Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
535 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.47% | — | Dell Unity Operating Environment | 4/8/2025 | 17/6/2026 | Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nas utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges. | |
| Analizada | Alta (7.8) | 0.46% | — | Dell Unity Operating Environment | 4/8/2025 | 17/6/2026 | Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nfssupport utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges. | |
| Analizada | Media (6.1) | 0.24% | — | Dell Unity Operating Environment | 4/8/2025 | 17/6/2026 | Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'). An unauthenticated attacker with remote access could potentially… | |
| Modificada | Crítica (9.8) | 66% | 💥 Exploit | Dell Unity Operating Environment | 4/8/2025 | 17/6/2026 | Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution. | |
| Aplazada | Alta (8.1) | 0.36% | — | Opennebula Community EditionAIOpennebula Enterprise EditionAI | 3/8/2025 | 17/6/2026 | OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition (EE) before 6.10.3 have a critical FireEdge race condition that can lead to full account takeover. By exploiting this, an unauthenticated attacker can obtain a valid JSON Web Token (JWT) belonging to a legitimate user without knowledge of their… | |
| Aplazada | Media (6.4) | 0.23% | — | MMM Unity LoaderAI | 2/8/2025 | 17/6/2026 | The Mmm Unity Loader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘attributes’ parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Crítica (9.1) | 0.57% | — | Saurus CMS Community EditionAI | 1/8/2025 | 17/6/2026 | Saurus CMS Community Edition since commit d886e5b0 (2010-04-23) is vulnerable to a SQL Injection vulnerability in the `prepareSearchQuery()` method in `FulltextSearch.class.php`. The application directly concatenates user-supplied input (`$search_word`) into SQL queries without sanitization, allowing attackers to… | |
| Aplazada | Crítica (9.8) | 0.46% | — | Unity Business Technology PTY LTD THE E-commerce ERPAI | 16/7/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Unity Business Technology Pty Ltd The E-Commerce ERP profitori allows Privilege Escalation.This issue affects The E-Commerce ERP: from n/a through <= 2.1.1.3. | |
| Aplazada | Crítica (9.8) | 7.9% | 💥 Exploit | Alfresco Community EditionAI | 17/6/2025 | 17/6/2026 | Teleport provides connectivity, authentication, access controls and audit for infrastructure. Community Edition versions before and including 17.5.1 are vulnerable to remote authentication bypass. At time of posting, there is no available open-source patch. | |
| Aplazada | Media (6.8) | 0.40% | — | Portainer Community EditionAI | 17/6/2025 | 17/6/2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. Prior to STS version 2.31.0 and LTS version 2.27.7, if a Portainer administrator can be convinced to register a malicious container registry,… | |
| Analizada | Media (6.7) | 0.18% | — | Cisco FinesseCisco SocialminerCisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence Service+4 | 4/6/2025 | 17/6/2026 | A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user. This vulnerability is due to improper validation of user-supplied command arguments. An… | |
| Analizada | Crítica (9.8) | 84% | 💥 Exploit | Invisioncommunity | 16/5/2025 | 17/6/2026 | Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The issue lies within the themeeditor controller (file: /applications/core/modules/front/system/themeeditor.php), where a protected method named customCss can be invoked by unauthenticated users. This… | |
| Aplazada | Crítica (9.8) | 0.50% | — | Shahjahan Jewel Fluent-communityAI | 17/4/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Shahjahan Jewel FluentCommunity fluent-community allows Object Injection.This issue affects FluentCommunity: from n/a through <= 1.2.15. | |
| Analizada | Media (5.9) | 0.44% | — | Steve-community Steve | 15/4/2025 | 17/6/2026 | An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass authentication and execute arbitrary coammands via supplying crafted OCPP requests. | |
| Analizada | Alta (7.8) | 0.57% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges. | |
| Analizada | Alta (7.8) | 0.53% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of privileges. | |
| Analizada | Alta (8.8) | 1.4% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to a targeted application user being redirected to arbitrary web URLs. The vulnerability could be… | |
| Analizada | Alta (7.8) | 0.57% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges. | |
| Analizada | Alta (7.8) | 0.59% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges. | |
| Analizada | Alta (7.8) | 0.59% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges. | |
| Analizada | Alta (7.8) | 0.54% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of privileges. | |
| Analizada | Alta (7.8) | 0.57% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges. | |
| Analizada | Crítica (9.8) | 1.5% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution. | |
| Analizada | Crítica (9.1) | 1.1% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to delete arbitrary files. This vulnerability is considered critical… | |
| Analizada | Alta (7.3) | 1.3% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution. |