Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
31 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.39% | — | Ankaref Innovation AND Technology INC LibridAIAnkaref Innovation AND Technology INC LibrefAI | 10/9/2026 | 23/9/2026 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Password Recovery Exploitation. This issue affects LIBRID/LIBREF: from 2.01.0.2183 before 18.9.26.2319. | |
| Aplazada | Media (5.4) | 0.16% | — | Ankaref Innovation AND Technology INC LibridAI | 10/9/2026 | 23/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS. This issue affects LIBRID/LIBREF: from 2.01.0.2183 before 18.9.26.2319. | |
| Aplazada | Media (5.4) | 0.16% | — | Ankaref Innovation AND Technology INC LibridAI | 10/9/2026 | 23/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS. This issue affects LIBRID/LIBREF: from 2.01.0.2183 before 18.9.26.2319. | |
| Aplazada | Crítica (9.8) | 0.47% | — | Faydam Innovation INC Faydam DataloggerAI | 19/8/2026 | 26/8/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Faydam Innovation Inc. FAYDAM Datalogger allows SQL Injection. This issue affects FAYDAM Datalogger: from 2.7.1 before 2.8.0. | |
| Aplazada | Alta (8.2) | 0.33% | — | Codriapp Innovation AND Software Technologies INC HeygarsonAI | 30/1/2026 | 7/8/2026 | Generation of Error Message Containing Sensitive Information vulnerability in Codriapp Innovation and Software Technologies Inc. HeyGarson allows Fuzzing for application mapping. This issue affects HeyGarson: through 30012026. NOTE: The vendor was contacted and it was learned that the product is not supported. | |
| Aplazada | Media (6.5) | 0.21% | — | Theplus Innovation THE Plus Addons FOR Elementor PROAI | 7/1/2026 | 30/9/2026 | Missing Authorization vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro theplus_elementor_addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Plus Addons for Elementor Pro: from n/a through < 6.3.7. | |
| Aplazada | Media (6.9) | 0.31% | — | Fujifilm Business Innovation MFPAI | 4/8/2025 | 17/6/2026 | Out-of-bounds write vulnerability exists in FUJIFILM Business Innovation MFPs. A specially crafted IPP (Internet Printing Protocol) or LPD (Line Printer Daemon) packet may cause a denial-of-service (DoS) condition on an affected MFP. Resetting the MFP is required to recover from the denial-of-service (DoS) condition. | |
| Aplazada | Media (5.4) | 0.30% | — | Posimyth Innovation THE Plus Addons FOR Elementor PROAI | 1/7/2025 | 17/6/2026 | Missing Authorization vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Plus Addons for Elementor Pro: from n/a before 6.3.7. | |
| Analizada | Alta (7.2) | 0.54% | — | Ocuco Innovation | 22/5/2025 | 17/6/2026 | An issue in Ocuco Innovation - JOBMANAGER.EXE v2.10.24.16 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet. | |
| Analizada | Crítica (9.8) | 0.57% | — | Ocuco Innovation | 22/5/2025 | 17/6/2026 | An issue in Ocuco Innovation - REPORTS.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet. | |
| Analizada | Crítica (9.8) | 0.57% | — | Ocuco Innovation | 22/5/2025 | 17/6/2026 | An issue in Ocuco Innovation - INVCLIENT.EXE v2.10.24.5 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet. | |
| Analizada | Crítica (9.8) | 0.66% | — | Ocuco Innovation | 22/5/2025 | 17/6/2026 | An issue in Ocuco Innovation - REPORTSERVER.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet. | |
| Analizada | Crítica (9.8) | 0.57% | — | Ocuco Innovation | 22/5/2025 | 17/6/2026 | An issue in Ocuco Innovation - INNOVASERVICEINTF.EXE v2.10.24.17 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet. | |
| Analizada | Alta (7.8) | 0.20% | — | Ocuco Innovation | 22/5/2025 | 17/6/2026 | An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the SETTINGSVATIGATOR.EXE component | |
| Analizada | Alta (7.8) | 0.20% | — | Ocuco Innovation | 22/5/2025 | 17/6/2026 | An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the STOCKORDERENTRY.EXE component | |
| Analizada | Alta (7.8) | 0.20% | — | Ocuco Innovation | 22/5/2025 | 17/6/2026 | An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the JOBENTRY.EXE | |
| Analizada | Alta (7.8) | 0.20% | — | Ocuco Innovation | 22/5/2025 | 17/6/2026 | An issue in Ocuco Innovation APPMANAGER.EXE v.2.10.24.51 allows a local attacker to escalate privileges via the application manager function | |
| Analizada | Alta (7.8) | 0.20% | — | Ocuco Innovation | 22/5/2025 | 17/6/2026 | An issue in Ocuco Innovation Tracking.exe v.2.10.24.51 allows a local attacker to escalate privileges via the modification of TCP packets. | |
| Aplazada | Media (6.9) | 0.75% | — | Fujifilm Business Innovation Apeos C3070AIFujifilm Business Innovation Apeos C5570AIFujifilm Business Innovation Apeos C6580AI | 19/12/2024 | 17/6/2026 | A vulnerability has been found in Fujifilm Business Innovation Apeos C3070, Apeos C5570 and Apeos C6580 up to 24.8.28 and classified as critical. This vulnerability affects unknown code of the file /home/index.html#hashHome of the component Web Interface. The manipulation leads to improper authorization. The attack… | |
| Modificada | Alta (7.5) | 0.57% | — | Progress OpenedgeProgress Openedge Innovation | 18/1/2024 | 17/6/2026 | This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases prior to 12.8.0 . An attacker who can produce a malformed web request may cause the crash of a PASOE agent potentially disrupting the thread activities of many web… | |
| Modificada | Crítica (9.9) | 0.56% | — | Progress OpenedgeProgress Openedge Innovation | 18/1/2024 | 17/6/2026 | This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases prior to 12.8.0. An attacker can formulate a request for a WEB transport that allows unintended file uploads to a server directory path on the system running PASOE. If the… | |
| Modificada | Alta (7.8) | 0.30% | — | Eginnovations EG AgentEginnovations EG ManagerEginnovations EG RUM CollectorsEginnovations VM Agent | 2/6/2022 | 17/6/2026 | eG Agent before 7.2 has weak file permissions that enable escalation of privileges to SYSTEM. | |
| Modificada | Alta (7.5) | 0.89% | — | SAP Innovation Management | 28/3/2022 | 17/6/2026 | Under certain conditions, SAP Innovation management - version 2.0, allows an attacker to access information which could lead to information gathering for further exploits and attacks. | |
| Modificada | Alta (7.2) | 1.3% | — | Merkuryinnovations Geeni Gnc-cw028 FirmwareMerkuryinnovations Geeni Gnc-cw025 FirmwareMerkuryinnovations Merkury Mi-cw024 FirmwareMerkuryinnovations Merkury Mi-cw017 Firmware | 26/1/2021 | 17/6/2026 | An issue was discovered on Geeni GNC-CW028 Camera 2.7.2, Geeni GNC-CW025 Doorbell 2.9.5, Merkury MI-CW024 Doorbell 2.9.6, and Merkury MI-CW017 Camera 2.9.6 devices. A vulnerability exists in the RESTful Services API that allows a remote attacker to take full control of the camera with a high-privileged account. The… | |
| Modificada | Media (6.8) | 0.39% | — | Intel Innovation Engine Firmware | 15/6/2020 | 17/6/2026 | Insufficient control flow management in firmware build and signing tool for Intel(R) Innovation Engine before version 1.0.859 may allow an unauthenticated user to potentially enable escalation of privilege via physical access. |