Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2700▼ 69 respecto a la semana anterior
Críticas / altas1449▲ 307 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.44% | — | Caio WEB DEV CWD Stealth LinksAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Caio Web Dev CWD – Stealth Links cwd-stealth-links allows SQL Injection.This issue affects CWD – Stealth Links: from n/a through <= 1.3. | |
| Aplazada | Alta (7.5) | 0.40% | — | YS Corporation Stealthone D220AIYS Corporation Stealthone D340AI | 14/1/2025 | 17/6/2026 | SQL Injection vulnerability exists in STEALTHONE D220/D340 provided by Y'S corporation. An attacker who can access the affected product may obtain the administrative password of the web management page. | |
| Aplazada | Crítica (9.8) | 1.2% | — | Y S Corporation Stealthone D220AIY S Corporation Stealthone D340AI | 14/1/2025 | 17/6/2026 | OS command injection vulnerability exists in network storage servers STEALTHONE D220/D340 provided by Y'S corporation. An attacker who can access the affected product may execute an arbitrary OS command. | |
| Aplazada | Alta (7.2) | 1.1% | — | Y S Corporation Stealthone D220AIY S Corporation Stealthone D340AIY S Corporation Stealthone D440AI | 14/1/2025 | 17/6/2026 | OS command injection vulnerability exists in network storage servers STEALTHONE D220/D340/D440 provided by Y'S corporation. A user with an administrative privilege who logged in to the web management page of the affected product may execute an arbitrary OS command. | |
| Analizada | Alta (7.5) | 0.47% | — | Unisys Stealth | 20/2/2024 | 17/6/2026 | An issue discovered in Unisys Stealth 5.3.062.0 allows attackers to view sensitive information via the Enterprise ManagementInstaller_msi.log file. | |
| Modificada | Alta (8.8) | 1.0% | — | Cisco Secure Network AnalyticsCisco Stealthwatch Management Console 2200 Firmware | 5/4/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Secure Network Analytics could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system. This vulnerability is due to insufficient sanitization of user-provided data that is parsed into system memory. An attacker… | |
| Modificada | Media (6.7) | 0.25% | — | Unisys Stealth | 15/7/2021 | 17/6/2026 | Unisys Stealth 5.1 before 5.1.025.0 and 6.0 before 6.0.055.0 has an unquoted Windows search path for a scheduled task. An unintended executable might run. | |
| Modificada | Media (4.9) | 0.85% | — | Unisys Stealth | 20/4/2021 | 17/6/2026 | Unisys Stealth (core) 5.x before 5.0.048.0, 5.1.x before 5.1.017.0, and 6.x before 6.0.037.0 stores passwords in a recoverable format. | |
| Modificada | Alta (7.8) | 0.22% | — | Unisys Stealth | 18/3/2021 | 17/6/2026 | In Unisys Stealth (core) before 6.0.025.0, the Keycloak password is stored in a recoverable format that might be accessible by a local attacker, who could gain access to the Management Server and change the Stealth configuration. | |
| Modificada | Alta (7.8) | 0.29% | — | Unisys Stealth | 1/10/2020 | 17/6/2026 | Unisys Stealth(core) before 4.0.134 stores passwords in a recoverable format. Therefore, a search of Enterprise Manager can potentially reveal credentials. | |
| Modificada | Crítica (9.8) | 0.68% | — | Unisys Stealth | 22/6/2020 | 17/6/2026 | In Unisys Stealth 3.4.x, 4.x and 5.x before 5.0.026, if certificate-based authorization is used without HTTPS, an endpoint could be authorized without a private key. | |
| Modificada | Alta (7.5) | 0.28% | — | Unisys Stealth | 3/2/2020 | 17/6/2026 | In Unisys Stealth (core) 3.4.108.0, 3.4.209.x, 4.0.027.x and 4.0.114, key material inadvertently logged under certain conditions. Fixed included in 3.4.109, 4.0.027.13, 4.0.125 and 5.0.013.0. | |
| Modificada | Media (6.1) | 0.80% | — | Cisco Stealthwatch Enterprise | 26/11/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Stealthwatch Enterprise could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. The vulnerability is due to insufficient validation of… | |
| Modificada | Crítica (9.8) | 4.0% | — | Cisco Stealthwatch Enterprise | 8/11/2018 | 17/6/2026 | A vulnerability in the Stealthwatch Management Console (SMC) of Cisco Stealthwatch Enterprise could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected system. The vulnerability is due to an insecure system configuration. An… | |
| Modificada | Media (4.7) | 0.16% | — | Unisys Stealth Authorization Server | 30/5/2018 | 17/6/2026 | In Stealth Authorization Server before 3.3.017.0 in Unisys Stealth Solution, an encryption key may be left in memory. | |
| Modificada | Alta (7.5) | 1.5% | — | Unisys Stealth SVG | 3/4/2018 | 17/6/2026 | The Stealth endpoint in Unisys Stealth SVG 2.8.x, 3.0.x before 3.0.1999, 3.1.x, 3.2.x before 3.2.030, and 3.3.x before 3.3.016, when running on Linux and AIX, allows remote attackers to cause a denial of service (crash) via crafted packets. | |
| Modificada | Alta (7.8) | 0.29% | — | Unisys Stealth | 19/2/2018 | 17/6/2026 | Unisys Stealth 3.3 Windows endpoints before 3.3.016.1 allow local users to gain access to Stealth-enabled devices by leveraging improper cleanup of memory used for negotiation key storage. | |
| Modificada | Media (4.3) | 1.3% | — | N-stalker N-stealth | 8/9/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in N-Stealth Commercial Edition before 5.8.0.38 and Free Edition before 5.8.1.03 allows remote attackers to inject arbitrary web script or HTML via the Server field in an HTTP response header, which is directly injected into an HTML report. |