Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2571▼ 296 respecto a la semana anterior
Críticas / altas1355▲ 107 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.13% | — | Havelsan Liman Render EngineAI | 24/9/2026 | 24/9/2026 | Improper certificate validation vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Middle (AiTM). This issue affects Liman Render Engine: from 1.0 before 1.2-75. | |
| Aplazada | Media (5.9) | 0.24% | — | Havelsan Liman Render EngineAI | 24/9/2026 | 24/9/2026 | Key exchange without entity authentication vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Middle (AiTM). This issue affects Liman Render Engine: from 1.0 before 1.2-75. | |
| Aplazada | Media (5.3) | 0.26% | — | Havelsan Liman MYSAI | 24/9/2026 | 24/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in HAVELSAN Inc. Liman MYS allows Path Traversal. This issue affects Liman MYS: from 2.3.2 before 2.3.4-1124. | |
| Aplazada | Crítica (9.1) | 1.4% | — | LimanAI | 27/8/2026 | 9/9/2026 | Liman is open source server management software. Prior to 2.2.2 - 1103, an OS command injection vulnerability in the log rotation configuration endpoint allows an authenticated administrator to execute arbitrary operating system commands on the Liman server. The `ip_address` parameter is embedded directly into a shell… | |
| Aplazada | Alta (8.8) | 0.42% | — | Havelsan INC Liman MYSAI | 4/8/2026 | 26/8/2026 | Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation. This issue affects Liman MYS: from 2.2.3 before 2.3.1. | |
| Aplazada | Alta (8.8) | 0.42% | — | Havelsan INC Liman MYSAI | 4/8/2026 | 26/8/2026 | Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Liman MYS: from 2.2.3 before 2.3.1. | |
| Aplazada | Alta (8.8) | 0.52% | — | Havelsan Liman MYSAI | 7/7/2026 | 7/7/2026 | Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in HAVELSAN Inc. Liman MYS allows LDAP Injection. This issue affects Liman MYS: before release.Master.1107. | |
| Aplazada | Alta (8.1) | 0.25% | — | Havelsan Liman MYSAI | 7/7/2026 | 7/7/2026 | Improper verification of cryptographic signature vulnerability in HAVELSAN Inc. Liman MYS allows Fake the Source of Data. This issue affects Liman MYS: before release.Master.1107. | |
| Aplazada | Alta (8.3) | 0.35% | — | Havelsan Liman MYSAI | 7/7/2026 | 7/7/2026 | Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Liman MYS: before release.Master.1107. | |
| Modificada | Media (5.1) | 0.19% | — | Salihciftci Liman | 29/1/2026 | 17/6/2026 | Liman 0.7 contains a cross-site request forgery vulnerability that allows attackers to manipulate user account settings without proper request validation. Attackers can craft malicious HTML forms to change user passwords or modify account information by tricking logged-in users into submitting unauthorized requests. | |
| Aplazada | Media (4.8) | 0.18% | — | Havelsan Liman MYSAI | 18/2/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in HAVELSAN Liman MYS allows Cross-Site Flashing. This issue affects Liman MYS: before 2.1.1 - 1010. | |
| Modificada | Alta (8.8) | 1.8% | — | Liman Port MYS | 1/3/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Liman Central Management System Liman MYS (HTTP/Controllers, CronMail, Jobs modules) allows Command Injection. This issue affects Liman Central Management System: from 1.7.0 before 1.8.3-462. |