Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
234 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.3) | 0.36% | — | Novakon P SeriesAI | 23/9/2025 | 30/9/2026 | — | |
| Aplazada | Alta (8.6) | 0.22% | — | Novakon P SeriesAI | 23/9/2025 | 25/9/2026 | No password for the root user is set in Novakon P series. This allows phyiscal attackers to enter the console easily. This issue affects P series: P – V2001.A.C518o2 until P-2.0.05 Build 2026.02.06 (commit d0f97fd9). | |
| Aplazada | Crítica (10) | 1.1% | — | Novakon P SeriesAI | 23/9/2025 | 25/9/2026 | — | |
| Aplazada | Alta (7.5) | 0.12% | — | GE Vernova S1 Agile Configuration SoftwareAI | 22/9/2025 | 17/6/2026 | Improper Privilege Management vulnerability in GE Vernova S1 Agile Configuration Software on Windows allows Privilege Escalation.This issue affects S1 Agile Configuration Software: 3.1 and previous version. | |
| Aplazada | Media (4.7) | 0.24% | — | Zirve Information Technologies INC Zirve NovaAI | 17/9/2025 | 25/9/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zirve Information Technologies Inc. Zirve Nova allows Cross-Site Scripting (XSS). This issue affects Zirve Nova: from 235 through 20250131. | |
| Aplazada | Media (6.9) | 0.33% | — | T-innova DeporsiteAI | 2/9/2025 | 17/6/2026 | Lack of authorisation in Deporsite by T-INNOVA. This vulnerability allows an unauthenticated attacker to change other users' profile pictures via a POST request using the parameters ‘IdPersona’ and “Foto” in ‘/ajax/TInnova_c/FotoUsuario/llamadaAjax/uploadImage’. | |
| Aplazada | Media (6.9) | 0.33% | — | T-innova DeporsiteAI | 2/9/2025 | 17/6/2026 | Lack of authorisation in Deporsite by T-INNOVA. This vulnerability allows an unauthenticated attacker to obtain information from other users via GET ‘/ajax/TInnova_v2/Integrantes_Recurso_v2_1/llamadaAjax/buscarPersona’ using the ‘dni’ parameter. | |
| Aplazada | Crítica (9.3) | 0.28% | — | Minova TTAAI | 25/8/2025 | 17/6/2026 | Information disclosure and exposure of authentication FTP credentials over the debug port 1604 in the MINOVA TTA service. This allows unauthenticated remote access to an active FTP account containing sensitive internal data and import structures. In environments where this FTP server is part of automated business… | |
| Analizada | Baja (2) | 0.44% | — | Metaclinic Nanovault | 5/8/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in cronoh NanoVault up to 1.2.1. This issue affects the function executeJavaScript of the file /main.js of the component xrb URL Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been… | |
| Aplazada | Media (6.9) | 0.31% | — | Fujifilm Business Innovation MFPAI | 4/8/2025 | 17/6/2026 | Out-of-bounds write vulnerability exists in FUJIFILM Business Innovation MFPs. A specially crafted IPP (Internet Printing Protocol) or LPD (Line Printer Daemon) packet may cause a denial-of-service (DoS) condition on an affected MFP. Resetting the MFP is required to recover from the denial-of-service (DoS) condition. | |
| Aplazada | Alta (8.1) | 0.84% | — | Marshmallow-packages Nova-tiptapAILaravel NovaAI | 21/7/2025 | 17/6/2026 | marshmallow-packages/nova-tiptap is a rich text editor for Laravel Nova based on tiptap. Prior to 5.7.0, a vulnerability was discovered in the marshmallow-packages/nova-tiptap Laravel Nova package that allows unauthenticated users to upload arbitrary files to any Laravel disk configured in the application. The… | |
| Aplazada | Media (5.4) | 0.30% | — | Posimyth Innovation THE Plus Addons FOR Elementor PROAI | 1/7/2025 | 17/6/2026 | Missing Authorization vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Plus Addons for Elementor Pro: from n/a before 6.3.7. | |
| Analizada | Alta (7.2) | 0.54% | — | Ocuco Innovation | 22/5/2025 | 17/6/2026 | An issue in Ocuco Innovation - JOBMANAGER.EXE v2.10.24.16 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet. | |
| Analizada | Crítica (9.8) | 0.57% | — | Ocuco Innovation | 22/5/2025 | 17/6/2026 | An issue in Ocuco Innovation - REPORTS.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet. | |
| Analizada | Crítica (9.8) | 0.57% | — | Ocuco Innovation | 22/5/2025 | 17/6/2026 | An issue in Ocuco Innovation - INVCLIENT.EXE v2.10.24.5 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet. | |
| Analizada | Crítica (9.8) | 0.66% | — | Ocuco Innovation | 22/5/2025 | 17/6/2026 | An issue in Ocuco Innovation - REPORTSERVER.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet. | |
| Analizada | Crítica (9.8) | 0.57% | — | Ocuco Innovation | 22/5/2025 | 17/6/2026 | An issue in Ocuco Innovation - INNOVASERVICEINTF.EXE v2.10.24.17 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet. | |
| Analizada | Alta (7.8) | 0.20% | — | Ocuco Innovation | 22/5/2025 | 17/6/2026 | An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the SETTINGSVATIGATOR.EXE component | |
| Analizada | Alta (7.8) | 0.20% | — | Ocuco Innovation | 22/5/2025 | 17/6/2026 | An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the STOCKORDERENTRY.EXE component | |
| Analizada | Alta (7.8) | 0.20% | — | Ocuco Innovation | 22/5/2025 | 17/6/2026 | An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the JOBENTRY.EXE | |
| Analizada | Alta (7.8) | 0.20% | — | Ocuco Innovation | 22/5/2025 | 17/6/2026 | An issue in Ocuco Innovation APPMANAGER.EXE v.2.10.24.51 allows a local attacker to escalate privileges via the application manager function | |
| Analizada | Alta (7.8) | 0.20% | — | Ocuco Innovation | 22/5/2025 | 17/6/2026 | An issue in Ocuco Innovation Tracking.exe v.2.10.24.51 allows a local attacker to escalate privileges via the modification of TCP packets. | |
| Aplazada | Alta (8.7) | 0.46% | — | T-innova DeporsiteAI | 15/4/2025 | 17/6/2026 | Insecure Direct Object Reference vulnerability in Deporsite from T-INNOVA allows an attacker to retrieve sensitive information from others users via "idUsuario" parameter in "/helper/Familia/establecerUsuarioSeleccion" endpoint. | |
| Aplazada | Alta (8.7) | 0.46% | — | T-innova DeporsiteAI | 15/4/2025 | 17/6/2026 | Insecure Direct Object Reference vulnerability in Deporsite from T-INNOVA allows an attacker to retrieve sensitive information from others users via "idUsuario" parameter in "/helper/Familia/obtenerFamiliaUsuario" endpoint. | |
| Aplazada | Media (6.5) | 0.29% | — | Pixelgrade Nova BlocksAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pixelgrade Nova Blocks nova-blocks.This issue affects Nova Blocks: from n/a through <= 2.1.8. |