Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

73 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.1)0.15%—MinioAIPgsty SiloAI25/9/202630/9/2026
MinIO through 7aac2a2 does not verify that every x-amz-* header present on a request also appears in the client-supplied X-Amz-SignedHeaders list. extractSignedHeaders() in cmd/signature-v4-utils.go iterates only the claimed list and never enumerates the headers that actually arrived, and thus a header that arrives…
AplazadaAlta (7.1)0.12%—Upsilon 2000AI26/11/202517/6/2026
The RupsMon and USBMate services in UPSilon 2000 run with SYSTEM privileges and contain unquoted service paths. This allows a local attacker to perform path interception and escalate privileges if they have write permissions to the directories proceeding that of which the real service executables live in
AplazadaCrítica (9.3)0.14%—Upsilon 2000AI26/11/202517/6/2026
The RupsMon.exe service executable in UPSilon 2000 has insecure permissions, allowing the 'Everyone' group Full Control. A local attacker can replace the executable with a malicious binary to execute code with SYSTEM privileges or simply change the config path of the service to a command; starting and stopping the…
AplazadaMedia (6.9)0.30%—EpsilonnetAI29/10/202517/6/2026
This vulnerability allows an attacker to access parts of the application that are not protected by any type of access control. The attacker could access this path ‘…/epsilonnet/License/About.aspx’ and obtain information on both the licence and the configuration of the product by knowing which modules are installed.
AplazadaCrítica (9.3)0.47%—Grupo Castilla Epsilon RHAI20/10/202517/6/2026
A SQL Injection vulnerability has been found in Epsilon RH by Grupo Castilla. This vulnerability allows an attacker to retrieve, create, update and delete database via sending a POST request using the parameter ‘sEstadoUsr’ in ‘/epsilonnetws/WSAvisos.asmx’.
AplazadaMedia (4.3)0.14%—Epsiloncool WP Fast Total SearchAI22/8/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Epsiloncool WP Fast Total Search fulltext-search allows Cross Site Request Forgery.This issue affects WP Fast Total Search: from n/a through <= 1.79.270.
AplazadaMedia (4.7)0.14%—Arctera Veritas Data InsightAIDell Isilon OnefsAI16/4/202517/6/2026
Arctera/Veritas Data Insight before 7.1.2 can send cleartext credentials when configured to use HTTP Basic Authentication to a Dell Isilon OneFS server.
AplazadaMedia (4.3)0.32%—Epsiloncool WP Fast Total SearchAI27/3/202517/6/2026
Missing Authorization vulnerability in Epsiloncool WP Fast Total Search fulltext-search allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Fast Total Search: from n/a through <= 1.79.262.
AplazadaMedia (6.5)0.26%—Epsiloncool WP Fast Total SearchAI24/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Epsiloncool WP Fast Total Search fulltext-search allows Cross Site Request Forgery.This issue affects WP Fast Total Search: from n/a through <= 1.78.258.
AplazadaMedia (5.4)0.46%—Epsiloncool WP Fast Total SearchAI24/1/202517/6/2026
Missing Authorization vulnerability in Epsiloncool WP Fast Total Search fulltext-search allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Fast Total Search: from n/a through <= 1.78.258.
AplazadaMedia (4.3)0.17%—Epsiloncool WP Fast Total SearchAI2/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Epsiloncool WP Fast Total Search fulltext-search.This issue affects WP Fast Total Search: from n/a through <= 1.69.234.
AplazadaMedia (4.3)0.37%—Epsiloncool WP Fast Total SearchAI1/11/202417/6/2026
Missing Authorization vulnerability in Epsiloncool WP Fast Total Search fulltext-search.This issue affects WP Fast Total Search: from n/a through <= 1.68.232.
AplazadaAlta (7.1)0.27%—Epsiloncool WP Fast Total SearchAI1/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Epsiloncool WP Fast Total Search fulltext-search.This issue affects WP Fast Total Search: from n/a through <= 1.68.232.
