Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1785 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.35% | — | Gainsight Assist | 20/3/2026 | 17/6/2026 | An attacker can extract user email addresses (PII) exposed in base64 encoding via the state parameter in the OAuth callback URL. | |
| Aplazada | Media (6.5) | 0.13% | — | Wpsight WpcasaAI | 19/3/2026 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPSight WPCasa allows DOM-Based XSS.This issue affects WPCasa: from n/a through 1.4.1. | |
| Analizada | Media (5.4) | 0.66% | — | Microsoft Azure Hdinsight | 10/2/2026 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsights allows an authorized attacker to perform spoofing over a network. | |
| Aplazada | Crítica (9.6) | 0.16% | — | Rapid7 InsightvmAI | 3/2/2026 | 17/6/2026 | Rapid7 InsightVM versions before 8.34.0 contain a signature verification issue on the Assertion Consumer Service (ACS) cloud endpoint that could allow an attacker to gain unauthorized access to InsightVM accounts setup via "Security Console" installations, resulting in full account takeover. The issue occurs due to… | |
| Aplazada | Media (6) | 0.12% | — | Cisco Intersight Virtual ApplianceAI | 21/1/2026 | 17/6/2026 | A vulnerability in the read-only maintenance shell of Cisco Intersight Virtual Appliance could allow an authenticated, local attacker with administrative privileges to elevate privileges to root on the virtual appliance. This vulnerability is due to improper file permissions on configuration files for system accounts… | |
| Analizada | Alta (7.8) | 0.93% | — | Nvidia Nsight Graphics | 14/1/2026 | 17/6/2026 | NVIDIA NSIGHT Graphics for Linux contains a vulnerability where an attacker could cause command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and denial of service. | |
| Analizada | Media (4.9) | 0.35% | — | Hcltech Bigfix Insights FOR Vulnerability Remediation | 7/1/2026 | 30/9/2026 | Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged attacker to impact service availability via exposure of administrative services bound to external network interfaces instead of the local authentication interface. | |
| Analizada | Baja (3.3) | 0.09% | — | Hcltech Bigfix Insights FOR Vulnerability Remediation | 7/1/2026 | 30/9/2026 | Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2 allows a local attacker to perform unauthorized configuration changes via unauthenticated administrative configuration requests. | |
| Analizada | Media (4.3) | 0.18% | — | Hcltech Bigfix Insights FOR Vulnerability Remediation | 7/1/2026 | 30/9/2026 | Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authenticated attacker to gain prolonged unauthorized access to protected API endpoints due to excessive expiration periods. | |
| Aplazada | Media (5.1) | 0.24% | — | Netvision Information IsoinsightAI | 30/12/2025 | 30/9/2026 | ISOinsight developed by NetVision Information has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks. | |
| Modificada | Crítica (9.8) | 0.47% | — | Crmperks WP Gravity Forms Insightly | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Insightly gf-insightly allows Object Injection.This issue affects WP Gravity Forms Insightly: from n/a through <= 1.1.6. | |
| Aplazada | Media (6.3) | 0.26% | — | Gainsight AssistAI | 2/10/2025 | 17/6/2026 | Use of Hard-coded Credentials, Authorization Bypass Through User-Controlled Key vulnerability in PosCube Hardware Software and Consulting Ltd. Co. Assist allows Excavation, Authentication Bypass. This issue affects Assist: through 10.02.2025. | |
| Analizada | Alta (7.8) | 0.15% | — | Nvidia Nsight Graphics | 1/10/2025 | 17/6/2026 | NVIDIA Nsight Graphics for Windows contains a vulnerability in an ngfx component, where an attacker could cause a DLL highjacking attack. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, data tampering, and denial of service. | |
| Aplazada | Alta (8.7) | 0.26% | — | Keysight Ixia VisionAI | 30/9/2025 | 17/6/2026 | Keysight Ixia Vision has an issue with hardcoded cryptographic material which may allow an attacker to intercept or decrypt payloads sent to the device via API calls or user authentication if the end user does not replace the TLS certificate that shipped with the device. Remediation is available in Version 6.9.1,… | |
