Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2684▼ 80 respecto a la semana anterior
Críticas / altas1442▲ 302 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

37 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RechazadaSin puntuar——Calix ExosAICalix GS7 XGSAI21/8/202615/9/2026
Rejected reason: Vendor could not replicate the vul, and reporter is unavailable to comment.
Pendiente de análisisAlta (8.7)0.56%—Extremenetworks ExtremexosAI20/7/202621/7/2026
The mv, cp, and rm file utilities exposed within the ExtremeXOS (EXOS) shell environment fail to safely canonicalize paths and follow symbolic links outside of the intended privilege boundary. An attacker with low-privilege CLI access can create a symbolic link that references a privileged filesystem location and then…
Pendiente de análisisAlta (8.7)0.38%—Extremenetworks ExosAI20/7/202621/7/2026
ExtremeXOS (EXOS) uses a challenge-response mechanism to authorize access to the privileged debug-mode function. The challenge value is generated using an insufficiently random source, which under certain conditions may allow an attacker to predict the expected response and activate debug-mode without authorization.…
AplazadaCrítica (9.3)0.66%—Dormakaba Exos 9300AIDormakaba Exos ServerAI26/1/202617/6/2026
The exos 9300 application can be used to configure Access Managers (e.g. 92xx, 9230 and 9290). The configuration is done in a graphical user interface on the dormakaba exos server. As soon as the save button is clicked in exos 9300, the whole configuration is sent to the selected Access Manager via SOAP. The SOAP…
AplazadaMedia (6.8)0.11%—Kaba Exos 9300AI26/1/202617/6/2026
The program libraries (DLL) and binaries used by exos 9300 contain multiple hard-coded secrets. One notable example is the function "EncryptAndDecrypt" in the library Kaba.EXOS.common.dll. This algorithm uses a simple XOR encryption technique combined with a cryptographic key (cryptoKey) to transform each character of…
AplazadaAlta (8.4)0.16%—Kaba Exos 9300AI26/1/202617/6/2026
A local privilege escalation vulnerability has been identified in the Kaba exos 9300 System management application (d9sysdef.exe). Within this application it is possible to specify an arbitrary executable as well as the weekday and start time, when the specified executable should be run with SYSTEM privileges.
AplazadaAlta (8.5)0.18%—Exos 9300AI26/1/202617/6/2026
Exos 9300 instances are using a randomly generated database password to connect to the configured MSSQL server. The password is derived from static random values, which are concatenated to the hostname and a random string that can be read by every user from the registry. This allows an attacker to derive the database…
AplazadaAlta (8.7)0.88%—Kaba Exos 9300AI26/1/202617/6/2026
An RPC service, which is part of exos 9300, is reachable on port 4000, run by the process FSMobilePhoneInterface.exe. This service is used for interprocess communication between services and the Kaba exos 9300 GUI, containing status information about the Access Managers. Interacting with the service does not require…
AplazadaCrítica (9.3)0.88%—Kaba Exos 9300AI26/1/202617/6/2026
Multiple hardcoded credentials have been identified, which are allowed to sign-in to the exos 9300 datapoint server running on port 1004 and 1005. This server is used for relaying status information from and to the Access Managers. This information, among other things, is used to graphically visualize open doors and…
AplazadaCrítica (9.3)1.2%—Exos 9300AI26/1/202617/6/2026
On the exos 9300 server, a SOAP API is reachable on port 8002. This API does not require any authentication prior to sending requests. Therefore, network access to the exos server allows e.g. the creation of arbitrary access log events as well as querying the 2FA PINs associated with the enrolled chip cards.
AplazadaAlta (7.1)0.30%—Flexostudio Flexo-posts-managerAI22/1/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flexostudio flexo-posts-manager flexo-posts-manager allows Reflected XSS.This issue affects flexo-posts-manager: from n/a through <= 1.0001.
AplazadaAlta (7.1)0.22%—Marielav FlexosliderAI6/11/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in marielav flexoslider flexoslider allows Reflected XSS.This issue affects flexoslider: from n/a through <= 1.0004.
AplazadaMedia (4.3)0.14%—Flexostudio Flexo-social-galleryAI14/8/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in flexostudio flexo-social-gallery flexo-social-gallery allows Cross Site Request Forgery.This issue affects flexo-social-gallery: from n/a through <= 1.0006.
AplazadaAlta (7.1)0.26%—Flexostudio Flexo CounterAI27/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flexostudio Flexo Counter flexo-countdown allows Reflected XSS.This issue affects Flexo Counter: from n/a through <= 1.0001.
AplazadaAlta (7.1)0.28%—Flexostudio Flexo SliderAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flexostudio Flexo Slider flexo-slider allows Reflected XSS.This issue affects Flexo Slider: from n/a through <= 1.0013.
AplazadaSin puntuar0.30%—Extremenetworks ExtremexosAI11/11/202417/6/2026
The BGP daemon in Extreme Networks ExtremeXOS (aka EXOS) 30.7.1.1 allows an attacker (who is not on a directly connected network) to cause a denial of service (BGP session reset) because of BGP attribute error mishandling (for attribute 21 and 25). NOTE: the vendor disputes this because it is "evaluating support for…
AnalizadaAlta (8)0.70%—Extremenetworks Extremexos14/5/202417/6/2026
Extreme Networks EXOS before v.22.7 and before v.30.2 was discovered to contain an issue in its Web GUI which fails to restrict URL access, allowing attackers to access sensitive information or escalate privileges.
AnalizadaAlta (8.6)0.73%—Extremenetworks Extremexos3/5/202417/6/2026
In Extreme XOS through 22.6.1.4, a read-only user can escalate privileges to root via a crafted HTTP POST request to the python method of the Machine-to-Machine Interface (MMI).
ModificadaAlta (7.5)0.98%—Extremenetworks Exos16/10/202317/6/2026
A Directory Traversal vulnerability discovered in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, before 22.7, and before 31.7.2 allows attackers to read arbitrary files.
ModificadaCrítica (9.8)0.60%—Extremenetworks Exos16/10/202317/6/2026
An Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, also fixed in 22.7, 31.7.2 allows attackers to gain escalated privileges using crafted telnet commands via Redis server.
ModificadaAlta (8.8)0.27%—Extremenetworks Exos16/10/202317/6/2026
Cross Site Request Forgery (CSRF) vulnerability in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, fixed in 31.7.2 and 32.5.1.5 allows attackers to run arbitrary code and cause other unspecified impacts via /jsonrpc API.
ModificadaAlta (8.8)0.71%—Extremenetworks Exos16/10/202317/6/2026
An issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, before 22.7 and before 31.7.1 allows attackers to gain escalated privileges via crafted HTTP request.
ModificadaAlta (7.5)1.1%—Antisip Exosip212/5/202117/6/2026
A NULL pointer dereference vulnerability exists in eXcall_api.c in Antisip eXosip2 through 5.2.0 when handling certain 3xx redirect responses.
ModificadaMedia (6.1)3.7%—Nexos Project Nexos28/6/202017/6/2026
The Nexos theme through 1.7 for WordPress allows top-map/?search_location= reflected XSS.
ModificadaCrítica (9.8)5.9%—Nexos Project Nexos28/6/202017/6/2026
The Nexos theme through 1.7 for WordPress allows side-map/?search_order= SQL Injection.