Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 29 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.46% | — | Controlid IdsecureAI | 16/9/2026 | 18/9/2026 | Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/dguardintegration/dguardVersion endpoint dereferences DGuard integration login state that may be unset, raising an unhandled null reference exception. The exception is thrown from an asynchronous method that… | |
| Aplazada | Alta (7.5) | 0.66% | — | Controlid IdsecureAI | 16/9/2026 | 18/9/2026 | Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/license/restartService endpoint is reachable without authentication and invokes an internal routine that terminates the iDSecure service process and relaunches it by way of a generated batch script. An… | |
| Analizada | Crítica (9.3) | 0.48% | — | Assaabloy Control ID Idsecure | 24/6/2025 | 17/6/2026 | ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to SQL injections which could allow an attacker to leak arbitrary information and insert arbitrary SQL syntax into SQL queries. | |
| Analizada | Alta (8.7) | 0.42% | — | Assaabloy Control ID Idsecure | 24/6/2025 | 17/6/2026 | ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to a server-side request forgery vulnerability which could allow an unauthenticated attacker to retrieve information from other servers. | |
| Analizada | Alta (8.7) | 0.57% | — | Assaabloy Control ID Idsecure | 24/6/2025 | 17/6/2026 | ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to an improper authentication vulnerability which could allow an attacker to bypass authentication and gain permissions in the product. | |
| Modificada | Crítica (9.8) | 65% | — | Controlid Idsecure | 27/11/2023 | 17/6/2026 | An authentication bypass vulnerability exists in Control iD iDSecure v4.7.32.0. The login routine used by iDS-Core.dll contains a "passwordCustom" option that allows an unauthenticated attacker to compute valid credentials that can be used to bypass authentication and act as an administrative user. | |
| Modificada | Crítica (9.8) | 1.1% | — | Assaabloy Control ID Idsecure | 5/8/2023 | 17/6/2026 | A SQL injection vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing unauthenticated attackers to write PHP files on the server's root directory, resulting in remote code execution. | |
| Modificada | Crítica (9.8) | 0.86% | — | Assaabloy Control ID Idsecure | 3/8/2023 | 17/6/2026 | Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens, allowing attackers to sign arbitrary session tokens and bypass authentication. | |
| Modificada | Alta (7.5) | 0.64% | — | Assaabloy Control ID Idsecure | 3/8/2023 | 17/6/2026 | An uncaught exception vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to cause the main web server of IDSecure to fault and crash, causing a denial of service. | |
| Modificada | Crítica (9.1) | 0.75% | — | Assaabloy Control ID Idsecure | 3/8/2023 | 17/6/2026 | A path traversal vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to delete arbitrary files on IDSecure filesystem, causing a denial of service. | |
| Modificada | Media (6.5) | 0.55% | — | Assaabloy Control ID Idsecure | 3/8/2023 | 17/6/2026 | Some API routes exists in Control ID IDSecure 4.7.26.0 and prior, exfiltrating sensitive information and passwords to users accessing these API routes. | |
| Modificada | Media (6.1) | 0.36% | — | Assaabloy Control ID Idsecure | 14/4/2023 | 17/6/2026 | A vulnerability has been found in Control iD iDSecure 4.7.29.1 and classified as problematic. This vulnerability affects unknown code of the component Dispositivos Page. The manipulation of the argument IP-DNS leads to cross site scripting. The attack can be initiated remotely. VDB-225922 is the identifier assigned to… |