Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2567▼ 333 respecto a la semana anterior
Críticas / altas1341▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.8) | 0.15% | — | Zkteco ZkbiosecurityAI | 16/3/2026 | 17/6/2026 | ZKTeco ZKBioSecurity 3.0 contains a local authorization bypass vulnerability in visLogin.jsp that allows attackers to authenticate without valid credentials by spoofing localhost requests. Attackers can exploit the EnvironmentUtil.getClientIp() method which treats IPv6 loopback address 0:0:0:0:0:0:0:1 as 127.0.0.1 and… | |
| Aplazada | Crítica (9.3) | 0.56% | — | Zkteco ZkbiosecurityAI | 16/3/2026 | 17/6/2026 | ZKTeco ZKBioSecurity 3.0 contains a user enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by submitting partial characters via the username parameter. Attackers can send requests to the authLoginAction!login.do script with varying username inputs to enumerate valid user… | |
| Aplazada | Media (6.9) | 0.21% | — | Zkteco ZkbiosecurityAI | 16/3/2026 | 17/6/2026 | ZKTeco ZKBioSecurity 3.0 contains a file path manipulation vulnerability that allows attackers to access arbitrary files by modifying file paths used to retrieve local resources. Attackers can manipulate path parameters to bypass access controls and retrieve sensitive information including configuration files, source… | |
| Aplazada | Media (5.3) | 0.21% | — | Zkteco ZkbiosecurityAI | 16/3/2026 | 17/6/2026 | ZKTeco ZKBioSecurity 3.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malicious websites. Attackers can craft HTTP requests that add superadmin accounts without validity checks, enabling unauthorized administrative… | |
| Aplazada | Media (5.1) | 0.25% | — | Zkteco ZkbiosecurityAI | 16/3/2026 | 17/6/2026 | ZKTeco ZKBioSecurity 3.0 contains multiple reflected cross-site scripting vulnerabilities that allow attackers to execute arbitrary HTML and script code by injecting malicious payloads through unsanitized parameters in multiple scripts. Attackers can craft malicious URLs with XSS payloads in vulnerable parameters to… | |
| Aplazada | Crítica (9.3) | 0.78% | — | Zkteco ZkbiosecurityAIApache TomcatAI | 16/3/2026 | 17/6/2026 | ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apache Tomcat server that allow unauthenticated attackers to access the manager application. Attackers can authenticate with hardcoded credentials stored in tomcat-users.xml to upload malicious WAR archives containing JSP applications and execute… | |
| Modificada | Baja (1.9) | 0.38% | — | Zkteco Zkbiosecurity V5000 | 26/6/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. This affects an unknown part of the component Push Configuration Section. The manipulation of the argument Configuration Name leads to cross site scripting. It is possible to initiate the attack remotely. It is… | |
| Modificada | Baja (2) | 0.43% | — | Zkteco Zkbiosecurity V5000 | 15/6/2024 | 17/6/2026 | A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Summer Schedule Handler. The manipulation of the argument Schedule Name leads to cross site scripting. The attack may be launched remotely. The… | |
| Modificada | Baja (2) | 0.43% | — | Zkteco Zkbiosecurity V5000 | 15/6/2024 | 17/6/2026 | A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Department Section. The manipulation of the argument Department Name leads to cross site scripting. The attack can be launched remotely. The… | |
| Modificada | Alta (8.8) | 17% | — | Zkteco Zkbiosecurity V5000 | 7/10/2022 | 9/7/2026 | ZKteco ZKBioSecurity V5000 4.1.3 was discovered to contain a SQL injection vulnerability via the component /baseOpLog.do. | |
| Modificada | Alta (8.8) | 1.2% | — | Zkteco Zkbiosecurity V5000 | 7/10/2022 | 9/7/2026 | An access control issue in ZKTeco ZKBioSecurity V5000 3.0.5_r allows attackers to arbitrarily create admin users via a crafted HTTP request. | |
| Modificada | Crítica (9.8) | 1.2% | — | Zkteco Zkbiosecurity ServerZkteco Facedepot 7B Firmware | 14/8/2020 | 17/6/2026 | A token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to create arbitrary new users, elevate users to administrators, delete users, and download user faces from the database. | |
| Modificada | Media (5.9) | 0.74% | — | Zkteco Zkbiosecurity ServerZkteco Facedepot 7B Firmware | 14/8/2020 | 17/6/2026 | Lack of mutual authentication in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to obtain a long-lasting token by impersonating the server. |