Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
1785 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (1.9) | 0.29% | — | Foresightnews Foresight News | 20/7/2025 | 17/6/2026 | A vulnerability classified as problematic was found in Foresight News App up to 2.6.4 on Android. This vulnerability affects unknown code of the file AndroidManifest.xml of the component pro.foresightnews.appa. The manipulation leads to improper export of android application components. Attacking locally is a… | |
| Aplazada | Media (6.5) | 0.45% | — | Asna RegistrarAIAsna Datagate FOR SQL ServerAIAsna Datagate Component SuiteAIAsna Datagate MonitorAI+13 | 3/7/2025 | 17/6/2026 | ASNA Assist and ASNA Registrar before 2025-03-31 allow deserialization attacks against .NET remoting. These are Windows system services that support license key management and deprecated Windows network authentication. The services are implemented with .NET remoting and can be exploited via well-known deserialization… | |
| Analizada | Crítica (9.8) | 0.76% | — | HPE Insight Remote Support | 1/7/2025 | 17/6/2026 | A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646. | |
| Analizada | Alta (7.5) | 46% | — | HPE Insight Remote Support | 1/7/2025 | 17/6/2026 | A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646. | |
| Analizada | Alta (7.5) | 0.54% | — | HPE Insight Remote Support | 1/7/2025 | 17/6/2026 | A vulnerability in HPE Insight Remote Support (IRS) prior to v7.15.0.646 may allow an unauthenticated denial of service | |
| Aplazada | Media (5.2) | 0.23% | — | Sight Bulb PROAI | 27/6/2025 | 17/6/2026 | Unauthenticated users on an adjacent network with the Sight Bulb Pro can run shell commands as root through a vulnerable proprietary TCP protocol available on Port 16668. This vulnerability allows an attacker to run arbitrary commands on the Sight Bulb Pro by passing a well formed JSON string. | |
| Aplazada | Media (6.8) | 0.09% | — | Sight Bulb PROAI | 27/6/2025 | 17/6/2026 | During the initial setup of the device the user connects to an access point broadcast by the Sight Bulb Pro. During the negotiation, AES Encryption keys are passed in cleartext. If captured, an attacker may be able to decrypt communications between the management app and the Sight Bulb Pro which may include sensitive… | |
| Aplazada | Alta (7.5) | 0.45% | — | Elfsight Contact FormAI | 9/6/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in elfsight elfsight Contact Form widget elfsight-contact-form allows Retrieve Embedded Sensitive Data.This issue affects elfsight Contact Form widget: from n/a through <= 2.3.1. | |
| Analizada | Alta (7.5) | 0.51% | — | Dell Insightiq | 15/5/2025 | 17/6/2026 | Dell PowerScale InsightIQ, version 5.2, contains an uncontrolled resource consumption vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service. | |
| Analizada | Crítica (9.8) | 0.39% | — | Dell Insightiq | 15/5/2025 | 17/6/2026 | Dell PowerScale InsightIQ, versions 5.0 through 5.2, contains an improper privilege management vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to elevation of privileges. | |
| Aplazada | Crítica (9.3) | 0.52% | — | Netvision IsosinsightAI | 12/5/2025 | 17/6/2026 | The ISOinsight from Netvision has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Analizada | Media (6.1) | 0.35% | — | Milesight Ug65-868m-ea Firmware | 7/5/2025 | 17/6/2026 | An admin user can gain unauthorized write access to the /etc/rc.local file on the device, which is executed on a system boot. | |
| Aplazada | Baja (2.3) | 0.44% | — | Opentext Arcsight Enterprise Security ManagerAI | 21/4/2025 | 17/6/2026 | Reference to Expired Domain Vulnerability in OpenText™ ArcSight Enterprise Security Manager. | |
| Aplazada | Media (4.7) | 0.14% | — | Arctera Veritas Data InsightAIDell Isilon OnefsAI | 16/4/2025 | 17/6/2026 | Arctera/Veritas Data Insight before 7.1.2 can send cleartext credentials when configured to use HTTP Basic Authentication to a Dell Isilon OneFS server. | |
| Aplazada | Media (6.5) | 0.32% | — | Wpsight WpcasaAI | 16/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPSight WPCasa wpcasa allows Stored XSS.This issue affects WPCasa: from n/a through <= 1.3.2. | |
| Aplazada | Alta (8.8) | 0.62% | — | Insightsoftware Hive JdbcAI | 3/4/2025 | 17/6/2026 | insightsoftware Hive JDBC through 2.6.13 has a remote code execution vulnerability. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote code execution. | |
| Aplazada | Alta (8.8) | 0.62% | — | Insightsoftware Spark JdbcAI | 3/4/2025 | 17/6/2026 | insightsoftware Spark JDBC 2.6.21 has a remote code execution vulnerability. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote code execution. | |
| Aplazada | Media (5.4) | 0.15% | — | Elfsight Testimonials SliderAI | 31/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in elfsight Elfsight Testimonials Slider elfsight-testimonials-slider allows Cross Site Request Forgery.This issue affects Elfsight Testimonials Slider: from n/a through <= 1.0.1. | |
| Aplazada | Media (5.9) | 0.26% | — | Elfsight Testimonials SliderAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in elfsight Elfsight Testimonials Slider elfsight-testimonials-slider allows Stored XSS.This issue affects Elfsight Testimonials Slider: from n/a through <= 1.0.1. | |
| Aplazada | Media (5.4) | 0.32% | — | Elfsight Testimonials SliderAI | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in elfsight Elfsight Testimonials Slider elfsight-testimonials-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elfsight Testimonials Slider: from n/a through <= 1.0.1. | |
| Aplazada | Crítica (9.8) | 0.49% | — | HPE Insight Cluster Management UtilityAI | 30/3/2025 | 17/6/2026 | Unauthenticated RCE in HPE Insight Cluster Management Utility | |
| Aplazada | Media (5.9) | 0.22% | — | Elfsight Yottie-liteAI | 13/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in elfsight Elfsight Yottie Lite yottie-lite allows Stored XSS.This issue affects Elfsight Yottie Lite: from n/a through <= 1.3.3. | |
| Analizada | Alta (7.5) | 2.2% | — | NettyNetapp Active IQ Unified ManagerNetapp Oncommand Insight | 10/2/2025 | 17/6/2026 | Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it doesn't correctly handle validation of such a packet in all cases which can lead to a native crash.… | |
| Analizada | Media (4.8) | 1.0% | — | Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+7 | 21/1/2025 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u431-perf, 11.0.25, 17.0.13, 21.0.5, 23.0.1; Oracle GraalVM for JDK: 17.0.13, 21.0.5, 23.0.1; Oracle GraalVM… | |
| Analizada | Media (4.9) | 0.96% | — | Oracle Mysql ServerNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation | 21/1/2025 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.36 and prior and 8.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of… |