Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2765▼ 50 respecto a la semana anterior
Críticas / altas1432▲ 200 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)95▼ 405 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.32% | — | Easyvirt DcscopeAIEasyvirt Co2scopeAI | 25/4/2025 | 17/6/2026 | Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.4 and CO2Scope <= 1.3.4 allows remote authenticated attackers to execute arbitrary SQL commands via the (1) timeago, (2) user, (3) filter, (4) target, (5) p1, (6) p2, (7) p3, (8) p4, (9) p5, (10) p6, (11) p7, (12) p8, (13) p9, (14) p10, (15) p11, (16)… | |
| Analizada | Crítica (9.1) | 0.58% | — | Easyvirt Co2scopeEasyvirt Dcscope | 31/1/2025 | 17/6/2026 | Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to /api/auth/login. | |
| Analizada | Crítica (9.8) | 1.1% | — | Easyvirt Co2scopeEasyvirt Dcscope | 31/1/2025 | 17/6/2026 | Code Injection vulnerability in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers to execute arbitrary code to /api/license/sendlicense/. | |
| Analizada | Alta (7.5) | 0.51% | — | Easyvirt Co2scopeEasyvirt Dcscope | 31/1/2025 | 17/6/2026 | Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated attackers, with low privileges, to (1) add an admin user via the /api/user/addalias route; (2) modifiy a user via the /api/user/updatealiasroute; (4) delete users via the /api/user/delalias route; (4)… | |
| Analizada | Crítica (9.8) | 0.66% | — | Easyvirt Co2scopeEasyvirt Dcscope | 31/1/2025 | 17/6/2026 | Weak JWT Secret vulnerabilitiy in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote attackers to generate JWT for privilege escalation. The HMAC secret used for generating tokens is hardcoded as "somerandomaccesstoken". A weak HMAC secret poses a risk because attackers can use the predictable secret to… | |
| Analizada | Alta (8.8) | 0.55% | — | Easyvirt Co2scopeEasyvirt Dcscope | 31/1/2025 | 17/6/2026 | Multiple incorrect access control issues in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated attackers, with low privileges, to (1) add an admin user via the /api/user/addalias route; (2) modifiy a user via the /api/user/updatealias route; (4) delete users via the /api/user/delalias route;… | |
| Analizada | Media (6.5) | 0.50% | — | Easyvirt Co2scopeEasyvirt Dcscope | 31/1/2025 | 17/6/2026 | Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated attackers to execute arbitrary SQL commands via the (1) user parameter to /api/management/findfilterlist; the (2) user or (3) filter parameter to /api/audit/findmetawatcher; the (4) user parameter to… |