Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 80 respecto a la semana anterior
Críticas / altas1442▲ 302 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Rechazada | Sin puntuar | — | — | Calix ExosAICalix GS7 XGSAI | 21/8/2026 | 15/9/2026 | Rejected reason: Vendor could not replicate the vul, and reporter is unavailable to comment. | |
| Pendiente de análisis | Alta (8.7) | 0.56% | — | Extremenetworks ExtremexosAI | 20/7/2026 | 21/7/2026 | The mv, cp, and rm file utilities exposed within the ExtremeXOS (EXOS) shell environment fail to safely canonicalize paths and follow symbolic links outside of the intended privilege boundary. An attacker with low-privilege CLI access can create a symbolic link that references a privileged filesystem location and then… | |
| Pendiente de análisis | Alta (8.7) | 0.38% | — | Extremenetworks ExosAI | 20/7/2026 | 21/7/2026 | ExtremeXOS (EXOS) uses a challenge-response mechanism to authorize access to the privileged debug-mode function. The challenge value is generated using an insufficiently random source, which under certain conditions may allow an attacker to predict the expected response and activate debug-mode without authorization.… | |
| Aplazada | Crítica (9.3) | 0.66% | — | Dormakaba Exos 9300AIDormakaba Exos ServerAI | 26/1/2026 | 17/6/2026 | The exos 9300 application can be used to configure Access Managers (e.g. 92xx, 9230 and 9290). The configuration is done in a graphical user interface on the dormakaba exos server. As soon as the save button is clicked in exos 9300, the whole configuration is sent to the selected Access Manager via SOAP. The SOAP… | |
| Aplazada | Media (6.8) | 0.11% | — | Kaba Exos 9300AI | 26/1/2026 | 17/6/2026 | The program libraries (DLL) and binaries used by exos 9300 contain multiple hard-coded secrets. One notable example is the function "EncryptAndDecrypt" in the library Kaba.EXOS.common.dll. This algorithm uses a simple XOR encryption technique combined with a cryptographic key (cryptoKey) to transform each character of… | |
| Aplazada | Alta (8.4) | 0.16% | — | Kaba Exos 9300AI | 26/1/2026 | 17/6/2026 | A local privilege escalation vulnerability has been identified in the Kaba exos 9300 System management application (d9sysdef.exe). Within this application it is possible to specify an arbitrary executable as well as the weekday and start time, when the specified executable should be run with SYSTEM privileges. | |
| Aplazada | Alta (8.5) | 0.18% | — | Exos 9300AI | 26/1/2026 | 17/6/2026 | Exos 9300 instances are using a randomly generated database password to connect to the configured MSSQL server. The password is derived from static random values, which are concatenated to the hostname and a random string that can be read by every user from the registry. This allows an attacker to derive the database… | |
| Aplazada | Alta (8.7) | 0.88% | — | Kaba Exos 9300AI | 26/1/2026 | 17/6/2026 | An RPC service, which is part of exos 9300, is reachable on port 4000, run by the process FSMobilePhoneInterface.exe. This service is used for interprocess communication between services and the Kaba exos 9300 GUI, containing status information about the Access Managers. Interacting with the service does not require… | |
| Aplazada | Crítica (9.3) | 0.88% | — | Kaba Exos 9300AI | 26/1/2026 | 17/6/2026 | Multiple hardcoded credentials have been identified, which are allowed to sign-in to the exos 9300 datapoint server running on port 1004 and 1005. This server is used for relaying status information from and to the Access Managers. This information, among other things, is used to graphically visualize open doors and… | |
| Aplazada | Crítica (9.3) | 1.2% | — | Exos 9300AI | 26/1/2026 | 17/6/2026 | On the exos 9300 server, a SOAP API is reachable on port 8002. This API does not require any authentication prior to sending requests. Therefore, network access to the exos server allows e.g. the creation of arbitrary access log events as well as querying the 2FA PINs associated with the enrolled chip cards. | |
