Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

237 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.7)0.77%—Siemens Omnivise T3000 Application Server2/8/202417/6/2026
A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), Omnivise T3000 R8.2 SP4 (All versions). The affected system exposes the port of an internal application on the public network interface allowing an attacker to circumvent authentication…
ModificadaMedia (6.9)11%—Siemens Omnivise T3000 Application Server2/8/202417/6/2026
A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), Omnivise T3000 R8.2 SP4 (All versions). Affected devices allow authenticated users to export diagnostics data. The corresponding API endpoint is susceptible to path traversal and could…
ModificadaAlta (8.3)0.19%—Siemens Omnivise T3000 Application ServerSiemens Omnivise T3000 Domain ControllerSiemens Omnivise T3000 Network Intrusion Detection SystemSiemens Omnivise T3000 Product Data Management+32/8/202417/6/2026
A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Controller R9.2 (All versions), Omnivise T3000 Network Intrusion Detection System (NIDS) R9.2 (All versions), Omnivise T3000 Product Data Management (PDM) R9.2 (All versions), Omnivise T3000 R8.2 SP3…
ModificadaAlta (8.5)0.24%—Siemens Omnivise T3000 Application ServerSiemens Omnivise T3000 Domain ControllerSiemens Omnivise T3000 Product Data ManagementSiemens Omnivise T3000 Terminal Server+22/8/202417/6/2026
A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Controller R9.2 (All versions), Omnivise T3000 Product Data Management (PDM) R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), Omnivise T3000 R8.2 SP4 (All versions), Omnivise T3000 Terminal…
ModificadaMedia (5.3)0.80%—Moderncampus Omni CMS13/6/202417/6/2026
A Directory Traversal vulnerability in Modern Campus - Omni CMS 2023.1 allows a remote, unauthenticated attacker to enumerate file system information via the dir parameter to listing.php or rss.php.
ModificadaMedia (6.1)0.30%—Moderncampus Omni CMS13/6/202417/6/2026
A Reflected Cross-Site Scripting (XSS) vulnerability in the blog function of Modern Campus - Omni CMS 2023.1 allows a remote attacker to inject arbitrary scripts or HTML via multiple parameters.
AnalizadaMedia (5.3)0.50%—Moderncampus Omni CMS13/6/202417/6/2026
XPath Injection vulnerabilities in the blog and RSS functions of Modern Campus - Omni CMS 2023.1 allow a remote, unauthenticated attacker to obtain application information.
AplazadaMedia (4.3)0.21%—Omnisend Email Marketing FOR WoocommerceAI15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Omnisend Email Marketing for WooCommerce by Omnisend omnisend-connect.This issue affects Email Marketing for WooCommerce by Omnisend: from n/a through <= 1.14.3.
ModificadaMedia (5.3)0.25%—Hidglobal Omnikey Secure Elements Reader Configuration Cards FirmwareHidglobal Iclass SE Reader Configuration Cards Firmware7/2/202417/6/2026
Sensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device administrator keys.
ModificadaAlta (7.8)0.17%—Hidglobal Iclass SE Cp1000 Encoder FirmwareHidglobal Iclass SE Readers FirmwareHidglobal Iclass SE Reader Modules FirmwareHidglobal Iclass SE Processors Firmware+46/2/202417/6/2026
Certain configuration available in the communication channel for encoders could expose sensitive data when reader configuration cards are programmed. This data could include credential and device administration keys.
ModificadaCrítica (9.8)0.90%—Recognizeapp Omniauth\2/1/202417/6/2026
omniauth-microsoft_graph provides an Omniauth strategy for the Microsoft Graph API. Prior to versions 2.0.0, the implementation did not validate the legitimacy of the `email` attribute of the user nor did it give/document an option to do so, making it susceptible to nOAuth misconfiguration in cases when the `email` is…
ModificadaAlta (7.5)0.55%—Omnisend Email Marketing FOR Woocommerce23/11/202317/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Omnisend Email Marketing for WooCommerce by Omnisend.This issue affects Email Marketing for WooCommerce by Omnisend: from n/a through 1.13.8.
ModificadaAlta (7.8)0.43%—Konghq Insomnia4/10/202317/6/2026
Kong Insomnia 2023.4.0 on macOS allows attackers to execute code and access restricted files, or make requests for TCC permissions, by using the DYLD_INSERT_LIBRARIES environment variable.
