Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3064▲ 586 respecto a la semana anterior
Críticas / altas1461▲ 295 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
362 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.5) | 0.36% | — | Mozilla Firefox AndroidAIMozilla Firefox Focus AndroidAI | 4/8/2026 | 18/8/2026 | Information disclosure in Firefox for Android and Firefox Focus for Android. This vulnerability was fixed in Firefox 153.0.3. | |
| Analizada | Alta (8.2) | 0.22% | — | Microfocus Access Manager | 24/6/2026 | 29/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText Access Manager allows Cross-Site Scripting (XSS). This issue affects Access Manager: from 5.1 through 5.1.2. | |
| Analizada | Media (6.3) | 0.30% | — | Microfocus Access Manager | 24/6/2026 | 29/6/2026 | An unauthorized user can modify configuration through API calls that affects the OpenText Access Manager. This issue affects Access Manager before 5.1.3. | |
| Analizada | Alta (7.5) | 0.22% | — | Mozilla FocusMozilla Klar | 9/6/2026 | 23/7/2026 | UXSS in Focus for iOS / Klar Webkit navigation. This vulnerability was fixed in Focus for iOS 151.3.1 and Klar for iOS 151.3.1. | |
| Modificada | Alta (7.5) | 0.40% | — | Mozilla FirefoxMozilla Firefox Focus | 19/5/2026 | 15/7/2026 | Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151. | |
| Analizada | Alta (8.6) | 0.10% | — | Microfocus Operations Agent | 31/3/2026 | 24/7/2026 | A security audit identified a privilege escalation vulnerability in Operations Agent(<=OA 12.29) on Windows. Under specific conditions Operations Agent may run executables from specific writeable locations.Thanks to Manuel Rickli & Philippe Leiser of Oneconsult AG for reporting this vulnerability | |
| Analizada | Media (4.3) | 0.25% | — | Mozilla Firefox Focus | 9/3/2026 | 17/6/2026 | Malicious scripts could display attacker-controlled web content under spoofed domains in Focus for iOS by stalling a _self navigation to an invalid port and triggering an iframe redirect, causing the UI to display a trusted domain without user interaction. This vulnerability was fixed in Focus for iOS 148.2. | |
| Aplazada | Baja (2) | 0.25% | — | EigenfocusAI | 24/11/2025 | 17/6/2026 | A security vulnerability has been detected in Eigenfocus up to 1.4.0. This vulnerability affects unknown code of the component Description Handler. The manipulation of the argument entry.description/time_entry.description leads to cross site scripting. The attack is possible to be carried out remotely. The exploit has… | |
| Aplazada | Crítica (9.3) | 0.52% | — | IBI WebfocusAI | 14/10/2025 | 17/6/2026 | A remote, unauthenticated privilege escalation in ibi WebFOCUS allows an attacker to gain administrative access to the application which may lead to unauthenticated Remote Code Execution | |
| Modificada | Media (6.5) | 0.25% | — | Mozilla Firefox Focus | 16/9/2025 | 17/6/2026 | Opening links via the contextual menu in Focus iOS for certain URL schemes would fail to load but would not refresh the toolbar correctly, allowing attackers to spoof websites if users were coerced into opening a link explicitly through a long-press. This vulnerability was fixed in Focus for iOS 143.0. | |
| Modificada | Alta (8.7) | 7.5% | — | Nsfocusglobal Secgate3600 Firmware | 27/8/2025 | 17/6/2026 | SecGate3600, a network firewall product developed by NSFOCUS, contains a sensitive information disclosure vulnerability in the /cgi-bin/authUser/authManageSet.cgi endpoint. The affected component fails to enforce authentication checks on POST requests to retrieve user data. An unauthenticated remote attacker can… | |
| Modificada | Media (6.1) | 0.17% | — | Mozilla Firefox Focus | 19/8/2025 | 17/6/2026 | Dragging JavaScript links to the URL bar in Focus for iOS could be utilized to run malicious scripts, potentially resulting in XSS attacks. This vulnerability was fixed in Focus for iOS 142. | |
| Modificada | Media (6.1) | 0.16% | — | Mozilla Firefox Focus | 19/8/2025 | 17/6/2026 | Focus for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the content inline, potentially allowing for XSS attacks. This vulnerability was fixed in Focus for iOS 142. | |
| Modificada | Crítica (9.8) | 0.41% | — | Mozilla FirefoxMozilla Firefox Focus | 19/8/2025 | 30/9/2026 | Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range could have used this to trick the user into using their passkey to log the attacker's computer into the target account. This vulnerability was fixed in Firefox for iOS… | |
| Modificada | Media (6.1) | 0.20% | — | Mozilla Firefox Focus | 30/4/2025 | 17/6/2026 | Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick users into thinking they were on a different webpage. This vulnerability was fixed in Focus 138. | |
| Analizada | Crítica (9.8) | 1.1% | — | Microfocus Imanager | 22/11/2024 | 17/6/2026 | Possible Command Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0000. | |
| Analizada | Crítica (9.8) | 0.53% | — | Microfocus Imanager | 22/11/2024 | 17/6/2026 | Possible XML External Entity Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0200. | |
| Analizada | Media (5.4) | 0.29% | — | Microfocus Imanager | 22/11/2024 | 17/6/2026 | Possible XSS in iManager URL for access Component has been discovered in OpenText™ iManager 3.2.6.0000. | |
| Analizada | Crítica (9.8) | 0.45% | — | Microfocus Imanager | 22/11/2024 | 17/6/2026 | Possible External Service Interaction attack in iManager has been discovered in OpenText™ iManager 3.2.6.0000. | |
| Analizada | Media (6.1) | 0.29% | — | Microfocus Imanager | 22/11/2024 | 17/6/2026 | Possible XSS in iManager URL for access Component has been discovered in OpenText™ iManager 3.2.5.0000. | |
| Analizada | Media (6.1) | 0.31% | — | Microfocus Imanager | 22/11/2024 | 17/6/2026 | Possible Reflected Cross-Site Scripting (XSS) Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000. | |
| Analizada | Alta (7.8) | 0.21% | — | Microfocus Imanager | 22/11/2024 | 17/6/2026 | Possible improper input validation Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000. | |
| Analizada | Crítica (9.8) | 1.1% | — | Microfocus Imanager | 22/11/2024 | 17/6/2026 | Possible Command injection Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000. | |
| Analizada | Alta (8.8) | 0.62% | — | Microfocus Imanager | 22/11/2024 | 17/6/2026 | Possible Elevation of Privilege Vulnerability in iManager has been discovered in OpenText™ iManager. This impacts all versions before 3.2.5 | |
| Analizada | Alta (7) | 0.24% | — | Microfocus Arcsight Management CenterMicrofocus Arcsight Platform | 8/11/2024 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Management Center and ArcSight Platform. The vulnerability could be remotely exploited. |