Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 82 respecto a la semana anterior
Críticas / altas1416▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)100▼ 400 respecto a la semana anterior
869 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.29% | — | Flexible PDF CouponsAI | 30/9/2026 | 30/9/2026 | Contributor Insecure Direct Object References (IDOR) in Flexible PDF Coupons <= 1.14.11 versions. | |
| Aplazada | Media (4.3) | 0.43% | — | Flex ImportAI | 19/9/2026 | 21/9/2026 | The Flex Import plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0. This is due to the license_activate_fleximp() and license_deactivate_fleximp() functions, hooked to the wp_ajax_license_activate_fleximp and wp_ajax_license_deactivate_fleximp AJAX actions, lacking… | |
| Aplazada | Media (4.8) | 0.10% | — | Veritas Netbackup Flex OSAI | 18/9/2026 | 18/9/2026 | An authenticated user with access to the NetBackup Flex OS management shell could read arbitrary files from the underlying operating system by supplying a specially crafted path argument to a diagnostic command. Successful exploitation could expose sensitive system configuration and credential material stored on the… | |
| Aplazada | Crítica (9.4) | 0.34% | — | Veritas Netbackup FlexAI | 18/9/2026 | 18/9/2026 | An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptographic signature verification step of a privileged support command by supplying a specially formed access credential. Successful exploitation grants the attacker an unrestricted root shell with full… | |
| Aplazada | Crítica (9.4) | 0.67% | — | Veritas Netbackup FlexAI | 18/9/2026 | 18/9/2026 | An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could supply a specially crafted input to a privileged administrative command, causing it to execute arbitrary code with root-level permissions. Successful exploitation grants the attacker unrestricted control over the Flex… | |
| Aplazada | Alta (7.2) | 0.54% | — | Flextype CMSAI | 15/9/2026 | 16/9/2026 | Flextype CMS through 1.0.0-alpha.3 fails to properly validate id and new_id parameters in the Entries REST API, allowing API token holders to read, create, or overwrite files outside the entries directory. Attackers can use traversal sequences in API requests to escape the project entries directory and manipulate… | |
| Aplazada | Media (5.3) | 0.29% | — | Flexible Quantity Measurement Price CalculatorAI | 11/9/2026 | 11/9/2026 | Unauthenticated Broken Access Control in Flexible Quantity – Measurement Price Calculator for WooCommerce <= 2.3.21 versions. | |
| Aplazada | Baja (2.4) | 0.18% | — | Flextype CMSAI | 11/9/2026 | 24/9/2026 | Flextype CMS versions 0.9.9 through 1.0.0-alpha.3 fail to HTML-escape plugin directory names in the dependency error page rendered by getValidPluginsDependencies(). Attackers with write access to the plugins directory can create a plugin with HTML characters in its name to execute arbitrary scripts in users' browsers… | |
| Aplazada | Alta (8.2) | 0.56% | — | Flextype CMSAI | 10/9/2026 | 15/9/2026 | Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes. Attackers with access to web server, proxy, or monitoring logs can recover valid API token pairs that grant full API access. | |
| Aplazada | Alta (8.6) | 0.19% | — | Siemens Desigo CC Clickonce ClientAISiemens Desigo CC Flex ClientAISiemens Desigo CC Installed ClientAISiemens Desigo CCAI | 8/9/2026 | 14/9/2026 | A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CC family V8 (All versions), Desigo CC family V9 (All versions), Desigo CC Flex Client V6 (All versions), Desigo CC Flex Client V7 (All versions), Desigo CC Installed Client V6 (All… | |
| Aplazada | Alta (7.1) | 0.61% | — | Flextype CMSAI | 28/8/2026 | 8/9/2026 | Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that allows authenticated attackers with a valid API token to read arbitrary files by passing unsanitized user-supplied input to the Symfony ExpressionLanguage engine via the POST /api/v1/query endpoint. Attackers can leverage… | |
