Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.61% | — | Vitodeploy Vito | 6/3/2026 | 17/6/2026 | Vito is a self-hosted web application that helps manage servers and deploy PHP applications into production servers. Prior to version 3.20.3, a missing authorization check in workflow site-creation actions allows an authenticated attacker with workflow write access in one project to create/manage sites on servers… | |
| Aplazada | Alta (8.7) | 0.24% | — | Viessmann Vitogate 300AI | 23/9/2025 | 17/6/2026 | The Vitogate 300 web interface fails to enforce proper server-side authentication and relies on frontend-based authentication controls. This allows an attacker to simply modify HTML elements in the browser’s developer tools to bypass login restrictions. By removing specific UI elements, an attacker can reveal the… | |
| Aplazada | Alta (8.5) | 0.68% | — | Viessmann Vitogate 300AI | 23/9/2025 | 17/6/2026 | An OS command injection vulnerability has been discovered in the Vitogate 300, which can be exploited by malicious users to compromise affected installations. Specifically, the `/cgi-bin/vitogate.cgi` endpoint is affected, when the `form` JSON parameter is set to `form-0-2`. The vulnerability stems from the fact that… | |
| Aplazada | Alta (8.7) | 0.34% | — | Leviton AcquisuiteAILeviton Energy Monitoring HUBAI | 18/7/2025 | 17/6/2026 | Leviton AcquiSuite and Energy Monitoring Hub are susceptible to a cross-site scripting vulnerability, allowing an attacker to craft a malicious payload in URL parameters, which would execute in a client browser when accessed by a user, steal session tokens, and control the service. | |
| Aplazada | Alta (7.1) | 0.32% | — | Icopydoc Xml-for-avitoAI | 3/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in icopydoc XML for Avito xml-for-avito allows Reflected XSS.This issue affects XML for Avito: from n/a through <= 2.5.2. | |
| Modificada | Alta (7.5) | 0.54% | — | Seweurodrive Movitools Motionstudio | 1/2/2024 | 17/6/2026 | When SEW-EURODRIVE MOVITOOLS MotionStudio processes XML information unrestricted file access can occur. | |
| Modificada | Media (6.5) | 15% | — | Viessmann Vitogate 300 Firmware | 23/10/2023 | 17/6/2026 | A vulnerability was found in Viessmann Vitogate 300 up to 2.1.3.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /cgi-bin/. The manipulation leads to direct request. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is… | |
| Modificada | Crítica (9.8) | 14% | — | Viessmann Vitogate 300 Firmware | 14/10/2023 | 17/6/2026 | In Vitogate 300 2.1.3.0, /cgi-bin/vitogate.cgi allows an unauthenticated attacker to bypass authentication and execute arbitrary commands via shell metacharacters in the ipaddr params JSON data for the put method. | |
| Modificada | Crítica (9.8) | 80% | — | Viessmann Vitogate 300 Firmware | 27/9/2023 | 17/6/2026 | A vulnerability classified as critical was found in Viessmann Vitogate 300 up to 2.1.3.0. This vulnerability affects the function isValidUser of the file /cgi-bin/vitogate.cgi of the component Web Management Interface. The manipulation leads to use of hard-coded password. The exploit has been disclosed to the public… | |
| Modificada | Alta (7.5) | 5.8% | — | Graviton-mediatech Visitor Logger | 3/6/2010 | 16/6/2026 | PHP remote file inclusion vulnerability in banned.php in Visitor Logger allows remote attackers to execute arbitrary PHP code via a URL in the VL_include_path parameter. |