Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
31 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.70% | — | NovuAI | 22/9/2026 | 24/9/2026 | Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu integration mutation use cases including remove-integration, update-integration, auto-configure-integration, and set-integration-as-primary look up an integration by integrationId and organizationId without consistently… | |
| Aplazada | Media (5.3) | 0.46% | — | NovuAI | 22/9/2026 | 25/9/2026 | Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu accepts chat webhook URLs from subscriber credentials.webhookUrl, channel endpoint endpoint.url, event payload.webhookUrl, and event overrides.webhookUrl, then passes the selected endpoint.url through… | |
| Aplazada | Media (5.1) | 0.35% | — | Novu JSAINovu ReactAI | 22/9/2026 | 24/9/2026 | Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu's @novu/js In-App Inbox and the @novu/react Inbox component accept a notification call-to-action redirect.url from the v1 cta.data object and pass it through apps/api/src/app/inbox/utils/notification-mapper.ts and… | |
| Pendiente de análisis | Crítica (9.1) | 0.24% | — | Novus Airgate 4GAI | 18/5/2026 | 5/7/2026 | Incorrect access control in the /uci/get/ endpoint of NOVUS AirGate 4G firmware v1.1.16 allows unauthenticated attackers to obtain administrator credentials via a crafted POST request. | |
| Analizada | Crítica (9) | 0.18% | — | Minecanton209 Novumos | 18/4/2026 | 17/6/2026 | NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 15 (MemoryMapRange) allows Ring 3 user-mode processes to map arbitrary virtual address ranges into their address space without validating against forbidden regions, including critical kernel structures such… | |
| Analizada | Crítica (9.3) | 0.20% | — | Minecanton209 Novumos | 18/4/2026 | 17/6/2026 | NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 12 (JumpToUser) accepts an arbitrary entry point address from user-space registers without validation, allowing any Ring 3 user-mode process to jump to kernel addresses and execute arbitrary code in Ring 0… | |
| Analizada | Alta (8.8) | 1.4% | — | It-novum Openitcockpit | 14/4/2026 | 25/7/2026 | openITCOCKPIT is an open source monitoring tool built for different monitoring engines. openITCOCKPIT Community Edition prior to version 5.5.2 contains a command injection vulnerability that allows an authenticated user with permission to add or modify hosts to execute arbitrary OS commands on the monitoring backend.… | |
| Analizada | Alta (8.8) | 0.83% | — | It-novum Openitcockpit | 20/2/2026 | 17/6/2026 | openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. openITCOCKPIT Community Edition 5.3.1 and earlier contains an unsafe PHP deserialization pattern in the processing of changelog entries. Serialized changelog data derived from attacker-influenced… | |
| Analizada | Alta (7.5) | 0.36% | — | It-novum Openitcockpit | 20/2/2026 | 17/6/2026 | openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. Versions 5.3.1 and below contain an unsafe deserialization sink in the Gearman worker implementation. The worker function registered as oitc_gearman calls PHP's unserialize() on job payloads… | |
| Modificada | Crítica (9.8) | 1.0% | — | Trispark NovuseduTrispark VEO Transportation | 29/8/2023 | 9/7/2026 | TripSpark VEO Transportation-2.2.x-XP_BB-20201123-184084 NovusEDU-2.2.x-XP_BB-20201123-184084 allows unsafe data inputs in POST body parameters from end users without sanitizing using server-side logic. It was possible to inject custom SQL commands into the "Student Busing Information" search queries. | |
