Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3070▲ 562 respecto a la semana anterior
Críticas / altas1457▲ 278 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
140 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.41% | — | IrisAI | 16/9/2026 | 24/9/2026 | IRIS through 2.4.29 fails to properly validate case authorization in comment listing endpoints for notes, tasks, IOCs, assets, and evidence items. Attackers with access to any single case can enumerate sequential object identifiers and read comment threads from cases they have no authorization to access. | |
| Aplazada | Media (5.9) | 0.37% | — | IrisAI | 30/7/2026 | 30/7/2026 | The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-force attacks. | |
| Aplazada | Alta (7.6) | 0.28% | — | IrisAI | 30/7/2026 | 30/7/2026 | The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the datastore upload function. | |
| Aplazada | Alta (7.6) | 0.28% | — | IrisAI | 30/7/2026 | 30/7/2026 | The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the custom attributes function. | |
| Aplazada | Media (5.9) | 0.33% | — | IrisAI | 30/7/2026 | 30/7/2026 | The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force attacks. | |
| Aplazada | Media (4.2) | 0.19% | — | IrisAI | 30/7/2026 | 4/8/2026 | The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Stolen session cookies can therefore be misused for a long time. | |
| Aplazada | Alta (7.6) | 0.28% | — | IrisAI | 30/7/2026 | 30/7/2026 | The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets function. | |
| Pendiente de análisis | Media (5.1) | 0.15% | — | Altiris WMI ProviderAI | 17/7/2026 | 21/7/2026 | The Altiris WMI provider exposes a class (AltirisAgent_Stream) that allows any local standard user to read the contents of any file accessible to the SYSTEM account, bypassing filesystem ACLs. No admin privileges required. The provider reverts to the LocalSystem context when servicing WMI queries without… | |
| Aplazada | Media (6.1) | 0.18% | — | Osiris Signature BannerAI | 24/6/2026 | 25/6/2026 | The Osiris Signature Banner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a… | |
| Aplazada | Media (5.4) | 0.26% | — | IrisAI | 4/6/2026 | 22/7/2026 | IRIS is a web collaborative platform that helps incident responders share technical details during investigations. In versions prior to 2.4.28, users can create alerts for customers that are not assigned to them. This can be abused to falsely attribute fake alerts to customers. In combination with Cross-Site… | |
| Aplazada | Media (4.3) | 0.29% | — | IrisAI | 4/6/2026 | 22/7/2026 | IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 are vulnerable to a cross-site request forgery attack, because they use the HTTP method `GET` to change state on the server. Version 2.4.28 contains a patch. | |
| Aplazada | Media (4.3) | 0.30% | — | IrisAI | 4/6/2026 | 22/7/2026 | IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 allow a user to alter values in the database via manipulated API requests. Version 2.4.28 contains a patch. | |
| Aplazada | Media (6.5) | 0.39% | — | IrisAI | 4/6/2026 | 22/7/2026 | IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 return sensitive data to the user which are not required for the client’s operation. Version 2.4.28 contains a patch. | |
| Aplazada | Media (6.3) | 0.30% | — | IrisAI | 4/6/2026 | 22/7/2026 | IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 do not properly validate uploaded files. The application can therefore be misused to host phishing pages, amongst other things. This also creates another instance of a Cross-Site… | |
| Aplazada | Media (4.7) | 0.29% | — | IrisAI | 4/6/2026 | 22/7/2026 | Iris is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 contain a weakness where an attacker can misuse it to redirect the user to a malicious website controlled by an attacker. Version 2.4.28 fixes the issue. | |
| Aplazada | Alta (7.1) | 0.38% | — | Dfir-irisAIGrapheneAIGraphene-sqlalchemyAIPalletsprojects FlaskAI | 4/6/2026 | 22/7/2026 | Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior to version 2.4.28, DFIR-IRIS exposes an optional GraphQL endpoint at `/graphql` that does not enforce the same authorization checks as the REST API. Any authenticated user can abuse it in three… | |
| Pendiente de análisis | Media (6.3) | 0.39% | — | Socomec Diris A-40AI | 16/3/2026 | 17/6/2026 | Socomec DIRIS A-40 HTTP API Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Socomec DIRIS A-40 power monitoring devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web… | |
| Aplazada | Media (6.5) | 0.26% | — | Vgdevsolutions Checkout Gateway FOR IrisAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in vgdevsolutions Checkout Gateway for IRIS checkout-gateway-iris allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Checkout Gateway for IRIS: from n/a through <= 1.3. | |
| Analizada | Alta (8.1) | 0.35% | — | Dfir-iris Iris | 12/1/2026 | 17/6/2026 | Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior to 2.4.24, the DFIR-IRIS datastore file management system has a vulnerability where mass assignment of the file_local_name field combined with path trust in the delete operation enables… | |
| Analizada | Alta (7.5) | 0.42% | — | Socomec Diris M-70 Firmware | 1/12/2025 | 26/9/2026 | A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to a denial of service. An attacker can send an unauthenticated packet to trigger this vulnerability.This vulnerability is… | |
| Analizada | Alta (7.5) | 0.42% | — | Socomec Diris M-70 Firmware | 1/12/2025 | 26/9/2026 | A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to a denial of service. An attacker can send an unauthenticated packet to trigger this vulnerability.This vulnerability is… | |
| Analizada | Alta (7.5) | 0.43% | — | Socomec Diris M-70 Firmware | 1/12/2025 | 26/9/2026 | A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted series of network requests can lead to a denial of service. An attacker can send a sequence of unauthenticated packets to trigger this vulnerability.An attacker can… | |
| Analizada | Alta (7.5) | 0.32% | — | Socomec Diris M-70 Firmware | 1/12/2025 | 26/9/2026 | A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted series of network requests can lead to a denial of service. An attacker can send a sequence of unauthenticated packets to trigger this vulnerability.An attacker can… | |
| Analizada | Alta (7.5) | 0.32% | — | Socomec Diris Digiware M-70 Firmware | 1/12/2025 | 26/9/2026 | A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted series of network requests can lead to a denial of service. An attacker can send a sequence of unauthenticated packets to trigger this vulnerability.An attacker can… | |
| Analizada | Alta (7.5) | 0.42% | — | Socomec Diris Digiware M-70 Firmware | 1/12/2025 | 26/9/2026 | A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted series of network requests can lead to a denial of service. An attacker can send a sequence of unauthenticated packets to trigger this vulnerability.An attacker can… |