Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.29% | — | Havelsan SEFAI | 2/10/2026 | 2/10/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows SQL Injection. This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was contacted and it was learned that the product is not supported. | |
| Aplazada | Media (4.9) | 0.27% | — | Havelsan SEFAI | 2/10/2026 | 2/10/2026 | Server-Side request forgery (SSRF) vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Server Side Request Forgery. This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was contacted and it was learned that the product is not supported. | |
| Aplazada | Alta (7.4) | 0.16% | — | Havelsan SEF AI Chatbot PlatformAI | 2/10/2026 | 2/10/2026 | Improper certificate validation vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Adversary in the Middle (AiTM). This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was contacted and it was learned that the product is not supported. | |
| Aplazada | Media (5.3) | 0.21% | — | Havelsan SEFAI | 2/10/2026 | 2/10/2026 | Missing Authorization vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was contacted and it was learned that the product is not supported. | |
| Aplazada | Media (5.9) | 0.13% | — | Havelsan Liman Render EngineAI | 24/9/2026 | 24/9/2026 | Improper certificate validation vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Middle (AiTM). This issue affects Liman Render Engine: from 1.0 before 1.2-75. | |
| Aplazada | Media (5.9) | 0.24% | — | Havelsan Liman Render EngineAI | 24/9/2026 | 24/9/2026 | Key exchange without entity authentication vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Middle (AiTM). This issue affects Liman Render Engine: from 1.0 before 1.2-75. | |
| Aplazada | Media (5.3) | 0.26% | — | Havelsan Liman MYSAI | 24/9/2026 | 24/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in HAVELSAN Inc. Liman MYS allows Path Traversal. This issue affects Liman MYS: from 2.3.2 before 2.3.4-1124. | |
| Aplazada | Alta (8.8) | 0.42% | — | Havelsan INC Liman MYSAI | 4/8/2026 | 26/8/2026 | Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation. This issue affects Liman MYS: from 2.2.3 before 2.3.1. | |
| Aplazada | Alta (8.8) | 0.42% | — | Havelsan INC Liman MYSAI | 4/8/2026 | 26/8/2026 | Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Liman MYS: from 2.2.3 before 2.3.1. | |
| Aplazada | Alta (8.8) | 0.52% | — | Havelsan Liman MYSAI | 7/7/2026 | 7/7/2026 | Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in HAVELSAN Inc. Liman MYS allows LDAP Injection. This issue affects Liman MYS: before release.Master.1107. | |
| Aplazada | Alta (8.1) | 0.25% | — | Havelsan Liman MYSAI | 7/7/2026 | 7/7/2026 | Improper verification of cryptographic signature vulnerability in HAVELSAN Inc. Liman MYS allows Fake the Source of Data. This issue affects Liman MYS: before release.Master.1107. | |
| Aplazada | Alta (8.3) | 0.35% | — | Havelsan Liman MYSAI | 7/7/2026 | 7/7/2026 | Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Liman MYS: before release.Master.1107. | |
| Aplazada | Media (4.8) | 0.18% | — | Havelsan Liman MYSAI | 18/2/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in HAVELSAN Liman MYS allows Cross-Site Flashing. This issue affects Liman MYS: before 2.1.1 - 1010. | |
| Aplazada | Crítica (9.4) | 0.47% | — | Havelsan INC DialogueAI | 29/4/2024 | 17/6/2026 | Incorrect Permission Assignment for Critical Resource vulnerability in Havelsan Inc. Dialogue allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Dialogue: from v1.83 before v1.83.1 or v1.84. |