Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
325 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.23% | ⚠ Explotación activa | Acronis Backup | 17/9/2026 | 18/9/2026 | Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238. | |
| Aplazada | Crítica (9.8) | 2.0% | — | Alseambusher Crontab-uiAI | 10/8/2026 | 28/8/2026 | An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker to inject arbitrary cron job entries by sending a crafted GET request to /crontab with URL-encoded newlines in the env_vars parameter. | |
| Aplazada | Crítica (9.8) | 1.9% | — | Alseambusher Crontab-uiAI | 10/8/2026 | 28/8/2026 | An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker to execute arbitrary system commands by importing a crafted crontab database file. The POST /import endpoint accepts arbitrary .db files and overwrites the application database without validation. | |
| Aplazada | Alta (8.3) | 0.44% | — | Omicronenergy StationscoutAI | 6/8/2026 | 3/9/2026 | OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may allow an unauthenticated attacker to forge valid authentication credentials, bypass authentication and authorization, and impersonate legitimate clients. An attacker can… | |
| Aplazada | Baja (1.3) | 0.24% | — | Omicronenergy StationguardAI | 6/8/2026 | 3/9/2026 | OMICRON StationGuard 4.00 contains an improper input validation vulnerability in its IEC 61850 Sampled Values (SV) frame processing. A specially crafted SV frame can cause the affected process to terminate, disrupting alert processing for Sampled Values traffic. The vulnerability does not affect overall system… | |
| Aplazada | Alta (8.1) | 0.42% | — | Omicronenergy StationguardAI | 6/8/2026 | 3/9/2026 | OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may allow an unauthenticated attacker to forge valid authentication credentials, bypass authentication and authorization, and impersonate legitimate clients. An attacker can… | |
| Aplazada | Alta (7.1) | 0.57% | — | Vacron Vin-ds783e-e6AI | 29/7/2026 | 30/7/2026 | VIN-DS783E-E6 developed by Vacron has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files. | |
| Aplazada | Crítica (9.3) | 0.69% | — | Vacron Vin-ds783e-e6AI | 29/7/2026 | 30/7/2026 | VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers to exploit a specific hidden function to obtain the administrator credentials of the device. | |
| Aplazada | Alta (7.3) | 0.15% | — | Acronis Devicelock DLPAI | 3/6/2026 | 22/7/2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227. | |
| Aplazada | Alta (7.3) | 0.15% | — | Acronis Devicelock DLPAI | 3/6/2026 | 22/7/2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227. | |
| Aplazada | Alta (7.3) | 0.15% | — | Acronis Devicelock DLPAI | 3/6/2026 | 22/7/2026 | Local privilege escalation due to EXE hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227. | |
| Aplazada | Alta (7.3) | 0.15% | — | Acronis Devicelock DLPAI | 3/6/2026 | 22/7/2026 | Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227. | |
| Aplazada | Baja (3.7) | 0.33% | — | Micronaut FrameworkAI | 12/5/2026 | 17/6/2026 | Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Prior to 4.10.22, the bundleCache is keyed by (Locale, baseName) where the locale originates from the HTTP Accept-Language header. In applications that explicitly register a… | |
| Aplazada | Alta (7.5) | 0.72% | — | Micronaut FrameworkAI | 12/5/2026 | 10/7/2026 | Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. From 4.3.0 to before 4.10.22, 3.10.6, and 3.8.14, TimeConverterRegistrar caches DateTimeFormatter instances in an unbounded ConcurrentHashMap<String, DateTimeFormatter> whose key is derived… | |
| Pendiente de análisis | Media (6.1) | 0.19% | — | Sidekiq-cronAI | 7/5/2026 | 17/6/2026 | Sidekiq-cron thru 2.3.1, an open-source scheduling add-on for Sidekiq, is vulnerable to a cross-site scripting (xss) vulnerability via crafted URL being rended from cron.erb. | |
| Aplazada | Alta (7.8) | 0.16% | — | Acronis Devicelock DLPAIAcronis Cyber Protect Cloud AgentAI | 29/4/2026 | 17/6/2026 | Local privilege escalation due to improper input validation. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.93212, Acronis Cyber Protect Cloud Agent (Windows) before build 42183. | |
| Aplazada | Alta (7.8) | 0.16% | — | Acronis Devicelock DLPAIAcronis Cyber Protect Cloud AgentAI | 29/4/2026 | 17/6/2026 | Local privilege escalation due to improper input validation. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.93212, Acronis Cyber Protect Cloud Agent (Windows) before build 42183. | |
| Aplazada | Media (6.7) | 0.13% | — | Acronis Devicelock DLPAI | 29/4/2026 | 17/6/2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.93212. | |
| Aplazada | Alta (7.8) | 0.16% | — | Acronis True Image OEMAIAcronis True ImageAI | 10/4/2026 | 17/6/2026 | Local privilege escalation due to improper handling of environment variables. The following products are affected: Acronis True Image OEM (macOS) before build 42571, Acronis True Image (macOS) before build 42902. | |
| Analizada | Media (5.3) | 0.26% | — | Cronicle | 7/4/2026 | 20/7/2026 | Cronicle is a multi-server task scheduler and runner, with a web based front-end UI. Prior to 0.9.111, jb child processes can include an update_event key in their JSON output. The server applies this directly to the parent event's stored configuration without any authorization check. A low-privilege user who can… | |
| Analizada | Media (5.3) | 0.24% | — | Cronicle | 7/4/2026 | 24/7/2026 | Cronicle is a multi-server task scheduler and runner, with a web based front-end UI. Prior to 0.9.111, a non-admin user with create_events and run_events privileges can inject arbitrary JavaScript through job output fields (html.content, html.title, table.header, table.rows, table.caption). The server stores this data… | |
| Analizada | Media (6.7) | 0.12% | — | Acronis True Image | 2/4/2026 | 24/7/2026 | Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis True Image (Windows) before build 42902. | |
| Analizada | Media (6.7) | 0.13% | — | Acronis True Image | 2/4/2026 | 24/7/2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before build 42902. | |
| Analizada | Media (6.7) | 0.13% | — | Acronis True Image | 2/4/2026 | 24/7/2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before build 42902. | |
| Analizada | Crítica (9.8) | 0.91% | — | Fccview Cronmaster | 1/4/2026 | 17/6/2026 | Cr*nMaster (cronmaster) is a Cronjob management UI with human readable syntax, live logging and log history for cronjobs. Prior to version 2.2.0, an authentication bypass in middleware allows unauthenticated requests with an invalid session cookie to be treated as authenticated when the middleware’s session-validation… |