Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2564▼ 301 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.14% | — | Cybelesoft Thinfinity Workspace | 13/11/2024 | 17/6/2026 | Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain a hardcoded cryptographic key used for encryption. | |
| Analizada | Alta (7.3) | 0.28% | — | Cybelesoft Thinfinity Workspace | 13/11/2024 | 17/6/2026 | Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This vulnerability allows attackers to create arbitrary user profiles with elevated privileges. | |
| Analizada | Alta (7.5) | 0.39% | — | Cybelesoft Thinfinity Workspace | 13/11/2024 | 17/6/2026 | A full path disclosure in Cybele Software Thinfinity Workspace before v7.0.2.113 allows attackers to obtain the root path of the application via unspecified vectors. | |
| Analizada | Alta (8.1) | 0.45% | — | Cybelesoft Thinfinity Workspace | 13/11/2024 | 17/6/2026 | Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a secondary broker via a crafted request. | |
| Analizada | Crítica (9.8) | 0.46% | — | Cybelesoft Thinfinity Workspace | 13/11/2024 | 17/6/2026 | Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endpoint where Web Sockets connections are established. |