Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2769▲ 8 respecto a la semana anterior
Críticas / altas1461▲ 292 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 416 respecto a la semana anterior
251 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.5) | 0.37% | — | Cisco Desk Phone 9800 SeriesAICisco IP Phone 7800 SeriesAICisco IP Phone 8800 SeriesAICisco Video Phone 8875AI+1 | 2/9/2026 | 2/9/2026 | A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session Initiation Protocol (SIP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is… | |
| Aplazada | Crítica (9.8) | 0.58% | — | User Session SynchronizerAI | 15/8/2026 | 20/8/2026 | The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 1.4.0. The `synchronize_session()` function, hooked on `init` and therefore executed on every request, performs no nonce, capability, or shared-secret validation… | |
| Aplazada | Media (5.9) | 0.51% | — | Perl CGI Session ID MD5AI | 1/7/2026 | 2/7/2026 | CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources. The generate_id method builds the session id from a MD5 digest of the process id, the epoch time, and the built-in rand() function. All three are predictable, low-entropy sources: the PID is drawn from a… | |
| Aplazada | Media (5.3) | 0.42% | — | Mojolicious Sessions StorableAI | 18/6/2026 | 22/6/2026 | Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurely. The default session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, the heap address of an anonymous hash, and the PID. These are predictable or low-entropy sources that are… | |
| Aplazada | Alta (8.5) | 0.36% | — | Swit WP Sessions Time Monitoring Full AutomaticAI | 16/6/2026 | 17/6/2026 | Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions. | |
| Analizada | Alta (8.7) | 0.81% | — | Paloaltonetworks Idira Privileged Session Manager FOR SSH | 11/6/2026 | 23/6/2026 | Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3, 14.2.5, and 14.0.6, an authenticated, low-privileged user could potentially execute arbitrary commands on the PSMP host. CyberArk Security Bulletins: CA26-17 and CA26-18 | |
| Analizada | Alta (8.7) | 0.72% | — | Paloaltonetworks Idira Privileged Session Manager | 11/6/2026 | 23/6/2026 | Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) versions prior to 15.0.3, 14.6.3, 14.2.5, and 14.0.5, an authenticated, low-privileged user could potentially execute arbitrary code. CyberArk Security Bulletin: CA26-17 and CA26-18 | |
| Aplazada | Media (4.3) | 0.34% | — | Workos Authkit-sessionAI | 11/5/2026 | 17/6/2026 | @workos/authkit-session is a toolkit for building WorkOS AuthKit framework integrations. Prior to 0.5.1, an open redirect vulnerability exists in AuthService.handleCallback due to insufficient validation of the returnPathname value derived from the OAuth state parameter. The state parameter is round-tripped through… | |
| Aplazada | Media (6.5) | 0.37% | — | Webdyne SessionAI | 11/5/2026 | 2/8/2026 | WebDyne::Session versions before 3.003_704 for Perl generate the session id insecurely. The session handler generates the session id from an MD5 hash seeded with a call to the built-in rand() function. The rand function is passed a maximum value based on the process id, the epoch time and the reference address of the… | |
| Analizada | Crítica (9.3) | 0.27% | — | Rack-session | 7/4/2026 | 17/6/2026 | Rack::Session is a session management implementation for Rack. From 2.0.0 to before 2.1.2, Rack::Session::Cookie incorrectly handles decryption failures when configured with secrets:. If cookie decryption fails, the implementation falls back to a default decoder instead of rejecting the cookie. This allows an… | |
| Aplazada | Media (5.3) | 0.29% | — | Swit WP Sessions Time Monitoring Full AutomaticAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in activity-log.com WP Sessions Time Monitoring Full Automatic activitytime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Sessions Time Monitoring Full Automatic: from n/a through <= 1.1.3. | |
| Aplazada | Crítica (9.3) | 1.6% | — | Juniper Networks Session Smart RouterAIJuniper Networks Session Smart ConductorAIJuniper Networks WAN Assurance Managed RoutersAI | 27/1/2026 | 17/6/2026 | An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router may allows a network-based attacker to bypass authentication and take administrative control of the device. This issue affects Session Smart Router: This issue affects Session Smart Conductor: This issue… | |
| Analizada | Media (4.8) | 0.17% | — | Groupsession | 12/12/2025 | 17/6/2026 | Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1. A logged-in user can prepare a malicious page or URL, and an arbitrary script may be executed on the web browser when another user accesses… | |
| Analizada | Media (5.1) | 0.19% | — | Groupsession | 12/12/2025 | 17/6/2026 | Reflected cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1. If a user accesses a crafted page or URL, an arbitrary script may be executed on the web browser of the user. | |
| Analizada | Media (5.3) | 0.19% | — | Groupsession | 12/12/2025 | 17/6/2026 | SQL Injection vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. If exploited, information stored in the database may be obtained or altered by an authenticated user. | |
| Analizada | Media (6.9) | 0.15% | — | Groupsession | 12/12/2025 | 17/6/2026 | GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. do not validate origins in WebSockets. If a user accesses a crafted page, Chat information sent to the user may be exposed. | |
| Analizada | Media (5.3) | 0.19% | — | Groupsession | 12/12/2025 | 17/6/2026 | In GroupSession, a Circular notice can be created with its memo field non-editable, but the authorization check is improperly implemented. With some crafted request, a logged-in user may alter the memo field. The affected products and versions are GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior… | |
| Analizada | Media (5.1) | 0.13% | — | Groupsession | 12/12/2025 | 17/6/2026 | Cross-site request forgery vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. If a user accesses a malicious page while logged in, unintended operations may be performed. | |
| Analizada | Media (4.8) | 0.17% | — | Groupsession | 12/12/2025 | 17/6/2026 | Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. A logged-in user can prepare a malicious page or URL, and an arbitrary script may be executed on the web browser when another user accesses… | |
| Analizada | Media (5.1) | 0.21% | — | Groupsession | 12/12/2025 | 1/10/2026 | In GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1, "External page display restriction" is set to "Do not limit" in the initial configuration. With this configuration, the user may be redirected to an arbitrary website when accessing a… | |
| Analizada | Media (5.1) | 0.19% | — | Groupsession | 12/12/2025 | 30/9/2026 | Reflected cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. If a user accesses a crafted page or URL, an arbitrary script may be executed on the web browser of the user. | |
| Analizada | Media (5.1) | 0.19% | — | Groupsession | 12/12/2025 | 30/9/2026 | Stored cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. If a user accesses a crafted page or URL, an arbitrary script may be executed on the web browser of the user. | |
| Analizada | Alta (7.5) | 0.29% | — | Plack-middleware-session | 9/12/2025 | 16/6/2026 | Plack-Middleware-Session versions before 0.17 may be vulnerable to HMAC comparison timing attacks | |
| Aplazada | Media (4.8) | 0.14% | — | Cyberark Secure WEB Sessions ExtensionAI | 27/11/2025 | 3/9/2026 | Improper Input Validation vulnerability in CyberArk CyberArk Secure Web Sessions Extension on Chrome, Edge allows Denial of Service when trying to starting new SWS sessions.This issue affects CyberArk Secure Web Sessions Extension: before 2.2.30305. | |
| Aplazada | Media (4.8) | 0.22% | — | Cisco Unified Communications ManagerAICisco Unified Communications Manager Session Management EditionAI | 1/10/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.… |