Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 29 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.4) | 0.10% | — | NI SystemlinkAINI Systemlink ServerAI | 10/9/2026 | 16/9/2026 | There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive information stored by the system in the clear. This vulnerability affects NI SystemLink and NI SystemLink Server versions prior to 2026 Q3. | |
| Pendiente de análisis | Alta (8.6) | 0.35% | — | NI SystemlinkAINI Systemlink ServerAI | 10/9/2026 | 16/9/2026 | There is an improper access control vulnerability in NI SystemLink that may allow an authenticated user with limited privileges to access host operating system files and directories that should be restricted. This vulnerability affects NI SystemLink and NI SystemLink Server versions prior to 2026 Q3. | |
| Aplazada | Alta (8.7) | 0.85% | — | ArcadedbAIArcadedb-gremlinAI | 19/8/2026 | 8/9/2026 | ArcadeDB before 26.8.1 (arcadedb-gremlin, affected <= 26.7.3) contains a remote code execution vulnerability in its Gremlin query engine. Although the engine defaults to the documented-secure java (gremlin-lang) engine, ArcadeGremlin.executeStatement() silently falls back to the insecure Groovy engine whenever a… | |
| Aplazada | Alta (8.7) | 0.59% | — | Arcadedb-gremlinAI | 18/8/2026 | 8/9/2026 | ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions <= 26.7.3 enforces authentication (SASL PLAIN) but performs no authorization: it never checks database access permissions (canAccessToDatabase) and never binds the authenticated principal into the engine. As a result, any valid server… | |
| Pendiente de análisis | Crítica (9.3) | 0.78% | — | National Instruments Systemlink EnterpriseAI | 29/5/2026 | 22/7/2026 | There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an unauthenticated remote attacker to bypass authentication controls leading to privilege escalation or information disclosure. Successful exploitation requires an attacker to send a specially crafted… | |
| Modificada | Media (5.5) | 0.24% | — | NI SystemlinkNI Flexlogger | 22/7/2024 | 17/6/2026 | An incorrect permission in the installation directory for the shared NI SystemLink Server KeyValueDatabase service may result in information disclosure via local access. This affects NI SystemLink Server 2024 Q1 and prior versions. It also affects NI FlexLogger 2023 Q2 and prior versions which installed this shared… | |
| Modificada | Alta (7.8) | 0.27% | — | NI FlexloggerNI Systemlink | 22/7/2024 | 17/6/2026 | An out-of-date version of Redis shipped with NI SystemLink Server is susceptible to multiple vulnerabilities, including CVE-2022-24834. This affects NI SystemLink Server 2024 Q1 and prior versions. It also affects NI FlexLogger 2023 Q2 and prior versions which installed this shared service. | |
| Analizada | Alta (7.8) | 0.35% | — | Emerson Data Record ADEmerson FlexloggerEmerson G WEB Development SoftwareEmerson Labview NXG+4 | 20/2/2024 | 17/6/2026 | Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ configuration information and potentially enable escalation of privileges. | |
| Analizada | Alta (7.8) | 0.27% | — | Emerson Data Record ADEmerson FlexloggerEmerson G WEB Development SoftwareEmerson Labview NXG+4 | 20/2/2024 | 17/6/2026 | Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.1) | 0.56% | — | NI FlexloggerNI G WEB Development SoftwareNI LabviewNI Static Test Software Suite+1 | 21/4/2022 | 17/6/2026 | There is a cross-site scripting (XSS) vulnerability in an NI Web Server component installed with several NI products. Depending on the product(s) in use, remediation guidance includes: install SystemLink version 2021 R3 or later, install FlexLogger 2022 Q2 or later, install LabVIEW 2021 SP1, install G Web Development… | |
| Modificada | Media (6.1) | 0.67% | — | Auromeera Emli | 11/4/2017 | 17/6/2026 | Cross Site Scripting Vulnerability in core-eMLi in AuroMeera Technometrix Pvt. Ltd. eMLi V1.0 allows an Attacker to send malicious code, generally in the form of a browser-side script, to a different end user via the page parameter to code/student_portal/home.php. The affected versions are eMLi School Management 1.0,… | |
| Modificada | Alta (7.5) | 2.2% | — | Auromeera Emli | 29/3/2017 | 17/6/2026 | HTTP Exploit in eMLi Portal in AuroMeera Technometrix Pvt. Ltd. eMLi allows an Attacker to View Restricted Information or (even more seriously) execute powerful commands on the web server which can lead to a full compromise of the system via Directory Path Traversal, as demonstrated by reading core-emli/Storage. The… | |
| Modificada | Media (4.3) | 1.8% | — | Jason A Donenfeld CgitLars Hjemli Cgit | 9/8/2013 | 16/6/2026 | Directory traversal vulnerability in the cgit_parse_readme function in ui-summary.c in cgit before 0.9.2, when a readme file is set to a filesystem path, allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter. | |
| Modificada | Media (6) | 2.8% | — | Lars Hjemli Cgit | 11/11/2012 | 16/6/2026 | Argument injection vulnerability in syntax-highlighting.sh in cgit 9.0.3 and earlier allows remote authenticated users with permissions to add files to execute arbitrary commands via the --plug-in argument to the highlight command. | |
| Modificada | Media (6.5) | 3.4% | — | Lars Hjemli Cgit | 10/10/2012 | 16/6/2026 | Heap-based buffer overflow in the substr function in parsing.c in cgit 0.9.0.3 and earlier allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via an empty username in the "Author" field in a commit. | |
| Modificada | Baja (3.5) | 1.9% | — | Lars Hjemli Cgit | 3/8/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the print_fileinfo function in ui-diff.c in cgit 0.9.0.2 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the filename associated with the rename hint. | |
| Modificada | Media (5) | 3.7% | — | Lars Hjemli CgitFedoraproject Fedora | 20/3/2011 | 16/6/2026 | Off-by-one error in the convert_query_hexchar function in html.c in cgit.cgi in cgit before 0.8.3.5 allows remote attackers to cause a denial of service (infinite loop) via a string composed of a % (percent) character followed by invalid hex characters, as demonstrated by a %gg sequence. | |
| Modificada | Media (5) | 1.2% | — | Dellsystemlite.scanner Activex Control | 21/2/2011 | 16/6/2026 | The Dell DellSystemLite.Scanner ActiveX control in DellSystemLite.ocx 1.0.0.0 does not properly restrict the values of the WMIAttributesOfInterest property, which allows remote attackers to execute arbitrary WMI Query Language (WQL) statements via a crafted value, as demonstrated by a value that triggers disclosure of… | |
| Modificada | Media (5) | 1.6% | — | Dellsystemlite.scanner Activex Control | 21/2/2011 | 16/6/2026 | Directory traversal vulnerability in the GetData method in the Dell DellSystemLite.Scanner ActiveX control in DellSystemLite.ocx 1.0.0.0 allows remote attackers to read arbitrary files via directory traversal sequences in the fileID parameter. |