Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2585▼ 303 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.58% | — | Themerex BeaconAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Beacon beacon allows PHP Local File Inclusion.This issue affects Beacon: from n/a through <= 2.24. | |
| Aplazada | Alta (8) | 0.42% | — | BeaconAI | 2/2/2026 | 17/6/2026 | The unified WEBUI application of the ONT/Beacon device contains an input handling flaw that allows authenticated users to trigger unintended system-level command execution. Due to insufficient validation of user-supplied data, a low-privileged authenticated attacker may be able to execute arbitrary commands on the… | |
| Aplazada | Media (5.9) | 0.17% | — | Janhenckels Wp-dashboard-beaconAI | 31/12/2025 | 23/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in janhenckens Dashboard Beacon wp-dashboard-beacon allows Stored XSS.This issue affects Dashboard Beacon: from n/a through <= 1.2.0. | |
| Aplazada | Media (4.3) | 0.17% | — | Syedbalkhi Beacon Lead Magnets AND Lead CaptureAI | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Beacon Lead Magnets and Lead Capture beacon-by allows Cross Site Request Forgery.This issue affects Beacon Lead Magnets and Lead Capture: from n/a through <= 1.5.8. | |
| Aplazada | Alta (7.1) | 0.29% | — | Syedbalkhi Beacon Lead Magnets AND Lead CaptureAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi Beacon Lead Magnets and Lead Capture beacon-by allows Reflected XSS.This issue affects Beacon Lead Magnets and Lead Capture: from n/a through <= 1.5.7. | |
| Aplazada | Media (6.5) | 0.38% | — | DAN Griffiths Beacon FOR HelpscoutAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Griffiths Beacon For Help Scout beacon-for-helpscout allows DOM-Based XSS.This issue affects Beacon For Help Scout: from n/a through <= 1.3.0. | |
| Modificada | Media (5.5) | 0.23% | — | Flexera Flexnet Inventory Agent AND Beacon | 21/9/2021 | 17/6/2026 | An issue related to modification of otherwise restricted files through a locally authenticated attacker exists in FlexNet inventory agent and inventory beacon versions 2020 R2.5 and prior. | |
| Modificada | Crítica (9.8) | 1.4% | — | Beaconmedaes Scroll Medical AIR Systems Firmware | 6/6/2018 | 17/6/2026 | In the web application in BeaconMedaes TotalAlert Scroll Medical Air Systems running software versions prior to 4107600010.23, passwords are presented in plaintext in a file that is accessible without authentication. | |
| Modificada | Alta (7.5) | 1.3% | — | Beaconmedaes Scroll Medical AIR Systems Firmware | 24/5/2018 | 17/6/2026 | In TotalAlert Web Application in BeaconMedaes Scroll Medical Air Systems prior to v4107600010.23, by accessing a specific uniform resource locator (URL) on the webserver, a malicious user may be able to access information in the application without authenticating. | |
| Modificada | Crítica (9.8) | 1.3% | — | Beaconmedaes Scroll Medical AIR Systems Firmware | 24/5/2018 | 17/6/2026 | In TotalAlert Web Application in BeaconMedaes Scroll Medical Air Systems prior to v4107600010.23, an attacker with network access to the integrated web server could retrieve default or user defined credentials stored and transmitted in an insecure manner. | |
| Modificada | Alta (7.5) | 2.8% | — | Beacon | 14/5/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in language/1/splash.lang.php in Beacon 0.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the languagePath parameter. |