Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

1785 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.35%—Gainsight Assist20/3/202617/6/2026
An attacker can extract user email addresses (PII) exposed in base64 encoding via the state parameter in the OAuth callback URL.
AplazadaMedia (6.5)0.13%—Wpsight WpcasaAI19/3/202617/6/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPSight WPCasa allows DOM-Based XSS.This issue affects WPCasa: from n/a through 1.4.1.
AnalizadaMedia (5.4)0.66%—Microsoft Azure Hdinsight10/2/202617/6/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsights allows an authorized attacker to perform spoofing over a network.
AplazadaCrítica (9.6)0.16%—Rapid7 InsightvmAI3/2/202617/6/2026
Rapid7 InsightVM versions before 8.34.0 contain a signature verification issue on the Assertion Consumer Service (ACS) cloud endpoint that could allow an attacker to gain unauthorized access to InsightVM accounts setup via "Security Console" installations, resulting in full account takeover. The issue occurs due to…
AplazadaMedia (6)0.12%—Cisco Intersight Virtual ApplianceAI21/1/202617/6/2026
A vulnerability in the read-only maintenance shell of Cisco Intersight Virtual Appliance could allow an authenticated, local attacker with administrative privileges to elevate privileges to root on the virtual appliance. This vulnerability is due to improper file permissions on configuration files for system accounts…
AnalizadaAlta (7.8)0.93%—Nvidia Nsight Graphics14/1/202617/6/2026
NVIDIA NSIGHT Graphics for Linux contains a vulnerability where an attacker could cause command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and denial of service.
AnalizadaMedia (4.9)0.35%—Hcltech Bigfix Insights FOR Vulnerability Remediation7/1/202630/9/2026
Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged attacker to impact service availability via exposure of administrative services bound to external network interfaces instead of the local authentication interface.
AnalizadaBaja (3.3)0.09%—Hcltech Bigfix Insights FOR Vulnerability Remediation7/1/202630/9/2026
Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2 allows a local attacker to perform unauthorized configuration changes via unauthenticated administrative configuration requests.
AnalizadaMedia (4.3)0.18%—Hcltech Bigfix Insights FOR Vulnerability Remediation7/1/202630/9/2026
Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authenticated attacker to gain prolonged unauthorized access to protected API endpoints due to excessive expiration periods.
AplazadaMedia (5.1)0.24%—Netvision Information IsoinsightAI30/12/202530/9/2026
ISOinsight developed by NetVision Information has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.
ModificadaCrítica (9.8)0.47%—Crmperks WP Gravity Forms Insightly18/12/202517/6/2026
Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Insightly gf-insightly allows Object Injection.This issue affects WP Gravity Forms Insightly: from n/a through <= 1.1.6.
AplazadaMedia (6.3)0.26%—Gainsight AssistAI2/10/202517/6/2026
Use of Hard-coded Credentials, Authorization Bypass Through User-Controlled Key vulnerability in PosCube Hardware Software and Consulting Ltd. Co. Assist allows Excavation, Authentication Bypass. This issue affects Assist: through 10.02.2025.
AnalizadaAlta (7.8)0.15%—Nvidia Nsight Graphics1/10/202517/6/2026
NVIDIA Nsight Graphics for Windows contains a vulnerability in an ngfx component, where an attacker could cause a DLL highjacking attack. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, data tampering, and denial of service.
AplazadaAlta (8.7)0.26%—Keysight Ixia VisionAI30/9/202517/6/2026
Keysight Ixia Vision has an issue with hardcoded cryptographic material which may allow an attacker to intercept or decrypt payloads sent to the device via API calls or user authentication if the end user does not replace the TLS certificate that shipped with the device. Remediation is available in Version 6.9.1,…
AplazadaMedia (4.4)0.28%—Activewebsight SEO Backlink MonitorAI22/9/202517/6/2026
Server-Side Request Forgery (SSRF) vulnerability in activewebsight SEO Backlink Monitor seo-backlink-monitor allows Server Side Request Forgery.This issue affects SEO Backlink Monitor: from n/a through <= 1.8.0.
AplazadaMedia (4.3)0.17%—Activewebsight SEO Backlink MonitorAI22/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in activewebsight SEO Backlink Monitor seo-backlink-monitor allows Cross Site Request Forgery.This issue affects SEO Backlink Monitor: from n/a through <= 1.8.0.
AplazadaMedia (6.9)0.13%—Cognex In-sight ExplorerAICognex In-sight Camera FirmwareAI18/9/202517/6/2026
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 in order to allow management operations on the device such as firmware upgrades and device reboot requiring an authentication. A wrong management of login failures of the service allows a denial-of-service attack, leaving…
AplazadaAlta (8.6)0.15%—Cognex In-sight ExplorerAICognex In-sight Camera FirmwareAI18/9/202517/6/2026
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a proprietary protocol on TCP port 1069 to perform management operations such as modifying system properties. The user management functionality handles sensitive data such as registered usernames and passwords over an unencrypted channel, allowing an…
AplazadaAlta (8.6)0.20%—Cognex In-sight ExplorerAICognex In-sight Camera FirmwareAI18/9/202517/6/2026
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a proprietary protocol on TCP port 1069 to perform management operations such as modifying system properties. The user management functionality handles sensitive data such as registered usernames and passwords over an unencrypted channel, allowing an…
AplazadaAlta (7.2)0.31%—Cognex In-sight ExplorerAICognex In-sight Camera FirmwareAI18/9/202517/6/2026
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgrades and device reboots, which require authentication. A user with protected privileges can successfully invoke the SetSerialPort functionality to modify relevant device…
AplazadaAlta (8.6)0.39%—Cognex In-sight ExplorerAICognex In-sight CameraAI18/9/202517/6/2026
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a service implementing a proprietary protocol on TCP port 1069 to allow the client-side software, such as the In-Sight Explorer tool, to perform management operations such as changing network settings or modifying users' access to the device.
AplazadaAlta (7.2)0.31%—Cognex In-sight ExplorerAICognex In-sight Camera FirmwareAI18/9/202517/6/2026
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgrades and device reboots, which require authentication. A user with protected privileges can successfully invoke the SetSystemConfig functionality to modify relevant device…
AplazadaMedia (4.3)0.14%—Lisensee Netinsight Analytics Implementation PluginAI14/8/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in lisensee NetInsight Analytics Implementation Plugin netinsight-analytics-implementation-plugin allows Cross Site Request Forgery.This issue affects NetInsight Analytics Implementation Plugin: from n/a through <= 1.0.3.
AplazadaAlta (7.1)0.13%—Lisensee Netinsight Analytics Implementation PluginAI14/8/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in lisensee NetInsight Analytics Implementation Plugin netinsight-analytics-implementation-plugin allows Stored XSS.This issue affects NetInsight Analytics Implementation Plugin: from n/a through <= 1.0.3.
AplazadaMedia (5.3)0.34%—Tera Insights TicryptAI4/8/202517/6/2026
tiaudit in Tera Insights tiCrypt before 2025-07-17 allows unauthenticated REST API requests that reveal sensitive information about the underlying SQL queries and database structure.