Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2598▼ 321 respecto a la semana anterior
Críticas / altas1342▲ 74 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
1620 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.68% | — | Aelsantex Runcommand | 30/1/2026 | 17/6/2026 | aelsantex runcommand 2014-04-01, a plugin for DokuWiki, allows unauthenticated attackers to execute arbitrary system commands via lib/plugins/runcommand/postaction.php. | |
| Aplazada | Alta (7.5) | 0.30% | — | Gerstrong Commander GeniusAI | 27/1/2026 | 17/6/2026 | Out-of-bounds Write vulnerability in gerstrong Commander-Genius.This issue affects Commander-Genius: before Release refs/pull/358/merge. | |
| Aplazada | Media (5.1) | 0.43% | — | SnippcommandAI | 16/1/2026 | 17/6/2026 | SnipCommand 0.1.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious payloads into command snippets. Attackers can execute arbitrary code by embedding malicious JavaScript that triggers remote command execution through file or title inputs. | |
| Analizada | Alta (8.7) | 4.1% | — | Kyocera Command Center RX | 13/1/2026 | 17/6/2026 | Kyocera Command Center RX ECOSYS M2035dn contains a directory traversal vulnerability that allows unauthenticated attackers to read sensitive system files by manipulating file paths under the /js/ path. Attackers can exploit the issue by sending requests like /js/../../../../.../etc/passwd%00.jpg (null-byte appended… | |
| Modificada | Alta (8.3) | 0.47% | — | Fntsoftware FNT Command | 15/12/2025 | 5/7/2026 | FNT Command 13.4.0 is vulnerable to Directory Traversal. | |
| Modificada | Alta (8.8) | 0.39% | — | Fntsoftware FNT Command | 15/12/2025 | 5/7/2026 | FNT Command 13.4.0 is vulnerable to Code Execution via the C Base Module. | |
| Aplazada | Media (6.5) | 0.25% | — | MediacommanderAI | 13/12/2025 | 17/6/2026 | The MediaCommander – Bring Folders to Media, Posts, and Pages plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the import-csv REST API endpoint in all versions up to, and including, 2.3.1. This is due to the endpoint using `upload_files` capability check (Author… | |
| Analizada | Alta (7.5) | 0.70% | — | Onecommander | 19/11/2025 | 17/6/2026 | Milos Paripovic OneCommander 3.102.0.0 is vulnerable to Directory Traversal. The vulnerability resides in the ZIP file processing component, specifically in the functionality responsible for extracting and handling ZIP archive contents. | |
| Aplazada | Baja (2.4) | 0.16% | — | Johnsoncontrols Command Centre ServerAIJohnsoncontrols T21 ReaderAI | 18/11/2025 | 17/6/2026 | Missing Release of Resource after Effective Lifetime (CWE-772) in the T21 Reader allows an attacker with physical access to the Reader to perform a denial-of-service attack against that specific reader, preventing cardholders from badging for entry. This issue affects Command Centre Server: 9.30 prior to… | |
| Aplazada | Media (5.7) | 0.15% | — | Tyco Command Centre ServerAIELM Development Group ELMAI | 18/11/2025 | 17/6/2026 | Incorrect Usage of Seeds in Pseudo-Random Number Generator (CWE- 335) vulnerability in the High Sec ELM may allow a sophisticated attacker with physical access, to compromise internal device communications. This issue affects Command Centre Server: 9.30 prior to vCR9.30.251028a (distributed in 9.30.2881 (MR3)), 9.20… | |
| Aplazada | Media (5.7) | 0.15% | — | Honeywell Command Centre ServerAI | 18/11/2025 | 17/6/2026 | Observable Timing Discrepancy (CWE-208) in HBUS devices may allow an attacker with physical access to the device to extract device-specific keys, potentially compromising further site security. This issue affects Command Centre Server: 9.30 prior to vCR9.30.251028a (distributed in 9.30.2881 (MR3)), 9.20 prior to… | |
| Analizada | Media (5.5) | 0.11% | — | Dell Alienware Command Center | 13/11/2025 | 17/6/2026 | Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain a Process Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure. | |
| Analizada | Alta (7.8) | 0.12% | — | Dell Alienware Command Center | 13/11/2025 | 17/6/2026 | Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contains an Insecure Temporary File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation. | |
