft FleetCart up to 4.1.1 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument razorpayKeyId leads to information disclosure. The attack can be launched remotely. It is recommended to upgrade the affected… | |
| Modificada | Alta (7.5) | 0.32% | — | Elastic BeatsElastic AgentElastic APM ServerElastic Fleet Server | 26/10/2023 | 17/6/2026 | It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet Server did not verify whether the server certificate is valid for the target IP address; however, certificate signature validation is still performed. More specifically, when the client is configured to connect to an IP… | |
| Modificada | Alta (8.1) | 0.55% | — | Elastic Fleet Server | 26/10/2023 | 17/6/2026 | An issue was discovered in Fleet Server >= v8.10.0 and < v8.10.3 where Agent enrolment tokens are being inserted into the Fleet Server’s log file in plain text. These enrolment tokens could allow someone to enrol an agent into an agent policy, and potentially use that to retrieve other secrets in the policy including… | |
| Modificada | Alta (8.1) | 0.85% | — | Fleetdm Fleet | 18/4/2022 | 17/6/2026 | fleetdm/fleet is an open source device management, built on osquery. All versions of fleet making use of the teams feature are affected by this authorization bypass issue. Fleet instances without teams, or with teams but without restricted team accounts are not affected. In affected versions a team admin can… | |
| Analizada | Crítica (9.8) | 1.9% | — | Tsg-solutions Tokheim Profleet Dialog | 11/2/2022 | 17/6/2026 | Tokheim Profleet DiaLOG 11.005.02 is affected by SQL Injection. The component is the Field__UserLogin parameter on the logon page. | |
| Modificada | Media (6.5) | 0.90% | — | Fleetdm Fleet | 4/2/2022 | 17/6/2026 | fleet is an open source device management, built on osquery. Versions prior to 4.9.1 expose a limited ability to spoof SAML authentication with missing audience verification. This impacts deployments using SAML SSO in two specific cases: 1. A malicious or compromised Service Provider (SP) could reuse the SAML response… | |
| Analizada | Baja (2.7) | 1.9% | — | Fleetdm Fleet | 10/2/2021 | 6/10/2026 | Fleet is an open source osquery manager. In Fleet before version 3.7.0 a malicious actor with a valid node key can send a badly formatted request that causes the Fleet server to exit, resulting in denial of service. This is possible only while a live query is currently ongoing. We believe the impact of this… | |
| Modificada | Crítica (9.8) | 2.2% | — | Fleetdm Fleet | 17/12/2020 | 17/6/2026 | Fleet is an open source osquery manager. In Fleet before version 3.5.1, due to issues in Go's standard library XML parsing, a valid SAML response may be mutated by an attacker to modify the trusted document. This can result in allowing unverified logins from a SAML IdP. Users that configure Fleet with SSO login may be… | |
| Modificada | Alta (8.8) | 3.1% | — | Fleetco Fleet Maintenance Management | 2/3/2020 | 17/6/2026 | Fleetco Fleet Maintenance Management (FMM) 1.2 and earlier allows uploading an arbitrary ".php" file with the application/x-php Content-Type to the accidents_add.php?submit=1 URI, as demonstrated by the value_Images_1 field, which leads to remote command execution on the remote server. Any authenticated user can… | |
| Modificada | Alta (7.5) | 1.4% | — | Kolide Fleet | 29/7/2019 | 17/6/2026 | Fleet before 2.1.2 allows exposure of SMTP credentials. | |
| Modificada | Media (6.5) | 1.2% | — | Oracle Hospitality Cruise Fleet Management | 17/10/2018 | 17/6/2026 | Vulnerability in the Oracle Hospitality Cruise Fleet Management component of Oracle Hospitality Applications (subcomponent: Emergency Response System). The supported version that is affected is 9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Media (6.5) | 1.7% | — | Oracle Hospitality Cruise Fleet Management | 17/10/2018 | 17/6/2026 | Vulnerability in the Oracle Hospitality Cruise Fleet Management component of Oracle Hospitality Applications (subcomponent: Emergency Response System). The supported version that is affected is 9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Media (6.1) | 0.42% | — | Oracle Hospitality Cruise Fleet Management | 17/10/2018 | 17/6/2026 | Vulnerability in the Oracle Hospitality Cruise Fleet Management component of Oracle Hospitality Applications (subcomponent: Sender and Receiver). The supported version that is affected is 9.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hospitality… | |
| Modificada | Alta (7.1) | 1.2% | — | Oracle Hospitality Cruise Fleet Management | 17/10/2018 | 17/6/2026 | Vulnerability in the Oracle Hospitality Cruise Fleet Management component of Oracle Hospitality Applications (subcomponent: Emergency Response System). The supported version that is affected is 9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… |