Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

42 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.5)0.26%—Secomea GatemanagerAI15/9/202618/9/2026
Improper handling of insufficient permissions or privileges vulnerability in Secomea GateManager allows Privilege Escalation. This issue affects GateManager: 11.5;0, 11.4.625515072:0. Fixed in Version 11.6 or 11.4.626194074 and above
Pendiente de análisisAlta (8.3)0.24%—Secomea GatemanagerAI15/9/202618/9/2026
Session fixation vulnerability in Secomea GateManager (webserver module) allows Session Fixation. This issue affects GateManager: 11.5;0, 11.4.625515072:0. Fixed in Version 11.6 or 11.4.626194074 and above
AplazadaMedia (6.5)0.35%—Secomea GatemanagerAI19/3/202617/6/2026
Improper Authentication vulnerability in Secomea GateManager (webserver modules) allows Authentication Bypass.This issue affects GateManager: 11.4;0.
AplazadaBaja (3.5)0.26%—Secomea GatemanagerAI13/12/202417/6/2026
This issue affects: Secomea GateManager Version 9.5 and all prior versions. Protection Mechanism Failure vulnerability in web server of Secomea GateManager to potentially leak information to remote servers.
AplazadaAlta (8.2)0.46%—Secomea GatemanagerAI29/4/202417/6/2026
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Secomea GateManager (webserver modules) allows crash of GateManager.This issue affects GateManager: from 9.7 before 11.2.624095033.
AplazadaAlta (8.1)0.52%—Secomea GatemanagerAI29/4/202417/6/2026
Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Secomea GateManager (Webserver modules) allows Session Hijacking.This issue affects GateManager: before 11.2.624071020.
AplazadaMedia (6.5)0.54%—Secomea GatemanagerAI18/4/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Secomea GateManager (Web GUI) allows Reading Data from System Resources.This issue affects GateManager: from 11.0.623074018 before 11.0.623373051.
ModificadaMedia (4.9)0.52%—Secomea Gatemanager19/4/202317/6/2026
Unprotected Alternate Channel vulnerability in debug console of GateManager allows system administrator to obtain sensitive information.
ModificadaAlta (8.8)0.17%—Secomea Gatemanager19/4/202317/6/2026
Plaintext Storage of a Password vulnerability in Secomea GateManager (USB wizard) allows Authentication abuse on SiteManager, if the generated file is leaked.
ModificadaAlta (7.8)0.18%—Secomea Gatemanager9/12/202217/6/2026
A vulnerability in the web server of Secomea GateManager allows a local user to impersonate as the previous user under some failed login conditions. This issue affects: Secomea GateManager versions from 9.4 through 9.7.
ModificadaAlta (7.2)0.80%—Secomea Gatemanager6/12/202217/6/2026
Improper Input Validation of plugin files in Administrator Interface of Secomea GateManager allows a server administrator to inject code into the GateManager interface. This issue affects: Secomea GateManager versions prior to 10.0.
ModificadaMedia (4.9)0.74%—Secomea Gatemanager4/5/202217/6/2026
Unprotected Alternate Channel vulnerability in debug console of GateManager allows system administrator to obtain sensitive information. This issue affects: GateManager all versions prior to 9.7.
ModificadaMedia (6.7)0.24%—Secomea Gatemanager 4250 FirmwareSecomea Gatemanager 4260 FirmwareSecomea Gatemanager 8250 FirmwareSecomea Gatemanager 9250 Firmware4/5/202217/6/2026
Information Exposure Through Query Strings in GET Request vulnerability in LMM API of Secomea GateManager allows system administrator to hijack connection. This issue affects: Secomea GateManager all versions prior to 9.7.
ModificadaMedia (4.3)0.63%—Secomea Gatemanager 4250 FirmwareSecomea Gatemanager 4260 FirmwareSecomea Gatemanager 8250 FirmwareSecomea Gatemanager 9250 Firmware4/5/202217/6/2026
Insufficient Logging vulnerability in web server of Secomea GateManager allows logged in user to issue improper queries without logging. This issue affects: Secomea GateManager versions prior to 9.7.
