Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2632▼ 307 respecto a la semana anterior
Críticas / altas1348▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.1) | 0.31% | — | Saltosystem Proaccess SpaceAI | 16/7/2026 | 17/7/2026 | SALTO ProAccess Space software using the tenancy feature / logical partition is vulnerable to a privilege escalation attack that could allow an authorized attacker to access any space managed by the affected product. | |
| Aplazada | Alta (8.7) | 0.19% | — | Gallagher Command CentreAISaltoAI | 10/3/2025 | 17/6/2026 | Improper Certificate Validation (CWE-295) in the Gallagher Command Centre SALTO integration allowed an attacker to spoof the SALTO server. This issue affects all versions of Gallagher Command Centre prior to 9.20.1043. | |
| Aplazada | Media (4.6) | 0.23% | — | Salto Controller 6000AISalto Controller 7000AI | 11/9/2024 | 17/6/2026 | Incorrect Calculation of Buffer Size (CWE-131) in the Controller 6000 and Controller 7000 OSDP message handling, allows an attacker with physical access to Controller wiring to instigate a reboot leading to a denial of service. This issue affects: Controller 6000 and Controller 7000 9.10 prior to vCR9.10.240816a… | |
| Analizada | Media (6.1) | 0.28% | — | Saltos Rhinos | 27/5/2024 | 17/6/2026 | RhinOS 3.0-1190 is vulnerable to an XSS via the "tamper" parameter in /admin/lib/phpthumb/phpthumb.php. An attacker could create a malicious URL and send it to a victim to obtain their session details. | |
| Analizada | Media (6.1) | 0.33% | — | Saltos Rhinos | 27/5/2024 | 17/6/2026 | Vulnerability in RhinOS 3.0-1190 consisting of an XSS through the "search" parameter of /portal/search.htm. This vulnerability could allow a remote attacker to steal details of a victim's user session by submitting a specially crafted URL. | |
| Analizada | Crítica (9.8) | 0.60% | — | Saltos Rhinos | 27/5/2024 | 17/6/2026 | A vulnerability in RhinOS 3.0-1190 could allow PHP code injection through the "search" parameter in /portal/search.htm. This vulnerability could allow a remote attacker to perform a reverse shell on the remote system, compromising the entire infrastructure. | |
| Modificada | Crítica (9.8) | 3.5% | — | Saltosystem Proaccess Space | 3/12/2019 | 17/6/2026 | An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. An attacker can write arbitrary content to arbitrary files, as demonstrated by CVE-2019-19458 files under the web root, or .bat files that will be used with auto start. This allows an attacker to execute arbitrary commands on the server. | |
| Modificada | Alta (8.6) | 2.8% | — | Saltosystem Proaccess Space | 3/12/2019 | 17/6/2026 | SALTO ProAccess SPACE 5.4.3.0 allows Directory Traversal in the Data Export feature. | |
| Modificada | Media (5.4) | 0.64% | — | Saltosystem Proaccess Space | 3/12/2019 | 17/6/2026 | SALTO ProAccess SPACE 5.4.3.0 allows XSS. | |
| Modificada | Media (5.5) | 0.42% | — | Saltosystem Proaccess Space | 3/12/2019 | 17/6/2026 | An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. The product's webserver runs as a Windows service with local SYSTEM permissions by default. This is against the principle of least privilege. An attacker who is able to exploit CVE-2019-19458 or CVE-2019-19459 is basically able to write to every single path on… | |
| Modificada | Media (6.5) | 6.2% | — | Saltos | 21/3/2019 | 17/6/2026 | SaltOS 3.1 r8126 contains a database download vulnerability. | |
| Modificada | Crítica (9.8) | 3.2% | — | Saltos | 16/11/2018 | 17/6/2026 | SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection. | |
| Modificada | Crítica (9.8) | 16% | — | Saltos | 16/11/2018 | 17/6/2026 | SaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection. | |
| Modificada | Media (6.5) | 2.6% | — | Saltos Rhinos | 16/11/2018 | 17/6/2026 | RhinOS 3.0 build 1190 allows CSRF. |