Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
1385 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 4.5% | ⚠ Explotación activa💥 PoC | Cisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence ServiceCisco Unity Connection | 21/1/2026 | 17/6/2026 | — | |
| Aplazada | Media (6.9) | 0.42% | — | Browan Communications Prismx Mx100AI | 20/1/2026 | 17/6/2026 | PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has an Insufficiently Protected Credentials vulnerability, allowing privileged remote attackers to allowing authenticated remote attackers to obtain SMTP plaintext passwords through the web frontend. | |
| Aplazada | Alta (8.6) | 0.65% | — | Browan Communications Prismx Mx100AI | 20/1/2026 | 17/6/2026 | PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | |
| Aplazada | Crítica (9.3) | 0.50% | — | Browan Communications Prismx Mx100AI | 20/1/2026 | 17/6/2026 | PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to the database using hardcoded database credentials stored in the firmware. | |
| Aplazada | Alta (7.6) | 0.33% | — | Verisay Communication AND Information Technology Industry AND Trade TrizbiAI | 25/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Communication and Information Technology Industry and Trade Ltd. Co. Trizbi allows Cross-Site Scripting (XSS). This issue affects Trizbi: before 2.144.4. | |
| Aplazada | Alta (7.6) | 0.31% | — | Verisay Communication AND Information Technology Industry AND Trade TitarusAI | 25/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Communication and Information Technology Industry and Trade Ltd. Co. Titarus allows Cross-Site Scripting (XSS). This issue affects Titarus: before 2.144.4. | |
| Aplazada | Alta (7.6) | 0.31% | — | Verisay Communication AND Information Technology Industry AND Trade LTD CO AidangoAI | 25/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Communication and Information Technology Industry and Trade Ltd. Co. Aidango allows Cross-Site Scripting (XSS). This issue affects Aidango: before 2.144.4. | |
| Analizada | Alta (8.8) | 0.32% | 💥 PoC | Eaton Xcomfort Ethernet Communication Interface | 23/12/2025 | 17/6/2026 | Improper input validation at one of the endpoints of Eaton xComfort ECI's web interface, could lead into an attacker with network access to the device executing privileged user commands. As cybersecurity standards continue to evolve and to meet our requirements today, Eaton has decided to discontinue the product. Upon… | |
| Aplazada | Alta (7.5) | 0.54% | — | SAP WEB DispatcherAISAP Internet Communication ManagerAISAP Content ServerAI | 9/12/2025 | 17/6/2026 | SAP Web Dispatcher, Internet Communication Manager (ICM), and SAP Content Server allow an unauthenticated user to exploit logical errors that lead to a memory corruption vulnerability. This results in high impact on the availability with no impact on confidentiality or integrity of the application. | |
| Aplazada | Media (6.6) | 0.34% | — | SAP Internet Communication FrameworkAI | 9/12/2025 | 17/6/2026 | The SAP Internet Communication Framework does not conduct any authentication checks for features that need user identification allowing an attacker to reuse authorization tokens, violating secure authentication practices causing low impact on Confidentiality, Integrity and Availability of the application. | |
| Analizada | Media (6.3) | 0.20% | — | Hcltech Unica | 28/11/2025 | 17/6/2026 | File upload vulnerability in HCL Technologies Ltd. Unica 12.0.0. | |
| Analizada | Alta (7.5) | 0.34% | — | Hcltech Unica | 28/11/2025 | 17/6/2026 | CSV formula injection vulnerability in HCL Technologies Ltd. Unica 12.0.0. | |
| Analizada | Media (5.4) | 0.18% | — | Hcltech Unica | 28/11/2025 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in HCL Technologies Ltd. Unica 12.0.0. | |
| Analizada | Media (5.5) | 0.10% | — | Hcltech Unica | 28/11/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in HCL Technologies Ltd. Unica 12.0.0. | |
| Aplazada | Alta (7.2) | 0.35% | — | Narkom Communication AND Software Technologies Trade LTD CO Pyxis SignageAI | 20/11/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Narkom Communication and Software Technologies Trade Ltd. Co. Pyxis Signage allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Pyxis Signage: through 31012025. | |
| Aplazada | Alta (7.2) | 0.37% | — | Narkom Communication AND Software Technologies Trade LTD CO Pyxis SignageAI | 20/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Narkom Communication and Software Technologies Trade Ltd. Co. Pyxis Signage allows Stored XSS. This issue affects Pyxis Signage: through 31012025. | |
| Aplazada | Alta (8.8) | 0.14% | — | Bizerba Communication ServerAI | 31/10/2025 | 17/6/2026 | The service Bizerba Communication Server (BCS) has an unquoted service path. Due to the way Windows searches the executable for the BCS service, malicious programs can be executed. | |
| Aplazada | Media (6.5) | 0.43% | — | Starnet Communications Corporation FastxAI | 14/10/2025 | 17/6/2026 | A path traversal in StarNet Communications Corporation FastX v.4 through v4.1.51 allows unauthenticated attackers to read arbitrary files. | |
| Analizada | Alta (7.5) | 0.24% | — | Hcltech Unica | 13/10/2025 | 17/6/2026 | HCL Unica Platform is affected by unprotected files due to improper access controls. These files may contain sensitive information such as private or system information that can be exploited by attackers to compromise the application, infrastructure, or users. | |
| Aplazada | Media (4.3) | 0.18% | — | HCL Unica CampaignAI | 13/10/2025 | 17/6/2026 | HCL Unica Campaign 12.1.10 is vulnerable to Reflected Cross-Site Scripting (XSS) where an attacker injects malicious script into an HTTP request, which is then reflected unsafely in the server's immediate response to the victim's browser, executing the script as if it originated from the trusted website. | |
| Aplazada | Baja (3.5) | 0.50% | — | HCL Unica Maxai WorkbenchAI | 13/10/2025 | 30/9/2026 | HCL Unica MaxAI Workbench is vulnerable to improper input validation. This allows attackers to exploit vulnerabilities such as SQL Injection, XSS, or command injection, leading to unauthorized access or data breaches, etc. | |
| Analizada | Media (5.3) | 0.21% | — | Hcltech Unica | 12/10/2025 | 17/6/2026 | HCL Unica Platform is impacted by misconfigured security related HTTP headers. This can lead to less secure browser default treatment for the policies controlled by these headers. | |
| Analizada | Media (4.3) | 0.14% | — | Hcltech Unica | 12/10/2025 | 17/6/2026 | HCL Unica Platform is affected by a Cookie without HTTPOnly Flag Set vulnerability. A malicious agent may be able to induce this event by feeding a user suitable links, either directly or via another web site. | |
| Analizada | Media (6.1) | 0.16% | — | Hcltech Unica | 12/10/2025 | 17/6/2026 | HCL Unica Platform is impacted by misconfigured Content Security Policy (CSP). These can result in malicious resources getting loaded and browsers may come across certain types of attacks, such as cross-site scripting and clickjacking. | |
| Aplazada | Media (4.6) | 0.17% | — | HCL Unica Maxai AssistantAI | 12/10/2025 | 17/6/2026 | HCL Unica MaxAI Assistant is susceptible to a HTML injection vulnerability. An attacker could insert special characters that are processed client-side in the context of the user's session. |