Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.1) | 0.31% | — | Saltosystem Proaccess SpaceAI | 16/7/2026 | 17/7/2026 | SALTO ProAccess Space software using the tenancy feature / logical partition is vulnerable to a privilege escalation attack that could allow an authorized attacker to access any space managed by the affected product. | |
| Analizada | Media (6.1) | 0.28% | — | Saltos Rhinos | 27/5/2024 | 17/6/2026 | RhinOS 3.0-1190 is vulnerable to an XSS via the "tamper" parameter in /admin/lib/phpthumb/phpthumb.php. An attacker could create a malicious URL and send it to a victim to obtain their session details. | |
| Analizada | Media (6.1) | 0.33% | — | Saltos Rhinos | 27/5/2024 | 17/6/2026 | Vulnerability in RhinOS 3.0-1190 consisting of an XSS through the "search" parameter of /portal/search.htm. This vulnerability could allow a remote attacker to steal details of a victim's user session by submitting a specially crafted URL. | |
| Analizada | Crítica (9.8) | 0.60% | — | Saltos Rhinos | 27/5/2024 | 17/6/2026 | A vulnerability in RhinOS 3.0-1190 could allow PHP code injection through the "search" parameter in /portal/search.htm. This vulnerability could allow a remote attacker to perform a reverse shell on the remote system, compromising the entire infrastructure. | |
| Modificada | Crítica (9.8) | 3.5% | — | Saltosystem Proaccess Space | 3/12/2019 | 17/6/2026 | An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. An attacker can write arbitrary content to arbitrary files, as demonstrated by CVE-2019-19458 files under the web root, or .bat files that will be used with auto start. This allows an attacker to execute arbitrary commands on the server. | |
| Modificada | Alta (8.6) | 2.8% | — | Saltosystem Proaccess Space | 3/12/2019 | 17/6/2026 | SALTO ProAccess SPACE 5.4.3.0 allows Directory Traversal in the Data Export feature. | |
| Modificada | Media (5.4) | 0.64% | — | Saltosystem Proaccess Space | 3/12/2019 | 17/6/2026 | SALTO ProAccess SPACE 5.4.3.0 allows XSS. | |
| Modificada | Media (5.5) | 0.42% | — | Saltosystem Proaccess Space | 3/12/2019 | 17/6/2026 | An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. The product's webserver runs as a Windows service with local SYSTEM permissions by default. This is against the principle of least privilege. An attacker who is able to exploit CVE-2019-19458 or CVE-2019-19459 is basically able to write to every single path on… | |
| Modificada | Media (6.5) | 6.2% | — | Saltos | 21/3/2019 | 17/6/2026 | SaltOS 3.1 r8126 contains a database download vulnerability. | |
| Modificada | Crítica (9.8) | 3.2% | — | Saltos | 16/11/2018 | 17/6/2026 | SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection. | |
| Modificada | Crítica (9.8) | 16% | — | Saltos | 16/11/2018 | 17/6/2026 | SaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection. | |
| Modificada | Media (6.5) | 2.6% | — | Saltos Rhinos | 16/11/2018 | 17/6/2026 | RhinOS 3.0 build 1190 allows CSRF. |