ModificadaMedia (5.4)0.50%—Secomea Gatemanager 4250 FirmwareSecomea Gatemanager 4260 FirmwareSecomea Gatemanager 8250 FirmwareSecomea Gatemanager 9250 Firmware4/5/202217/6/2026
Improper Handling of Insufficient Privileges vulnerability in Web UI of Secomea GateManager allows logged in user to access and update privileged information. This issue affects: Secomea GateManager versions prior to 9.7.
ModificadaMedia (6.1)0.50%—Secomea Gatemanager 4250 FirmwareSecomea Gatemanager 4260 FirmwareSecomea Gatemanager 8250 FirmwareSecomea Gatemanager 9250 Firmware4/5/202217/6/2026
Cross-site Scripting (XSS) vulnerability in Web UI of Secomea GateManager allows phishing attacker to inject javascript or html into logged in user session.
ModificadaMedia (4.3)0.63%—Secomea Gatemanager 4250 FirmwareSecomea Gatemanager 4260 FirmwareSecomea Gatemanager 8250 FirmwareSecomea Gatemanager 9250 Firmware4/5/202217/6/2026
Information Exposure vulnerability in web UI of Secomea GateManager allows logged in user to query devices outside own scope.
ModificadaMedia (4.3)0.55%—Secomea Gatemanager 4250 FirmwareSecomea Gatemanager 4260 FirmwareSecomea Gatemanager 8250 FirmwareSecomea Gatemanager 9250 Firmware4/5/202217/6/2026
Logging of Excessive Data vulnerability in audit log of Secomea GateManager allows logged in user to write text entries in audit log. This issue affects: Secomea GateManager versions prior to 9.7.
ModificadaAlta (8.8)0.28%—Secomea Gatemanager 4250 FirmwareSecomea Gatemanager 4260 FirmwareSecomea Gatemanager 8250 FirmwareSecomea Gatemanager 9250 Firmware4/5/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Web UI of Secomea GateManager allows phishing attacker to issue get request in logged in user session.
ModificadaAlta (8.1)0.23%—Secomea Sitemanager 1129 FirmwareSecomea Sitemanager 1139 FirmwareSecomea Sitemanager 1149 FirmwareSecomea Sitemanager 3329 Firmware+104/5/202217/6/2026
Inadequate Encryption Strength vulnerability in TLS stack of Secomea SiteManager, LinkManager, GateManager may facilitate man in the middle attacks. This issue affects: Secomea SiteManager All versions prior to 9.7. Secomea LinkManager versions prior to 9.7. Secomea GateManager versions prior to 9.7.
ModificadaMedia (6.1)0.50%—Secomea Gatemanager11/3/202217/6/2026
Cross-site Scripting (XSS) vulnerability in firmware section of Secomea GateManager allows logged in user to inject javascript in browser session. This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions.
ModificadaMedia (4.3)0.64%—Secomea Gatemanager10/3/202217/6/2026
This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Permission Issues vulnerability in LinkManager web portal of Secomea GateManager allows logged in LinkManager user to access stored SiteManager backup files.
ModificadaAlta (8.7)1.00%—Secomea Gatemanager4/3/202217/6/2026
This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Improper Limitation of a Pathname to restricted directory, allows logged in GateManager admin to delete system Files or Directories.
ModificadaMedia (5.3)0.64%—Secomea Gatemanager 8250 Firmware22/11/202117/6/2026
This issue affects: Secomea GateManager All versions prior to 9.6. Improper Check of host header in web server of Secomea GateManager allows attacker to cause browser cache poisoning.
ModificadaAlta (8.8)0.52%—Secomea Gatemanager Firmware5/3/202117/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in web GUI of Secomea GateManager allows an attacker to execute malicious code. This issue affects: Secomea GateManager All versions prior to 9.4.