Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▲ 64 respecto a la semana anterior
Críticas / altas1484▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 448 respecto a la semana anterior
148 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.32% | — | MobilitydbAI | 29/9/2026 | 2/10/2026 | MobilityDB version 1.3.0 and earlier contains an out-of-bounds read vulnerability in the MEOS binary and library WKB deserialization logic that allows unprivileged database users to crash the PostgreSQL backend process by supplying a crafted WKB payload with a negative length field. The negative length value wraps to… | |
| Modificada | Media (6.9) | 0.60% | — | Mobility46.se | 27/2/2026 | 17/6/2026 | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the most recent connection displaces the… | |
| Modificada | Crítica (9.3) | 0.96% | — | Mobility46.se | 27/2/2026 | 17/6/2026 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then issue or receive OCPP… | |
| Modificada | Alta (8.7) | 0.93% | — | Mobility46.se | 27/2/2026 | 17/6/2026 | The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct brute-force attacks to gain unauthorized access. | |
| Modificada | Media (6.9) | 0.28% | — | Mobility46.se | 27/2/2026 | 17/6/2026 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. | |
| Analizada | Media (6.5) | 0.56% | — | Wso2 API Control PlaneWso2 API ManagerWso2 API Manager AnalyticsWso2 Data Analytics Server+11 | 16/10/2025 | 25/9/2026 | An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A low-privileged user may exploit this flaw to perform unauthorized operations, including accessing server-level information. This… | |
| Aplazada | Media (5.3) | 0.25% | — | Synapse MobilityAI | 20/8/2025 | 17/6/2026 | Synapse Mobility 8.0, 8.0.1, 8.0.2, 8.1, and 8.1.1 contain a privilege escalation vulnerability through external control of Web parameter. If exploited, a user of the product may escalate the privilege and access data that the user do not have permission to view by altering the parameters of the search function. | |
| Aplazada | Media (4.6) | 0.21% | — | Motorola Mobility Droid Razr HDAI | 27/2/2025 | 17/6/2026 | An issue in Motorola Mobility Droid Razr HD (Model XT926) System Version: 9.18.94.XT926.Verizon.en.US allows physically proximate unauthorized attackers to access USB debugging, leading to control of the host device itself. | |
| Analizada | Media (5.6) | 0.23% | — | Cisco Anyconnect Secure Mobility Client | 12/2/2025 | 17/6/2026 | A vulnerability in the uninstaller component of Cisco AnyConnect Secure Mobility Client for Mac OS could allow an authenticated, local attacker to corrupt the content of any file in the filesystem. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by… | |
| Analizada | Media (6.5) | 0.62% | — | Cisco Anyconnect Secure Mobility ClientCisco Secure Client | 23/10/2024 | 17/6/2026 | A vulnerability in Internet Key Exchange version 2 (IKEv2) processing of Cisco Secure Client Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of Cisco Secure Client. This vulnerability is due to an integer underflow condition. An attacker could exploit this vulnerability by… | |
| Aplazada | Media (6.5) | 0.27% | — | Ericsson Packet Core ControllerAIEricsson Access AND Mobility Management FunctionAI | 20/8/2024 | 17/6/2026 | Ericsson Packet Core Controller (PCC) contains a vulnerability in Access and Mobility Management Function (AMF) where improper input validation can lead to denial of service which may result in service degradation. | |
| Modificada | Media (5.5) | 0.20% | — | Cisco Anyconnect Secure Mobility ClientCisco Secure Client | 22/11/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client, could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system. These vulnerabilities are due to an out-of-bounds memory read from Cisco Secure Client Software. An… | |
| Modificada | Media (5.5) | 0.20% | — | Cisco Anyconnect Secure Mobility ClientCisco Secure Client | 22/11/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client, could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system. These vulnerabilities are due to an out-of-bounds memory read from Cisco Secure Client Software. An… | |
| Modificada | Media (5.5) | 0.23% | — | Baramundi Enterprise Mobility Management | 2/10/2023 | 17/6/2026 | Weak Exception Handling vulnerability in baramundi software GmbH EMM Agent 23.1.50 and before allows an attacker to cause a denial of service via a crafted request to the password parameter. | |
| Modificada | Media (5.3) | 0.26% | — | Cisco Mobility Express Software | 27/9/2023 | 17/6/2026 | A vulnerability in the memory buffer of Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause memory leaks that could eventually lead to a device reboot. This vulnerability is due to memory leaks caused by multiple clients connecting under specific conditions.… | |
| Modificada | Media (6.5) | 0.27% | — | Papercut Mobility Print Server | 20/9/2023 | 17/6/2026 | The `PaperCutNG Mobility Print` version 1.0.3512 application allows an unauthenticated attacker to perform a CSRF attack on an instance administrator to configure the clients host (in the "configure printer discovery" section). This is possible because the application has no protections against CSRF attacks, like… | |
| Modificada | Media (4.3) | 0.28% | — | Mitel Connect Mobility Router | 14/9/2023 | 17/6/2026 | A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2304.102 could allow an unauthenticated attacker to perform a Cross Site Request Forgery (CSRF) attack due to insufficient request validation. A successful exploit could allow an attacker to provide a modified URL,… | |
| Modificada | Crítica (9.8) | 2.0% | — | Wibu Codemeter RuntimeTrumpf OseonTrumpf ProgrammingtubeTrumpf Teczonebend+20 | 13/9/2023 | 17/6/2026 | A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system. | |
| Modificada | Alta (7.8) | 5.4% | — | Cisco Anyconnect Secure Mobility ClientCisco Secure Client | 28/6/2023 | 17/6/2026 | A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SYSTEM. The client update process is executed after a successful VPN… | |
| Modificada | Alta (7) | 0.25% | — | Cloud Mobility FOR Dell EMC Storage | 19/1/2023 | 17/6/2026 | Cloud Mobility for Dell EMC Storage, versions 1.3.0.X and below contains an Improper Check for Certificate Revocation vulnerability. A threat actor does not need any specific privileges to potentially exploit this vulnerability. An attacker could perform a man-in-the-middle attack and eavesdrop on encrypted… | |
| Modificada | Crítica (9.8) | 0.88% | — | Sierrawireless Airlink Mobility Manager | 26/12/2022 | 17/6/2026 | Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login session with administrator privileges. | |
| Modificada | Media (6.7) | 0.18% | — | Cloud Mobility FOR Dell EMC Storage | 11/10/2022 | 17/6/2026 | Cloud Mobility for Dell Storage versions 1.3.0 and earlier contains an Improper Access Control vulnerability within the Postgres database. A threat actor with root level access to either the vApp or containerized versions of Cloud Mobility may potentially exploit this vulnerability, leading to the modification or… | |
| Modificada | Crítica (9.8) | 1.0% | — | Cloud Mobility FOR Dell EMC Storage | 7/7/2022 | 17/6/2026 | Cloud Mobility for Dell EMC Storage, 1.3.0.XXX contains a RCE vulnerability. A non-privileged user could potentially exploit this vulnerability, leading to achieving a root shell. This is a critical issue; so Dell recommends customers to upgrade at the earliest opportunity. | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Alta (7.8) | 0.24% | — | Cisco Anyconnect Secure Mobility Client | 4/11/2021 | 17/6/2026 | A vulnerability in the Network Access Manager (NAM) module of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to escalate privileges on an affected device. This vulnerability is due to incorrect privilege assignment to scripts executed before user logon. An attacker… |