Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2774▲ 9 respecto a la semana anterior
Críticas / altas1289▼ 242 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
5138 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6) | 0.24% | — | Nozominetworks CMCNozominetworks Guardian | 7/10/2025 | 17/6/2026 | A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SELECT SQL statements on the DBMS used by the web application, potentially exposing unauthorized data. | |
| Analizada | Alta (7.7) | 0.27% | — | Nozominetworks CMCNozominetworks Guardian | 7/10/2025 | 17/6/2026 | A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SQL statements on the DBMS used by the web application, potentially exposing unauthorized data, altering their structure and… | |
| Analizada | Media (6) | 0.24% | — | Nozominetworks CMCNozominetworks Guardian | 7/10/2025 | 17/6/2026 | A SQL Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SELECT SQL statements on the DBMS used by the web application, potentially exposing unauthorized data. | |
| Analizada | Alta (7.2) | 0.27% | — | Nozominetworks CMCNozominetworks Guardian | 7/10/2025 | 17/6/2026 | An access control vulnerability was discovered in the CLI functionality due to a specific access restriction not being properly enforced for users with limited privileges. An authenticated user with limited privileges can issue administrative CLI commands, altering the device configuration, and/or affecting its… | |
| Analizada | Media (5.9) | 0.22% | — | Nozominetworks CMCNozominetworks Guardian | 7/10/2025 | 17/6/2026 | A client-side path traversal vulnerability was discovered in the web management interface front-end due to missing validation of an input parameter. An authenticated user with limited privileges can craft a malicious URL which, if visited by an authenticated victim, leads to a Cross-Site Scripting (XSS) attack. | |
| Aplazada | Media (6.5) | 0.38% | — | Mediawiki BucketAI | 6/10/2025 | 9/10/2026 | Bucket es una extensión de MediaWiki para almacenar y recuperar datos estructurados en artículos. Antes de la versión 1.0.0, puede ocurrir una recursión infinita si un usuario consulta un bucket usando el comparador '!='. Esto resultará en la superación del límite de la pila de llamadas de PHP y/o un aumento del… | |
| Analizada | Alta (7.5) | 0.32% | — | Sick Baggage AnalyticsSick Logistic Diagnostic AnalyticsSick Package AnalyticsSick Tire Analytics | 6/10/2025 | 17/6/2026 | The credentials of the users stored in the system's local database can be used for the log in, making it possible for an attacker to gain unauthorized access. This could potentially affect the confidentiality of the application. | |
| Analizada | Media (6.1) | 0.29% | — | Sick Baggage AnalyticsSick Logistic Diagnostic AnalyticsSick Package AnalyticsSick Tire Analytics | 6/10/2025 | 17/6/2026 | JavaScript can be ran inside the address bar via the dashboard "Open in new Tab" Button, making the application vulnerable to session hijacking. | |
| Analizada | Alta (7.5) | 0.53% | — | Sick Baggage AnalyticsSick Logistic Diagnostic AnalyticsSick Package AnalyticsSick Tire Analytics | 6/10/2025 | 17/6/2026 | A remote, unauthorized attacker can brute force folders and files and read them like private keys or configurations, making the application vulnerable for gathering sensitive information. | |
| Analizada | Alta (7.5) | 0.53% | — | Sick Baggage AnalyticsSick Logistic Diagnostic AnalyticsSick Package AnalyticsSick Tire Analytics | 6/10/2025 | 17/6/2026 | It's possible to brute force folders and files, what can be used by an attacker to steal sensitve information. | |
| Analizada | Media (6.5) | 0.36% | — | Sick Baggage AnalyticsSick Logistic Diagnostic AnalyticsSick Package AnalyticsSick Tire Analytics | 6/10/2025 | 17/6/2026 | When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other internal information. An attacker thus receives information about the technology used and the structure of the application. | |
| Analizada | Crítica (9.8) | 0.49% | — | Sick Baggage AnalyticsSick Enterprise AnalyticsSick Logistic Diagnostic AnalyticsSick Package Analytics+1 | 6/10/2025 | 17/6/2026 | The application does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it possible for an attacker to guess user credentials. | |
