Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2950▲ 8 respecto a la semana anterior
Críticas / altas1450▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
1620 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 3.5% | — | Wonderwhy-er Desktopcommandermcp | 8/10/2025 | 17/6/2026 | A vulnerability has been found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The affected element is the function extractBaseCommand of the file src/command-manager.ts of the component Absolute Path Handler. Such manipulation leads to os command injection. The attack may be performed from remote. The exploit has… | |
| Analizada | Baja (1.1) | 0.25% | — | Wonderwhy-er Desktopcommandermcp | 8/10/2025 | 17/6/2026 | A security vulnerability has been detected in wonderwhy-er DesktopCommanderMCP up to 0.2.13. This vulnerability affects the function isPathAllowed of the file src/tools/filesystem.ts. The manipulation leads to symlink following. The attack can only be performed from a local environment. The attack's complexity is… | |
| Aplazada | Alta (8.8) | 0.31% | — | Kyocera Command Center RXAI | 18/9/2025 | 5/7/2026 | An issue in user interface in Kyocera Command Center RX EXOSYS M5521cdn allows remote to obtain sensitive information via inspecting sent packages by user. | |
| Analizada | Alta (7.8) | 0.14% | — | Dell Alienware Command Center | 2/9/2025 | 17/6/2026 | Dell Alienware Command Center 5.x (AWCC), versions prior to 5.10.2.0, contains an Improper Link Resolution Before File Access ('Link Following')" vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Analizada | Crítica (9.3) | 0.36% | — | IBM Cognos Command Center | 26/8/2025 | 17/6/2026 | IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site… | |
| Analizada | Alta (7.8) | 0.16% | — | IBM Cognos Command Center | 26/8/2025 | 17/6/2026 | IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a local user to execute arbitrary code on the system due to the use of unsafe use of the BinaryFormatter function. | |
| Analizada | Media (6.1) | 0.29% | — | IBM Cognos Command Center | 26/8/2025 | 17/6/2026 | IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. | |
| Aplazada | Crítica (9.2) | 0.40% | — | Phoca CommanderAIJoomlaAI | 15/8/2025 | 17/6/2026 | An authenticated RCE vulnerability in Phoca Commander component 1.0.0-4.0.0 and 5.0.0-5.0.1 for Joomla was discovered. The issue allows code execution via the unzip feature. | |
| Aplazada | Media (5.6) | 0.12% | — | Command Center ServerAI | 10/7/2025 | 17/6/2026 | A Privilege Context Switching Error (CWE-270) in the Command Center Server could allow a privileged Operator with high level access in one Division to perform limited privileged activities across the Division boundary. This issue affects Command Centre Server: 9.30 prior to 9.30.1874 (MR1), 9.20 prior to 9.20.2337… | |
| Aplazada | Alta (8.7) | 1.0% | — | Command Center LCD KVM Over IP Switch Cl5708imAI | 9/5/2025 | 17/6/2026 | The LCD KVM over IP Switch CL5708IM has a Heap-based Buffer Overflow vulnerability in firmware versions prior to v2.2.215, allowing unauthenticated remote attackers to exploit this vulnerability to perform a denial-of-service attack. | |
| Analizada | Alta (7.8) | 0.13% | — | Dell Alienware Command Center | 16/4/2025 | 17/6/2026 | Dell Alienware Command Center 6.x, versions prior to 6.7.37.0 contain an Improper Access Control Vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Aplazada | Media (6.9) | 0.66% | — | Amazon Serverless Application Model Command Line InterfaceAI | 31/3/2025 | 17/6/2026 | After completing a build with AWS Serverless Application Model Command Line Interface (SAM CLI) which include symlinks, the content of those symlinks are copied to the cache of the local workspace as regular files or directories. As a result, a user who does not have access to those symlinks outside of the Docker… | |
| Analizada | Alta (8.4) | 0.43% | — | Microsoft Azure Command-line Interface | 11/3/2025 | 17/6/2026 | Improper neutralization of special elements used in a command ('command injection') in Azure Command Line Integration (CLI) allows an unauthorized attacker to elevate privileges locally. | |
