Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 306 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (3.5) | 0.26% | — | SEP SesamAIMicrosoft Active DirectoryAI | 12/9/2026 | 22/9/2026 | SEP sesam before 5.2.0.24 mishandles User Authorization with MFA. If AD authentication is configured and MFA is enforced, an attacker can create a second OTP access capability. SEP sesam and Active Directory handle username capitalization differently, which may allow multiple SEP sesam user accounts to be created for… | |
| Aplazada | Alta (8.7) | 0.44% | — | Sesame TimeAI | 14/7/2026 | 15/7/2026 | A vulnerability relating to insufficient access control has been identified in the session management of the Sesame Time web application and its REST v3 API. The flaw lies in the fact that the system uses the session identifier (USID) as the sole validation mechanism, without verifying whether that identifier… | |
| Aplazada | Media (5.1) | 0.35% | — | SesameAI | 20/1/2026 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerability in Sesame web application, due to the fact that uploaded SVG images are not properly sanitized. This allows attackers to embed malicious scripts in SVG files by sending a POST request using the 'logo' parameter in '/api/v3/companies/<ID>/logo', which are then stored on… | |
| Modificada | Media (6.1) | 0.46% | — | Sesami Cash Point & Transport Optimizer | 29/12/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows remote attackers to execute arbitrary code via the Teller field. | |
| Modificada | Alta (7.5) | 0.36% | — | Sesami Cash Point & Transport Optimizer | 29/12/2023 | 17/6/2026 | An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via transmission of unencrypted, cleartext credentials during Password Reset feature. | |
| Modificada | Alta (7.5) | 0.58% | — | Sesami Cash Point & Transport Optimizer | 29/12/2023 | 17/6/2026 | CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the User Profile field. | |
| Modificada | Media (6.1) | 0.46% | — | Sesami Cash Point & Transport Optimizer | 29/12/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code via the Barcode field of a container. | |
| Modificada | Media (5.3) | 0.38% | — | Sesami Cash Point & Transport Optimizer | 29/12/2023 | 17/6/2026 | CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows attackers to obtain sensitive information via the User Name field. | |
| Modificada | Alta (7.5) | 0.58% | — | Sesami Cash Point & Transport Optimizer | 29/12/2023 | 17/6/2026 | CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the Delivery Name field. | |
| Modificada | Media (4.3) | 0.47% | — | Sesami Cash Point & Transport Optimizer | 29/12/2023 | 17/6/2026 | An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows remote attackers to obtain sensitive information and bypass profile restriction via improper access control in the Reader system user's web browser, allowing the journal to be displayed, despite the option being disabled. | |
| Modificada | Media (6.1) | 0.46% | — | Sesami Cash Point & Transport Optimizer | 29/12/2023 | 17/6/2026 | Stored Cross Site Scripting (XSS) Vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code and obtain sensitive information via the Username field of the login form and application log. | |
| Modificada | Media (4.8) | 0.44% | — | Sesami Cash Point & Transport Optimizer | 29/12/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code and obtain sensitive information via the User ID field when creating a new system user. | |
| Modificada | Media (5.5) | 0.17% | — | Sesami Cash Point & Transport Optimizer | 29/12/2023 | 17/6/2026 | An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows local attackers to obtain sensitive information and bypass authentication via "Back Button Refresh" attack. | |
| Modificada | Media (4.8) | 0.31% | — | Sesami Cash Point & Transport Optimizer | 25/12/2023 | 17/6/2026 | An issue was discovered in SESAMI planfocus CPTO (Cash Point & Transport Optimizer) 6.3.8.6 718. There is XSS via the Name field when modifying a client. | |
| Modificada | Media (5.3) | 1.4% | — | Sesame-system Web-sesame | 6/1/2021 | 17/6/2026 | A misconfiguration in Web-Sesame 2020.1.1.3375 allows an unauthenticated attacker to download the source code of the application, facilitating its comprehension (code review). Specifically, JavaScript source maps were inadvertently included in the production Webpack configuration. These maps contain sources used to… | |
| Modificada | Media (5.1) | 1.2% | — | Arjohn Kampman Sesame RDF Container | 31/12/2004 | 16/6/2026 | Unspecified vulnerability in Sesamie 1.0 allows remote anonymous attackers to gain access to repositories of other users via unknown vectors. | |
| Modificada | Alta (7.5) | 8.3% | — | Isesam Gemitel | 15/4/2004 | 16/6/2026 | PHP remote file inclusion vulnerability in affich.php in Gemitel 3.50 allows remote attackers to execute arbitrary PHP code via the base parameter. |