Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
1785 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 1.3% | — | Rapid7 Insightconnect RPM | 25/6/2026 | 29/6/2026 | OS Command Injection vulnerability in Rapid7 InsightConnect RPM Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the repo, key, or name parameters due to insufficient input sanitization in shell command construction. | |
| Analizada | Alta (8.8) | 1.3% | — | Rapid7 Insightconnect Sqlmap | 25/6/2026 | 29/6/2026 | OS Command Injection vulnerability in Rapid7 InsightConnect SQLmap Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the api_host or api_port parameters during connection configuration due to insufficient input validation. | |
| Aplazada | Crítica (9.8) | 0.56% | — | WP InsightlyAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions. | |
| Aplazada | Alta (7.1) | 0.40% | — | MonsterinsightsAI | 12/5/2026 | 17/6/2026 | The MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability checks on the get_ads_access_token() and reset_experience() functions in all versions up to, and including, 10.1.2.… | |
| Analizada | Crítica (9.9) | 0.77% | — | Microsoft Dynamics 365 Customer Insights | 12/5/2026 | 17/6/2026 | Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (6.7) | 0.17% | — | Dell Insightiq | 12/5/2026 | 17/6/2026 | Dell PowerScale InsightIQ, versions 5.0.0 through 6.2.0, contains an execution with unnecessary privileges vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges. | |
| Analizada | Alta (8.2) | 0.62% | — | Dell Insightiq | 12/5/2026 | 17/6/2026 | Dell PowerScale InsightIQ, versions 6.0.0 through 6.2.0, contains an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution. | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Analizada | Media (5.3) | 0.18% | — | Hcltech Bigfix Webui APIHcltech Bigfix Webui Application AdministrationHcltech Bigfix Webui CmepHcltech Bigfix Webui Common+17 | 9/5/2026 | 25/7/2026 | A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page. | |
| Analizada | Media (5.3) | 0.22% | — | Hcltech Bigfix Webui APIHcltech Bigfix Webui Application AdministrationHcltech Bigfix Webui CmepHcltech Bigfix Webui Common+17 | 9/5/2026 | 25/7/2026 | An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables) and bypass privilege requirements via unprotected endpoints lacking adequate security headers. | |
| Analizada | Media (6.7) | 0.91% | — | Cisco Intersight Device Connector | 28/4/2026 | 17/6/2026 | An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The service exposes an API passthrough endpoint on TCP port 7373 that is accessible within the network scope of the deployment environment without authentication. An unauthenticated attacker with network… | |
| Pendiente de análisis | Alta (7.3) | 1.5% | — | Milesight Camera FirmwareAI | 28/4/2026 | 25/7/2026 | A command injection vulnerability exists in the web server of specific firmware versions of Milesight cameras. | |
| Pendiente de análisis | Crítica (9.2) | 0.39% | — | Milesight Aiot CamerasAI | 28/4/2026 | 25/7/2026 | Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys. | |
| Pendiente de análisis | Alta (8.6) | 0.29% | — | Milesight Aiot Camera FirmwareAI | 28/4/2026 | 20/7/2026 | An out-of-bounds memory access vulnerability exists in specific firmware versions of Milesight AIOT cameras. | |
| Pendiente de análisis | Alta (7.7) | 0.35% | — | Milesight Aiot Camera FirmwareAI | 28/4/2026 | 25/7/2026 | Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials. | |
| Pendiente de análisis | Alta (7.3) | 0.28% | — | Milesight Aiot CamerasAI | 27/4/2026 | 25/7/2026 | A weak key generation vulnerability exists in specific firmware versions of Milesight AIOT cameras allows authorization to be bypassed. | |
| Analizada | Alta (8.5) | 0.19% | — | Rapid7 Insight Agent | 17/4/2026 | 17/6/2026 | The Rapid7 Insight Agent (versions > 4.1.0.2) is vulnerable to a local privilege escalation attack that allows users to gain SYSTEM level control of a Windows host. Upon startup the agent service attempts to load an OpenSSL configuration file from a non-existent directory that is writable by standard users. By… | |
| Analizada | Media (6.8) | 0.10% | — | Rapid7 Insight Agent | 10/4/2026 | 17/6/2026 | The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windows systems (users have read and execute access). For the client.key file in particular, this could potentially lead to exploits, as this exposes agent identity material to any locally authenticated… | |
| Analizada | Alta (7.2) | 0.72% | — | Rapid7 Insight Agent | 8/4/2026 | 24/7/2026 | An eval() injection vulnerability in the Rapid7 Insight Agent beaconing logic for Linux versions could theoretically allow an attacker to achieve remote code execution as root via a crafted beacon response. Because the Agent uses mutual TLS (mTLS) to verify commands from the Rapid7 Platform, it is unlikely that the… | |
| Aplazada | Media (6.5) | 0.22% | — | Elfsight Whatsapp Chat CCAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elfsight Elfsight WhatsApp Chat CC elfsight-whatsapp-chat allows DOM-Based XSS.This issue affects Elfsight WhatsApp Chat CC: from n/a through <= 1.2.0. | |
| Analizada | Media (4.9) | 0.49% | — | Cisco Nexus Dashboard InsightsCisco Nexus Dashboard | 1/4/2026 | 1/7/2026 | A vulnerability in the Metadata update feature of Cisco Nexus Dashboard Insights could allow an authenticated, remote attacker to write arbitrary files to an affected system. This vulnerability is due to insufficient validation of the metadata update file. An attacker could exploit this vulnerability by crafting a… | |
| En análisis | Media (6.1) | 0.24% | — | Cisco Nexus DashboardAICisco Nexus Dashboard InsightsAI | 1/4/2026 | 17/6/2026 | A vulnerability in Cisco Nexus Dashboard and Cisco Nexus Dashboard Insights could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit… | |
| Aplazada | Media (6.5) | 0.28% | — | Crmperks WP InsightlyAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in CRM Perks WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms cf7-insightly allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms: from… | |
| Aplazada | Crítica (9.4) | 0.43% | — | Insightsoftwareconsortium ITKAIExpatAI | 24/3/2026 | 17/6/2026 | Integer Overflow or Wraparound vulnerability in InsightSoftwareConsortium ITK (Modules/ThirdParty/Expat/src/expat modules).This issue affects ITK: before 2.7.1. | |
| Analizada | Media (6.1) | 0.28% | — | Gainsight Assist | 20/3/2026 | 17/6/2026 | The error_description parameter is vulnerable to Reflected XSS. An attacker can bypass the domain's WAF using a Safari-specific onpagereveal payload. |