Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
307 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 0.57% | — | Blixhq Bluemail | 16/12/2025 | 5/7/2026 | When using the attachment interaction functionality, Blue Mail 1.140.103 and below saves documents to a file system without a Mark-of-the-Web tag, which allows attackers to bypass the built-in file protection mechanisms of both Windows OS and third-party software. | |
| Aplazada | Media (6.5) | 0.33% | — | Sovlix MeetinghubAI | 6/11/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Sovlix MeetingHub meetinghub allows Retrieve Embedded Sensitive Data.This issue affects MeetingHub: from n/a through <= 1.23.9. | |
| Aplazada | Alta (8.1) | 0.52% | — | Creatives Planet LeblixAI | 6/11/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Creatives_Planet Leblix leblix allows PHP Local File Inclusion.This issue affects Leblix: from n/a through <= 2.4. | |
| Aplazada | Media (4.3) | 0.20% | — | Sovlix MeetinghubAI | 22/10/2025 | 17/6/2026 | Missing Authorization vulnerability in Sovlix MeetingHub meetinghub.This issue affects MeetingHub: from n/a through <= 1.23.9. | |
| Aplazada | Alta (8.2) | 0.43% | — | Felixriddle Dev-jobs-handlebarsAI | 16/10/2025 | 17/6/2026 | FelixRiddle dev-jobs-handlebars 1.0 uses absolute password-reset (magic) links using the untrusted `req.headers.host` header and forces the `http://` scheme. An attacker who can control the `Host` header (or exploit a misconfigured proxy/load-balancer that forwards the header unchanged) can cause reset links to point… | |
| Rechazada | Sin puntuar | — | — | Apache FelixAI | 3/10/2025 | 3/10/2025 | Rejected reason: Further research determined the issue is not an independent vulnerability as it originates from Apache Felix. | |
| Aplazada | Media (4.4) | 0.10% | — | Wallix BastionAI | 17/9/2025 | 17/6/2026 | The Bastion provides authentication, authorization, traceability and auditability for SSH accesses. Session-recording ttyrec files, may be handled by the provided osh-encrypt-rsync script that is a helper to rotate, encrypt, sign, copy, and optionally move them to a remote storage periodically, if configured to. When… | |
| Aplazada | Alta (8.5) | 0.80% | — | Calix Gigacenter ONTAI | 9/9/2025 | 17/6/2026 | OS Command ('OS Command Injection') vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows authenticated attackers with 'super' user credentials to execute arbitrary OS commands through improper input validation, potentially leading to full system compromise.This issue affects GigaCenter ONT: 844E, 844G,… | |
| Aplazada | Media (5.1) | 0.21% | — | Quantenna SOCAICalix Gigacenter ONTAI | 9/9/2025 | 17/6/2026 | Insecure Storage of Sensitive Information vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows admin access to the web interface.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE. | |
| Analizada | Alta (8.7) | 0.35% | — | Calix Gigacenter ONT | 9/9/2025 | 17/6/2026 | Unauthenticated Telnet access vulnerability in Calix GigaCenter ONT allows root access.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE. | |
| Aplazada | Alta (7) | 0.21% | — | Quantenna SOCAICalix Gigacenter ONTAI | 9/9/2025 | 17/6/2026 | Excessive Privileges vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows Privilege Abuse.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE, 812G, 813G, 818G. | |
| Aplazada | Alta (7) | 0.23% | — | Broadcom SOCAICalix Gigacenter ONTAI | 9/9/2025 | 30/9/2026 | Excessive Privileges vulnerability in Calix GigaCenter ONT (Broadcom SoC modules) allows Privilege Abuse.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE, 812G, 813G, 818G. | |
| Aplazada | Crítica (9.8) | 0.71% | — | Netflix ConductorAI | 30/6/2025 | 17/6/2026 | Orkes Conductor v3.21.11 allows remote attackers to execute arbitrary OS commands through unrestricted access to Java classes. | |
