Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

823 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.7)0.46%—Amazon WorkspacesAI15/1/202517/6/2026
An issue in the native clients for Amazon WorkSpaces (when running PCoIP protocol) may allow an attacker to access remote sessions via man-in-the-middle.
AplazadaAlta (7.7)0.51%—Amazon WorkspacesAIAmazon Appstream 2.0AIAmazon DCV ClientsAI15/1/202517/6/2026
An issue in the native clients for Amazon WorkSpaces (when running Amazon DCV protocol), Amazon AppStream 2.0, and Amazon DCV Clients may allow an attacker to access remote sessions via man-in-the-middle.
AplazadaAlta (7.1)0.33%—Farinspace PartnersAI15/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in farinspace Partners partners allows Reflected XSS.This issue affects Partners: from n/a through <= 0.2.0.
AplazadaMedia (4.3)0.29%—Space Codes AI FOR SEOAI7/1/202517/6/2026
Missing Authorization vulnerability in Space Codes AI for SEO ai-for-seo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI for SEO: from n/a through <= 1.2.9.
AplazadaBaja (3.1)0.34%—Clevelandwebdeveloper SpacerAI7/1/202517/6/2026
The Spacer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the motech_spacer_callback() function in all versions up to, and including, 3.0.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view limited setting…
AnalizadaMedia (5.3)0.32%—Huawei IPS Module FirmwareHuawei Ngfw Module FirmwareHuawei Nip6300 FirmwareHuawei Nip6600 Firmware+528/12/202417/6/2026
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt…
AnalizadaMedia (5.3)0.25%—Huawei IPS Module FirmwareHuawei Ngfw Module FirmwareHuawei Nip6300 FirmwareHuawei Nip6600 Firmware+528/12/202417/6/2026
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt…
AnalizadaMedia (5.3)0.25%—Huawei IPS Module FirmwareHuawei Ngfw Module FirmwareHuawei Nip6300 FirmwareHuawei Nip6600 Firmware+528/12/202417/6/2026
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt…
AnalizadaMedia (5.3)0.25%—Huawei IPS Module FirmwareHuawei Ngfw Module FirmwareHuawei Nip6300 FirmwareHuawei Nip6600 Firmware+528/12/202417/6/2026
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt…
AnalizadaMedia (5.3)0.25%—Huawei IPS Module FirmwareHuawei Ngfw Module FirmwareHuawei Nip6300 FirmwareHuawei Nip6600 Firmware+528/12/202417/6/2026
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt…
AnalizadaMedia (5.3)0.25%—Huawei IPS Module FirmwareHuawei Ngfw Module FirmwareHuawei Nip6300 FirmwareHuawei Nip6600 Firmware+527/12/202417/6/2026
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt…
AnalizadaMedia (5.3)0.25%—Huawei IPS Module FirmwareHuawei Ngfw Module FirmwareHuawei Nip6300 FirmwareHuawei Nip6600 Firmware+527/12/202417/6/2026
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt…
AplazadaCrítica (9.8)1.7%💥 PoCFarinspace PartnersAI18/12/202417/6/2026
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in farinspace Partners partners allows Object Injection.This issue affects Partners: from n/a through <= 0.2.0.
AplazadaMedia (6.4)0.31%—Onlyoffice DocspaceAI12/12/202417/6/2026
The ONLYOFFICE DocSpace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'onlyoffice-docspace' shortcode in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AnalizadaAlta (7.8)0.21%—Ivanti Workspace Control11/12/202417/6/2026
Under specific circumstances, insecure permissions in Ivanti Workspace Control before version 10.18.40.0 allows a local authenticated attacker to achieve local privilege escalation.
AnalizadaAlta (7.5)0.60%—Monospace Directus9/12/202417/6/2026
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 11.0.0 and prior to version 11.3.0, when setting `WEBSOCKETS_GRAPHQL_AUTH` or `WEBSOCKETS_REST_AUTH` to "public", an unauthenticated user is able to do any of the supported operations (CRUD, subscriptions) with full…
ModificadaMedia (5.4)0.26%—Wpthemespace Magical Addons FOR Elementor6/12/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Magical Addons For Elementor magical-addons-for-elementor allows Stored XSS.This issue affects Magical Addons For Elementor: from n/a through <= 1.3.6.
AnalizadaMedia (4.6)0.34%—Monospace Directus5/12/202417/6/2026
Directus is a real-time API and App dashboard for managing SQL database content. The Comment feature has implemented a filter to prevent users from adding restricted characters, such as HTML tags. However, this filter operates on the client-side, which can be bypassed, making the application vulnerable to HTML…
AplazadaMedia (4.6)0.28%—Suse ManagerAISuse Spacewalk-webAI28/11/202417/6/2026
A Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in the Setup Wizard, HTTP Proxy credentials pane in spacewalk-web allows attackers to attack users by providing specially crafted URLs to click. This issue affects Container…
AnalizadaMedia (4.8)0.14%—Cybelesoft Thinfinity Workspace13/11/202417/6/2026
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain a hardcoded cryptographic key used for encryption.
AnalizadaAlta (7.3)0.28%—Cybelesoft Thinfinity Workspace13/11/202417/6/2026
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This vulnerability allows attackers to create arbitrary user profiles with elevated privileges.
AnalizadaAlta (7.5)0.39%—Cybelesoft Thinfinity Workspace13/11/202417/6/2026
A full path disclosure in Cybele Software Thinfinity Workspace before v7.0.2.113 allows attackers to obtain the root path of the application via unspecified vectors.
AnalizadaAlta (8.1)0.45%—Cybelesoft Thinfinity Workspace13/11/202417/6/2026
Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a secondary broker via a crafted request.
AnalizadaCrítica (9.8)0.46%—Cybelesoft Thinfinity Workspace13/11/202417/6/2026
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endpoint where Web Sockets connections are established.
AnalizadaMedia (6.5)0.40%—Appspace12/11/202417/6/2026
Appspace 6.2.4 is affected by Incorrect Access Control via the Appspace Web Portal password reset page.