Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2509▼ 448 respecto a la semana anterior
Críticas / altas1286▼ 7 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 464 respecto a la semana anterior
51 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.3) | 0.50% | — | IBM I Access FamilyAI | 14/9/2026 | 17/9/2026 | IBM i Access Family 1.1.2.0 through 1.1.9.15 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a session file. | |
| Pendiente de análisis | Media (6.3) | 0.27% | — | IBM I Access FamilyAIIBM I Access Client SolutionsAI | 14/9/2026 | 17/9/2026 | IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a malicious emulator macro RunProgram action. | |
| Pendiente de análisis | Media (6.3) | 0.27% | — | IBM I Access FamilyAIIBM I Access Client SolutionsAI | 14/9/2026 | 17/9/2026 | IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a STRPCCMD CL command. | |
| Aplazada | Crítica (9.9) | 0.47% | — | UI Unifi AccessAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device. | |
| Aplazada | Crítica (9.9) | 1.4% | — | UI Unifi AccessAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. | |
| Aplazada | Crítica (9.9) | 1.4% | — | UI Unifi AccessAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. | |
| Aplazada | Crítica (9.9) | 1.4% | — | UI Unifi AccessAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. | |
| Analizada | Alta (7.8) | 0.17% | — | IBM I Access Client Solutions | 13/8/2026 | 17/8/2026 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable directory. | |
| Analizada | Alta (7.8) | 0.21% | — | IBM I Access Client Solutions | 12/8/2026 | 18/8/2026 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a local attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (7.1) | 0.11% | — | IBM I Access Client Solutions | 12/8/2026 | 18/8/2026 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injection of rogue certificate authority due to publicly writeable truststore. | |
| Analizada | Crítica (9.6) | 0.17% | — | IBM I Access Client Solutions | 12/8/2026 | 18/8/2026 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when configured to update from an IBM i. A bad actor could use this vulnerablity to run compromised code on the ACS user's workstation. | |
| Analizada | Alta (8.8) | 0.50% | — | IBM I Access Client Solutions | 12/8/2026 | 18/8/2026 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal exploit when importing a configuration. | |
| Analizada | Alta (7.8) | 0.20% | — | IBM I Access Client Solutions | 12/8/2026 | 18/8/2026 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable configuration file. | |
| Analizada | Alta (8.6) | 0.56% | — | UI Unifi Access | 2/7/2026 | 17/8/2026 | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Access Application to access files on the host device. | |
| Analizada | Crítica (9.1) | 0.52% | — | UI Unifi Access | 2/7/2026 | 17/8/2026 | A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device. | |
| Analizada | Crítica (9.9) | 1.6% | — | UI Unifi Access | 2/7/2026 | 17/8/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. | |
| Analizada | Alta (8.8) | 0.81% | — | IBM I Access Client Solutions | 1/6/2026 | 26/8/2026 | IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS) is vulnerable to remote code execution when configured to listen for requests from IBM i Navigator. | |
| Aplazada | Media (5.1) | 0.20% | — | Zucchetti Axess Cloki Access ControlAI | 23/12/2025 | 17/6/2026 | Zucchetti Axess CLOKI Access Control 1.64 contains a cross-site request forgery vulnerability that allows attackers to manipulate access control settings without user interaction. Attackers can craft malicious web pages with hidden forms to disable or modify access control parameters by tricking authenticated users… | |
| Analizada | Crítica (10) | 41% | — | UI Unifi Access | 31/10/2025 | 17/6/2026 | A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API without proper authentication. This vulnerability was introduced in Version 3.3.22 and was fixed in Version 4.0.21 and later. Affected Products: UniFi… | |
| Aplazada | Crítica (9.8) | 1.2% | — | UI Unifi Access Reader PROAIUI Unifi Access G2 Reader PROAIUI Unifi Access G3 Reader PROAIUI Unifi Access IntercomAI+2 | 4/8/2025 | 17/6/2026 | An Improper Input Validation in certain UniFi Access devices could allow a Command Injection by a malicious actor with access to UniFi Access management network. Affected Products: UniFi Access Reader Pro (Version 2.14.21 and earlier) UniFi Access G2 Reader Pro (Version 1.10.32 and earlier) UniFi Access G3 Reader Pro… | |
| Aplazada | Media (4.8) | 0.20% | — | UI Unifi IOS APPAIUI Unifi Access PointAI | 9/7/2024 | 17/6/2026 | UniFi iOS app 10.15.0 introduces a misconfiguration on 2nd Generation UniFi Access Points configured as standalone (not using UniFi Network Application) that could cause the SSID name to change and/or the WiFi Password to be removed on the 5GHz Radio. This vulnerability is fixed in UniFi iOS app 10.15.2 and later. | |
| Modificada | Media (6.1) | 0.25% | — | Vantiva Mediaaccess Dga2232 Firmware | 16/6/2024 | 17/6/2026 | Vantiva - MediaAccess DGA2232 v19.4 - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Aplazada | Baja (2.2) | 0.44% | — | UI Unifi Connect EV StationAIUI Unifi Connect EV Station PROAIUI Unifi Access G2 Reader PROAIUI Unifi Access Reader PROAI+4 | 7/5/2024 | 17/6/2026 | An Improper Access Control could allow a malicious actor authenticated in the API to enable Android Debug Bridge (ADB) and make unsupported changes to the system. Affected Products: UniFi Connect EV Station (Version 1.1.18 and earlier) UniFi Connect EV Station Pro (Version 1.1.18 and earlier) UniFi Access G2 Reader… | |
| Aplazada | Alta (7.5) | 0.52% | — | UI Unifi Access PointsAIUI Unifi SwitchesAIUI Unifi LTE BackupAIUI Unifi ExpressAI | 20/2/2024 | 17/6/2026 | A malformed discovery packet sent by a malicious actor with preexisting access to the network could interrupt the functionality of device management and discovery. Affected Products: UniFi Access Points UniFi Switches UniFi LTE Backup UniFi Express (Only Mesh Mode, Router mode is not affected) Mitigation: Update UniFi… | |
| Modificada | Crítica (9.8) | 0.61% | — | Prestamonster Multi Accessories PRO | 9/2/2024 | 17/6/2026 | SQL injection vulnerability in Presta Monster "Multi Accessories Pro" (hsmultiaccessoriespro) module for PrestaShop versions 5.1.1 and before, allows remote attackers to escalate privileges and obtain sensitive information via the method HsAccessoriesGroupProductAbstract::getAccessoriesByIdProducts(). |