Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.72% | — | SipsorceryAI | 14/9/2026 | 30/9/2026 | SIPSorcery is a WebRTC, SIP, and VoIP library for C# and .NET. Prior to 10.0.9, RTPChannel.OnRTPPacketReceived and the STUNAttribute.ParseMessageAttributes, STUNXORAddressAttribute, and STUNAddressAttribute parsing path index untrusted bytes without sufficient length checks, while UdpReceiver.EndReceiveFrom closes the… | |
| Aplazada | Alta (8.1) | 0.54% | — | Gavias KipsoAI | 28/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Kipso kipso allows PHP Local File Inclusion.This issue affects Kipso: from n/a through <= 1.3.4. | |
| Modificada | Alta (7.1) | 0.43% | — | Calipso Project Calipso | 7/6/2021 | 17/6/2026 | This affects all versions of package calipso. It is possible for a malicious module to overwrite files on an arbitrary file system through the module install functionality. | |
| Modificada | Media (6.5) | 1.3% | — | Clipsoft Rexpert | 30/10/2019 | 17/6/2026 | ClipSoft REXPERT 1.0.0.527 and earlier version allows remote attacker to arbitrary file deletion by issuing a HTTP GET request with a specially crafted parameter. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page. | |
| Modificada | Media (6.5) | 1.2% | — | Clipsoft Rexpert | 30/10/2019 | 17/6/2026 | ClipSoft REXPERT 1.0.0.527 and earlier version allows remote attacker to upload arbitrary local file via the ActiveX method in RexViewerCtrl30.ocx. That could lead to disclosure of sensitive information. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page. | |
| Modificada | Media (6.5) | 1.2% | — | Clipsoft Rexpert | 30/10/2019 | 17/6/2026 | ClipSoft REXPERT 1.0.0.527 and earlier version allows directory traversal by issuing a special HTTP POST request with ../ characters. This could lead to create malicious HTML file, because they can inject a content with crafted template. User interaction is required to exploit this vulnerability in that the target… | |
| Modificada | Alta (8.8) | 1.6% | — | Clipsoft Rexpert | 30/10/2019 | 17/6/2026 | ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation and execution via report print function of rexpert viewer with modified XML document. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page. | |
| Modificada | Media (6.5) | 1.2% | — | Clipsoft Rexpert | 30/10/2019 | 17/6/2026 | ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation via a POST request with the parameter set to the file path to be written. This can be an executable file that is written to in the arbitrary directory. User interaction is required to exploit this vulnerability in that the target must visit… | |
| Modificada | Media (5.3) | 0.93% | — | Clipsoft Rexpert | 30/10/2019 | 17/6/2026 | ClipSoft REXPERT 1.0.0.527 and earlier version have an information disclosure issue. When requesting web page associated with session, could leak username via session file path of HTTP response data. No authentication is required. | |
| Modificada | Crítica (9.8) | 1.4% | — | Cipsoft Gesior-aac | 26/8/2019 | 17/6/2026 | Gesior-AAC before 2019-05-01 allows serviceID SQL injection in accountmanagement.php. | |
| Modificada | Crítica (9.8) | 1.4% | — | Cipsoft Gesior-aac | 26/8/2019 | 17/6/2026 | Gesior-AAC before 2019-05-01 allows SQL injection in tankyou.php. | |
| Modificada | Crítica (9.8) | 1.4% | — | Cipsoft Gesior-aac | 26/8/2019 | 17/6/2026 | Gesior-AAC before 2019-05-01 allows ServiceCategoryID SQL injection in shop.php. | |
| Modificada | Media (5.4) | 0.61% | — | Checkpoint Gaia OSCheckpoint Ipso OS | 23/1/2014 | 17/6/2026 | The OSPF implementation in Check Point Gaia OS R75.X and R76 and IPSO OS 6.2 R75.X and R76 does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing… | |
| Modificada | Alta (7.5) | 69% | 💥 Exploit | Flipsource Flip | 6/2/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in previewtheme.php in Flipsource Flip 2.01-final 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the inc_path parameter. | |
| Modificada | Media (5) | 1.6% | — | Nokia Ipso | 29/10/2003 | 16/6/2026 | Unknown vulnerability in Nokia IPSO 3.7, configured as IP Clusters, allows remote attackers to cause a denial of service via unknown attack vectors. |