Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2865▼ 160 respecto a la semana anterior
Críticas / altas1384▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.7) | 0.62% | — | Siemens License ServerAI | 11/8/2026 | 28/8/2026 | A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3). The affected application is vulnerable to a path traversal vulnerability due to lack of sanitization of user input. This could allow a remote attacker to access arbitrary files on the application. | |
| Pendiente de análisis | Alta (8.3) | 0.17% | — | Siemens License ServerAI | 11/8/2026 | 28/8/2026 | A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1). The affected application is vulnerable to a local privilege escalation due to an insecure sudoers policy. This could allow an attacker to execute arbitrary commands and plant malicious files as root, leading to full system… | |
| Analizada | Crítica (10) | 0.98% | — | HPE Autopass License Server | 2/3/2026 | 10/8/2026 | A remote authentication bypass vulnerability exists in HPE AutoPass License Server (APLS). | |
| Analizada | Crítica (9.8) | 0.44% | — | HPE Autopass License Server | 16/7/2025 | 17/6/2026 | An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18. | |
| Analizada | Crítica (9.8) | 0.44% | — | HPE Autopass License Server | 16/7/2025 | 17/6/2026 | An authentication bypass and disclosure of information vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18. | |
| Analizada | Crítica (9.8) | 0.62% | — | HPE Autopass License Server | 16/7/2025 | 17/6/2026 | An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18. | |
| Analizada | Alta (7.5) | 0.42% | — | HPE Autopass License Server | 14/7/2025 | 17/6/2026 | An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17. | |
| Analizada | Alta (7.5) | 0.42% | — | HPE Autopass License Server | 14/7/2025 | 17/6/2026 | An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17. | |
| Analizada | Alta (8) | 0.43% | — | HPE Autopass License Server | 14/7/2025 | 17/6/2026 | An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17. | |
| Analizada | Alta (7.3) | 1.3% | — | HPE Autopass License Server | 14/7/2025 | 17/6/2026 | An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17. | |
| Aplazada | Media (5.4) | 0.14% | — | Siemens License ServerAI | 8/4/2025 | 17/6/2026 | A vulnerability has been identified in Siemens License Server (SLS) (All versions < V4.3). The affected application does not properly restrict permissions of the users. This could allow a lowly-privileged attacker to escalate their privileges. | |
| Aplazada | Media (5.4) | 0.16% | — | Siemens License ServerAI | 8/4/2025 | 17/6/2026 | A vulnerability has been identified in Siemens License Server (SLS) (All versions < V4.3). The affected application searches for executable files in the application folder without proper validation. This could allow an attacker to execute arbitrary code with administrative privileges by placing a malicious executable… | |
| Aplazada | Media (4.7) | 0.48% | — | Numerix License Server Administration SystemAI | 11/12/2024 | 17/6/2026 | Users who click on a malicious link or visit a website under the control of an attacker can be infected with arbitrary JavaScript which is running in the context of the "Numerix License Server Administration System Login" (nlslogin.jsp) page. The vulnerability can be triggered by sending a specially crafted HTTP POST… | |
| Analizada | Alta (7.8) | 0.23% | — | Ivanti Velocity License Server | 8/10/2024 | 17/6/2026 | Under specific circumstances, insecure permissions in Ivanti Velocity License Server before version 5.2 allows a local authenticated attacker to achieve local privilege escalation. | |
| Aplazada | Crítica (10) | 1.1% | — | PTC Creo Elements Direct License ServerAI | 27/6/2024 | 17/6/2026 | PTC Creo Elements/Direct License Server exposes a web interface which can be used by unauthenticated remote attackers to execute arbitrary OS commands on the server. | |
| Modificada | Alta (8.8) | 0.84% | — | Mimsoftware MIM Concurrent License ServerMimsoftware MIM Local Concurrent License Server | 9/6/2023 | 17/6/2026 | An issue found in MIM software Inc MIM License Server and MIMpacs services v.6.9 thru v.7.0 fixed in v.7.0.10 allows a remote unauthenticated attacker to execute arbitrary code via the RMI Registry service. | |
| Modificada | Alta (8.2) | 1.5% | — | Kuka Visual Components Network License Server | 6/11/2020 | 17/6/2026 | Visual Components (owned by KUKA) is a robotic simulator that allows simulating factories and robots in order toimprove planning and decision-making processes. Visual Components software requires a special license which can beobtained from a network license server. The network license server binds to all interfaces… | |
| Modificada | Alta (7.5) | 1.4% | — | Kuka Visual Components Network License Server | 6/11/2020 | 17/6/2026 | Visual Components (owned by KUKA) is a robotic simulator that allows simulating factories and robots in order toimprove planning and decision-making processes. Visual Components software requires a special license which can beobtained from a network license server. The network license server binds to all interfaces… | |
| Modificada | Crítica (9.8) | 1.9% | — | Gemnet License Server | 20/3/2018 | 17/6/2026 | GE GEMNet License server (EchoServer) all current versions are affected these devices use default or hard-coded credentials. Successful exploitation of this vulnerability may allow a remote attacker to bypass authentication and gain access to the affected devices. | |
| Modificada | Alta (7.5) | 1.8% | — | Citrix License ServerCitrix License Server VPX | 7/10/2016 | 17/6/2026 | The lmadmin component in Flexera FlexNet Publisher (aka Flex License Manager) before 2015 SP5 and 2016 before R1 SP1, as used by Citrix License Server for Windows before 11.14.0.1 and Citrix License Server VPX before 11.14.0.1, allows remote attackers to cause a denial of service (crash) via a type 2F packet with a… | |
| Modificada | Alta (10) | 6.8% | — | IBM Rational License KEY ServerIBM Rational License ServerIBM Telelogic License Server | 19/1/2012 | 16/6/2026 | Multiple directory traversal vulnerabilities in the vendor daemon in Rational Common Licensing in Telelogic License Server 2.0, Rational License Server 7.x, and ibmratl in IBM Rational License Key Server (RLKS) 8.0 through 8.1.2 allow remote attackers to execute arbitrary code via vectors related to save, rename, and… |