| Aplazada | Media (5.6) | 0.14% | — | NIXAILIXAIGNU GuixAI | 27/6/2025 | 17/6/2026 | A race condition in the Nix, Lix, and Guix package managers enables changing the ownership of arbitrary files to the UID and GID of the build user (e.g., nixbld* or guixbuild*). This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b. | |
| Aplazada | Baja (3.2) | 0.17% | — | Nixos NIXAILIXAIGNU GuixAI | 27/6/2025 | 17/6/2026 | The Nix, Lix, and Guix package managers fail to properly set permissions when a derivation build fails. This may allow arbitrary processes to modify the content of a store outside of the build sandbox. This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before… | |
| Aplazada | Baja (3.2) | 0.17% | — | Nixos NIXAILIXAIGNU GuixAI | 27/6/2025 | 17/6/2026 | The Nix, Lix, and Guix package managers default to using temporary build directories in a world-readable and world-writable location. This allows standard users to deceive the package manager into using directories with pre-existing content, potentially leading to unauthorized actions or data manipulation. This… | |
| Aplazada | Baja (2.9) | 0.18% | — | NIXAILIXAIGNU GuixAI | 27/6/2025 | 17/6/2026 | The Nix, Lix, and Guix package managers allow a bypass of build isolation in which a user can elevate their privileges to the build user account (e.g., nixbld or guixbuild). This affects Nix through 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix through 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b. | |
| Aplazada | Baja (3.2) | 0.14% | — | NIXAILIXAIGNU GuixAI | 27/6/2025 | 17/6/2026 | A race condition in the Nix, Lix, and Guix package managers allows the removal of content from arbitrary folders. This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b. | |
| Analizada | Ninguna (0) | 0.14% | — | Trellix System Information Reporter | 26/6/2025 | 17/6/2026 | A sensitive information exposure vulnerability in System Information Reporter (SIR) 1.0.3 and prior allows an authenticated non-admin local user to extract sensitive information stored in a registry backup folder. | |
| Analizada | Alta (7.2) | 0.16% | — | Trellix System Information Reporter | 26/6/2025 | 17/6/2026 | A path or symbolic link manipulation vulnerability in SIR 1.0.3 and prior versions allows an authenticated non-admin local user to overwrite system files with SIR backup files, which can potentially cause a system crash. This was achieved by adding a malicious entry to the registry under the Trellix SIR registry… | |
| Analizada | Ninguna (0) | 0.18% | — | Trellix System Information Reporter | 26/6/2025 | 17/6/2026 | A path traversal vulnerability in System Information Reporter (SIR) 1.0.3 and prior allowed an authenticated high privileged user to issue malicious ePO post requests to System Information Reporter, leading to creation of files anywhere on the filesystem and possibly overwriting existing files and exposing sensitive… | |
| Aplazada | Alta (7.5) | 0.48% | — | SysmonelixirAI | 24/6/2025 | 17/6/2026 | SysmonElixir is a system monitor HTTP service in Elixir. Prior to version 1.0.1, the /read endpoint reads any file from the server's /etc/passwd by default. In v1.0.1, a whitelist was added that limits reading to only files under priv/data. This issue has been patched in version 1.0.1. | |
| Aplazada | Alta (7.1) | 0.13% | — | Devfelixmoira Knowledge Base MakerAI | 20/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in devfelixmoira Knowledge Base – Knowledge Base Maker knowledge-base-maker allows Stored XSS.This issue affects Knowledge Base – Knowledge Base Maker: from n/a through <= 1.1.8. | |
| Aplazada | Media (5.9) | 0.26% | — | Felix Martinez Recipes Manager - WPHAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Félix Martínez Recipes manager - WPH allows Stored XSS. This issue affects Recipes manager - WPH: from n/a through 1.0.4. | |
| Analizada | Media (5.3) | 0.47% | — | Kirisun Fujian Kelixun | 23/5/2025 | 17/6/2026 | A vulnerability was found in Fujian Kelixun 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /app/xml_cdr/xml_cdr_details.php. The manipulation of the argument uuid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and… |