Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2684▼ 86 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

7 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.7%—Agilefleet FleetcommanderAgilefleet Fleetcommander Kiosk18/11/201216/6/2026
Agile FleetCommander and FleetCommander Kiosk before 4.08 store database credentials in cleartext, which allows remote attackers to obtain sensitive information via requests to unspecified pages.
ModificadaMedia (5)1.2%—Agilefleet FleetcommanderAgilefleet Fleetcommander Kiosk18/11/201216/6/2026
Agile FleetCommander and FleetCommander Kiosk before 4.08 use an XOR format for password encryption, which makes it easier for context-dependent attackers to obtain sensitive information by reading a key file and the encrypted strings.
ModificadaAlta (7.5)1.9%—Agilefleet FleetcommanderAgilefleet Fleetcommander Kiosk18/11/201216/6/2026
Agile FleetCommander and FleetCommander Kiosk before 4.08 allow remote attackers to execute arbitrary commands via unspecified vectors, related to a "command injection" issue.
ModificadaAlta (10)3.8%—Agilefleet FleetcommanderAgilefleet Fleetcommander Kiosk18/11/201216/6/2026
Multiple unrestricted file upload vulnerabilities in Agile FleetCommander and FleetCommander Kiosk before 4.08 allow remote attackers to execute arbitrary code by uploading a file via an unspecified page.
ModificadaMedia (6.8)0.73%—Agilefleet FleetcommanderAgilefleet Fleetcommander Kiosk18/11/201216/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in Agile FleetCommander and FleetCommander Kiosk before 4.08 allow remote attackers to hijack the authentication of arbitrary users for requests that modify (1) passwords, (2) accounts, or (3) permissions.
ModificadaMedia (4.3)1.0%—Agilefleet FleetcommanderAgilefleet Fleetcommander Kiosk18/11/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Agile FleetCommander and FleetCommander Kiosk before 4.08 allow remote attackers to inject arbitrary web script or HTML via an arbitrary text field.
ModificadaAlta (7.5)1.2%—Agilefleet FleetcommanderAgilefleet Fleetcommander Kiosk18/11/201216/6/2026
Multiple SQL injection vulnerabilities in Agile FleetCommander and FleetCommander Kiosk before 4.08 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.