Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2528▼ 418 respecto a la semana anterior
Críticas / altas1311▲ 21 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
30 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.24% | — | Iron Mountain Archiving Services EnvisionAI | 28/9/2026 | 28/9/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Iron Mountain Archiving Services Inc. EnVision allows SQL Injection. This issue affects enVision: before 260655. | |
| Aplazada | Media (6.5) | 0.22% | — | Envision Page BuilderAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Plugin Envision Envision Page Builder envision-page-builder allows DOM-Based XSS.This issue affects Envision Page Builder: from n/a through <= 0.22. | |
| Aplazada | Alta (7.5) | 0.35% | — | CBK Soft Software Hardware Electronic Computer Systems Industry AND Trade INC EnvisionAI | 24/10/2025 | 17/6/2026 | Observable Discrepancy, Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in CBK Soft Software Hardware Electronic Computer Systems Industry and Trade Inc. EnVision allows Account Footprinting. This issue affects enVision: before… | |
| Modificada | Crítica (9.8) | 1.1% | — | Ironmountain Envision | 23/9/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Iron Mountain Archiving Services Inc. EnVision allows Command Injection. This issue affects enVision: before 250563. | |
| Aplazada | Media (5.4) | 0.42% | — | Envisionware Computer Access AND Reservation Control SelfcheckAIEnvisionware OnestopAI | 24/6/2024 | 17/6/2026 | An issue in EnvisionWare Computer Access & Reservation Control SelfCheck v1.0 (fixed in OneStop 3.2.0.27184 Hotfix May 2024) allows unauthenticated attackers on the same network to perform a directory traversal. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | Horner Automation Cscape lacks proper validation of user-supplied data when parsing project files (e.g., HMI). This could lead to an out-of-bounds write at CScape_EnvisionRV+0x2e374b. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | Horner Automation Cscape lacks proper validation of user-supplied data when parsing project files (e.g., HMI). This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to potentially execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | The affected product does not properly validate user-supplied data. If a user opens a maliciously formed CSP file, then an attacker could execute arbitrary code within the current process by accessing an uninitialized pointer. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to a stack-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.24% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to a use-after-free vulnerability. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | The affected application lacks proper validation of user-supplied data when parsing font files (e.g., FNT). This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to potentially execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | Horner Automation Cscape lacks proper validation of user-supplied data when parsing project files (e.g., HMI). This could lead to an out-of-bounds write at CScape_EnvisionRV+0x2e3c04. An attacker could leverage this vulnerability to potentially execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | The affected application lacks proper validation of user-supplied data when parsing project files (e.g.., CSP). This could lead to an out-of-bounds read in IO_CFG. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to an out-of-bounds read in the FontManager. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to an out-of-bounds read in Cscape!CANPortMigration. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation Cscape Envision RV | 9/3/2023 | 17/6/2026 | Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds write vulnerability when parsing project (i.e. HMI) files. The product lacks proper validation of user-supplied data, which could result in writes past the end of allocated data structures. An attacker could leverage these vulnerabilities to execute… | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation Cscape Envision RV | 9/3/2023 | 17/6/2026 | Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds write vulnerability when parsing project (i.e. HMI) files. The product lacks proper validation of user-supplied data, which could result in writes past the end of allocated data structures. An attacker could leverage these vulnerabilities to execute… | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation Cscape Envision RV | 9/3/2023 | 17/6/2026 | Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds read vulnerability when parsing project (i.e. HMI) files. The product lacks proper validation of user-supplied data, which could result in reads past the end of allocated data structures. An attacker could leverage these vulnerabilities to execute… | |
| Modificada | Alta (7.1) | 0.71% | — | Hornerautomation Cscape Envisionrv | 25/3/2022 | 17/6/2026 | This vulnerability can be exploited by parsing maliciously crafted project files with Horner Automation Cscape EnvisionRV v4.50.3.1 and prior. The issues result from the lack of proper validation of user-supplied data, which can result in reads and writes past the end of allocated data structures. User interaction is… | |
| Modificada | Media (6.3) | 1.5% | — | RSA Envision | 20/3/2012 | 16/6/2026 | Directory traversal vulnerability in EMC RSA enVision 4.x before 4.1 Patch 4 allows remote authenticated users to have an unspecified impact via unknown vectors. | |
| Modificada | Alta (9.3) | 2.1% | — | RSA Envision | 20/3/2012 | 16/6/2026 | EMC RSA enVision 4.x before 4.1 Patch 4 uses unspecified hardcoded credentials, which makes it easier for remote attackers to obtain access via unknown vectors. | |
| Modificada | Media (6.5) | 1.0% | — | RSA Envision | 20/3/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in EMC RSA enVision 4.x before 4.1 Patch 4 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.9) | 1.3% | — | RSA Envision | 20/3/2012 | 16/6/2026 | EMC RSA enVision 4.x before 4.1 Patch 4 does not properly restrict the number of failed authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack. | |
| Modificada | Media (4.3) | 1.1% | — | RSA Envision | 20/3/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA enVision 4.x before 4.1 Patch 4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 1.1% | — | RSA Envision | 27/1/2012 | 16/6/2026 | EMC RSA enVision 4.0 before SP4 P5 and 4.1 before P3 allows remote attackers to obtain sensitive information about environment variables in the web system via unspecified vectors. |