Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2636▼ 301 respecto a la semana anterior
Críticas / altas1348▲ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
28 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Baja (2) | 0.19% | — | Omega Solution Coinex CryptoAI | 4/10/2026 | 5/10/2026 | A weakness has been identified in Omega Solution CoinEx Crypto 2025. Affected by this vulnerability is an unknown functionality of the file /user/ticket of the component Ticket Attachment Upload. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made… | |
| Recibida | Baja (2.1) | 0.28% | — | Omega Solution Coinex CryptoAI | 4/10/2026 | 4/10/2026 | A security flaw has been discovered in Omega Solution CoinEx Crypto 2025. Affected is an unknown function of the file /ticket/customer of the component Support Ticket API. The manipulation of the argument status/page/count results in information disclosure. The attack can be executed remotely. The exploit has been… | |
| Recibida | Baja (2.1) | 0.29% | — | Omega Solution Coinex CryptoAI | 4/10/2026 | 5/10/2026 | A vulnerability was identified in Omega Solution CoinEx Crypto 2025. This impacts an unknown function of the file /customer-currency/ of the component Customer Information API. The manipulation of the argument ID leads to authorization bypass. Remote exploitation of the attack is possible. The exploit is publicly… | |
| Recibida | Baja (2.1) | 0.29% | — | Omega Solution Coinex CryptoAI | 4/10/2026 | 5/10/2026 | A vulnerability was determined in Omega Solution CoinEx Crypto 2025. This affects an unknown function of the file /customer/ of the component Customer Profile API. Executing a manipulation of the argument ID can lead to authorization bypass. The attack may be launched remotely. The exploit has been publicly disclosed… | |
| Aplazada | Baja (2.1) | 0.37% | — | Omega Solution FBP Fulfillment BY PeopleAI | 21/9/2026 | 22/9/2026 | A security vulnerability has been detected in Omega Solution FBP Fulfillment by People 2025. This impacts an unknown function of the file /user/ of the component User Profile API. The manipulation of the argument ID leads to authorization bypass. Remote exploitation of the attack is possible. The exploit has been… | |
| Aplazada | Media (5.5) | 0.68% | — | Omega Solution HRM OSAI | 21/9/2026 | 21/9/2026 | A weakness has been identified in Omega Solution HRM OS up to 20260717. This affects an unknown function of the file /role-permission/permission of the component Role Permission API. Executing a manipulation of the argument roleId can lead to missing authentication. The attack may be launched remotely. The exploit has… | |
| Aplazada | Baja (1.9) | 0.35% | — | Omega Solution HRM OSAI | 21/9/2026 | 24/9/2026 | A security flaw has been discovered in Omega Solution HRM OS up to 20260717. The impacted element is an unknown function of the file /media/view/ of the component SVG File Upload. Performing a manipulation results in cross site scripting. The attack may be initiated remotely. The exploit has been released to the… | |
| Aplazada | Baja (2.1) | 0.38% | — | Omega Solution HRM OSAI | 21/9/2026 | 21/9/2026 | A vulnerability was identified in Omega Solution HRM OS up to 20260717. The affected element is an unknown function of the file /role-permission/permission of the component Role Permission Retrieval Endpoint. Such manipulation of the argument roleId leads to improper control of resource identifiers. The attack can be… | |
| Analizada | Alta (7.5) | 0.56% | — | Home-gallery Homegallery | 6/3/2026 | 17/6/2026 | Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. Prior to version 1.21.0, when a user requests a download, the application does not verify whether the requested file is located within the media source directory, which can result in sensitive system files being… | |
| Analizada | Media (5.1) | 0.16% | — | PW Omega-psir | 27/2/2026 | 17/6/2026 | Omega-PSIR is vulnerable to Reflected XSS via the lang parameter. An attacker can craft a malicious URL that, when opened, causes arbitrary JavaScript to execute in the victim’s browser. This issue was fixed in 4.6.7. | |
| Analizada | Alta (7.5) | 0.40% | — | Dwyeromega Isensix Advanced Remote Monitoring System Firmware | 6/1/2026 | 17/6/2026 | DwyerOmega Isensix Advanced Remote Monitoring System (ARMS) 1.5.7 allows an attacker to retrieve sensitive information from the underlying SQL database via Blind SQL Injection through the user parameter in the login page. This allows an attacker to steal credentials, which may be cleartext, from existing users (and… | |
