Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2760▲ 27 respecto a la semana anterior
Críticas / altas1467▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 441 respecto a la semana anterior
71 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.25% | — | Eksagate Electronic Engineering AND Computer Industry Trade Sysguard 6001AI | 30/6/2026 | 30/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. SYSGUARD 6001 allows Stored XSS. This issue affects SYSGUARD 6001: from 2.0.2 before 6.1.4.0. NOTE: The vendor was contacted and it was learned that the… | |
| Aplazada | Crítica (9.8) | 0.47% | — | Eksagate Electronic Engineering AND Computer Industry Trade Sysguard 6001AI | 30/6/2026 | 30/6/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. SYSGUARD 6001 allows Blind SQL Injection. This issue affects SYSGUARD 6001: from 2.0.2 before 6.1.16.0. NOTE: The vendor was contacted and it was… | |
| Aplazada | Crítica (9.3) | 0.57% | — | BackpropagateAI | 17/6/2026 | 18/6/2026 | Backpropagate is a Python library for fine-tuning large language models on a single GPU. In versions 1.1.0 and 1.1.1, the optional Reflex web UI exposes a training control plane without authentication: dataset upload, model load, training start/stop, multi-run orchestration, GGUF export, and HuggingFace Hub push. The… | |
| Pendiente de análisis | Baja (1.8) | 0.10% | — | Seagate OpenseachestAI | 2/6/2026 | 22/7/2026 | Out of bounds write in openSeaChest’s --showSupportedFormats in Seagate’s openSeaChest v25.05.3 on all supported platforms allows for writing 1 extra byte outside of allocated memory which sets a value to 1 via a maliciously crafted NVMe device with a bogus value in the namespace FLBAS byte. | |
| Pendiente de análisis | Media (4.6) | 0.11% | — | Seagate OpenseachestAI | 2/6/2026 | 22/7/2026 | Out of bounds write in openSeaChest’s Trim/Unmap operation in Seagate’s openSeaChest v26.03.0 on all supported platforms allows for writing extra memory describing a range of LBAs to deallocate 16 bytes outside of the allocated space when running this operation. | |
| Pendiente de análisis | Baja (1.8) | 0.10% | — | Seagate OpenseachestAI | 2/6/2026 | 22/7/2026 | Out of bounds write and reads in openSeaChest’s --showSCSIDefects in Seagate’s openSeaChest v25.05.3 on all supported platforms allows for writing defect information out of bounds for very large defects lists via a very bad drive with lots of defects or a maliciously crafted SCSI device’s defect response length. | |
| Aplazada | Media (5.1) | 0.19% | — | Exagate Sysguard 6001AI | 5/2/2026 | 17/6/2026 | Exagate SYSGuard 6001 contains a cross-site request forgery vulnerability that allows attackers to create unauthorized admin accounts through a crafted HTML form. Attackers can trick users into submitting a malicious form to /kulyon.php that adds a new user with administrative privileges without the victim's consent. | |
| Aplazada | Crítica (9.8) | 0.33% | — | Eksagate Electronic Engineering AND Computer Industry Trade INC Webpack Management SystemAI | 19/11/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. Webpack Management System allows SQL Injection. This issue affects Webpack Management System: through 20251119. | |
| Aplazada | Alta (7) | 0.25% | — | Seagate ToolkitAI | 26/9/2025 | 17/6/2026 | In Seagate Toolkit on Windows a vulnerability exists in the Toolkit Installer prior to versions 2.35.0.6 where it attempts to load DLLs from the current working directory without validating their origin or integrity. This behavior can be exploited by placing a malicious DLL in the same directory as the installer… | |
| Aplazada | Media (6.7) | 0.14% | — | Seagate ToolkitAI | 14/8/2025 | 17/6/2026 | The service executable path in Seagate Toolkit on Versions prior to 2.34.0.33 on Windows allows an attacker with Admin privileges to exploit a vulnerability as classified under CWE-428: Unquoted Search Path or Element. An attacker with write permissions to the root could place a malicious Program.exe file, which would… | |
| Aplazada | Media (6.5) | 0.44% | — | Asna RegistrarAIAsna Datagate FOR SQL ServerAIAsna Datagate Component SuiteAIAsna Datagate MonitorAI+13 | 3/7/2025 | 17/6/2026 | ASNA Assist and ASNA Registrar before 2025-03-31 allow deserialization attacks against .NET remoting. These are Windows system services that support license key management and deprecated Windows network authentication. The services are implemented with .NET remoting and can be exploited via well-known deserialization… | |
