Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

1785 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (1.9)0.29%—Foresightnews Foresight News20/7/202517/6/2026
A vulnerability classified as problematic was found in Foresight News App up to 2.6.4 on Android. This vulnerability affects unknown code of the file AndroidManifest.xml of the component pro.foresightnews.appa. The manipulation leads to improper export of android application components. Attacking locally is a…
AplazadaMedia (6.5)0.45%—Asna RegistrarAIAsna Datagate FOR SQL ServerAIAsna Datagate Component SuiteAIAsna Datagate MonitorAI+133/7/202517/6/2026
ASNA Assist and ASNA Registrar before 2025-03-31 allow deserialization attacks against .NET remoting. These are Windows system services that support license key management and deprecated Windows network authentication. The services are implemented with .NET remoting and can be exploited via well-known deserialization…
AnalizadaCrítica (9.8)0.76%—HPE Insight Remote Support1/7/202517/6/2026
A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.
AnalizadaAlta (7.5)46%—HPE Insight Remote Support1/7/202517/6/2026
A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.
AnalizadaAlta (7.5)0.54%—HPE Insight Remote Support1/7/202517/6/2026
A vulnerability in HPE Insight Remote Support (IRS) prior to v7.15.0.646 may allow an unauthenticated denial of service
AplazadaMedia (5.2)0.23%—Sight Bulb PROAI27/6/202517/6/2026
Unauthenticated users on an adjacent network with the Sight Bulb Pro can run shell commands as root through a vulnerable proprietary TCP protocol available on Port 16668. This vulnerability allows an attacker to run arbitrary commands on the Sight Bulb Pro by passing a well formed JSON string.
AplazadaMedia (6.8)0.09%—Sight Bulb PROAI27/6/202517/6/2026
During the initial setup of the device the user connects to an access point broadcast by the Sight Bulb Pro. During the negotiation, AES Encryption keys are passed in cleartext. If captured, an attacker may be able to decrypt communications between the management app and the Sight Bulb Pro which may include sensitive…
AplazadaAlta (7.5)0.45%—Elfsight Contact FormAI9/6/202517/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in elfsight elfsight Contact Form widget elfsight-contact-form allows Retrieve Embedded Sensitive Data.This issue affects elfsight Contact Form widget: from n/a through <= 2.3.1.
AnalizadaAlta (7.5)0.51%—Dell Insightiq15/5/202517/6/2026
Dell PowerScale InsightIQ, version 5.2, contains an uncontrolled resource consumption vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.
AnalizadaCrítica (9.8)0.39%—Dell Insightiq15/5/202517/6/2026
Dell PowerScale InsightIQ, versions 5.0 through 5.2, contains an improper privilege management vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to elevation of privileges.
AplazadaCrítica (9.3)0.52%—Netvision IsosinsightAI12/5/202517/6/2026
The ISOinsight from Netvision has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
AnalizadaMedia (6.1)0.35%—Milesight Ug65-868m-ea Firmware7/5/202517/6/2026
An admin user can gain unauthorized write access to the /etc/rc.local file on the device, which is executed on a system boot.
AplazadaBaja (2.3)0.44%—Opentext Arcsight Enterprise Security ManagerAI21/4/202517/6/2026
Reference to Expired Domain Vulnerability in OpenText™ ArcSight Enterprise Security Manager.
AplazadaMedia (4.7)0.14%—Arctera Veritas Data InsightAIDell Isilon OnefsAI16/4/202517/6/2026
Arctera/Veritas Data Insight before 7.1.2 can send cleartext credentials when configured to use HTTP Basic Authentication to a Dell Isilon OneFS server.
AplazadaMedia (6.5)0.32%—Wpsight WpcasaAI16/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPSight WPCasa wpcasa allows Stored XSS.This issue affects WPCasa: from n/a through <= 1.3.2.
AplazadaAlta (8.8)0.62%—Insightsoftware Hive JdbcAI3/4/202517/6/2026
insightsoftware Hive JDBC through 2.6.13 has a remote code execution vulnerability. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote code execution.
AplazadaAlta (8.8)0.62%—Insightsoftware Spark JdbcAI3/4/202517/6/2026
insightsoftware Spark JDBC 2.6.21 has a remote code execution vulnerability. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote code execution.
AplazadaMedia (5.4)0.15%—Elfsight Testimonials SliderAI31/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in elfsight Elfsight Testimonials Slider elfsight-testimonials-slider allows Cross Site Request Forgery.This issue affects Elfsight Testimonials Slider: from n/a through <= 1.0.1.
AplazadaMedia (5.9)0.26%—Elfsight Testimonials SliderAI31/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in elfsight Elfsight Testimonials Slider elfsight-testimonials-slider allows Stored XSS.This issue affects Elfsight Testimonials Slider: from n/a through <= 1.0.1.
AplazadaMedia (5.4)0.32%—Elfsight Testimonials SliderAI31/3/202517/6/2026
Missing Authorization vulnerability in elfsight Elfsight Testimonials Slider elfsight-testimonials-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elfsight Testimonials Slider: from n/a through <= 1.0.1.
AplazadaCrítica (9.8)0.49%—HPE Insight Cluster Management UtilityAI30/3/202517/6/2026
Unauthenticated RCE in HPE Insight Cluster Management Utility
AplazadaMedia (5.9)0.22%—Elfsight Yottie-liteAI13/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in elfsight Elfsight Yottie Lite yottie-lite allows Stored XSS.This issue affects Elfsight Yottie Lite: from n/a through <= 1.3.3.
AnalizadaAlta (7.5)2.2%—NettyNetapp Active IQ Unified ManagerNetapp Oncommand Insight10/2/202517/6/2026
Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it doesn't correctly handle validation of such a packet in all cases which can lead to a native crash.…
AnalizadaMedia (4.8)1.0%—Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+721/1/202517/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u431-perf, 11.0.25, 17.0.13, 21.0.5, 23.0.1; Oracle GraalVM for JDK: 17.0.13, 21.0.5, 23.0.1; Oracle GraalVM…
AnalizadaMedia (4.9)0.96%—Oracle Mysql ServerNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation21/1/202517/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.36 and prior and 8.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of…