Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

1385 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)4.5%⚠ Explotación activa💥 PoCCisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence ServiceCisco Unity Connection21/1/202617/6/2026
—
AplazadaMedia (6.9)0.42%—Browan Communications Prismx Mx100AI20/1/202617/6/2026
PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has an Insufficiently Protected Credentials vulnerability, allowing privileged remote attackers to allowing authenticated remote attackers to obtain SMTP plaintext passwords through the web frontend.
AplazadaAlta (8.6)0.65%—Browan Communications Prismx Mx100AI20/1/202617/6/2026
PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
AplazadaCrítica (9.3)0.50%—Browan Communications Prismx Mx100AI20/1/202617/6/2026
PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to the database using hardcoded database credentials stored in the firmware.
AplazadaAlta (7.6)0.33%—Verisay Communication AND Information Technology Industry AND Trade TrizbiAI25/12/20257/10/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Communication and Information Technology Industry and Trade Ltd. Co. Trizbi allows Cross-Site Scripting (XSS). This issue affects Trizbi: before 2.144.4.
AplazadaAlta (7.6)0.31%—Verisay Communication AND Information Technology Industry AND Trade TitarusAI25/12/20257/10/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Communication and Information Technology Industry and Trade Ltd. Co. Titarus allows Cross-Site Scripting (XSS). This issue affects Titarus: before 2.144.4.
AplazadaAlta (7.6)0.31%—Verisay Communication AND Information Technology Industry AND Trade LTD CO AidangoAI25/12/20257/10/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Communication and Information Technology Industry and Trade Ltd. Co. Aidango allows Cross-Site Scripting (XSS). This issue affects Aidango: before 2.144.4.
AnalizadaAlta (8.8)0.32%💥 PoCEaton Xcomfort Ethernet Communication Interface23/12/202517/6/2026
Improper input validation at one of the endpoints of Eaton xComfort ECI's web interface, could lead into an attacker with network access to the device executing privileged user commands. As cybersecurity standards continue to evolve and to meet our requirements today, Eaton has decided to discontinue the product. Upon…
AplazadaAlta (7.5)0.54%—SAP WEB DispatcherAISAP Internet Communication ManagerAISAP Content ServerAI9/12/202517/6/2026
SAP Web Dispatcher, Internet Communication Manager (ICM), and SAP Content Server allow an unauthenticated user to exploit logical errors that lead to a memory corruption vulnerability. This results in high impact on the availability with no impact on confidentiality or integrity of the application.
AplazadaMedia (6.6)0.34%—SAP Internet Communication FrameworkAI9/12/202517/6/2026
The SAP Internet Communication Framework does not conduct any authentication checks for features that need user identification allowing an attacker to reuse authorization tokens, violating secure authentication practices causing low impact on Confidentiality, Integrity and Availability of the application.
AnalizadaMedia (6.3)0.20%—Hcltech Unica28/11/202517/6/2026
File upload vulnerability in HCL Technologies Ltd. Unica 12.0.0.
AnalizadaAlta (7.5)0.34%—Hcltech Unica28/11/202517/6/2026
CSV formula injection vulnerability in HCL Technologies Ltd. Unica 12.0.0.
AnalizadaMedia (5.4)0.18%—Hcltech Unica28/11/202517/6/2026
Cross-site scripting (XSS) vulnerability in HCL Technologies Ltd. Unica 12.0.0.
AnalizadaMedia (5.5)0.10%—Hcltech Unica28/11/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in HCL Technologies Ltd. Unica 12.0.0.
AplazadaAlta (7.2)0.35%—Narkom Communication AND Software Technologies Trade LTD CO Pyxis SignageAI20/11/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Narkom Communication and Software Technologies Trade Ltd. Co. Pyxis Signage allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Pyxis Signage: through 31012025.
AplazadaAlta (7.2)0.37%—Narkom Communication AND Software Technologies Trade LTD CO Pyxis SignageAI20/11/202517/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Narkom Communication and Software Technologies Trade Ltd. Co. Pyxis Signage allows Stored XSS. This issue affects Pyxis Signage: through 31012025.
AplazadaAlta (8.8)0.14%—Bizerba Communication ServerAI31/10/202517/6/2026
The service Bizerba Communication Server (BCS) has an unquoted service path. Due to the way Windows searches the executable for the BCS service, malicious programs can be executed.
AplazadaMedia (6.5)0.43%—Starnet Communications Corporation FastxAI14/10/202517/6/2026
A path traversal in StarNet Communications Corporation FastX v.4 through v4.1.51 allows unauthenticated attackers to read arbitrary files.
AnalizadaAlta (7.5)0.24%—Hcltech Unica13/10/202517/6/2026
HCL Unica Platform is affected by unprotected files due to improper access controls. These files may contain sensitive information such as private or system information that can be exploited by attackers to compromise the application, infrastructure, or users.
AplazadaMedia (4.3)0.18%—HCL Unica CampaignAI13/10/202517/6/2026
HCL Unica Campaign 12.1.10 is vulnerable to Reflected Cross-Site Scripting (XSS) where an attacker injects malicious script into an HTTP request, which is then reflected unsafely in the server's immediate response to the victim's browser, executing the script as if it originated from the trusted website.
AplazadaBaja (3.5)0.50%—HCL Unica Maxai WorkbenchAI13/10/202530/9/2026
HCL Unica MaxAI Workbench is vulnerable to improper input validation. This allows attackers to exploit vulnerabilities such as SQL Injection, XSS, or command injection, leading to unauthorized access or data breaches, etc.
AnalizadaMedia (5.3)0.21%—Hcltech Unica12/10/202517/6/2026
HCL Unica Platform is impacted by misconfigured security related HTTP headers. This can lead to less secure browser default treatment for the policies controlled by these headers.
AnalizadaMedia (4.3)0.14%—Hcltech Unica12/10/202517/6/2026
HCL Unica Platform is affected by a Cookie without HTTPOnly Flag Set vulnerability. A malicious agent may be able to induce this event by feeding a user suitable links, either directly or via another web site.
AnalizadaMedia (6.1)0.16%—Hcltech Unica12/10/202517/6/2026
HCL Unica Platform is impacted by misconfigured Content Security Policy (CSP). These can result in malicious resources getting loaded and browsers may come across certain types of attacks, such as cross-site scripting and clickjacking.
AplazadaMedia (4.6)0.17%—HCL Unica Maxai AssistantAI12/10/202517/6/2026
HCL Unica MaxAI Assistant is susceptible to a HTML injection vulnerability. An attacker could insert special characters that are processed client-side in the context of the user's session.