| Aplazada | Alta (7.1) | 0.18% | — | Alphaomegaplugins Alphaomega Captcha Anti Spam FilterAI | 24/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in alphaomegaplugins AlphaOmega Captcha & Anti-Spam Filter alphaomega-captcha-anti-spam allows Stored XSS.This issue affects AlphaOmega Captcha & Anti-Spam Filter: from n/a through <= 3.3. | |
| Aplazada | Crítica (9.8) | 0.72% | — | OmegatAI | 21/11/2024 | 5/7/2026 | An arbitrary file upload vulnerability in the component \Roaming\Omega of OmegaT v6.0.1 allows attackers to execute arbitrary code via uploading a crafted .conf file. | |
| Modificada | Media (5.5) | 0.94% | — | EMC LifelineIomega Home Media Network Hard DriveIomega IconnectIomega Storcenter | 16/8/2012 | 16/6/2026 | The Iomega Home Media Network Hard Drive with EMC Lifeline firmware before 2.104, Home Media Network Hard Drive Cloud Edition with EMC Lifeline firmware before 3.2.3.15290, iConnect with EMC Lifeline firmware before 2.5.26.18966, and StorCenter with EMC Lifeline firmware before 2.0.18.23122, 2.1.x before 2.1.42.18967,… | |
| Modificada | Media (4.3) | 1.9% | — | Xapian Omega | 14/9/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Xapian Omega before 1.0.16 allows remote attackers to inject arbitrary web script or HTML via unspecified CGI parameter values, which are sometimes included in exception messages. | |
| Modificada | Crítica (9.8) | 23% | — | Iomega Storcenter PRO Firmware | 8/7/2009 | 16/6/2026 | cgi-bin/makecgi-pro in Iomega StorCenter Pro generates predictable session IDs, which allows remote attackers to hijack active sessions and gain privileges via brute force guessing attacks on the session_id parameter. | |
| Modificada | Media (6.4) | 2.2% | — | Omegasoft Interneserviceslosungen | 4/3/2008 | 16/6/2026 | OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) 7 supports authentication with a cookie that lacks a shared secret, which allows remote attackers to login as an arbitrary user via a modified cookie. | |
| Modificada | Media (5) | 1.3% | — | Omegasoft Interneserviceslosungen | 4/3/2008 | 16/6/2026 | OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) 7 generates different responses depending on whether or not a username is valid in a failed login attempt, which allows remote attackers to enumerate valid usernames. | |
| Modificada | Media (4.3) | 1.3% | — | Omegasoft Interneserviceslosungen | 4/6/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in OmegaMw7.asp in OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) allow remote attackers to inject arbitrary web script or HTML via (1) user-created text fields; the (2) F05003, (3) F05005, and (4) F05015 fields; and other unspecified standard fields. | |
| Modificada | Alta (7.5) | 1.3% | — | Omegasoft Interneserviceslosungen | 4/6/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in OmegaMw7.asp in OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) allow remote attackers to execute arbitrary SQL commands via (1) user-created text fields; the (2) F05003, (3) F05005, and (4) F05015 fields; and other unspecified standard fields. | |
| Modificada | Alta (7.5) | 4.8% | — | Omegaboard Project Omegaboard | 3/2/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/functions.php in Omegaboard 1.0beta4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | |
| Modificada | Media (5.8) | 1.2% | — | Omegasoft Interneserviceslosungen | 30/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in OmegaMw7a.ASP in OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) allows remote attackers to inject arbitrary web script or HTML via the WCE parameter. | |
| Modificada | Media (4.6) | 0.40% | — | Omega-rpg | 15/12/2003 | 16/6/2026 | Buffer overflow in omega-rpg 0.90 allows local users to execute arbitrary code via a long (1) command line or (2) environment variable. | |
| Modificada | Media (4.6) | 0.31% | — | Iomega Network Attached Storage | 31/12/2002 | 16/6/2026 | Iomega Network Attached Storage (NAS) A300U, and possibly other models, does not allow the FTP service to be disabled, which allows local users to access home directories via FTP even when access to all shared directories have been disabled. | |
| Modificada | Media (5) | 1.3% | — | Iomega NAS | 31/12/2002 | 16/6/2026 | Iomega NAS A300U uses cleartext LANMAN authentication when mounting CIFS/SMB drives, which allows remote attackers to perform a man-in-the-middle attack. |