Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 237 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
56 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.27% | — | Eleveo Quality ManagementAI | 28/9/2026 | 29/9/2026 | A security flaw has been discovered in Eleveo Quality Management 9.7.0. This issue affects the function UtilsService.createAndSaveAudit of the file /qm/cz.zoom.scorecard.webui.Scorecard/QMUtilsService of the component GWT RPC Handler. Performing a manipulation results in information disclosure. The attack is possible… | |
| Aplazada | Baja (2.1) | 0.22% | — | Eleveo Call Recording SoftwareAI | 28/9/2026 | 1/10/2026 | A vulnerability was identified in Eleveo Call Recording Software 9.7.0. This vulnerability affects unknown code of the file /callrec/userAddAction.do of the component User Management. Such manipulation of the argument Username leads to ldap injection. The attack can be executed remotely. The exploit is publicly… | |
| Aplazada | Baja (2.1) | 0.20% | — | Eleveo Call Recording SoftwareAI | 28/9/2026 | 29/9/2026 | A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/searchAction.do of the component Query Builder. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be… | |
| Aplazada | Baja (2.1) | 0.36% | — | Eleveo Quality ManagementAI | 28/9/2026 | 29/9/2026 | A vulnerability was found in Eleveo Quality Management 9.7.0. Affected by this issue is some unknown functionality of the file /qm/cz.zoom.scorecard.webui.Scorecard/cz.zoom.scorecard.webui.Scorecard/QMBODownload. The manipulation results in information disclosure. The attack may be launched remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 0.34% | — | Eleveo Quality ManagementAI | 28/9/2026 | 1/10/2026 | A vulnerability has been found in Eleveo Quality Management 9.7.0. Affected by this vulnerability is an unknown functionality of the file Scorecard.jsp of the component Questionnaire Audio Upload. The manipulation leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Aplazada | Baja (2) | 0.19% | — | Eleveo Call Recording SoftwareAI | 28/9/2026 | 29/9/2026 | A flaw has been found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/audio.jsp of the component Play Audio Page. Executing a manipulation of the argument viewRoleId/cfType can lead to cross site scripting. The attack can be launched remotely. The exploit has been… | |
| Aplazada | Alta (7.7) | 0.16% | — | VEOAIVEO XSAI | 16/9/2026 | 18/9/2026 | The lack of signature verification of firmware update packages in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker who controls the delivery of an update to install unauthorised firmware. | |
| Aplazada | Alta (7.7) | 0.13% | — | VEOAIVEO XSAI | 16/9/2026 | 18/9/2026 | The lack of TLS certificate validation when downloading firmware updates in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker to perform man-in-the-middle attacks on the update channel. | |
| Aplazada | Alta (7) | 0.09% | — | Duoxme ApplicationAIVEO Wifi MonitorAIVEO XS Wifi MonitorAI | 16/9/2026 | 18/9/2026 | Transmission of the home Wi-Fi credentials without encryption during the pairing process between the DuoxMe application and VEO and VEO-XS Wi-Fi monitors, in versions prior to 4.3.4 of the application and 01.50.001 of the monitor firmware, allows an attacker on the Wi-Fi Direct network to intercept the network… | |
| Aplazada | Baja (2.1) | 0.49% | — | Eleveo Quality ManagementAI | 4/9/2026 | 4/9/2026 | A vulnerability was identified in Eleveo Quality Management 9.7.0. The affected element is the function QuestionnaireService.runDataExportNow of the component Questionnaire Service. Such manipulation of the argument file_name leads to path traversal. The attack may be performed from remote. The exploit is publicly… | |
| Aplazada | Baja (2.1) | 0.40% | — | Eleveo Quality ManagementAI | 4/9/2026 | 11/9/2026 | A vulnerability was determined in Eleveo Quality Management 9.7.0. Impacted is an unknown function of the file /enc-fwk-data/api/v3/conversations/<ID>/events of the component Conversation Handler. This manipulation of the argument createdBy causes dynamically-determined object attributes. The attack is possible to be… | |
| Aplazada | Baja (2.1) | 0.47% | — | Eleveo Quality ManagementAI | 4/9/2026 | 4/9/2026 | A vulnerability was found in Eleveo Quality Management 9.7.0. This issue affects some unknown processing of the file /enc-fwk-data/api/v3/conversations/<ID>/events of the component Conversation Handler. The manipulation of the argument labels results in denial of service. The attack can be executed remotely. The… | |
