Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.8) | 0.15% | — | Yamaha Vocaloid6AI | 21/8/2026 | 28/8/2026 | Missing authentication for critical function vulnerability exists in VOCALOID6. Any process running under the same local user account as a running VOCALOID6 Editor instance may escalate privileges via a local named pipe. | |
| Aplazada | Media (6.9) | 0.33% | — | Yamaha Vocaloid6AI | 21/8/2026 | 31/8/2026 | Use of hard-coded credentials issue exists in VOCALOID6 , which may allow an attacker to impersonate a legitimate VOCALOID6 Editor and gain access to Yamaha's activation and content servers. | |
| Modificada | Alta (8.1) | 0.50% | — | Axiomthemes Vocal | 18/12/2025 | 5/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Vocal vocal allows PHP Local File Inclusion.This issue affects Vocal: from n/a through <= 1.12. | |
| Modificada | Alta (7.5) | 3.3% | — | Vocaltec Vgw4 8 Telephony Gateway | 31/12/2004 | 16/6/2026 | VocalTec VGW4/8 Gateway 8.0 allows remote attackers to bypass authentication via an HTTP request to home.asp with a trailing slash (/). | |
| Modificada | Media (5) | 1.8% | — | Vocaltec Vgw4 8 Telephony Gateway | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in VocalTec VGW4/8 Gateway 8.0 allows remote attackers to read protected files via .. (dot dot) sequences in an HTTP request, as demonstrated using home.asp. | |
| Modificada | Media (5) | 3.0% | — | Vocaltec Vgw120 Telephony GatewayVocaltec Vgw480 Telephony Gateway | 31/12/2004 | 16/6/2026 | Unknown vulnerability in the ASN.1/H.323/H.225 stack of VocalTec VGW120 and VGW480 allows remote attackers to cause a denial of service. |