| Aplazada | Media (4.4) | 0.28% | — | Activewebsight SEO Backlink MonitorAI | 22/9/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in activewebsight SEO Backlink Monitor seo-backlink-monitor allows Server Side Request Forgery.This issue affects SEO Backlink Monitor: from n/a through <= 1.8.0. | |
| Aplazada | Media (4.3) | 0.17% | — | Activewebsight SEO Backlink MonitorAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in activewebsight SEO Backlink Monitor seo-backlink-monitor allows Cross Site Request Forgery.This issue affects SEO Backlink Monitor: from n/a through <= 1.8.0. | |
| Aplazada | Media (6.9) | 0.13% | — | Cognex In-sight ExplorerAICognex In-sight Camera FirmwareAI | 18/9/2025 | 17/6/2026 | Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 in order to allow management operations on the device such as firmware upgrades and device reboot requiring an authentication. A wrong management of login failures of the service allows a denial-of-service attack, leaving… | |
| Aplazada | Alta (8.6) | 0.15% | — | Cognex In-sight ExplorerAICognex In-sight Camera FirmwareAI | 18/9/2025 | 17/6/2026 | Cognex In-Sight Explorer and In-Sight Camera Firmware expose a proprietary protocol on TCP port 1069 to perform management operations such as modifying system properties. The user management functionality handles sensitive data such as registered usernames and passwords over an unencrypted channel, allowing an… | |
| Aplazada | Alta (8.6) | 0.20% | — | Cognex In-sight ExplorerAICognex In-sight Camera FirmwareAI | 18/9/2025 | 17/6/2026 | Cognex In-Sight Explorer and In-Sight Camera Firmware expose a proprietary protocol on TCP port 1069 to perform management operations such as modifying system properties. The user management functionality handles sensitive data such as registered usernames and passwords over an unencrypted channel, allowing an… | |
| Aplazada | Alta (7.2) | 0.31% | — | Cognex In-sight ExplorerAICognex In-sight Camera FirmwareAI | 18/9/2025 | 17/6/2026 | Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgrades and device reboots, which require authentication. A user with protected privileges can successfully invoke the SetSerialPort functionality to modify relevant device… | |
| Aplazada | Alta (8.6) | 0.39% | — | Cognex In-sight ExplorerAICognex In-sight CameraAI | 18/9/2025 | 17/6/2026 | Cognex In-Sight Explorer and In-Sight Camera Firmware expose a service implementing a proprietary protocol on TCP port 1069 to allow the client-side software, such as the In-Sight Explorer tool, to perform management operations such as changing network settings or modifying users' access to the device. | |
| Aplazada | Alta (7.2) | 0.31% | — | Cognex In-sight ExplorerAICognex In-sight Camera FirmwareAI | 18/9/2025 | 17/6/2026 | Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgrades and device reboots, which require authentication. A user with protected privileges can successfully invoke the SetSystemConfig functionality to modify relevant device… | |
| Aplazada | Media (4.3) | 0.14% | — | Lisensee Netinsight Analytics Implementation PluginAI | 14/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in lisensee NetInsight Analytics Implementation Plugin netinsight-analytics-implementation-plugin allows Cross Site Request Forgery.This issue affects NetInsight Analytics Implementation Plugin: from n/a through <= 1.0.3. | |
| Aplazada | Alta (7.1) | 0.13% | — | Lisensee Netinsight Analytics Implementation PluginAI | 14/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in lisensee NetInsight Analytics Implementation Plugin netinsight-analytics-implementation-plugin allows Stored XSS.This issue affects NetInsight Analytics Implementation Plugin: from n/a through <= 1.0.3. | |
| Aplazada | Media (5.3) | 0.34% | — | Tera Insights TicryptAI | 4/8/2025 | 17/6/2026 | tiaudit in Tera Insights tiCrypt before 2025-07-17 allows unauthenticated REST API requests that reveal sensitive information about the underlying SQL queries and database structure. |