Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 213 respecto a la semana anterior
Críticas / altas1376▲ 145 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.67% | — | Blueaccesstech Cobalt X1 | 6/1/2026 | 5/7/2026 | Blue Access Cobalt v02.000.195 suffers from an authentication bypass vulnerability, which allows an attacker to selectively proxy requests in order to operate functionality on the web application without the need to authenticate with legitimate credentials. | |
| Aplazada | Media (6.5) | 0.30% | — | Blueaccesstech Cobalt X1AI | 5/8/2025 | 17/6/2026 | An Authentication Bypass vulnerability in Blue Access' Cobalt X1 thru 02.000.187 allows an unauthorized attacker to log into the application as an administrator without valid credentials. | |
| Aplazada | Alta (7.9) | 0.19% | — | Sandisk PrivateaccessAI | 13/3/2024 | 17/6/2026 | A potential DLL hijacking vulnerability in the SanDisk PrivateAccess application for Windows that could lead to arbitrary code execution in the context of the system user. This vulnerability is only exploitable locally if an attacker has access to a copy of the user's vault or has already gained access into a user's… | |
| Modificada | Alta (7.4) | 0.31% | — | Westerndigital Sandisk Privateaccess | 24/3/2023 | 17/6/2026 | SanDisk PrivateAccess versions prior to 6.4.9 support insecure TLS 1.0 and TLS 1.1 protocols which are susceptible to man-in-the-middle attacks thereby compromising confidentiality and integrity of data. | |
| Modificada | Alta (8.8) | 0.42% | — | Theaccessgroup Corehr Core Portal | 9/6/2022 | 17/6/2026 | A vulnerability was found in CoreHR Core Portal up to 27.0.7. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site request forgery. It is possible to launch the attack remotely. Upgrading to version 27.0.8 is able to address this issue. It is recommended to… | |
| Modificada | Media (5.4) | 0.61% | — | Collectiveaccess Providence | 23/5/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository collectiveaccess/providence prior to 1.8. | |
| Modificada | Alta (8.1) | 14% | — | Zendesk ENC DatavaultZendesk ENC VaultapiSandisk Secureaccess | 22/12/2021 | 17/6/2026 | ENC DataVault before 7.2 and VaultAPI v67 mishandle key derivation, making it easier for attackers to determine the passwords of all DataVault users (across USB drives sold under multiple brand names). | |
| Modificada | Crítica (9.8) | 4.6% | — | Synology Safeaccess | 30/11/2020 | 17/6/2026 | SQL injection vulnerability in request.cgi in Synology SafeAccess before 1.2.3-0234 allows remote attackers to execute arbitrary SQL commands via the domain parameter. | |
| Modificada | Media (4.8) | 5.2% | — | Synology Safeaccess | 30/11/2020 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Synology SafeAccess before 1.2.3-0234 allow remote attackers to inject arbitrary web script or HTML via the (1) domain or (2) profile parameter. | |
| Modificada | Alta (7.5) | 11% | — | Genieaccess Wip3bvaf Firmware | 17/6/2019 | 17/6/2026 | Genie Access WIP3BVAF WISH IP 3MP IR Auto Focus Bullet Camera devices through 3.x are vulnerable to directory traversal via the web interface, as demonstrated by reading /etc/shadow. NOTE: this product is discontinued, and its final firmware version has this vulnerability (4.x versions exist only for other Genie… | |
| Modificada | Media (4.3) | 0.42% | — | Sandisk Secureaccess | 16/11/2017 | 17/6/2026 | SanDisk Secure Access 3.01 vault decrypts and copies encrypted files to a temporary folder, where they can remain indefinitely in certain situations, such as if the file is being edited when the user exits the application or if the application crashes. | |
| Modificada | Media (6.9) | 0.46% | — | Cimon CmnviewCimon Ultimateaccess | 14/3/2015 | 17/6/2026 | Untrusted search path vulnerability in CmnView.exe in CIMON CmnView 2.14.0.1 and 3.x before UltimateAccess 3.02 allows local users to gain privileges via a Trojan horse DLL in the current working directory. | |
| Modificada | Media (5.8) | 1.2% | — | Danielkorte Nodeaccesskeys | 2/6/2014 | 16/6/2026 | The Node Access Keys module 7.x-1.x before 7.x-1.1 for Drupal does not properly check permissions, which allows remote attackers to bypass access restrictions via a node listing. | |
| Modificada | Media (4.3) | 0.93% | — | Collectiveaccess PawtucketCollectiveaccess Providence | 20/11/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in CollectiveAccess Providence and Pawtucket before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.8) | 1.3% | — | Node Access User Reference Project Nodeaccess Userreference Module | 28/8/2013 | 16/6/2026 | The Node access user reference module 6.x-3.x before 6.x-3.5 and 7.x-3.x before 7.x-3.10 for Drupal does not properly restrict access to content containing a user reference field when the author update/delete grants are enabled and the author's user account is deleted, which allows remote attackers to modify the… | |
| Modificada | Alta (10) | 1.7% | — | S2sys NetboxLinearcorp Emerge 50Linearcorp Emerge 5000Sonitrol Eaccess | 25/6/2010 | 16/6/2026 | The S2 Security NetBox 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, uses a weak hash algorithm for storing the Administrator password, which makes it easier for context-dependent attackers to obtain privileged access by recovering the cleartext of this password. | |
| Modificada | Media (5) | 1.4% | — | S2sys NetboxLinearcorp Emerge 50Linearcorp Emerge 5000Sonitrol Eaccess | 25/6/2010 | 16/6/2026 | The S2 Security NetBox, possibly 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, does not require setting a password for the FTP server that stores database backups, which makes it easier for remote attackers to download backup files via unspecified FTP requests. | |
| Modificada | Media (5) | 1.9% | — | S2sys NetboxLinearcorp Emerge 50Linearcorp Emerge 5000Sonitrol Eaccess | 25/6/2010 | 16/6/2026 | The S2 Security NetBox, possibly 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, does not properly prevent downloading of database backups, which allows remote attackers to obtain sensitive information via requests for full_*.dar files with predictable filenames. | |
| Modificada | Media (5) | 2.5% | — | S2sys NetboxLinearcorp Emerge 50Linearcorp Emerge 5000Sonitrol Eaccess | 25/6/2010 | 16/6/2026 | The S2 Security NetBox 2.5, 3.3, and 4.0, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, stores sensitive information under the web root with insufficient access control, which allows remote attackers to download node logs, photographs of persons, and backup files via unspecified HTTP requests. | |
| Modificada | Alta (7.5) | 1.4% | — | Drupal Nodeaccess Userreference | 1/5/2009 | 16/6/2026 | The Node Access User Reference module 5.x before 5.x-2.0-beta4 and 6.x before 6.x-2.0-beta6, a module for Drupal, interprets an empty CCK user reference as a reference to the anonymous user, which might allow remote attackers to bypass intended access restrictions to read or modify a node. | |
| Modificada | Baja (2.1) | 0.21% | — | Securecomputing Safeword Remoteaccess | 17/10/2006 | 16/6/2026 | Secure Computing SafeWord RemoteAccess 2.1 allows local users to obtain the UserCenter webportal password, database encryption keys, and signing keys by reading (1) base-64 encoded data in SERVERS\Web\Tomcat\usercenter\WEB-INF\login.conf and (2) plaintext data in SERVERS\Shared\signers.cfg. NOTE: the provenance of… |