Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.2)0.60%—Eclipse 4diac Forte18/6/20262/7/2026
In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling pointer. This allows subsequent commands to access freed memory (use-after-free).
AplazadaMedia (6.9)0.41%—Newtype Infortech NUP PortalAI12/9/202517/6/2026
NUP Portal developed by NewType Infortech has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly upload files. If the attacker manages to bypass the file extension restrictions, they could upload a webshell and execute it on the server side.
AplazadaCrítica (9.3)0.57%—Newtype Infortech NUP PROAI12/9/202517/6/2026
NUP Pro developed by NewType Infortech has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
ModificadaAlta (7.8)0.25%—Fortect27/9/202317/6/2026
Fortect - CWE-428: Unquoted Search Path or Element, may be used by local user to elevate privileges.
ModificadaAlta (8.2)1.3%—CEF Fortessa Ftbtld Firmware25/3/202217/6/2026
Incorrect permissions in the Bluetooth Services in the Fortessa FTBTLD Smart Lock as of 12-13-2022 allows a remote attacker to disable the lock via an unauthenticated edit to the lock name.
ModificadaAlta (7.5)50%—Auerswald Comfortel 3600 IP FirmwareAuerswald Comfortel 2600 IP FirmwareAuerswald Comfortel 1400 IP Firmware13/12/202117/6/2026
Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/../ substring.
ModificadaAlta (7)1.9%—Haikuforteams Diez17/8/202117/6/2026
The @diez/generation npm package is a client for Diez. The locateFont method of @diez/generation has a command injection vulnerability. Clients of the @diez/generation library are unlikely to be aware of this, so they might unwittingly write code that contains a vulnerability. This issue may lead to remote code…
ModificadaAlta (8)4.0%—Auerswald Comfortel 1200 IP Firmware29/5/201917/6/2026
A buffer overflow vulnerability in the DHCP and PPPOE configuration interface of the Auerswald COMfort 1200 IP phone 3.4.4.1-10589 allows a remote attacker (authenticated as simple user in the same network as the device) to trigger remote code execution via a POST request (ManufacturerName parameter) to the web server…
ModificadaAlta (8)4.2%—Auerswald Comfortel 1200 IP Firmware29/5/201917/6/2026
A command injection (missing input validation, escaping) in the ftp upgrade configuration interface on the Auerswald COMfort 1200 IP phone 3.4.4.1-10589 allows an authenticated remote attacker (simple user) -- in the same network as the device -- to trigger OS commands (like starting telnetd or opening a reverse…
ModificadaMedia (5.3)0.41%—Comforte Swap1/3/201817/6/2026
comforte SWAP 1049 through 1069 and 20.0.0 through 21.5.3 (as used in SSLOBJ on HPE NonStop SSL T0910, and in the comforte SecurCS, SecurFTP, SecurLib/SSL-AT, and SecurTN products), after executing the RELOAD CERTIFICATES command, does not ensure that clients use a strong TLS cipher suite, which makes it easier for…
ModificadaMedia (5)1.6%—Fortech Proxy+26/6/200016/6/2026
Fortech Proxy+ allows remote attackers to bypass access restrictions for to the administration service by redirecting their connections through the telnet proxy.
ModificadaAlta (7.5)2.3%—SUN ForteSUN Netbeans Developer23/11/199916/6/2026
Internal HTTP server in Sun Netbeans Java IDE in Netbeans Developer 3.0 Beta and Forte Community Edition 1.0 Beta does not properly restrict access to IP addresses as specified in its configuration, which allows arbitrary remote attackers to access the server.