Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.40% | — | Dos-osaka SS1AI | 28/8/2025 | 17/6/2026 | Use of hard-coded password issue/vulnerability in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to view arbitrary files with root privileges. | |
| Aplazada | Alta (8.7) | 0.62% | — | Dos-osaka SS1AI | 28/8/2025 | 17/6/2026 | Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If this vulnerability is exploited, arbitrary files may be viewed by a remote unauthenticated attacker. | |
| Aplazada | Alta (7.1) | 0.47% | — | Dos-osaka SS1AI | 28/8/2025 | 17/6/2026 | Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If this vulnerability is exploited, legitimate files may be overwritten by a remote authenticated attacker. | |
| Aplazada | Crítica (9.3) | 0.53% | — | Dos-osaka SS1AI | 28/8/2025 | 17/6/2026 | SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to upload arbitrary files and execute OS commands with SYSTEM privileges. | |
| Aplazada | Crítica (9.3) | 0.53% | — | Dos-osaka SS1AI | 28/8/2025 | 17/6/2026 | SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to upload arbitrary files and execute OS commands with SYSTEM privileges. | |
| Aplazada | Alta (7.3) | 0.12% | — | Dos-osaka SS1AI | 28/8/2025 | 17/6/2026 | Incorrect permission assignment for critical resource issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier), which may allow users who can log in to a client terminal to obtain root privileges. | |
| Aplazada | Media (6.9) | 0.34% | — | Dos-osaka SS1AI | 28/8/2025 | 17/6/2026 | Files or directories accessible to external parties issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If exploited, uploaded files and SS1 configuration files may be accessed by a remote unauthenticated attacker. | |
| Aplazada | Alta (8.7) | 0.18% | — | Dos-osaka SS1AI | 28/8/2025 | 17/6/2026 | Inadequate encryption strength issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If this vulnerability is exploited, a function that requires authentication may be accessed by a remote unauthenticated attacker. | |
| Modificada | Crítica (9.8) | 0.86% | — | Dos-osaka Rakuraku PC Cloud AgentDos-osaka SS1 | 6/3/2023 | 17/6/2026 | Use of hard-coded credentials vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to obtain the password of the debug tool and execute it. As a result of exploiting this vulnerability with CVE-2023-22335 and CVE-2023-22336 vulnerabilities together,… | |
| Modificada | Crítica (9.8) | 1.1% | — | Dos-osaka Rakuraku PC Cloud AgentDos-osaka SS1 | 6/3/2023 | 17/6/2026 | Path traversal vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to upload a specially crafted file to an arbitrary directory. As a result of exploiting this vulnerability with CVE-2023-22335 and CVE-2023-22344 vulnerabilities together, it may… | |
| Modificada | Alta (7.5) | 0.74% | — | Dos-osaka Rakuraku PC Cloud AgentDos-osaka SS1 | 6/3/2023 | 17/6/2026 | Improper access control vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to bypass access restriction and download an arbitrary file of the directory where the product runs. As a result of exploiting this vulnerability with CVE-2023-22336 and… |