ModificadaMedia (5.3)0.36%—Nvidia Omniverse Launcher3/8/202317/6/2026
NVIDIA Omniverse Workstation Launcher for Windows and Linux contains a vulnerability in the authentication flow, where a user’s access token is displayed in the browser user's address bar. An attacker could use this token to impersonate the user to access launcher resources. A successful exploit of this vulnerability…
ModificadaMedia (5.3)1.2%—Omnis Studio20/7/202317/6/2026
Omnis Studio 10.22.00 has incorrect access control. It advertises a feature for making Omnis libraries "always private" - this is supposed to be an irreversible operation. However, due to implementation issues, "always private" Omnis libraries can be opened by the Omnis Studio browser by bypassing specific checks.…
ModificadaMedia (6.5)0.88%—Omnis Studio20/7/202317/6/2026
Omnis Studio 10.22.00 has incorrect access control. It advertises an irreversible feature for locking classes within Omnis libraries: it should be no longer possible to delete, view, change, copy, rename, duplicate, or print a locked class. Due to implementation issues, locked classes in Omnis libraries can be…
ModificadaCrítica (9.8)1.0%—Kerawen Omnichannel Stocks7/7/202317/6/2026
SQL injection vulnerability found in PrestaShop lekerawen_ocs before v.1.4.1 allow a remote attacker to gain privileges via the KerawenHelper::setCartOperationInfo, and KerawenHelper::resetCheckoutSessionData components.
ModificadaMedia (5.5)0.33%—Omninotes Omni Notes27/5/202317/6/2026
Omni-notes is an open source note-taking application for Android. The Omni-notes Android app had an insufficient path validation vulnerability when displaying the details of a note received through an externally-provided intent. The paths of the note's attachments were not properly validated, allowing malicious or…
ModificadaAlta (7.8)0.57%—Nvidia Isaac SIMNvidia Omniverse Audio2faceNvidia Omniverse CodeNvidia Omniverse Create+213/1/202317/6/2026
Omniverse Kit contains a vulnerability in the reference applications Create, Audio2Face, Isaac Sim, View, Code, and Machinima. These applications allow executable Python code to be embedded in Universal Scene Description (USD) files to customize all aspects of a scene. If a user opens a USD file that contains embedded…
ModificadaMedia (5.5)0.33%—IllumosOmniosce OmniosOpenindianaJoyent Smartos+126/12/202217/6/2026
An issue was discovered in illumos before f859e7171bb5db34321e45585839c6c3200ebb90, OmniOS Community Edition r151038, OpenIndiana Hipster 2021.04, and SmartOS 20210923. A local unprivileged user can cause a deadlock and kernel panic via crafted rename and rmdir calls on tmpfs filesystems. Oracle Solaris 10 and 11 is…
ModificadaAlta (8.8)1.1%—Telosalliance Omnia MPX Node Firmware2/12/202217/6/2026
Insecure permissions in Telos Alliance Omnia MPX Node v1.0.0 to v1.4.9 allow attackers to manipulate and access system settings with backdoor account low privilege, this can lead to change hardware settings and execute arbitrary commands in vulnerable system functions that is requires high privilege to access.
ModificadaCrítica (9.8)6.0%—Telosalliance Omnia MPX Node Firmware2/12/202217/6/2026
An unauthenticated command injection vulnerability in the product license validation function of Telos Alliance Omnia MPX Node 1.3.* - 1.4.* allows attackers to execute arbitrary commands via a crafted payload injected into the license input.
ModificadaAlta (7.5)0.70%—Telosalliance Omnia MPX Node Firmware29/11/202217/6/2026
An Insecure Direct Object Reference (IDOR) vulnerability in the password reset function of Telos Alliance Omnia MPX Node 1.0.0-1.4.[*] allows attackers to arbitrarily change user and Administrator account passwords.
ModificadaCrítica (9.8)0.97%—Moderncampus Omni CMS18/9/202217/6/2026
Modern Campus Omni CMS (formerly OU Campus) 10.2.4 allows login-page SQL injection via a '" OR 1 = 1 -- - , <?php' substring.
ModificadaCrítica (9.8)13%💥 ExploitTelosalliance Omnia MPX Node Firmware2/9/202217/6/2026
A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 allows attackers to access users credentials which makes him able to gain initial access to the control panel with high privilege because the cleartext storage of sensitive information which can be…
Orbitaley — Vulnerabilidades