| Aplazada | Alta (8.7) | 0.19% | — | Gallagher Command CentreAISaltoAI | 10/3/2025 | 17/6/2026 | Improper Certificate Validation (CWE-295) in the Gallagher Command Centre SALTO integration allowed an attacker to spoof the SALTO server. This issue affects all versions of Gallagher Command Centre prior to 9.20.1043. | |
| Aplazada | Media (5.5) | 0.27% | — | Effectmatrix Total Video Converter Command LineAI | 13/2/2025 | 17/6/2026 | A Structured Exception Handler based buffer overflow vulnerability exists in Effectmatrix Total Video Converter Command Line (TVCC) 2.50 when a specially crafted file is passed to the -ff parameter. The vulnerability occurs due to improper handling of file input with overly long characters, leading to memory… | |
| Aplazada | Media (5.5) | 0.27% | — | Effectmatrix Total Video Converter Command LineAI | 13/2/2025 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in Effectmatrix Total Video Converter Command Line (TVCC) 2.50 when an overly long string is passed to the "-f" parameter. This can lead to memory corruption, potentially allowing arbitrary code execution or causing a denial of service via specially crafted input. | |
| Analizada | Alta (7.5) | 2.2% | — | NettyNetapp Active IQ Unified ManagerNetapp Oncommand Insight | 10/2/2025 | 17/6/2026 | Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it doesn't correctly handle validation of such a packet in all cases which can lead to a native crash.… | |
| Aplazada | Alta (8.1) | 0.14% | — | 2N Access CommanderAI | 6/2/2025 | 17/6/2026 | 2N Access Commander version 2.1 and prior is vulnerable in default settings to Man In The Middle attack due to not verifying certificates of 2N edge devices. 2N has currently released an updated version 3.3 of 2N Access Commander, with added Certificate Fingerprint Verification. Since version 2.2 of 2N Access… | |
| Aplazada | Media (6) | 0.16% | — | 2N Access CommanderAI | 6/2/2025 | 17/6/2026 | Successful exploitation of this vulnerability could allow an attacker (who needs to have Admin access privileges) to read hardcoded AES passphrase, which may be used for decryption of certain data within backup files of 2N Access Commander version 1.14 and older. 2N has released an updated version 3.3 of 2N Access… | |
| Analizada | Media (6.8) | 0.90% | — | Sparkle-project SparkleNetapp HCI Compute NodeNetapp Oncommand Workflow Automation | 4/2/2025 | 17/6/2026 | A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks. | |
| Analizada | Media (4.8) | 1.0% | — | Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+7 | 21/1/2025 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u431-perf, 11.0.25, 17.0.13, 21.0.5, 23.0.1; Oracle GraalVM for JDK: 17.0.13, 21.0.5, 23.0.1; Oracle GraalVM… | |
| Analizada | Media (4.9) | 0.96% | — | Oracle Mysql ServerNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation | 21/1/2025 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.36 and prior and 8.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of… | |
| Aplazada | Alta (7.6) | 0.30% | — | Keyfactor CommandAI | 18/12/2024 | 17/6/2026 | Keyfactor Command before 12.5.0 has Incorrect Access Control: access tokens are over permissioned, aka 64099. The fixed versions are 11.5.1.1, 11.5.2.1, 11.5.3.1, 11.5.4.5, 11.5.6.1, 11.6.0, 12.2.0.1, 12.3.0.1, 12.4.0.1, 12.5.0, and 24.4.0. | |
| Aplazada | Alta (8.5) | 0.32% | — | Gallagher Command CentreAI | 12/12/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File (CWE-532) in the Gallagher Command Centre Alarm Transmitter feature could allow an authenticated Operator to view some security sensitive information to which they have not been granted access. This issue affects: Command Centre Server 9.10 prior to 9.10.2149 (MR4),… | |
| Aplazada | Media (4.4) | 0.13% | — | Nvidia Base Command ManagerAIBright Computing Bright Cluster ManagerAI | 6/12/2024 | 17/6/2026 | NVIDIA Base Command Manager and Bright Cluster Manager for Linux contain an insecure temporary file vulnerability. A successful exploit of this vulnerability might lead to denial of service. |