| Aplazada | Media (5.4) | 0.46% | — | Obiba AgateAI | 17/3/2025 | 17/6/2026 | Agate is central authentication server software for OBiBa epidemiology applications. Prior to version 3.3.0, when registering for an Agate account, arbitrary HTML code can be injected into a user's first and last name. This HTML is then rendered in the email sent to administrative users. The Agate service account… | |
| Analizada | Alta (7.5) | 0.81% | — | Unified-automation Uagateway | 3/5/2024 | 17/6/2026 | Unified Automation UaGateway Certificate Parsing Integer Overflow Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation UaGateway. Authentication is not required to exploit this vulnerability. The specific… | |
| Analizada | Crítica (9.1) | 1.9% | — | Unified-automation Uagateway | 3/5/2024 | 17/6/2026 | Unified Automation UaGateway NodeManagerOpcUa Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Unified Automation UaGateway. Authentication is required to exploit this vulnerability when the product is in its default… | |
| Analizada | Media (5.8) | 1.2% | — | Unified-automation Uagateway | 3/5/2024 | 17/6/2026 | Unified Automation UaGateway AddServer XML Injection Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation UaGateway. Authentication is required to exploit this vulnerability when the product is in its default… | |
| Analizada | Media (6.5) | 1.4% | — | Unified-automation Uagateway | 3/5/2024 | 17/6/2026 | Unified Automation UaGateway OPC UA Server Use-After-Free Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation UaGateway. Authentication is required to exploit this vulnerability. The specific flaw exists… | |
| Analizada | Media (6.5) | 1.4% | — | Unified-automation Uagateway | 3/5/2024 | 17/6/2026 | Unified Automation UaGateway OPC UA Server Null Pointer Dereference Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation UaGateway. Authentication is required to exploit this vulnerability. The specific flaw… | |
| Analizada | Media (6.5) | 0.59% | — | Unified-automation Uagateway | 3/5/2024 | 17/6/2026 | Unified Automation UaGateway OPC UA Server Improper Input Validation Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation UaGateway. User interaction is required to exploit this vulnerability in that the… | |
| Modificada | Crítica (9.8) | 1.2% | — | Exagate Sysguard 3001 Firmware | 14/9/2023 | 17/6/2026 | Authentication Bypass by Assumed-Immutable Data vulnerability in Exagate SYSGuard 3001 allows Authentication Bypass. This issue affects SYSGuard 3001: before 3.2.20.0. | |
| Modificada | Media (6.1) | 4.1% | — | Buildagate Project Buildagate | 11/7/2023 | 17/6/2026 | Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code via a crafted script to the mc parameter of the URL. | |
| Modificada | Crítica (9.8) | 13% | — | Seagate Stcg2000300 FirmwareSeagate Stcg3000300 FirmwareSeagate Stcg4000300 Firmware | 6/12/2022 | 17/6/2026 | The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/helpers/mv_backend_helper.php by leveraging the "start" state and sending a check_device_name request. | |
| Modificada | Alta (7.5) | 0.77% | — | Softing EdgeaggregatorSofting EdgeconnectorSofting OPCSofting OPC UA C++ Software Development KIT+2 | 20/10/2022 | 17/6/2026 | An issue was discovered in Softing OPC UA C++ SDK before 6.10. A buffer overflow or an excess allocation happens due to unchecked array and matrix bounds in structure data types. | |
| Modificada | Alta (7.5) | 1.5% | — | Softing EdgeaggregatorSofting EdgeconnectorSofting OPCSofting OPC UA C++ Software Development KIT+2 | 17/8/2022 | 17/6/2026 | A crafted HTTP packet without a content-type header can create a denial-of-service condition in Softing Secure Integration Server V1.22. | |
| Modificada | Media (5.3) | 0.21% | — | Softing EdgeaggregatorSofting EdgeconnectorSofting OPCSofting OPC UA C++ Software Development KIT+2 | 17/8/2022 | 17/6/2026 | Softing Secure Integration Server V1.22 is vulnerable to authentication bypass via a machine-in-the-middle attack. The default the administration interface is accessible via plaintext HTTP protocol, facilitating the attack. The HTTP request may contain the session cookie in the request, which may be captured for use… | |
| Modificada | Alta (7.5) | 1.5% | — | Softing EdgeaggregatorSofting EdgeconnectorSofting OPCSofting OPC UA C++ Software Development KIT+2 | 17/8/2022 | 17/6/2026 | A crafted HTTP packet with a missing HTTP URI can create a denial-of-service condition in Softing Secure Integration Server V1.22. |