Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

920 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)2.1%—Polarvista Xcode-mcp-serverAI29/4/202617/6/2026
A vulnerability was found in PolarVista xcode-mcp-server 1.0.0. This issue affects the function build_project/run_tests of the file src/index.ts of the component MCP Interface. The manipulation of the argument Request results in os command injection. The attack may be launched remotely. The exploit has been made…
AplazadaMedia (4.6)0.21%—GE Vernova EnervistaAI10/2/202617/6/2026
Vulnerability in GE Vernova Enervista UR Setup on Windows.This issue affects Enervista: 8.6 and previous versions.
AplazadaBaja (2.9)0.24%—GE Vernova Enervista UR SetupAI10/2/202617/6/2026
A vulnerability in GE Vernova Enervista UR Setup on Windows allows File Manipulation.This issue affects Enervista: 8.6 and prior versions.
AplazadaCrítica (9.3)0.65%—Pyvista Project PyvistaAI6/10/202517/6/2026
PyVista provides 3D plotting and mesh analysis through an interface for the Visualization Toolkit (VTK). Version 0.46.3 of the PyVista Project is vulnerable to remote code execution via dependency confusion. Two pieces of code use`--extra-index-url`. But when `--extra-index-url` is used, pip always checks for the PyPI…
AnalizadaAlta (8.8)0.54%—Saison Dataspider Servista29/9/202517/6/2026
Improper restriction of XML external entity reference issue exists in DataSpider Servista 4.4 and earlier. If a specially crafted request is processed, arbitrary files on the file system where the server application for the product is installed may be read, or a denial-of-service (DoS) condition may occur.
AplazadaAlta (7.8)0.11%—Smartvista SuiteAI18/9/202517/6/2026
Cross Site Request Forgery (CSRF) vulnerability in Smartvista BackOffice SmartVista Suite 2.2.22 via crafted GET request.
AplazadaMedia (6.1)0.18%—GE Vernova UR IEDAIGE Vernova Enervista UR SetupAI10/3/202517/6/2026
Insufficient Verification of Data Authenticity vulnerability in GE Vernova UR IED family devices allows an authenticated user to install a modified firmware. The firmware signature verification is enforced only on the client-side dedicated software Enervista UR Setup, allowing the integration check to be bypassed.
AplazadaAlta (8.3)0.28%—GE Vernova Enervista UR SetupAI10/3/202517/6/2026
Missing Authentication for Critical Function vulnerability in GE Vernova Enervista UR Setup application allows Authentication Bypass due to a missing SSH server authentication. Since the client connection is not authenticated, an attacker may perform a man-in-the-middle attack on the network.
AplazadaAlta (8)0.15%—GE Vernova Enervista UR SetupAI10/3/202517/6/2026
Use of Hard-coded Credentials vulnerability in GE Vernova EnerVista UR Setup allows Privilege Escalation. The local user database is encrypted using an hardcoded password retrievable by an attacker analyzing the application code.
AplazadaAlta (8)0.19%—GE Vernova Enervista UR SetupAI10/3/202517/6/2026
CWE-282 "Improper Ownership Management" in GE Vernova EnerVista UR Setup allows Authentication Bypass. The software's startup authentication can be disabled by altering a Windows registry setting that any user can modify.
AnalizadaMedia (6.5)0.49%—Gleamtech Filevista7/2/202517/6/2026
Incorrect Access Control in the Preview Function of Gleamtech FileVista 9.2.0.0 allows remote attackers to gain unauthorized access via exploiting a vulnerability in access control mechanisms by removing authentication-related HTTP headers, such as the Cookie header, in the request. This bypasses the authentication…
AnalizadaMedia (6.3)3.2%—Gleamtech Filevista7/2/202517/6/2026
Directory Traversal in File Upload in Gleamtech FileVista 9.2.0.0 allows remote attackers to achieve Code Execution, Information Disclosure, and Escalation of Privileges via injecting malicious payloads in HTTP requests to manipulate file paths, bypass access controls, and upload malicious files.
AplazadaMedia (6.5)0.21%—Movistar 4G RouterAIMovistar ES Wld71-t1AI13/3/202417/6/2026
Cross-Site Request Forgery vulnerability in Movistar's 4G router affecting version ES_WLD71-T1_v2.0.201820. This vulnerability allows an attacker to force an end user to execute unwanted actions in a web application in which they are currently authenticated.
AplazadaAlta (7.8)0.74%—Movistar 4G RouterAI13/3/202417/6/2026
Command injection vulnerability in Movistar 4G router affecting version ES_WLD71-T1_v2.0.201820. This vulnerability allows an authenticated user to execute commands inside the router by making a POST request to the URL '/cgi-bin/gui.cgi'.
AplazadaAlta (8.8)0.28%—Movistar 4G Router E S Wld71-t1 V2.0.201820AI13/3/202417/6/2026
The primary channel is unprotected on Movistar 4G router affecting E version S_WLD71-T1_v2.0.201820. This device has the 'adb' service open on port 5555 and provides access to a shell with root privileges.
AplazadaMedia (5.3)0.43%—Heimavista RpageAIHeimavista EpageAI13/3/202417/6/2026
The disabling function of the user registration page for Heimavista Rpage and Epage is not properly implemented, allowing remote attackers to complete user registration on sites where user registration is supposed to be disabled.
ModificadaAlta (8.8)0.81%—Saison Dataspider Servista1/6/202317/6/2026
DataSpider Servista version 4.4 and earlier uses a hard-coded cryptographic key. DataSpider Servista is data integration software. ScriptRunner and ScriptRunner for Amazon SQS are used to start the configured processes on DataSpider Servista. The cryptographic key is embedded in ScriptRunner and ScriptRunner for…
ModificadaAlta (8.8)0.71%—Easyvista Service Manager10/1/202317/6/2026
An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. One parameter allows SQL injection. Version 2022.1.110.1.02 fixes the vulnerability.
ModificadaAlta (7.5)0.53%—Easyvista Service Manager10/1/202317/6/2026
An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Part of the application does not implement protection against brute-force attacks. Version 2022.1.133.0 corrects this issue.
ModificadaAlta (8.8)0.71%—Easyvista Service Manager10/1/202317/6/2026
An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Some parameters allow SQL injection. Version 2022.1.110.1.02 corrects this issue.
ModificadaMedia (5.4)0.35%—Easyvista Service Manager10/1/202317/6/2026
An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03 It is prone to stored Cross-site Scripting (XSS). Version 2022.1.110.1.02 fixes the vulnerably.
ModificadaMedia (5.4)0.59%—Easyvista Service Manager20/10/20229/7/2026
Cross Site Scripting (XSS) vulnerability in New equipment page in EasyVista Service Manager 2018.1.181.1 allows remote attackers to run arbitrary code via the notes field.
ModificadaMedia (6.1)0.61%—Heimavista Dark Horse Rpage28/9/202217/6/2026
Heimavista Rpage has insufficient filtering for platform web URL. An unauthenticated remote attacker can inject JavaScript and perform XSS (Reflected Cross-Site Scripting) attack.
ModificadaCrítica (9.8)0.90%—Bpcbt Smartvista Front-end21/9/20229/7/2026
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /SVFE2/pages/feegroups/mcc_group.jsf.
ModificadaAlta (8.8)0.76%—Bpcbt Smartvista19/9/20229/7/2026
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/feegroups/country_group.jsf.