Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
920 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 2.1% | — | Polarvista Xcode-mcp-serverAI | 29/4/2026 | 17/6/2026 | A vulnerability was found in PolarVista xcode-mcp-server 1.0.0. This issue affects the function build_project/run_tests of the file src/index.ts of the component MCP Interface. The manipulation of the argument Request results in os command injection. The attack may be launched remotely. The exploit has been made… | |
| Aplazada | Media (4.6) | 0.21% | — | GE Vernova EnervistaAI | 10/2/2026 | 17/6/2026 | Vulnerability in GE Vernova Enervista UR Setup on Windows.This issue affects Enervista: 8.6 and previous versions. | |
| Aplazada | Baja (2.9) | 0.24% | — | GE Vernova Enervista UR SetupAI | 10/2/2026 | 17/6/2026 | A vulnerability in GE Vernova Enervista UR Setup on Windows allows File Manipulation.This issue affects Enervista: 8.6 and prior versions. | |
| Aplazada | Crítica (9.3) | 0.65% | — | Pyvista Project PyvistaAI | 6/10/2025 | 17/6/2026 | PyVista provides 3D plotting and mesh analysis through an interface for the Visualization Toolkit (VTK). Version 0.46.3 of the PyVista Project is vulnerable to remote code execution via dependency confusion. Two pieces of code use`--extra-index-url`. But when `--extra-index-url` is used, pip always checks for the PyPI… | |
| Analizada | Alta (8.8) | 0.54% | — | Saison Dataspider Servista | 29/9/2025 | 17/6/2026 | Improper restriction of XML external entity reference issue exists in DataSpider Servista 4.4 and earlier. If a specially crafted request is processed, arbitrary files on the file system where the server application for the product is installed may be read, or a denial-of-service (DoS) condition may occur. | |
| Aplazada | Alta (7.8) | 0.11% | — | Smartvista SuiteAI | 18/9/2025 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability in Smartvista BackOffice SmartVista Suite 2.2.22 via crafted GET request. | |
| Aplazada | Media (6.1) | 0.18% | — | GE Vernova UR IEDAIGE Vernova Enervista UR SetupAI | 10/3/2025 | 17/6/2026 | Insufficient Verification of Data Authenticity vulnerability in GE Vernova UR IED family devices allows an authenticated user to install a modified firmware. The firmware signature verification is enforced only on the client-side dedicated software Enervista UR Setup, allowing the integration check to be bypassed. | |
| Aplazada | Alta (8.3) | 0.28% | — | GE Vernova Enervista UR SetupAI | 10/3/2025 | 17/6/2026 | Missing Authentication for Critical Function vulnerability in GE Vernova Enervista UR Setup application allows Authentication Bypass due to a missing SSH server authentication. Since the client connection is not authenticated, an attacker may perform a man-in-the-middle attack on the network. | |
| Aplazada | Alta (8) | 0.15% | — | GE Vernova Enervista UR SetupAI | 10/3/2025 | 17/6/2026 | Use of Hard-coded Credentials vulnerability in GE Vernova EnerVista UR Setup allows Privilege Escalation. The local user database is encrypted using an hardcoded password retrievable by an attacker analyzing the application code. | |
| Aplazada | Alta (8) | 0.19% | — | GE Vernova Enervista UR SetupAI | 10/3/2025 | 17/6/2026 | CWE-282 "Improper Ownership Management" in GE Vernova EnerVista UR Setup allows Authentication Bypass. The software's startup authentication can be disabled by altering a Windows registry setting that any user can modify. | |
| Analizada | Media (6.5) | 0.49% | — | Gleamtech Filevista | 7/2/2025 | 17/6/2026 | Incorrect Access Control in the Preview Function of Gleamtech FileVista 9.2.0.0 allows remote attackers to gain unauthorized access via exploiting a vulnerability in access control mechanisms by removing authentication-related HTTP headers, such as the Cookie header, in the request. This bypasses the authentication… | |