| Aplazada | Baja (2) | 0.33% | — | Eleveo Quality ManagementAI | 4/9/2026 | 8/9/2026 | A vulnerability has been found in Eleveo Quality Management 9.7.0. This vulnerability affects unknown code of the component Conversation Review. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was… | |
| Aplazada | Baja (2) | 0.33% | — | Eleveo Call Recording SoftwareAI | 4/9/2026 | 4/9/2026 | A flaw has been found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/roleAddAction.do. Executing a manipulation of the argument name/username can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used. The vendor was… | |
| Aplazada | Baja (2) | 0.51% | — | Faveo HelpdeskAI | 24/8/2026 | 27/8/2026 | A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the component Logo Handler. Such manipulation of the argument data1 leads to path traversal. The attack can be launched remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.72% | — | Faveo HelpdeskAI | 24/8/2026 | 26/8/2026 | A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the function FormController::post_ticket_reply of the file app/Http/Controllers/Client/helpdesk/FormController.php of the component post-ticket-reply Endpoint. This manipulation causes missing authentication. The attack can be initiated remotely. The… | |
| Aplazada | Media (6.5) | 0.37% | — | Ladybirdweb Faveo HelpdeskAI | 11/8/2026 | 3/9/2026 | A broken access control vulnerability in Ladybird Web Solution Faveo Helpdesk 2.0.3 allows any self-registered customer to read ticket conversations belonging to other customers via the v1 REST API. The API verifies the existence of the requested ticket but not ownership, enabling any authenticated user to access… | |
| Aplazada | Baja (2.1) | 0.35% | — | Eleveo Call Recording SoftwareAI | 12/7/2026 | 16/7/2026 | A security flaw has been discovered in Eleveo Call Recording Software 9.7.0. Impacted is an unknown function of the file /callrec/audio.jsp of the component Call Recording Handler. The manipulation of the argument callId results in improper authorization. The attack may be performed from remote. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.35% | — | Eleveo Call Recording SoftwareAI | 12/7/2026 | 14/7/2026 | A vulnerability was identified in Eleveo Call Recording Software 9.7.0. This issue affects some unknown processing of the file /callrec/restoreCallAction.do of the component Recorded Calls Page. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly… | |
| Aplazada | Baja (2.1) | 0.35% | — | Eleveo Call Recording SoftwareAI | 12/7/2026 | 13/7/2026 | A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This vulnerability affects unknown code of the file /callrec/composeEmailAction.do. Executing a manipulation can lead to improper authorization. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The… | |
| Aplazada | Baja (2.1) | 0.35% | — | Eleveo Call Recording SoftwareAI | 12/7/2026 | 13/7/2026 | A vulnerability was found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/pci_dss_status.jsp. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was… | |
| Aplazada | Baja (2.1) | 0.35% | — | Eleveo Call Recording SoftwareAI | 12/7/2026 | 13/7/2026 | A vulnerability has been found in Eleveo Call Recording Software 9.7.0. Affected by this issue is some unknown functionality of the file /callrec/group.jsp. Such manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor… | |
| Aplazada | Baja (2.1) | 0.35% | — | Eleveo Call Recording SoftwareAI | 10/7/2026 | 13/7/2026 | A vulnerability was determined in Eleveo Call Recording Software 9.7.0. Affected by this vulnerability is an unknown functionality of the file /callrec/sendlogfile. This manipulation causes improper authorization. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The… | |
| Aplazada | Baja (2.1) | 0.35% | — | Eleveo Call Recording SoftwareAI | 10/7/2026 | 13/7/2026 | A vulnerability was found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/statisticReportAction.do. The manipulation results in improper authorization. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early… | |
| Aplazada | Baja (2.1) | 0.39% | — | Eleveo Call Recording SoftwareAI | 10/7/2026 | 14/7/2026 | A vulnerability has been found in Eleveo Call Recording Software 9.7.0. This impacts an unknown function of the file /callrec/users_ldap.jsp of the component LDAP User Interface. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may… |