AnalizadaAlta (7.5)0.45%—Unitronics Visilogic21/7/202417/6/2026
Unitronics Vision PLC – CWE-703: Improper Check or Handling of Exceptional Conditions may allow denial of service
AplazadaMedia (6.5)0.35%—Epsiloncool WP Fast Total SearchAI27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Epsiloncool WP Fast Total Search allows Stored XSS.This issue affects WP Fast Total Search: from n/a through 1.59.211.
AnalizadaCrítica (9.8)2.1%⚠ Explotación activaUnitronics Vision1210 FirmwareUnitronics Vision1040 FirmwareUnitronics Vision700 FirmwareUnitronics Vision570 Firmware+135/12/202317/6/2026
Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative control of a vulnerable system.
ModificadaMedia (6.1)0.43%—Webpsilon Ultimate Tables17/11/202217/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Webpsilon ULTIMATE TABLES plugin <= 1.6.5 versions.
ModificadaMedia (4.3)0.42%—Dell EMC Isilon Onefs21/10/202217/6/2026
The Dell Isilon OneFS versions 8.2.2 and earlier SSHD process improperly allows Transmission Control Protocol (TCP) and stream forwarding. This provides the remotesupport user and users with restricted shells more access than is intended.
ModificadaBaja (2.7)0.80%—Webpsilon Cube Slider8/6/202217/6/2026
The Cube Slider WordPress plugin through 1.2 does not sanitise and escape the idslider parameter before using it in various SQL queries, leading to SQL Injections exploitable by high privileged users such as admin
ModificadaCrítica (9.8)0.83%—Dell Isilon Insightiq Firmware1/10/202117/6/2026
Dell EMC InsightIQ, versions prior to 4.1.4, contain risky cryptographic algorithms in the SSH component. A remote unauthenticated attacker could potentially exploit this vulnerability leading to authentication bypass and remote takeover of the InsightIQ. This allows an attacker to take complete control of InsightIQ…
ModificadaAlta (7.2)1.5%—Webpsilon Responsive 3D Slider20/9/202117/6/2026
The Add new scene functionality in the Responsive 3D Slider WordPress plugin through 1.2 uses an id parameter which is not sanitised, escaped or validated before being inserted to a SQL statement, leading to SQL injection. This is a time based SQLI and in the same function vulnerable parameter is passed twice so if we…
ModificadaAlta (8.8)0.99%—Dell EMC Isilon OnefsDell EMC Powerscale Onefs29/7/202117/6/2026
The Dell Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 default configuration for Network File System (NFS) allows access to an 'admin' home directory. An attacker may leverage a spoofed Unique Identifier (UID) over NFS to rewrite sensitive files to gain administrative access to…
ModificadaAlta (8.8)0.59%—Dell EMC Isilon OnefsDell EMC Powerscale Onefs28/7/202117/6/2026
Dell EMC Isilon OneFS supported versions 8.1 and later and Dell EMC PowerScale OneFS supported version 9.0.0 contain an access issue with the remotesupport user account. A remote malicious user with low privileges may gain access to data stored on the /ifs directory through most protocols.
ModificadaAlta (7.8)0.26%—Dell EMC Isilon OnefsDell EMC Powerscale Onefs5/1/202117/6/2026
Dell EMC Isilon OneFS versions 8.1 and later and Dell EMC PowerScale OneFS version 9.0.0 contain a privilege escalation vulnerability on a SmartLock Compliance mode cluster. The compadmin user connecting using ISI PRIV LOGIN SSH or ISI PRIV LOGIN CONSOLE can elevate privileges to the root user if they have ISI PRIV…
ModificadaAlta (8.8)1.2%—Dell EMC Isilon OnefsDell EMC Powerscale Onefs2/9/202017/6/2026
Dell EMC Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 contain a privilege escalation vulnerability. An authenticated malicious user may exploit this vulnerability by using SyncIQ to gain unauthorized access to system management files.