| Analizada | Media (6.3) | 3.2% | — | Gleamtech Filevista | 7/2/2025 | 17/6/2026 | Directory Traversal in File Upload in Gleamtech FileVista 9.2.0.0 allows remote attackers to achieve Code Execution, Information Disclosure, and Escalation of Privileges via injecting malicious payloads in HTTP requests to manipulate file paths, bypass access controls, and upload malicious files. | |
| Aplazada | Media (6.5) | 0.21% | — | Movistar 4G RouterAIMovistar ES Wld71-t1AI | 13/3/2024 | 17/6/2026 | Cross-Site Request Forgery vulnerability in Movistar's 4G router affecting version ES_WLD71-T1_v2.0.201820. This vulnerability allows an attacker to force an end user to execute unwanted actions in a web application in which they are currently authenticated. | |
| Aplazada | Alta (7.8) | 0.74% | — | Movistar 4G RouterAI | 13/3/2024 | 17/6/2026 | Command injection vulnerability in Movistar 4G router affecting version ES_WLD71-T1_v2.0.201820. This vulnerability allows an authenticated user to execute commands inside the router by making a POST request to the URL '/cgi-bin/gui.cgi'. | |
| Aplazada | Alta (8.8) | 0.28% | — | Movistar 4G Router E S Wld71-t1 V2.0.201820AI | 13/3/2024 | 17/6/2026 | The primary channel is unprotected on Movistar 4G router affecting E version S_WLD71-T1_v2.0.201820. This device has the 'adb' service open on port 5555 and provides access to a shell with root privileges. | |
| Aplazada | Media (5.3) | 0.43% | — | Heimavista RpageAIHeimavista EpageAI | 13/3/2024 | 17/6/2026 | The disabling function of the user registration page for Heimavista Rpage and Epage is not properly implemented, allowing remote attackers to complete user registration on sites where user registration is supposed to be disabled. | |
| Modificada | Alta (8.8) | 0.81% | — | Saison Dataspider Servista | 1/6/2023 | 17/6/2026 | DataSpider Servista version 4.4 and earlier uses a hard-coded cryptographic key. DataSpider Servista is data integration software. ScriptRunner and ScriptRunner for Amazon SQS are used to start the configured processes on DataSpider Servista. The cryptographic key is embedded in ScriptRunner and ScriptRunner for… | |
| Modificada | Alta (8.8) | 0.71% | — | Easyvista Service Manager | 10/1/2023 | 17/6/2026 | An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. One parameter allows SQL injection. Version 2022.1.110.1.02 fixes the vulnerability. | |
| Modificada | Alta (7.5) | 0.53% | — | Easyvista Service Manager | 10/1/2023 | 17/6/2026 | An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Part of the application does not implement protection against brute-force attacks. Version 2022.1.133.0 corrects this issue. | |
| Modificada | Alta (8.8) | 0.71% | — | Easyvista Service Manager | 10/1/2023 | 17/6/2026 | An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Some parameters allow SQL injection. Version 2022.1.110.1.02 corrects this issue. | |
| Modificada | Media (5.4) | 0.35% | — | Easyvista Service Manager | 10/1/2023 | 17/6/2026 | An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03 It is prone to stored Cross-site Scripting (XSS). Version 2022.1.110.1.02 fixes the vulnerably. | |
| Modificada | Media (5.4) | 0.59% | — | Easyvista Service Manager | 20/10/2022 | 9/7/2026 | Cross Site Scripting (XSS) vulnerability in New equipment page in EasyVista Service Manager 2018.1.181.1 allows remote attackers to run arbitrary code via the notes field. | |
| Modificada | Media (6.1) | 0.61% | — | Heimavista Dark Horse Rpage | 28/9/2022 | 17/6/2026 | Heimavista Rpage has insufficient filtering for platform web URL. An unauthenticated remote attacker can inject JavaScript and perform XSS (Reflected Cross-Site Scripting) attack. | |
| Modificada | Crítica (9.8) | 0.90% | — | Bpcbt Smartvista Front-end | 21/9/2022 | 9/7/2026 | SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /SVFE2/pages/feegroups/mcc_group.jsf. | |
| Modificada | Alta (8.8) | 0.76% | — | Bpcbt Smartvista | 19/9/2022 | 9/7/2026 | SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/feegroups/country_group.jsf. |