| Aplazada | Alta (8.3) | 0.38% | — | Grav Flex ObjectsAI | 25/8/2026 | 31/8/2026 | Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability in the flex-objects shortcode that allows users with page-edit access to render any registered Flex collection without permission checks. Attackers can place the shortcode in published pages to expose sensitive… | |
| Aplazada | Alta (7.7) | 0.44% | — | PTC Windchill PdmlinkAIPTC FlexplmAI | 20/8/2026 | 9/9/2026 | A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. | |
| Aplazada | Crítica (9.2) | 0.56% | — | PTC WindchillAIPTC FlexplmAI | 20/8/2026 | 9/9/2026 | A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. | |
| Aplazada | Media (6.3) | 0.33% | — | Getgrav Flex ObjectsAI | 19/8/2026 | 9/9/2026 | Grav Flex Objects Plugin allows you to build custom collections of objects. Prior to 1.4.3, the Grav Flex Objects Admin Next API requireFlexPermission() method in classes/Api/FlexApiController.php returns without denying access when a directory blueprint omits config.admin.permissions. An authenticated account with… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Flexible SubscriptionsAI | 19/8/2026 | 20/8/2026 | Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions. | |
| Pendiente de análisis | Alta (7.3) | 0.17% | — | Dell AppsyncAIDell Metro NodeAIDell UCC EdgeAIDell VxrailAI+5 | 18/8/2026 | 20/8/2026 | Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00 and Dell PowerFlex Rack version 4.5.4… | |
| Aplazada | Alta (8.7) | 0.56% | — | Getgrav Flex ObjectsAIGetgrav GravAI | 14/8/2026 | 31/8/2026 | The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerability in its Flex Objects API. FlexApiController::update() checks only the general Flex directory permission and does not apply the additional target/field/super-admin checks enforced by the dedicated Users and… | |
| Aplazada | Alta (8.7) | 0.90% | — | Getgrav GravAIGetgrav Flex ObjectsAI | 14/8/2026 | 8/9/2026 | Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by uploading a ZIP file containing PHP code. Attackers can bypass routine name validation by using array notation instead of string notation,… | |
| Analizada | Alta (8.3) | 0.14% | — | Thermofisher ABI Prism 310 Data Collection SoftwareThermofisher ABI Prism 3100/3100-avant Data Collection SoftwareThermofisher Applied Biosystems 3130 Series Data Collection SoftwareThermofisher Applied Biosystems 3500/3500xl Series Data Collection Software+4 | 5/8/2026 | 26/8/2026 | The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes. | |
| Pendiente de análisis | Alta (7.2) | 0.57% | — | Zyxel ATP Series FirmwareAIZyxel USG Flex Series FirmwareAIZyxel USG Flex 50 Series FirmwareAIZyxel Usg20 VPN Series FirmwareAI | 4/8/2026 | 4/8/2026 | A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 through V5.42 Patch 1, USG FLEX series firmware versions from V4.50 through V5.42 Patch 1, USG FLEX 50(W) series firmware versions from V4.16 through V5.42 Patch 1, and USG20(W)-VPN… | |
| Aplazada | Media (4.3) | 0.41% | — | Uni-yaz FlexcityAI | 21/7/2026 | 28/7/2026 | Improper restriction of excessive authentication attempts vulnerability in Universal Software Inc. FlexCity allows Excessive Allocation. This issue affects FlexCity: from 5.536.0 before 5.542.0. | |
| Aplazada | Media (6.1) | 0.24% | — | Uni-yaz FlexcityAI | 21/7/2026 | 28/7/2026 | URL redirection to untrusted site ('open redirect') vulnerability in Universal Software Inc. FlexCity allows Input Data Manipulation. This issue affects FlexCity: from 5.536.0 before 5.542.0. | |
| Aplazada | Media (6.5) | 0.34% | — | Uni-yaz FlexcityAI | 21/7/2026 | 28/7/2026 | Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FlexCity: from 5.536.0 before 5.542.0. | |
| Aplazada | Baja (2.3) | 0.29% | — | Getgrav GravAIGetgrav Flex-objectsAI | 17/7/2026 | 17/7/2026 | Grav Flex-Objects before version 1.4.3 contains a broken access control vulnerability in the admin-next REST API that allows authenticated users with only api.access permission to perform unauthorized CRUD operations on permission-less directories. Attackers with api.access credentials can create, read, update,… |