Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

325 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.23%⚠ Explotación activaAcronis Backup17/9/202618/9/2026
Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.
AplazadaCrítica (9.8)2.0%—Alseambusher Crontab-uiAI10/8/202628/8/2026
An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker to inject arbitrary cron job entries by sending a crafted GET request to /crontab with URL-encoded newlines in the env_vars parameter.
AplazadaCrítica (9.8)1.9%—Alseambusher Crontab-uiAI10/8/202628/8/2026
An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker to execute arbitrary system commands by importing a crafted crontab database file. The POST /import endpoint accepts arbitrary .db files and overwrites the application database without validation.
AplazadaAlta (8.3)0.44%—Omicronenergy StationscoutAI6/8/20263/9/2026
OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may allow an unauthenticated attacker to forge valid authentication credentials, bypass authentication and authorization, and impersonate legitimate clients. An attacker can…
AplazadaBaja (1.3)0.24%—Omicronenergy StationguardAI6/8/20263/9/2026
OMICRON StationGuard 4.00 contains an improper input validation vulnerability in its IEC 61850 Sampled Values (SV) frame processing. A specially crafted SV frame can cause the affected process to terminate, disrupting alert processing for Sampled Values traffic. The vulnerability does not affect overall system…
AplazadaAlta (8.1)0.42%—Omicronenergy StationguardAI6/8/20263/9/2026
OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may allow an unauthenticated attacker to forge valid authentication credentials, bypass authentication and authorization, and impersonate legitimate clients. An attacker can…
AplazadaAlta (7.1)0.57%—Vacron Vin-ds783e-e6AI29/7/202630/7/2026
VIN-DS783E-E6 developed by Vacron has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.
AplazadaCrítica (9.3)0.69%—Vacron Vin-ds783e-e6AI29/7/202630/7/2026
VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers to exploit a specific hidden function to obtain the administrator credentials of the device.
AplazadaAlta (7.3)0.15%—Acronis Devicelock DLPAI3/6/202622/7/2026
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.
AplazadaAlta (7.3)0.15%—Acronis Devicelock DLPAI3/6/202622/7/2026
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.
AplazadaAlta (7.3)0.15%—Acronis Devicelock DLPAI3/6/202622/7/2026
Local privilege escalation due to EXE hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.
AplazadaAlta (7.3)0.15%—Acronis Devicelock DLPAI3/6/202622/7/2026
Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.
AplazadaBaja (3.7)0.33%—Micronaut FrameworkAI12/5/202617/6/2026
Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Prior to 4.10.22, the bundleCache is keyed by (Locale, baseName) where the locale originates from the HTTP Accept-Language header. In applications that explicitly register a…
AplazadaAlta (7.5)0.72%—Micronaut FrameworkAI12/5/202610/7/2026
Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. From 4.3.0 to before 4.10.22, 3.10.6, and 3.8.14, TimeConverterRegistrar caches DateTimeFormatter instances in an unbounded ConcurrentHashMap<String, DateTimeFormatter> whose key is derived…
Pendiente de análisisMedia (6.1)0.19%—Sidekiq-cronAI7/5/202617/6/2026
Sidekiq-cron thru 2.3.1, an open-source scheduling add-on for Sidekiq, is vulnerable to a cross-site scripting (xss) vulnerability via crafted URL being rended from cron.erb.
AplazadaAlta (7.8)0.16%—Acronis Devicelock DLPAIAcronis Cyber Protect Cloud AgentAI29/4/202617/6/2026
Local privilege escalation due to improper input validation. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.93212, Acronis Cyber Protect Cloud Agent (Windows) before build 42183.
AplazadaAlta (7.8)0.16%—Acronis Devicelock DLPAIAcronis Cyber Protect Cloud AgentAI29/4/202617/6/2026
Local privilege escalation due to improper input validation. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.93212, Acronis Cyber Protect Cloud Agent (Windows) before build 42183.
AplazadaMedia (6.7)0.13%—Acronis Devicelock DLPAI29/4/202617/6/2026
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.93212.
AplazadaAlta (7.8)0.16%—Acronis True Image OEMAIAcronis True ImageAI10/4/202617/6/2026
Local privilege escalation due to improper handling of environment variables. The following products are affected: Acronis True Image OEM (macOS) before build 42571, Acronis True Image (macOS) before build 42902.
AnalizadaMedia (5.3)0.26%—Cronicle7/4/202620/7/2026
Cronicle is a multi-server task scheduler and runner, with a web based front-end UI. Prior to 0.9.111, jb child processes can include an update_event key in their JSON output. The server applies this directly to the parent event's stored configuration without any authorization check. A low-privilege user who can…
AnalizadaMedia (5.3)0.24%—Cronicle7/4/202624/7/2026
Cronicle is a multi-server task scheduler and runner, with a web based front-end UI. Prior to 0.9.111, a non-admin user with create_events and run_events privileges can inject arbitrary JavaScript through job output fields (html.content, html.title, table.header, table.rows, table.caption). The server stores this data…
AnalizadaMedia (6.7)0.12%—Acronis True Image2/4/202624/7/2026
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis True Image (Windows) before build 42902.
AnalizadaMedia (6.7)0.13%—Acronis True Image2/4/202624/7/2026
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before build 42902.
AnalizadaMedia (6.7)0.13%—Acronis True Image2/4/202624/7/2026
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before build 42902.
AnalizadaCrítica (9.8)0.91%—Fccview Cronmaster1/4/202617/6/2026
Cr*nMaster (cronmaster) is a Cronjob management UI with human readable syntax, live logging and log history for cronjobs. Prior to version 2.2.0, an authentication bypass in middleware allows unauthenticated requests with an invalid session cookie to be treated as authenticated when the middleware’s session-validation…