Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
73 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.1) | 0.15% | — | MinioAIPgsty SiloAI | 25/9/2026 | 30/9/2026 | MinIO through 7aac2a2 does not verify that every x-amz-* header present on a request also appears in the client-supplied X-Amz-SignedHeaders list. extractSignedHeaders() in cmd/signature-v4-utils.go iterates only the claimed list and never enumerates the headers that actually arrived, and thus a header that arrives… | |
| Aplazada | Alta (7.1) | 0.12% | — | Upsilon 2000AI | 26/11/2025 | 17/6/2026 | The RupsMon and USBMate services in UPSilon 2000 run with SYSTEM privileges and contain unquoted service paths. This allows a local attacker to perform path interception and escalate privileges if they have write permissions to the directories proceeding that of which the real service executables live in | |
| Aplazada | Crítica (9.3) | 0.14% | — | Upsilon 2000AI | 26/11/2025 | 17/6/2026 | The RupsMon.exe service executable in UPSilon 2000 has insecure permissions, allowing the 'Everyone' group Full Control. A local attacker can replace the executable with a malicious binary to execute code with SYSTEM privileges or simply change the config path of the service to a command; starting and stopping the… | |
| Aplazada | Media (6.9) | 0.30% | — | EpsilonnetAI | 29/10/2025 | 17/6/2026 | This vulnerability allows an attacker to access parts of the application that are not protected by any type of access control. The attacker could access this path ‘…/epsilonnet/License/About.aspx’ and obtain information on both the licence and the configuration of the product by knowing which modules are installed. | |
| Aplazada | Crítica (9.3) | 0.47% | — | Grupo Castilla Epsilon RHAI | 20/10/2025 | 17/6/2026 | A SQL Injection vulnerability has been found in Epsilon RH by Grupo Castilla. This vulnerability allows an attacker to retrieve, create, update and delete database via sending a POST request using the parameter ‘sEstadoUsr’ in ‘/epsilonnetws/WSAvisos.asmx’. | |
| Aplazada | Media (4.3) | 0.14% | — | Epsiloncool WP Fast Total SearchAI | 22/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Epsiloncool WP Fast Total Search fulltext-search allows Cross Site Request Forgery.This issue affects WP Fast Total Search: from n/a through <= 1.79.270. | |
| Aplazada | Media (4.7) | 0.14% | — | Arctera Veritas Data InsightAIDell Isilon OnefsAI | 16/4/2025 | 17/6/2026 | Arctera/Veritas Data Insight before 7.1.2 can send cleartext credentials when configured to use HTTP Basic Authentication to a Dell Isilon OneFS server. | |
| Aplazada | Media (4.3) | 0.32% | — | Epsiloncool WP Fast Total SearchAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Epsiloncool WP Fast Total Search fulltext-search allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Fast Total Search: from n/a through <= 1.79.262. | |
| Aplazada | Media (6.5) | 0.26% | — | Epsiloncool WP Fast Total SearchAI | 24/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Epsiloncool WP Fast Total Search fulltext-search allows Cross Site Request Forgery.This issue affects WP Fast Total Search: from n/a through <= 1.78.258. | |
| Aplazada | Media (5.4) | 0.46% | — | Epsiloncool WP Fast Total SearchAI | 24/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Epsiloncool WP Fast Total Search fulltext-search allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Fast Total Search: from n/a through <= 1.78.258. | |
| Aplazada | Media (4.3) | 0.17% | — | Epsiloncool WP Fast Total SearchAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Epsiloncool WP Fast Total Search fulltext-search.This issue affects WP Fast Total Search: from n/a through <= 1.69.234. | |
| Aplazada | Media (4.3) | 0.37% | — | Epsiloncool WP Fast Total SearchAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Epsiloncool WP Fast Total Search fulltext-search.This issue affects WP Fast Total Search: from n/a through <= 1.68.232. | |
| Aplazada | Alta (7.1) | 0.27% | — | Epsiloncool WP Fast Total SearchAI | 1/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Epsiloncool WP Fast Total Search fulltext-search.This issue affects WP Fast Total Search: from n/a through <= 1.68.232. | |
