Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2557▼ 320 respecto a la semana anterior
Críticas / altas1342▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
281 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.3) | 0.58% | — | Remote Spectrum Monitor Ms27102aAI | 31/3/2026 | 24/7/2026 | The MS27102A Remote Spectrum Monitor is vulnerable to an authentication bypass that allows unauthorized users to access and manipulate its management interface. Because the device provides no mechanism to enable or configure authentication, the issue is inherent to its design rather than a deployment error. | |
| Analizada | Baja (2.3) | 0.30% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Object Injection.This issue affects DX NetOps Spectrum: 24.3.13 and earlier. | |
| Analizada | Alta (7.1) | 0.14% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Dependency on Vulnerable Third-Party Component vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows DOM-Based XSS.This issue affects DX NetOps Spectrum: 24.3.9 and earlier. | |
| Analizada | Baja (2.3) | 0.27% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Privilege Escalation.This issue affects DX NetOps Spectrum: 24.3.10 and earlier. | |
| Analizada | Alta (8.7) | 0.35% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Improper Authentication vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Authentication Bypass.This issue affects DX NetOps Spectrum: 24.3.10 and earlier. | |
| Analizada | Media (5.3) | 0.17% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Cleartext Transmission of Sensitive Information vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sniffing Attacks.This issue affects DX NetOps Spectrum: 21.2.1 and earlier. | |
| Analizada | Baja (2.3) | 0.24% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Insufficiently Protected Credentials vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sniffing Attacks.This issue affects DX NetOps Spectrum: 24.3.13 and earlier. | |
| Analizada | Baja (2.3) | 0.32% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Information Exposure Through Query Strings in GET Request vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Session Hijacking.This issue affects DX NetOps Spectrum: 24.3.8 and earlier. | |
| Analizada | Alta (7.1) | 0.90% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows OS Command Injection.This issue affects DX NetOps Spectrum: 23.3.6 and earlier. | |
| Analizada | Media (5.3) | 0.16% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Reflected XSS.This issue affects DX NetOps Spectrum: 24.3.8 and earlier. | |
| Analizada | Alta (8.8) | 0.33% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Path Traversal.This issue affects DX NetOps Spectrum: 24.3.8 and earlier. | |
| Aplazada | Media (5.6) | 0.11% | — | Schneider-electric Spectrum Power 4AI | 11/11/2025 | 26/9/2026 | A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to alter the local database which contains the application credentials. This allows an attacker to gain administrative application privileges. | |
| Aplazada | Alta (8.7) | 0.39% | — | Schneider-electric Spectrum PowerAI | 11/11/2025 | 26/9/2026 | A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to run arbitrary commands via the user interface. This user interface can be used via the network and allows the execution of commands as administrative application user. | |
| Aplazada | Alta (8.5) | 0.12% | — | Spectrum Power 4AI | 11/11/2025 | 26/9/2026 | A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to extraction of database credentials via a world-readable credential file. This allows an attacker to connect to the database as privileged application user and to run system commands… | |
| Aplazada | Alta (8.5) | 0.11% | — | CA Spectrum PowerAI | 11/11/2025 | 26/9/2026 | A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to a local privilege escalation due to wrongly set permissions to a binary which allows any local attacker to gain administrative privileges. | |
| Aplazada | Alta (8.5) | 0.12% | — | Spectrum Power 4AI | 11/11/2025 | 26/9/2026 | A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to a local privilege escalation due to an exposed debug interface on the localhost. This allows any local user to gain code execution as administrative application user. | |
| Analizada | Crítica (9.8) | 0.37% | — | IBM Spectrum Protect Server | 20/6/2025 | 17/6/2026 | IBM Spectrum Protect Server 8.1 through 8.1.26 could allow attacker to bypass authentication due to improper session authentication which can result in access to unauthorized resources. | |
| Aplazada | Media (6.5) | 0.29% | — | Philspectrum Icon Widget With LinksAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in philspectrum Icon Widget icon-widget-with-links allows DOM-Based XSS.This issue affects Icon Widget: from n/a through <= 1.1.0. | |
| Analizada | Alta (8.5) | 0.14% | — | Siemens Spectrum Power 7 | 12/11/2024 | 17/6/2026 | A vulnerability has been identified in Spectrum Power 7 (All versions < V24Q3). The affected product contains several root-owned SUID binaries that could allow an authenticated local attacker to escalate privileges. | |
| Analizada | Crítica (9.8) | 0.40% | — | Loftware Spectrum | 10/9/2024 | 17/6/2026 | Loftware Spectrum through 4.6 has unprotected JMX Registry. | |
| Analizada | Alta (8.8) | 0.45% | — | Loftware Spectrum | 10/9/2024 | 17/6/2026 | Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks. | |
| Analizada | Alta (7.5) | 0.38% | — | Loftware Spectrum | 10/9/2024 | 17/6/2026 | Loftware Spectrum through 4.6 exposes Sensitive Information (Logs) to an Unauthorized Actor. | |
| Analizada | Crítica (9.8) | 0.52% | — | Loftware Spectrum | 10/9/2024 | 17/6/2026 | Loftware Spectrum before 4.6 HF14 uses a Hard-coded Password. | |
| Analizada | Alta (8.8) | 0.37% | — | Loftware Spectrum | 10/9/2024 | 17/6/2026 | Loftware Spectrum (testDeviceConnection) before 5.1 allows SSRF. | |
| Analizada | Alta (8.8) | 0.37% | — | Loftware Spectrum | 10/9/2024 | 17/6/2026 | Loftware Spectrum before 5.1 allows SSRF. |