Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
5089 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.25% | — | Vmware Spring Security | 10/6/2026 | 23/7/2026 | An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generated by Spring Security filters. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5. | |
| Analizada | Alta (7.2) | 0.30% | — | Vmware Spring Security | 10/6/2026 | 23/7/2026 | An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_asserting_party_metadata) may be able to store malicious serialized payloads in the columns containing the collection of verification or encryption credentials (verification_credentials and… | |
| Analizada | Alta (7.5) | 0.46% | — | Vmware Spring Security | 10/6/2026 | 23/7/2026 | An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be vulnerable to a denial of service by way of an unbounded writer that inflates the compressed SAML payload into memory. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25;… | |
| Aplazada | Alta (8.7) | 0.79% | — | Xcitium Client SecurityAIComodo Internet SecurityAI | 7/6/2026 | 23/7/2026 | Xcitium Client Security (XCS) before 13.8.2.10019 and Comodo Internet Security (CIS) through 12.3.4.8162 (fix expected by 2026 Q3) contain an integer underflow vulnerability in the firewall driver Inspect.sys that allows remote unauthenticated attackers to crash the system by sending a crafted IPv6 packet with a… | |
| Aplazada | Alta (7.2) | 0.59% | — | ALL IN ONE SecurityAI | 6/6/2026 | 23/7/2026 | The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.4.7. This is due to insufficient input sanitization in the get_rest_route() function and missing output escaping in the column_default() method of the debug log… | |
| Pendiente de análisis | Alta (7.8) | 0.15% | — | Genetec Security CenterAI | 2/6/2026 | 22/7/2026 | A high security vulnerability affecting Security Center main server installations has been identified. It could allow an attacker with local OS privileges to the main server to access the Server Admin credentials. A third party hired by Genetec found the issue. There is currently no evidence of active exploitation.… | |
| Aplazada | Alta (7.5) | 0.39% | — | Really-simple-plugins Really Simple SecurityAI | 2/6/2026 | 22/7/2026 | The Really Simple Security WordPress plugin before 9.5.10.1 does not enforce the second-factor challenge in two of its two-factor authentication REST endpoints, allowing an attacker who knows a user's password to obtain a WordPress authentication session for that user without completing the email OTP challenge. | |
| Pendiente de análisis | Alta (7.8) | 0.18% | — | PC Tools Internet SecurityAIPC Tools Pctcore64AI | 1/6/2026 | 22/7/2026 | Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security allows user-mode processes to access the PCTCoreDriver WDM device interface and invoke privileged IOCTL handlers. A local attacker with the ability to access or load the affected driver can exploit this vulnerability to… | |
| Aplazada | Media (5.3) | 0.30% | — | Stormshield Network SecurityAI | 1/6/2026 | 22/7/2026 | A vulnerability was discovered on Stormshield Network Security It is possible to execute a reflected XSS attack on the login API available on Stormshield SNS appliance by executing a script on the victim's machine. The risks include the theft of cookies or other sensitive data, as well as the modification of page… | |
| Aplazada | Crítica (9.1) | 0.59% | — | KMW Cctv Security CameraAI | 29/5/2026 | 22/7/2026 | The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an attacker to remotely reset the administrator password to a known value without authentication, granting full access to the camera feeds and settings. | |
| Analizada | Media (6.5) | 0.28% | — | Springaicommunity MCP Security | 29/5/2026 | 21/7/2026 | mcp-security provides Security and Authorization support for Model Context Protocol in Spring AI. Prior to 0.1.9, the mcp-security framework fails to implement the mandatory SSRF mitigations outlined in the Model Context Protocol (MCP) security specifications. Specifically, it processes untrusted URLs for… | |
| Analizada | Alta (7.5) | 0.51% | — | Waterfall-security Wf-500 Firmware | 29/5/2026 | 21/7/2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL connector is configured. | |
| Analizada | Alta (7.5) | 0.15% | — | Waterfall-security Wf-500 Firmware | 29/5/2026 | 21/7/2026 | Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL connector is configured and file compression is enabled. | |
| Analizada | Alta (8.6) | 0.88% | — | Waterfall-security Wf-500 Firmware | 29/5/2026 | 21/7/2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operating system commands on the… | |
| Analizada | Alta (7.5) | 0.12% | — | Waterfall-security Wf-500 Firmware | 29/5/2026 | 21/7/2026 | Nozomi Networks Labs identified a CWE-125: Out-of-bounds Read in Waterfall WF-500 RX Host in version 7.10.0.0 R2601141040 that allows attackers with access to the TX Host to execute code on the RX Host. | |
| Analizada | Crítica (9.3) | 1.4% | — | Waterfall-security Wf-500 Firmware | 29/5/2026 | 21/7/2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the… | |
| Analizada | Crítica (9.3) | 1.4% | — | Waterfall-security Wf-500 Firmware | 29/5/2026 | 21/7/2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the… | |
| Analizada | Crítica (9.3) | 1.4% | — | Waterfall-security Wf-500 Firmware | 29/5/2026 | 21/7/2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the… | |
| Analizada | Crítica (9.3) | 1.4% | — | Waterfall-security Wf-500 Firmware | 29/5/2026 | 21/7/2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the… | |
| Analizada | Crítica (9.3) | 0.41% | — | Waterfall-security Wf-500 Firmware | 29/5/2026 | 21/7/2026 | Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to bypass authentication of the Console web application and perform actions as an… | |
| Analizada | Crítica (9.3) | 1.4% | — | Waterfall-security Wf-500 Firmware | 29/5/2026 | 21/7/2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the… | |
| Analizada | Alta (8.7) | 0.43% | — | Waterfall-security Wf-500 Firmware | 29/5/2026 | 21/7/2026 | Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to read arbitrary files from the device. | |
| Analizada | Crítica (9.3) | 1.4% | — | Waterfall-security Wf-500 Firmware | 29/5/2026 | 21/7/2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the… | |
| Analizada | Crítica (9.3) | 1.4% | — | Waterfall-security Wf-500 Firmware | 29/5/2026 | 21/7/2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the… | |
| Analizada | Alta (8.8) | 0.44% | — | Waterfall-security Wf-500 Firmware | 29/5/2026 | 21/7/2026 | Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to delete arbitrary files on the Host machines. |