Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2567▼ 333 respecto a la semana anterior
Críticas / altas1341▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.3) | 0.48% | — | Assaabloy Control ID Idsecure | 24/6/2025 | 17/6/2026 | ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to SQL injections which could allow an attacker to leak arbitrary information and insert arbitrary SQL syntax into SQL queries. | |
| Analizada | Alta (8.7) | 0.42% | — | Assaabloy Control ID Idsecure | 24/6/2025 | 17/6/2026 | ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to a server-side request forgery vulnerability which could allow an unauthenticated attacker to retrieve information from other servers. | |
| Analizada | Alta (8.7) | 0.57% | — | Assaabloy Control ID Idsecure | 24/6/2025 | 17/6/2026 | ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to an improper authentication vulnerability which could allow an attacker to bypass authentication and gain permissions in the product. | |
| Modificada | Crítica (9.8) | 1.1% | — | Assaabloy Control ID Idsecure | 5/8/2023 | 17/6/2026 | A SQL injection vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing unauthenticated attackers to write PHP files on the server's root directory, resulting in remote code execution. | |
| Modificada | Crítica (9.8) | 0.86% | — | Assaabloy Control ID Idsecure | 3/8/2023 | 17/6/2026 | Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens, allowing attackers to sign arbitrary session tokens and bypass authentication. | |
| Modificada | Alta (7.5) | 0.64% | — | Assaabloy Control ID Idsecure | 3/8/2023 | 17/6/2026 | An uncaught exception vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to cause the main web server of IDSecure to fault and crash, causing a denial of service. | |
| Modificada | Crítica (9.1) | 0.75% | — | Assaabloy Control ID Idsecure | 3/8/2023 | 17/6/2026 | A path traversal vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to delete arbitrary files on IDSecure filesystem, causing a denial of service. | |
| Modificada | Media (6.5) | 0.55% | — | Assaabloy Control ID Idsecure | 3/8/2023 | 17/6/2026 | Some API routes exists in Control ID IDSecure 4.7.26.0 and prior, exfiltrating sensitive information and passwords to users accessing these API routes. | |
| Modificada | Media (6.1) | 0.36% | — | Assaabloy Control ID Idsecure | 14/4/2023 | 17/6/2026 | A vulnerability has been found in Control iD iDSecure 4.7.29.1 and classified as problematic. This vulnerability affects unknown code of the component Dispositivos Page. The manipulation of the argument IP-DNS leads to cross site scripting. The attack can be initiated remotely. VDB-225922 is the identifier assigned to… |