Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 213 respecto a la semana anterior
Críticas / altas1376▲ 145 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.51%—Arctic Security Arctic HUBAI20/12/202417/6/2026
Server-Side Request Forgery in URL Mapper in Arctic Security's Arctic Hub versions 3.0.1764-5.6.1877 allows an unauthenticated remote attacker to exfiltrate and modify configurations and data.
ModificadaCrítica (9.8)0.88%—ABB Arg600a1220na FirmwareABB Arg600a1230na FirmwareABB Arg600a1240na FirmwareABB Arg600a1260na Firmware+2010/5/202217/6/2026
A vulnerability in ABB ARG600 Wireless Gateway series that could allow an attacker to exploit the vulnerability by remotely connecting to the serial port gateway, and/or protocol converter, depending on the configuration.
ModificadaMedia (6.5)0.33%—Siemens Simatic HMI Basic Panels 1ST GenerationSiemens Simatic HMI Basic Panels 2ND GenerationSiemens Simatic Wincc Runtime AdvancedSiemens Simatic HMI Comfort Panels Firmware+214/7/202017/6/2026
A vulnerability has been identified in SIMATIC HMI Basic Panels 1st Generation (incl. SIPLUS variants) (All versions), SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) (All versions), SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions), SIMATIC HMI KTP700F Mobile Arctic (All versions),…
ModificadaAlta (7.5)1.1%—Arctic Torrent Project Arctic Torrent6/2/202016/6/2026
A vulnerability exists in Arctic Torrent 1.4 via unspecified vectors in .torrent file handling, which could let a malicious user cause a Denial of Service.
ModificadaAlta (7.5)1.2%—Licensepal Arcticdesk13/1/201517/6/2026
SQL injection vulnerability in the ticket grid in the admin interface in LicensePal ArcticDesk before 1.2.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (4.3)1.1%—Licensepal Arcticdesk13/1/201517/6/2026
Cross-site scripting (XSS) vulnerability in the frontend interface in LicensePal ArcticDesk before 1.2.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5)1.9%—Licensepal Arcticdesk13/1/201517/6/2026
Directory traversal vulnerability in LicensePal ArcticDesk before 1.2.5 allows remote attackers to read arbitrary files via unspecified vectors.
ModificadaMedia (5)1.3%—Michael Armbruster Arctic FOX CMS23/9/201116/6/2026
Arctic Fox CMS 0.9.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by acp/includes/edit.inc.php and certain other files.
ModificadaAlta (7.5)1.2%—Boldfx Arctic Issue Tracker17/12/200916/6/2026
SQL injection vulnerability in index.php in Arctic Issue Tracker 2.1.1 allows remote attackers to execute arbitrary SQL commands via the (1) matchings[id] or (2) matchings[title] parameters in a Login action to an unspecified program, or (3) the matchings[id] parameter in a search action to index.php, a different…
ModificadaAlta (7.5)2.3%—Arctictracker Arctic Issue Tracker21/7/200816/6/2026
SQL injection vulnerability in index.php in Arctic Issue Tracker 2.0.0 allows remote attackers to execute arbitrary SQL commands via the filter parameter.
ModificadaBaja (2.6)1.4%—Olate Arctic3/7/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Arctic 1.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the query parameter in a search cmd.