Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.2) | 0.60% | — | Eclipse 4diac Forte | 18/6/2026 | 2/7/2026 | In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling pointer. This allows subsequent commands to access freed memory (use-after-free). | |
| Aplazada | Media (6.9) | 0.41% | — | Newtype Infortech NUP PortalAI | 12/9/2025 | 17/6/2026 | NUP Portal developed by NewType Infortech has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly upload files. If the attacker manages to bypass the file extension restrictions, they could upload a webshell and execute it on the server side. | |
| Aplazada | Crítica (9.3) | 0.57% | — | Newtype Infortech NUP PROAI | 12/9/2025 | 17/6/2026 | NUP Pro developed by NewType Infortech has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Modificada | Alta (7.8) | 0.25% | — | Fortect | 27/9/2023 | 17/6/2026 | Fortect - CWE-428: Unquoted Search Path or Element, may be used by local user to elevate privileges. | |
| Modificada | Alta (8.2) | 1.3% | — | CEF Fortessa Ftbtld Firmware | 25/3/2022 | 17/6/2026 | Incorrect permissions in the Bluetooth Services in the Fortessa FTBTLD Smart Lock as of 12-13-2022 allows a remote attacker to disable the lock via an unauthenticated edit to the lock name. | |
| Modificada | Alta (7.5) | 50% | — | Auerswald Comfortel 3600 IP FirmwareAuerswald Comfortel 2600 IP FirmwareAuerswald Comfortel 1400 IP Firmware | 13/12/2021 | 17/6/2026 | Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/../ substring. | |
| Modificada | Alta (7) | 1.9% | — | Haikuforteams Diez | 17/8/2021 | 17/6/2026 | The @diez/generation npm package is a client for Diez. The locateFont method of @diez/generation has a command injection vulnerability. Clients of the @diez/generation library are unlikely to be aware of this, so they might unwittingly write code that contains a vulnerability. This issue may lead to remote code… | |
| Modificada | Alta (8) | 4.0% | — | Auerswald Comfortel 1200 IP Firmware | 29/5/2019 | 17/6/2026 | A buffer overflow vulnerability in the DHCP and PPPOE configuration interface of the Auerswald COMfort 1200 IP phone 3.4.4.1-10589 allows a remote attacker (authenticated as simple user in the same network as the device) to trigger remote code execution via a POST request (ManufacturerName parameter) to the web server… | |
| Modificada | Alta (8) | 4.2% | — | Auerswald Comfortel 1200 IP Firmware | 29/5/2019 | 17/6/2026 | A command injection (missing input validation, escaping) in the ftp upgrade configuration interface on the Auerswald COMfort 1200 IP phone 3.4.4.1-10589 allows an authenticated remote attacker (simple user) -- in the same network as the device -- to trigger OS commands (like starting telnetd or opening a reverse… | |
| Modificada | Media (5.3) | 0.41% | — | Comforte Swap | 1/3/2018 | 17/6/2026 | comforte SWAP 1049 through 1069 and 20.0.0 through 21.5.3 (as used in SSLOBJ on HPE NonStop SSL T0910, and in the comforte SecurCS, SecurFTP, SecurLib/SSL-AT, and SecurTN products), after executing the RELOAD CERTIFICATES command, does not ensure that clients use a strong TLS cipher suite, which makes it easier for… | |
| Modificada | Media (5) | 1.6% | — | Fortech Proxy+ | 26/6/2000 | 16/6/2026 | Fortech Proxy+ allows remote attackers to bypass access restrictions for to the administration service by redirecting their connections through the telnet proxy. | |
| Modificada | Alta (7.5) | 2.3% | — | SUN ForteSUN Netbeans Developer | 23/11/1999 | 16/6/2026 | Internal HTTP server in Sun Netbeans Java IDE in Netbeans Developer 3.0 Beta and Forte Community Edition 1.0 Beta does not properly restrict access to IP addresses as specified in its configuration, which allows arbitrary remote attackers to access the server. |