Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
66 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.2) | 0.46% | — | AspectAI | 11/8/2025 | 17/6/2026 | The ASPECT system allows users to bypass authentication. This issue affects all versions of ASPECT | |
| Aplazada | Alta (8.2) | 0.33% | — | AspectAI | 11/8/2025 | 17/6/2026 | A denial-of-service (DoS) attack is possible if access to the local network is provided to unauthorized users. This is due to a buffer copy issue that may lead to a software crash. This issue affects all versions of ASPECT. | |
| Aplazada | Crítica (9.3) | 0.61% | — | Aspect FWAI | 11/8/2025 | 17/6/2026 | Due to an issue in configuration, code that was intended for debugging purposes was included in the market release of the ASPECT FW allowing an attacker to bypass authentication. This vulnerability may allow an attacker to change the system time, access files, and make function calls without prior authentication. This… | |
| Aplazada | Alta (8.4) | 0.41% | — | Aspect-enterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI | 23/5/2025 | 17/6/2026 | Stored Absolute Path Traversal vulnerabilities in ASPECT could expose sensitive data if administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*. | |
| Aplazada | Alta (7) | 0.34% | — | Aspect-enterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI | 22/5/2025 | 17/6/2026 | Predictable filename vulnerabilities in ASPECT may expose sensitive information to a potential attacker if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*. | |
| Aplazada | Alta (7.1) | 0.31% | — | Aspect-enterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI | 22/5/2025 | 17/6/2026 | Weak password storage vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*. | |
| Aplazada | Alta (7) | 0.37% | — | Aspect-enterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI | 22/5/2025 | 17/6/2026 | Large content vulnerabilities are present in ASPECT exposing a device to disk overutilization on a system if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*. | |
| Aplazada | Media (4.6) | 0.22% | — | Aspect EnterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI | 22/5/2025 | 17/6/2026 | Stored Cross Site Scripting vulnerabilities exist in ASPECT if administrator creden-tials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*. | |
| Aplazada | Alta (7) | 0.28% | — | Aspect-enterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI | 22/5/2025 | 17/6/2026 | SSRF Server Side Request Forgery vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*. | |
| Aplazada | Alta (8.8) | 0.43% | — | Aspect-enterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI | 22/5/2025 | 17/6/2026 | SSL Verification Bypass vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*. | |
| Aplazada | Crítica (9.4) | 0.37% | — | Aspect-enterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI | 22/5/2025 | 17/6/2026 | 2nd Order SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if administrator credentials become compromised.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*. | |
| Aplazada | Media (5.1) | 0.19% | — | Aspect-enterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI | 22/5/2025 | 17/6/2026 | Serialized configuration information may be disclosed during device commissioning while using ASPECT's configuration toolsetThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*. | |
| Aplazada | Media (6.9) | 0.35% | — | Aspect-enterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI | 22/5/2025 | 17/6/2026 | Sensitive device logger information in ASPECT may be exposed if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*. | |
| Aplazada | Alta (8.7) | 0.41% | — | Aspect EnterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI | 22/5/2025 | 17/6/2026 | Predictable filename vulnerabilities in ASPECT may expose sensitive information to a potential attacker if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*. | |
| Aplazada | Media (6.1) | 0.20% | — | Aspect-enterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI | 22/5/2025 | 17/6/2026 | One way hash with predictable salt vulnerabilities in ASPECT may expose sensitive information to a potential attackerThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*. | |
| Aplazada | Media (6.9) | 0.40% | — | Aspect-enterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI | 22/5/2025 | 17/6/2026 | Log injection vulnerabilities in ASPECT provide attacker access to inject malicious browser scripts if administrator credentials become compromised.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*. | |
| Aplazada | Media (6.9) | 0.37% | — | Aspect-enterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI | 22/5/2025 | 17/6/2026 | Large content vulnerabilities are present in ASPECT exposing a device to disk overutilization on a system if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*. | |
| Aplazada | Media (6.9) | 0.15% | — | Aspect EnterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI | 22/5/2025 | 17/6/2026 | Windows permissions for ASPECT configuration toolsets are not fully secured allow-ing exposure of configuration informationThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*. | |
| Aplazada | Alta (7.1) | 0.37% | — | Aspect-enterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI | 22/5/2025 | 17/6/2026 | Device commissioning parameters in ASPECT may be modified by an external source if administrative credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*. | |
| Aplazada | Alta (7.1) | 1.0% | — | Aspect-enterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI | 22/5/2025 | 17/6/2026 | DLL's are not digitally signed when loaded in ASPECT's configuration toolset exposing the application to binary planting during device commissioning.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*. | |
| Aplazada | Media (6) | 0.35% | — | Aspect-enterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI | 22/5/2025 | 17/6/2026 | File upload vulnerabilities are present in ASPECT if session administrator credentials become compromised This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03. | |
| Aplazada | Alta (8.9) | 0.54% | — | Aspect-enterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI | 22/5/2025 | 17/6/2026 | Remote Code Execution vulnerabilities are present in ASPECT if session administrator credentials become compromised This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03. | |
| Aplazada | Alta (7.3) | 0.32% | — | Aspect-enterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI | 22/5/2025 | 17/6/2026 | System File Deletion vulnerabilities in ASPECT provide attackers access to delete system files if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03. | |
| Aplazada | Media (5.9) | 0.30% | — | Aspect-enterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI | 22/5/2025 | 17/6/2026 | Exposure of file path, file size or file existence vulnerabilities in ASPECT provide attackers access to file system information if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03. | |
| Aplazada | Media (6) | 0.35% | — | Aspect-enterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI | 22/5/2025 | 17/6/2026 | File upload and execute vulnerabilities in ASPECT allow PHP script injection if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03. |