| Modificada | Media (6.1) | 0.39% | — | Novu | 6/7/2023 | 17/6/2026 | Novu provides an API for sending notifications through multiple channels. Versions prior to 0.16.0 contain an open redirect vulnerability in the "Sign In with GitHub" functionality of Novu's open-source repository. It could have allowed an attacker to force a victim into opening a malicious URL and thus, potentially… | |
| Modificada | Media (4.6) | 0.30% | — | It-novum Openitcockpit | 6/7/2023 | 17/6/2026 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository it-novum/openitcockpit prior to 4.6.6. | |
| Modificada | Alta (8.8) | 0.71% | — | It-novum Openitcockpit | 25/6/2023 | 17/6/2026 | it-novum openITCOCKPIT (aka open IT COCKPIT) 4.6.4 before 4.6.5 allows SQL Injection (by authenticated users) via the sort parameter of the API interface. | |
| Modificada | Media (4.4) | 0.47% | — | It-novum Openitcockpit | 13/6/2023 | 17/6/2026 | Race Condition within a Thread in GitHub repository it-novum/openitcockpit prior to 4.6.5. | |
| Modificada | Media (6.1) | 0.82% | — | AAT Novus Management System | 19/7/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability exists in AAT Novus Management System through 1.51.2. The WebUI has wrong HTTP 404 error handling implemented. A remote, unauthenticated attacker may be able to exploit the issue by sending malicious HTTP requests to non-existing URIs. The value of the URL path filename is… | |
| Modificada | Alta (7.5) | 4.0% | — | AAT Novus Management System | 19/7/2021 | 17/6/2026 | Web Path Directory Traversal in the Novus HTTP Server. The Novus HTTP Server is affected by the Directory Traversal for Arbitrary File Access vulnerability. A remote, unauthenticated attacker using an HTTP GET request may be able to exploit this issue to access sensitive data. The issue was discovered in the NMS… | |
| Modificada | Crítica (9.1) | 1.6% | — | It-novum Openitcockpit | 25/3/2020 | 17/6/2026 | openITCOCKPIT before 3.7.3 uses the 1fea123e07f730f76e661bced33a94152378611e API key rather than generating a random API Key for WebSocket connections. | |
| Modificada | Media (6.5) | 1.2% | — | It-novum Openitcockpit | 25/3/2020 | 17/6/2026 | app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated users to trigger outbound TCP requests (aka SSRF) via the Test Connection feature (aka testGrafanaConnection) of the Grafana Module. | |
| Modificada | Media (5.4) | 0.91% | — | It-novum Openitcockpit | 25/3/2020 | 17/6/2026 | openITCOCKPIT before 3.7.3 has unnecessary files (such as Lodash files) under the web root, which leads to XSS. | |
| Modificada | Crítica (9.8) | 2.0% | — | It-novum Openitcockpit | 25/3/2020 | 17/6/2026 | openITCOCKPIT before 3.7.3 has a web-based terminal that allows attackers to execute arbitrary OS commands via shell metacharacters that are mishandled on an su command line in app/Lib/SudoMessageInterface.php. | |
| Modificada | Alta (7.5) | 1.9% | — | It-novum Openitcockpit | 20/3/2020 | 17/6/2026 | openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev" or "staging" in the HTTP Host header. | |
| Modificada | Media (6.1) | 1.2% | — | It-novum Openitcockpit | 31/12/2019 | 17/6/2026 | openITCOCKPIT before 3.7.1 has reflected XSS in the 404-not-found component. | |
| Modificada | Alta (7.5) | 76% | — | Huntcctv Dvr-04ch FirmwareHuntcctv Dvr-04nc FirmwareHuntcctv Dvr-08ch FirmwareHuntcctv Dvr-08nc Firmware+16 | 30/10/2019 | 16/6/2026 | Authentication bypass vulnerability in the the web interface in Hunt CCTV, Capture CCTV, Hachi CCTV, NoVus CCTV, and Well-Vision Inc DVR systems allows a remote attacker to retrieve the device configuration. | |
| Modificada | Crítica (9.8) | 1.5% | — | It-novum Openitcockpit | 23/8/2019 | 17/6/2026 | openITCOCKPIT before 3.7.1 allows SSRF, aka RVID 5-445b21. | |
| Modificada | Alta (7.5) | 1.2% | — | It-novum Openitcockpit | 23/8/2019 | 17/6/2026 | openITCOCKPIT before 3.7.1 allows deletion of files, aka RVID 4-445b21. |