| Analizada | Media (5.3) | 0.36% | — | Sick Baggage AnalyticsSick Enterprise AnalyticsSick Logistic Diagnostic AnalyticsSick Package Analytics+1 | 6/10/2025 | 17/6/2026 | For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one. | |
| Analizada | Alta (7.5) | 0.43% | — | Sick Baggage AnalyticsSick Logistic Diagnostic AnalyticsSick Package AnalyticsSick Tire Analytics | 6/10/2025 | 17/6/2026 | Multiple endpoints with sensitive information do not require authentication, making the application susceptible to information gathering. | |
| Analizada | Alta (7.5) | 0.39% | — | Sick Baggage AnalyticsSick Enterprise AnalyticsSick Logistic Diagnostic AnalyticsSick Package Analytics+1 | 6/10/2025 | 17/6/2026 | In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be stored in various systems such as server logs, browser histories or proxy servers. As a result, there is a high risk that this sensitive data will be disclosed unintentionally. | |
| Analizada | Media (5.3) | 0.40% | — | Sick Baggage AnalyticsSick Enterprise AnalyticsSick Logistic Diagnostic AnalyticsSick Package Analytics+1 | 6/10/2025 | 17/6/2026 | Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint, making the application vulnerable for user enumeration. | |
| Analizada | Media (6.8) | 0.19% | — | Deltaww Diascreen | 3/10/2025 | 8/10/2026 | Delta Electronics DIAScreen carece de validación adecuada del archivo proporcionado por el usuario. Si un usuario abre un archivo malicioso, un atacante puede aprovechar esta vulnerabilidad para ejecutar código en el contexto del proceso actual. | |
| Analizada | Media (6.8) | 0.16% | — | Deltaww Diascreen | 3/10/2025 | 8/10/2026 | Delta Electronics DIAScreen carece de validación adecuada del archivo proporcionado por el usuario. Si un usuario abre un archivo malicioso, un atacante puede aprovechar esta vulnerabilidad para ejecutar código en el contexto del proceso actual. | |
| Analizada | Media (6.8) | 0.16% | — | Deltaww Diascreen | 3/10/2025 | 8/10/2026 | Delta Electronics DIAScreen carece de validación adecuada del archivo proporcionado por el usuario. Si un usuario abre un archivo malicioso, un atacante puede aprovechar esta vulnerabilidad para ejecutar código en el contexto del proceso actual. | |
| Analizada | Media (6.8) | 0.16% | — | Deltaww Diascreen | 3/10/2025 | 8/10/2026 | Delta Electronics DIAScreen carece de validación adecuada del archivo proporcionado por el usuario. Si un usuario abre un archivo malicioso, un atacante puede aprovechar esta vulnerabilidad para ejecutar código en el contexto del proceso actual. | |
| Analizada | Alta (7.8) | 0.15% | — | Nvidia Nsight Graphics | 1/10/2025 | 17/6/2026 | NVIDIA Nsight Graphics for Windows contains a vulnerability in an ngfx component, where an attacker could cause a DLL highjacking attack. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, data tampering, and denial of service. | |
| Aplazada | Alta (7.8) | 0.15% | — | Nvidia Installer FOR Nvapp FOR WindowsAINvidia Frameview SDKAI | 1/10/2025 | 17/6/2026 | NVIDIA Installer for NvAPP for Windows contains a vulnerability in the FrameviewSDK installation process, where an attacker with local unprivileged access could modify files in the Frameview SDK directory. A successful exploit of this vulnerability might lead to escalation of privileges. | |
| Aplazada | Alta (8.7) | 0.23% | — | Nvidia Delegated Licensing ServiceAI | 30/9/2025 | 17/6/2026 | El Servicio de Licencias Delegadas de NVIDIA para todas las plataformas de dispositivos contiene una vulnerabilidad donde un Usuario/atacante puede causar una acción autorizada. Un exploit exitoso de esta vulnerabilidad puede conducir a la revelación de información. | |
| Aplazada | Media (4.6) | 0.22% | — | Nvidia Delegated Licensing ServiceAI | 30/9/2025 | 17/6/2026 | Servicio de Licencias Delegadas de NVIDIA para todas las plataformas de dispositivos contiene una vulnerabilidad de inyección SQL donde un Usuario/Atacante puede causar una acción autorizada. Un exploit exitoso de esta vulnerabilidad puede conducir a una denegación de servicio parcial (componente de la interfaz de… | |
| Aplazada | Baja (2.4) | 0.13% | — | Nvidia Delegated Licensing ServiceAI | 30/9/2025 | 17/6/2026 | El Servicio de Licencias Delegadas de NVIDIA para todas las plataformas de dispositivos contiene una vulnerabilidad donde un Usuario/atacante puede causar una acción autorizada. Un exploit exitoso de esta vulnerabilidad puede conducir a la revelación de información. |