Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2616▼ 309 respecto a la semana anterior
Críticas / altas1342▲ 71 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.7) | 0.28% | — | Acustica-audio Aquarius | 3/12/2025 | 17/6/2026 | Aquarius Desktop 3.0.069 for macOS contains an insecure file handling vulnerability in its support data archive generation feature. The application follows symbolic links placed inside the ~/Library/Logs/Aquarius directory and treats them as regular files. When building the support ZIP, Aquarius recursively enumerates… | |
| Analizada | Media (5.1) | 0.17% | — | Acustica-audio Aquarius Helpertool | 3/12/2025 | 17/6/2026 | The Aquarius HelperTool (1.0.003) privileged XPC service on macOS contains multiple flaws that allow local privilege escalation. The service accepts XPC connections from any local process without validating the client's identity, and its authorization logic incorrectly calls AuthorizationCopyRights with a NULL… | |
| Modificada | Media (6.2) | 0.20% | — | Acustica-audio Aquarius | 3/12/2025 | 5/7/2026 | Aquarius Desktop 3.0.069 for macOS stores user authentication credentials in the local file ~/Library/Application Support/Aquarius/aquarius.settings using a weak obfuscation scheme. The password is "encrypted" through predictable byte-substitution that can be trivially reversed, allowing immediate recovery of the… | |
| Modificada | Alta (8.8) | 1.5% | — | Terarecon Aquariusnet | 1/9/2021 | 17/6/2026 | NMSAccess32.exe in TeraRecon AQNetClient 4.4.13 allows attackers to execute a malicious binary with SYSTEM privileges via a low-privileged user account. To exploit this, a low-privileged user must change the service configuration or overwrite the binary service. | |
| Modificada | Crítica (9.8) | 1.6% | — | Aquaverde Aquarius CMS | 15/7/2019 | 17/6/2026 | Aquaverde GmbH Aquarius CMS prior to version 4.1.1 is affected by: Incorrect Access Control. The impact is: The access to the log file is not restricted. It contains sensitive information like passwords etc. The component is: log file. The attack vector is: open the file. | |
| Modificada | Alta (7.5) | 1.6% | — | Aquaverde Aquarius CMS | 24/4/2019 | 17/6/2026 | Aquarius CMS through 4.3.5 writes POST and GET parameters (including passwords) to a log file due to an overwriting of configuration parameters under certain circumstances. | |
| Modificada | Alta (7.5) | 1.4% | — | Aquaverde Aquarius CMS | 24/4/2019 | 17/6/2026 | aquaverde Aquarius CMS through 4.3.5 allows Information Exposure through Log Files because of an error in the Log-File writer component. |