Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.1)0.31%—Saltosystem Proaccess SpaceAI16/7/202617/7/2026
SALTO ProAccess Space software using the tenancy feature / logical partition is vulnerable to a privilege escalation attack that could allow an authorized attacker to access any space managed by the affected product.
AnalizadaMedia (6.1)0.28%—Saltos Rhinos27/5/202417/6/2026
RhinOS 3.0-1190 is vulnerable to an XSS via the "tamper" parameter in /admin/lib/phpthumb/phpthumb.php. An attacker could create a malicious URL and send it to a victim to obtain their session details.
AnalizadaMedia (6.1)0.33%—Saltos Rhinos27/5/202417/6/2026
Vulnerability in RhinOS 3.0-1190 consisting of an XSS through the "search" parameter of /portal/search.htm. This vulnerability could allow a remote attacker to steal details of a victim's user session by submitting a specially crafted URL.
AnalizadaCrítica (9.8)0.60%—Saltos Rhinos27/5/202417/6/2026
A vulnerability in RhinOS 3.0-1190 could allow PHP code injection through the "search" parameter in /portal/search.htm. This vulnerability could allow a remote attacker to perform a reverse shell on the remote system, compromising the entire infrastructure.
ModificadaCrítica (9.8)3.5%—Saltosystem Proaccess Space3/12/201917/6/2026
An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. An attacker can write arbitrary content to arbitrary files, as demonstrated by CVE-2019-19458 files under the web root, or .bat files that will be used with auto start. This allows an attacker to execute arbitrary commands on the server.
ModificadaAlta (8.6)2.8%—Saltosystem Proaccess Space3/12/201917/6/2026
SALTO ProAccess SPACE 5.4.3.0 allows Directory Traversal in the Data Export feature.
ModificadaMedia (5.4)0.64%—Saltosystem Proaccess Space3/12/201917/6/2026
SALTO ProAccess SPACE 5.4.3.0 allows XSS.
ModificadaMedia (5.5)0.42%—Saltosystem Proaccess Space3/12/201917/6/2026
An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. The product's webserver runs as a Windows service with local SYSTEM permissions by default. This is against the principle of least privilege. An attacker who is able to exploit CVE-2019-19458 or CVE-2019-19459 is basically able to write to every single path on…
ModificadaMedia (6.5)6.2%—Saltos21/3/201917/6/2026
SaltOS 3.1 r8126 contains a database download vulnerability.
ModificadaCrítica (9.8)3.2%—Saltos16/11/201817/6/2026
SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection.
ModificadaCrítica (9.8)16%—Saltos16/11/201817/6/2026
SaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection.
ModificadaMedia (6.5)2.6%—Saltos Rhinos16/11/201817/6/2026
RhinOS 3.0 build 1190 allows CSRF.