Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.46%—Sayax Energy Technologies INC OsosAI9/7/20269/7/2026
Insertion of sensitive information into sent data vulnerability in Sayax Energy Technologies Inc. OSOS allows Authentication Bypass. This issue affects OSOS: through 09072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
AplazadaMedia (6.5)0.55%—Cososys Endpoint ProtectorAIUnify AgentAI27/6/202417/6/2026
The CoSoSys Endpoint Protector through 5.9.3 and Unify agent through 7.0.6 is susceptible to an arbitrary code execution vulnerability due to the way an archive obtained from the Endpoint Protector or Unify server is extracted on the endpoint. An attacker who is able to modify the archive on the server could obtain…
AplazadaAlta (7.2)0.78%—Netwrix Cososys UnifyAICososys Endpoint ProtectorAI27/6/202417/6/2026
Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the Endpoint Protector and Unify agent in the way that the EasyLock dependency is acquired from the server. An attacker with administrative access to the Endpoint Protector or Unify server…
AplazadaAlta (7.2)0.78%—Netwrix Cososys UnifyAICososys Endpoint ProtectorAI27/6/202417/6/2026
Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the shadowing component of the Endpoint Protector and Unify agent which allows an attacker with administrative access to the Endpoint Protector or Unify server to overwrite sensitive…
AplazadaCrítica (9.8)1.0%—Netwrix Endpoint ProtectorAICososys UnifyAI27/6/202417/6/2026
Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the logging component of the Endpoint Protector and Unify server application which allows an unauthenticated remote attacker to send a malicious request, resulting in the ability to execute…
AnalizadaCrítica (9.8)0.78%—Demososo DM Enterprise Website Building System23/2/202417/6/2026
A vulnerability has been found in Demososo DM Enterprise Website Building System up to 2022.8 and classified as critical. Affected by this vulnerability is the function dmlogin of the file indexDM_load.php of the component Cookie Handler. The manipulation of the argument is_admin with the input y leads to improper…
ModificadaAlta (7.5)0.97%—Cososys Endpoint Protector4/5/202017/6/2026
CoSoSys Endpoint Protector 5.1.0.2 allows Host Header Injection.
ModificadaAlta (7.5)1.2%—Cososys Endpoint Protector2/6/201417/6/2026
SQL injection vulnerability in the device registration component in wsf/webservice.php in CoSoSys Endpoint Protector 4 4.3.0.4 and 4.4.0.2 allows remote attackers to execute arbitrary SQL commands via unspecified parameters.
ModificadaAlta (7.5)6.3%💥 ExploitCososys Endpoint Protector Appliace 418/9/201216/6/2026
The CoSoSys Endpoint Protector 4 appliance establishes an EPProot password based entirely on the appliance serial number, which makes it easier for remote attackers to obtain access via a brute-force attack.
Orbitaley — Vulnerabilidades