| Aplazada | Alta (7.1) | 0.30% | — | Flexostudio Flexo-posts-managerAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flexostudio flexo-posts-manager flexo-posts-manager allows Reflected XSS.This issue affects flexo-posts-manager: from n/a through <= 1.0001. | |
| Aplazada | Alta (7.1) | 0.22% | — | Marielav FlexosliderAI | 6/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in marielav flexoslider flexoslider allows Reflected XSS.This issue affects flexoslider: from n/a through <= 1.0004. | |
| Aplazada | Media (4.3) | 0.14% | — | Flexostudio Flexo-social-galleryAI | 14/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in flexostudio flexo-social-gallery flexo-social-gallery allows Cross Site Request Forgery.This issue affects flexo-social-gallery: from n/a through <= 1.0006. | |
| Aplazada | Alta (7.1) | 0.26% | — | Flexostudio Flexo CounterAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flexostudio Flexo Counter flexo-countdown allows Reflected XSS.This issue affects Flexo Counter: from n/a through <= 1.0001. | |
| Aplazada | Alta (7.1) | 0.28% | — | Flexostudio Flexo SliderAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flexostudio Flexo Slider flexo-slider allows Reflected XSS.This issue affects Flexo Slider: from n/a through <= 1.0013. | |
| Aplazada | Sin puntuar | 0.30% | — | Extremenetworks ExtremexosAI | 11/11/2024 | 17/6/2026 | The BGP daemon in Extreme Networks ExtremeXOS (aka EXOS) 30.7.1.1 allows an attacker (who is not on a directly connected network) to cause a denial of service (BGP session reset) because of BGP attribute error mishandling (for attribute 21 and 25). NOTE: the vendor disputes this because it is "evaluating support for… | |
| Analizada | Alta (8) | 0.70% | — | Extremenetworks Extremexos | 14/5/2024 | 17/6/2026 | Extreme Networks EXOS before v.22.7 and before v.30.2 was discovered to contain an issue in its Web GUI which fails to restrict URL access, allowing attackers to access sensitive information or escalate privileges. | |
| Analizada | Alta (8.6) | 0.73% | — | Extremenetworks Extremexos | 3/5/2024 | 17/6/2026 | In Extreme XOS through 22.6.1.4, a read-only user can escalate privileges to root via a crafted HTTP POST request to the python method of the Machine-to-Machine Interface (MMI). | |
| Modificada | Alta (7.5) | 0.98% | — | Extremenetworks Exos | 16/10/2023 | 17/6/2026 | A Directory Traversal vulnerability discovered in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, before 22.7, and before 31.7.2 allows attackers to read arbitrary files. | |
| Modificada | Crítica (9.8) | 0.60% | — | Extremenetworks Exos | 16/10/2023 | 17/6/2026 | An Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, also fixed in 22.7, 31.7.2 allows attackers to gain escalated privileges using crafted telnet commands via Redis server. | |
| Modificada | Alta (8.8) | 0.27% | — | Extremenetworks Exos | 16/10/2023 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, fixed in 31.7.2 and 32.5.1.5 allows attackers to run arbitrary code and cause other unspecified impacts via /jsonrpc API. | |
| Modificada | Alta (8.8) | 0.71% | — | Extremenetworks Exos | 16/10/2023 | 17/6/2026 | An issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, before 22.7 and before 31.7.1 allows attackers to gain escalated privileges via crafted HTTP request. | |
| Modificada | Alta (7.5) | 1.1% | — | Antisip Exosip2 | 12/5/2021 | 17/6/2026 | A NULL pointer dereference vulnerability exists in eXcall_api.c in Antisip eXosip2 through 5.2.0 when handling certain 3xx redirect responses. | |
| Modificada | Media (6.1) | 3.7% | — | Nexos Project Nexos | 28/6/2020 | 17/6/2026 | The Nexos theme through 1.7 for WordPress allows top-map/?search_location= reflected XSS. | |
| Modificada | Crítica (9.8) | 5.9% | — | Nexos Project Nexos | 28/6/2020 | 17/6/2026 | The Nexos theme through 1.7 for WordPress allows side-map/?search_order= SQL Injection. |