Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2750▲ 27 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
266 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7) | 0.34% | — | BR Industrial Automation Gmbh Mapp AuditAIBR Industrial Automation Gmbh Mapp ServicesAI | 3/9/2026 | 3/9/2026 | Use of Weak Credentials vulnerability in B&R Industrial Automation GmbH mapp Audit used in mapp Services. This issue affects mapp Audit used in mapp Services: before 6.8.0. | |
| Aplazada | Alta (8.5) | 0.21% | — | Better-npm-auditAI | 22/8/2026 | 24/9/2026 | better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by interpolating the user-supplied --registry option into a command string in src/handlers/handleInput.ts without validation or quoting, then passes that string to child_process.exec() in index.ts, which spawns a shell. A… | |
| Pendiente de análisis | Crítica (10) | 4.7% | — | Zohocorp Manageengine Adaudit PlusAI | 23/7/2026 | 24/7/2026 | Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API. | |
| Analizada | Alta (7.8) | 0.26% | — | Adobe Audition | 14/7/2026 | 28/8/2026 | Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.26% | — | Adobe Audition | 14/7/2026 | 28/8/2026 | Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.26% | — | Adobe Audition | 14/7/2026 | 28/8/2026 | Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Media (5.5) | 0.26% | — | Adobe Audition | 14/7/2026 | 28/8/2026 | Audition is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.26% | — | Adobe Audition | 14/7/2026 | 28/8/2026 | Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.26% | — | Adobe Audition | 14/7/2026 | 28/8/2026 | Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Aplazada | Alta (7.5) | 0.42% | — | Johnson AND Johnson Audit Tracking Management SystemAI | 26/6/2026 | 26/6/2026 | Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21 allows viewing of meeting minutes and transcripts. | |
| Pendiente de análisis | Crítica (9) | 2.5% | — | Manageengine Adselfservice PlusAIManageengine Recoverymanager PlusAIManageengine M365 Manager PlusAIManageengine Adaudit PlusAI | 23/6/2026 | 24/6/2026 | In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover. | |
| Aplazada | Alta (8.7) | 0.57% | — | Openfind MailgatesAIOpenfind MailauditAI | 16/4/2026 | 17/6/2026 | MailGates/MailAudit developed by Openfind has a CRLF Injection vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read system files. | |
| Aplazada | Crítica (9.3) | 0.98% | — | Openfind MailgatesAIOpenfind MailauditAI | 16/4/2026 | 17/6/2026 | MailGates/MailAudit developed by Openfind has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and execute arbitrary code. | |
| Analizada | Media (6.9) | 0.20% | — | Nsasoft Blueauditor | 12/4/2026 | 17/6/2026 | BlueAuditor 1.7.2.0 contains a buffer overflow vulnerability in the registration key field that allows local attackers to crash the application by submitting an oversized key value. Attackers can trigger a denial of service by entering a 256-byte buffer of repeated characters in the Key registration field, causing the… | |
| Analizada | Media (6.9) | 0.24% | — | Nsasoft Spotauditor | 5/4/2026 | 24/7/2026 | SpotAuditor 3.6.7 contains a local buffer overflow vulnerability in the Base64 Password Decoder component that allows attackers to crash the application. Attackers can supply an oversized Base64 string through the decoder interface to trigger a denial of service condition. | |
| Analizada | Alta (8.6) | 0.25% | — | Nsasoft Nsauditor | 26/3/2026 | 17/6/2026 | Nsauditor 3.0.28.0 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input to the DNS Lookup tool. Attackers can craft a payload with SEH chain overwrite and inject shellcode through the DNS Query field to achieve code… | |
| Analizada | Media (6.9) | 0.24% | — | Nsasoft Nsauditor | 22/3/2026 | 17/6/2026 | NSauditor 3.1.2.0 contains a buffer overflow vulnerability in the SNMP Auditor Community field that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a large payload into the Community field and trigger the Walk function to cause a denial of service condition. | |
| Analizada | Media (6.9) | 0.19% | — | Nsasoft Spotauditor | 22/3/2026 | 17/6/2026 | SpotAuditor 5.2.6 contains a denial of service vulnerability in the registration dialog that allows local attackers to crash the application by supplying an excessively long string in the Name field. Attackers can paste a buffer of 300 repeated characters into the Name input during registration to trigger an… | |
| Analizada | Crítica (9.3) | 0.80% | — | Dragonsoft Gcb/fcb Government Financial Cybersecurity Configuration Audit Software | 17/3/2026 | 17/6/2026 | GCB/FCB Audit Software developed by DrangSoft has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access certain APIs to create a new administrative account. | |
| Aplazada | Alta (8.8) | 0.24% | — | Data Center AuditAI | 6/3/2026 | 17/6/2026 | Data Center Audit 2.6.2 contains an SQL injection vulnerability in the username parameter of dca_login.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can submit crafted SQL payloads through POST requests to extract sensitive database information including usernames, database… | |
| Aplazada | Media (6.9) | 0.13% | — | Data Center AuditAI | 6/3/2026 | 17/6/2026 | Data Center Audit 2.6.2 contains a cross-site request forgery vulnerability that allows attackers to reset administrator passwords without authentication by submitting crafted POST requests. Attackers can send requests to dca_resetpw.php with parameters updateuser, pass, pass2, and submit_reset to change the admin… | |
| Analizada | Media (6.7) | 0.32% | — | Nsasoft Spotauditor | 20/2/2026 | 29/6/2026 | SpotAuditor 5.3.1.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting excessive data in the registration name field. Attackers can enter a large string of characters (5000 bytes or more) in the name field during registration to trigger an unhandled… | |
| Analizada | Media (5.3) | 0.26% | — | Lintsinghua Deepaudit | 16/2/2026 | 17/6/2026 | A vulnerability was detected in lintsinghua DeepAudit up to 3.0.3. This issue affects some unknown processing of the file backend/app/api/v1/endpoints/embedding_config.py of the component IP Address Handler. Performing a manipulation results in server-side request forgery. It is possible to initiate the attack… | |
| Analizada | Media (6.7) | 0.45% | — | Nsasoft Spotauditor | 12/2/2026 | 17/6/2026 | SpotAuditor 5.3.2 contains a denial of service vulnerability in its Base64 decryption feature that allows attackers to crash the application by supplying an oversized buffer. Attackers can generate a malformed input file with 2000 repeated characters to trigger an application crash when pasted into the Base64… | |
| Analizada | Alta (8.4) | 0.22% | — | Nsasoft Spotauditor | 12/2/2026 | 17/6/2026 | SpotAuditor 5.3.2 contains a local buffer overflow vulnerability in the Base64 Encrypted Password tool that allows attackers to execute arbitrary code by crafting a malicious payload. Attackers can generate a specially crafted Base64 encoded payload to trigger a Structured Exception Handler (SEH) overwrite and execute… |