Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
823 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.7) | 0.46% | — | Amazon WorkspacesAI | 15/1/2025 | 17/6/2026 | An issue in the native clients for Amazon WorkSpaces (when running PCoIP protocol) may allow an attacker to access remote sessions via man-in-the-middle. | |
| Aplazada | Alta (7.7) | 0.51% | — | Amazon WorkspacesAIAmazon Appstream 2.0AIAmazon DCV ClientsAI | 15/1/2025 | 17/6/2026 | An issue in the native clients for Amazon WorkSpaces (when running Amazon DCV protocol), Amazon AppStream 2.0, and Amazon DCV Clients may allow an attacker to access remote sessions via man-in-the-middle. | |
| Aplazada | Alta (7.1) | 0.33% | — | Farinspace PartnersAI | 15/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in farinspace Partners partners allows Reflected XSS.This issue affects Partners: from n/a through <= 0.2.0. | |
| Aplazada | Media (4.3) | 0.29% | — | Space Codes AI FOR SEOAI | 7/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Space Codes AI for SEO ai-for-seo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI for SEO: from n/a through <= 1.2.9. | |
| Aplazada | Baja (3.1) | 0.34% | — | Clevelandwebdeveloper SpacerAI | 7/1/2025 | 17/6/2026 | The Spacer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the motech_spacer_callback() function in all versions up to, and including, 3.0.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view limited setting… | |
| Analizada | Media (5.3) | 0.32% | — | Huawei IPS Module FirmwareHuawei Ngfw Module FirmwareHuawei Nip6300 FirmwareHuawei Nip6600 Firmware+5 | 28/12/2024 | 17/6/2026 | There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt… | |
| Analizada | Media (5.3) | 0.25% | — | Huawei IPS Module FirmwareHuawei Ngfw Module FirmwareHuawei Nip6300 FirmwareHuawei Nip6600 Firmware+5 | 28/12/2024 | 17/6/2026 | There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt… | |
| Analizada | Media (5.3) | 0.25% | — | Huawei IPS Module FirmwareHuawei Ngfw Module FirmwareHuawei Nip6300 FirmwareHuawei Nip6600 Firmware+5 | 28/12/2024 | 17/6/2026 | There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt… | |
| Analizada | Media (5.3) | 0.25% | — | Huawei IPS Module FirmwareHuawei Ngfw Module FirmwareHuawei Nip6300 FirmwareHuawei Nip6600 Firmware+5 | 28/12/2024 | 17/6/2026 | There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt… | |
| Analizada | Media (5.3) | 0.25% | — | Huawei IPS Module FirmwareHuawei Ngfw Module FirmwareHuawei Nip6300 FirmwareHuawei Nip6600 Firmware+5 | 28/12/2024 | 17/6/2026 | There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt… | |
| Analizada | Media (5.3) | 0.25% | — | Huawei IPS Module FirmwareHuawei Ngfw Module FirmwareHuawei Nip6300 FirmwareHuawei Nip6600 Firmware+5 | 27/12/2024 | 17/6/2026 | There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt… | |
| Analizada | Media (5.3) | 0.25% | — | Huawei IPS Module FirmwareHuawei Ngfw Module FirmwareHuawei Nip6300 FirmwareHuawei Nip6600 Firmware+5 | 27/12/2024 | 17/6/2026 | There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt… | |
| Aplazada | Crítica (9.8) | 1.7% | 💥 PoC | Farinspace PartnersAI | 18/12/2024 | 17/6/2026 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in farinspace Partners partners allows Object Injection.This issue affects Partners: from n/a through <= 0.2.0. | |
| Aplazada | Media (6.4) | 0.31% | — | Onlyoffice DocspaceAI | 12/12/2024 | 17/6/2026 | The ONLYOFFICE DocSpace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'onlyoffice-docspace' shortcode in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Alta (7.8) | 0.21% | — | Ivanti Workspace Control | 11/12/2024 | 17/6/2026 | Under specific circumstances, insecure permissions in Ivanti Workspace Control before version 10.18.40.0 allows a local authenticated attacker to achieve local privilege escalation. | |
| Analizada | Alta (7.5) | 0.60% | — | Monospace Directus | 9/12/2024 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 11.0.0 and prior to version 11.3.0, when setting `WEBSOCKETS_GRAPHQL_AUTH` or `WEBSOCKETS_REST_AUTH` to "public", an unauthenticated user is able to do any of the supported operations (CRUD, subscriptions) with full… | |
| Modificada | Media (5.4) | 0.26% | — | Wpthemespace Magical Addons FOR Elementor | 6/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Magical Addons For Elementor magical-addons-for-elementor allows Stored XSS.This issue affects Magical Addons For Elementor: from n/a through <= 1.3.6. | |
| Analizada | Media (4.6) | 0.34% | — | Monospace Directus | 5/12/2024 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. The Comment feature has implemented a filter to prevent users from adding restricted characters, such as HTML tags. However, this filter operates on the client-side, which can be bypassed, making the application vulnerable to HTML… | |
| Aplazada | Media (4.6) | 0.28% | — | Suse ManagerAISuse Spacewalk-webAI | 28/11/2024 | 17/6/2026 | A Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in the Setup Wizard, HTTP Proxy credentials pane in spacewalk-web allows attackers to attack users by providing specially crafted URLs to click. This issue affects Container… | |
| Analizada | Media (4.8) | 0.14% | — | Cybelesoft Thinfinity Workspace | 13/11/2024 | 17/6/2026 | Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain a hardcoded cryptographic key used for encryption. | |
| Analizada | Alta (7.3) | 0.28% | — | Cybelesoft Thinfinity Workspace | 13/11/2024 | 17/6/2026 | Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This vulnerability allows attackers to create arbitrary user profiles with elevated privileges. | |
| Analizada | Alta (7.5) | 0.39% | — | Cybelesoft Thinfinity Workspace | 13/11/2024 | 17/6/2026 | A full path disclosure in Cybele Software Thinfinity Workspace before v7.0.2.113 allows attackers to obtain the root path of the application via unspecified vectors. | |
| Analizada | Alta (8.1) | 0.45% | — | Cybelesoft Thinfinity Workspace | 13/11/2024 | 17/6/2026 | Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a secondary broker via a crafted request. | |
| Analizada | Crítica (9.8) | 0.46% | — | Cybelesoft Thinfinity Workspace | 13/11/2024 | 17/6/2026 | Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endpoint where Web Sockets connections are established. | |
| Analizada | Media (6.5) | 0.40% | — | Appspace | 12/11/2024 | 17/6/2026 | Appspace 6.2.4 is affected by Incorrect Access Control via the Appspace Web Portal password reset page. |