| Analizada | Media (5.5) | 0.11% | — | Dell Alienware Command Center | 13/11/2025 | 17/6/2026 | Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contains an Insecure Temporary File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering. | |
| Analizada | Alta (7.8) | 0.14% | — | Dell Alienware Command Center | 13/11/2025 | 17/6/2026 | Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain a Detection of Error Condition Without Action vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary Code Execution. | |
| Analizada | Media (5.5) | 0.10% | — | Dell Alienware Command Center | 13/11/2025 | 17/6/2026 | Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Tampering. | |
| Aplazada | Crítica (9.8) | 0.41% | — | Holest Engineering Selling Commander FOR WoocommerceAI | 6/11/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Holest Engineering Selling Commander for WooCommerce selling-commander-connector allows Privilege Escalation.This issue affects Selling Commander for WooCommerce: from n/a through <= 1.2.46. | |
| Analizada | Alta (7.8) | 0.14% | — | Dell Command Monitor | 5/11/2025 | 17/6/2026 | Dell Command Monitor (DCM), versions prior to 10.12.3.28, contains an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Aplazada | Media (5.5) | 0.13% | — | Command Centre ServerAI | 23/10/2025 | 17/6/2026 | Uncaught Exception (CWE-248) in the Command Centre Server allows an Authorized and Privileged Operator to crash the Command Centre Server at will. This issue affects Command Centre Server: 9.30 prior to vEL9.30.2482 (MR2), 9.20 prior to vEL9.20.2819 (MR4), 9.10 prior to vEL9.10.3672 (MR7), 9.00 prior to vEL9.00.3831… | |
| Aplazada | Media (6.7) | 0.10% | — | Gallagher Command Centre ServerAI | 23/10/2025 | 17/6/2026 | Cleartext Storage of Sensitive Information (CWE-312) in the Gallagher Morpho integration could allow an authenticated user with access to the Command Centre Server to export a specific signing key while in use allowing them to deploy a compromised or counterfeit device on that site. This issue affects Command Centre… | |
| Aplazada | Crítica (9.9) | 0.34% | — | Gallagher Command Centre ServerAIGallagher MorphoAI | 23/10/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) in the Gallagher Morpho integration could allow an authenticated operator with limited site permissions to make critical changes to local Morpho devices. This issue affects Command Centre Server: 9.30 prior to vEL9.30.2482 (MR2), 9.20… | |
| Aplazada | Media (5.5) | 0.14% | — | Command Centre ServerAI | 23/10/2025 | 17/6/2026 | Client-Side Enforcement of Server-Side Security (CWE-602) in the Command Centre Server allows a privileged operator to enter invalid competency data, bypassing expiry checks. This issue affects Command Centre Server: 9.30 prior to vEL9.30.2482 (MR2), 9.20 prior to vEL9.20.2819 (MR4), 9.10 prior to vEL9.10.3672 (MR7),… | |
| Aplazada | Media (5.5) | 0.13% | — | Command Centre ServerAI | 23/10/2025 | 17/6/2026 | Exposure of Private Personal Information to an Unauthorized Actor (CWE-359) in the Command Centre Server allows a privileged Operator to view limited personal data about a Cardholder they would not normally have permissions to view. This issue affects Command Centre Server: 9.30.1874 (MR1), 9.20.2337 (MR3), 9.10.3194… | |
| Aplazada | Media (6.1) | 0.16% | — | CommandkitAI | 15/10/2025 | 17/6/2026 | CommandKit is the discord.js meta-framework for building Discord bots. In versions 1.2.0-rc.1 through 1.2.0-rc.11, a logic flaw exists in the message command handler that affects how the commandName property is exposed to both middleware functions and command execution contexts when handling command aliases. When a… | |
| Analizada | Baja (2.1) | 4.3% | — | Wonderwhy-er Desktopcommandermcp | 8/10/2025 | 17/6/2026 | A vulnerability was found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The impacted element is the function CommandManager of the file src/command-manager.ts. Performing manipulation results in os command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. |