| Analizada | Alta (7.5) | 0.45% | — | Unitronics Visilogic | 21/7/2024 | 17/6/2026 | Unitronics Vision PLC – CWE-703: Improper Check or Handling of Exceptional Conditions may allow denial of service | |
| Aplazada | Media (6.5) | 0.35% | — | Epsiloncool WP Fast Total SearchAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Epsiloncool WP Fast Total Search allows Stored XSS.This issue affects WP Fast Total Search: from n/a through 1.59.211. | |
| Analizada | Crítica (9.8) | 2.1% | ⚠ Explotación activa | Unitronics Vision1210 FirmwareUnitronics Vision1040 FirmwareUnitronics Vision700 FirmwareUnitronics Vision570 Firmware+13 | 5/12/2023 | 17/6/2026 | Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative control of a vulnerable system. | |
| Modificada | Media (6.1) | 0.43% | — | Webpsilon Ultimate Tables | 17/11/2022 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Webpsilon ULTIMATE TABLES plugin <= 1.6.5 versions. | |
| Modificada | Media (4.3) | 0.42% | — | Dell EMC Isilon Onefs | 21/10/2022 | 17/6/2026 | The Dell Isilon OneFS versions 8.2.2 and earlier SSHD process improperly allows Transmission Control Protocol (TCP) and stream forwarding. This provides the remotesupport user and users with restricted shells more access than is intended. | |
| Modificada | Baja (2.7) | 0.80% | — | Webpsilon Cube Slider | 8/6/2022 | 17/6/2026 | The Cube Slider WordPress plugin through 1.2 does not sanitise and escape the idslider parameter before using it in various SQL queries, leading to SQL Injections exploitable by high privileged users such as admin | |
| Modificada | Crítica (9.8) | 0.83% | — | Dell Isilon Insightiq Firmware | 1/10/2021 | 17/6/2026 | Dell EMC InsightIQ, versions prior to 4.1.4, contain risky cryptographic algorithms in the SSH component. A remote unauthenticated attacker could potentially exploit this vulnerability leading to authentication bypass and remote takeover of the InsightIQ. This allows an attacker to take complete control of InsightIQ… | |
| Modificada | Alta (7.2) | 1.5% | — | Webpsilon Responsive 3D Slider | 20/9/2021 | 17/6/2026 | The Add new scene functionality in the Responsive 3D Slider WordPress plugin through 1.2 uses an id parameter which is not sanitised, escaped or validated before being inserted to a SQL statement, leading to SQL injection. This is a time based SQLI and in the same function vulnerable parameter is passed twice so if we… | |
| Modificada | Alta (8.8) | 0.99% | — | Dell EMC Isilon OnefsDell EMC Powerscale Onefs | 29/7/2021 | 17/6/2026 | The Dell Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 default configuration for Network File System (NFS) allows access to an 'admin' home directory. An attacker may leverage a spoofed Unique Identifier (UID) over NFS to rewrite sensitive files to gain administrative access to… | |
| Modificada | Alta (8.8) | 0.59% | — | Dell EMC Isilon OnefsDell EMC Powerscale Onefs | 28/7/2021 | 17/6/2026 | Dell EMC Isilon OneFS supported versions 8.1 and later and Dell EMC PowerScale OneFS supported version 9.0.0 contain an access issue with the remotesupport user account. A remote malicious user with low privileges may gain access to data stored on the /ifs directory through most protocols. | |
| Modificada | Alta (7.8) | 0.26% | — | Dell EMC Isilon OnefsDell EMC Powerscale Onefs | 5/1/2021 | 17/6/2026 | Dell EMC Isilon OneFS versions 8.1 and later and Dell EMC PowerScale OneFS version 9.0.0 contain a privilege escalation vulnerability on a SmartLock Compliance mode cluster. The compadmin user connecting using ISI PRIV LOGIN SSH or ISI PRIV LOGIN CONSOLE can elevate privileges to the root user if they have ISI PRIV… | |
| Modificada | Alta (8.8) | 1.2% | — | Dell EMC Isilon OnefsDell EMC Powerscale Onefs | 2/9/2020 | 17/6/2026 | Dell EMC Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 contain a privilege escalation vulnerability. An authenticated malicious user may exploit this vulnerability by using SyncIQ to gain unauthorized access to system management files. |