Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

237 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.44%—Salesforce OmnistudioAI10/6/202517/6/2026
Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of Custom Settings data. This impacts OmniStudio: before version 254.
AplazadaAlta (7.5)0.43%—Salesforce OmnistudioAI10/6/202517/6/2026
Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of encrypted data. This impacts OmniStudio: before Spring 2025.
AplazadaMedia (5.3)0.42%—Salesforce OmnistudioAI10/6/202517/6/2026
Client-Side Enforcement of Server-Side Security vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of required permission check. This impacts OmniStudio: before Spring 2025
AplazadaCrítica (9.1)0.49%—Salesforce OmnistudioAI10/6/202517/6/2026
Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of field level security controls for Salesforce objects. This impacts OmniStudio: before Spring 2025
AplazadaAlta (7.5)0.44%—Salesforce OmnistudioAI10/6/202517/6/2026
Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (DataMapper) allows exposure of encrypted data. This impacts OmniStudio: before Spring 2025
AplazadaMedia (4.8)0.20%—Vita-mllm Freeze-omniAIPytorch TorchAI15/5/202517/6/2026
A vulnerability, which was classified as problematic, has been found in VITA-MLLM Freeze-Omni up to 20250421. This issue affects the function torch.load of the file models/utils.py. The manipulation of the argument path leads to deserialization. It is possible to launch the attack on the local host.
AplazadaCrítica (9.3)1.1%—Kong InsomniaAI9/5/202517/6/2026
Kong Insomnia Desktop Application before 11.0.2 contains a template injection vulnerability that allows attackers to execute arbitrary code. The vulnerability exists due to insufficient validation of user-supplied input when processing template strings, which can lead to arbitrary JavaScript execution in the context…
AnalizadaAlta (7.5)0.29%—Omnissa Unified Access Gateway17/4/202517/6/2026
Omnissa UAG contains a Cross-Origin Resource Sharing (CORS) bypass vulnerability. A malicious actor with network access to UAG may be able to bypass administrator-configured CORS restrictions to gain access to sensitive networks.
AplazadaAlta (7.8)0.15%—Omnissa Horizon Client FOR WindowsAI16/4/202517/6/2026
Omnissa Horizon Client for Windows contains an LPE Vulnerability. A malicious actor with local access where Horizon Client for Windows is installed may be able to elevate privileges.
AplazadaAlta (7.1)0.13%—Omnileads-scripts-and-tags-managerAI28/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in danielmuldernl OmniLeads Scripts and Tags Manager omnileads-scripts-and-tags-manager allows Stored XSS.This issue affects OmniLeads Scripts and Tags Manager: from n/a through <= 1.3.
AplazadaAlta (7.1)0.31%—Omnify INC Omnify WidgetAI26/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Omnify, Inc. Omnify omnify-widget allows Reflected XSS.This issue affects Omnify: from n/a through <= 2.0.3.
AnalizadaMedia (6.5)0.27%—Omnipressteam Omnipress14/3/202517/6/2026
The Omnipress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.5.4 via the megamenu block due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from…
ModificadaAlta (7.7)1.5%—Omniauth SamlOnelogin Ruby-saml12/3/202517/6/2026
ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of Service (DoS) with compressed SAML responses. ruby-saml uses zlib to decompress SAML responses in case they're compressed. It is possible to…
ModificadaCrítica (9.3)65%—Omniauth SamlOnelogin Ruby-samlNetapp Storagegrid12/3/202517/6/2026
ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differently, the parsers can generate entirely different document…
ModificadaCrítica (9.3)21%—Omniauth SamlOnelogin Ruby-samlNetapp Storagegrid12/3/202517/6/2026
ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differently; the parsers can generate entirely different document…
AplazadaAlta (7.3)0.21%—Kong InsomniaAI16/2/202517/6/2026
A vulnerability was found in Kong Insomnia up to 10.3.0 and classified as critical. This issue affects some unknown processing in the library profapi.dll. The manipulation leads to untrusted search path. An attack has to be approached locally. The complexity of an attack is rather high. The exploitation is known to be…
AplazadaAlta (7.5)0.35%—Newgensoft OmnidocsAI6/2/202517/6/2026
In Newgensoft OmniDocs 11.0_SP1_03_006, Insecure Direct Object Reference (IDOR) in the getuserproperty function allows user's configuration and PII to be stolen.
AplazadaAlta (7.8)0.17%—Omnissa Horizon Client MacosAI4/2/202517/6/2026
Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a flaw in the installation process. Successful exploitation of this issue may allow attackers with user privileges to escalate their privileges to root on the system where the Horizon Client for macOS is installed.
AplazadaAlta (7.8)0.19%💥 PoCOmnissa Horizon Client FOR MacosAI4/2/202517/6/2026
Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a logic flaw. Successful exploitation of this issue may allow attackers with user privileges to escalate their privileges to root on the system where the Horizon Client for macOS is installed.
AnalizadaCrítica (9.5)0.35%—Ecovacs Deebot X2 Omni FirmwareEcovacs Deebot X2 Combo FirmwareEcovacs Deebot X2S FirmwareEcovacs Deebot X5 PRO Firmware+1623/1/202517/6/2026
ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modifying firmware updates.
AnalizadaMedia (5.8)3.0%—Ecovacs Goat G1-2000 FirmwareEcovacs Goat G1 FirmwareEcovacs Goat G1-800 FirmwareEcovacs Gx-600 Firmware+823/1/202517/6/2026
ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.
AplazadaAlta (7.4)0.52%—Ecovacs Robotics Deebot T20 OmniAIEcovacs Robotics Deebot T20e OmniAI14/1/20255/7/2026
ECOVACS Robotics Deebot T20 OMNI and T20e OMNI before 1.24.0 was discovered to contain a WiFi Remote Code Execution vulnerability.
AplazadaMedia (5.4)0.31%—WC Price History FOR OmnibusAI24/12/202417/6/2026
The WC Price History for Omnibus plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX actions in all versions up to, and including, 2.1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view and modify history data.
AplazadaAlta (7.1)0.29%—Omnipressteam OmnipressAI17/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in omnipressteam Omnipress omnipress allows Stored XSS.This issue affects Omnipress: from n/a through <= 1.4.3.
ModificadaCrítica (9.8)11%💥 PoCOnelogin Ruby-samlOmniauth SamlGitlab10/9/202417/6/2026
The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Response. An unauthenticated attacker with access to any signed saml document (by the IdP) can thus forge a SAML Response/Assertion with…
Orbitaley — Vulnerabilidades