Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▲ 24 respecto a la semana anterior
Críticas / altas1467▲ 357 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (10) | 0.56% | — | Altium Enterprise ServerAI | 16/9/2026 | 18/9/2026 | A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An unauthenticated network attacker can cause the server to issue outbound HTTP requests to a destination of the attacker's choosing, including internal services that are reachable only from the server… | |
| Aplazada | Crítica (9.4) | 0.71% | — | Altium Enterprise ServerAIAltium 365AI | 1/7/2026 | 20/7/2026 | A path traversal vulnerability exists in the Git Service component shared by Altium Enterprise Server and Altium 365. The service accepts a sequence of post-clone file-manipulation operations that use user-supplied paths without validation, allowing an authenticated user with basic git access to move arbitrary files… | |
| Pendiente de análisis | Alta (8.3) | 0.52% | — | Altium Enterprise ServerAIAltium 365AI | 5/6/2026 | 23/7/2026 | A path traversal vulnerability exists in the Projects Service download endpoint shared by Altium Enterprise Server and Altium 365. An authenticated user can supply a crafted path parameter that bypasses validation, allowing arbitrary files (including entire directories returned as archives) to be read from the server… | |
| Pendiente de análisis | Crítica (10) | 1.1% | — | Altium Enterprise ServerAIAltium 365AI | 5/6/2026 | 23/7/2026 | Two endpoints in the Vault Service ScriptsController, shared by Altium Enterprise Server and Altium 365, accept file uploads where a user-supplied filename component is used to construct the destination path without validation, allowing arbitrary files to be written to any location writable by the service account.… | |
| Pendiente de análisis | Alta (8.3) | 0.23% | — | Altium Enterprise ServerAIAltium 365AI | 5/6/2026 | 23/7/2026 | A server-side request forgery (SSRF) vulnerability exists in a GraphQL service component shared by Altium Enterprise Server and Altium 365. An authenticated user can submit a request whose input is treated as a URL by the server and used to issue an outbound HTTP GET request without URL validation or destination… | |
| Pendiente de análisis | Crítica (9.4) | 0.32% | — | Altium Enterprise Server Collaboration ServiceAI | 5/6/2026 | 23/7/2026 | A path traversal vulnerability exists in the Altium Enterprise Server Collaboration Service due to improper handling of user-supplied filenames in the MCAD and Simulation file download flows. A regular authenticated user can submit a collaboration message containing a crafted filename, which is later used to construct… | |
| Analizada | Crítica (10) | 0.71% | — | Altium On-prem Enterprise Server | 5/6/2026 | 23/7/2026 | Two path traversal vulnerabilities in the Network Installation Service (NIS) of Altium Enterprise Server allow an unauthenticated network attacker to write arbitrary files to any writable location on the server filesystem and to read package archive files from the server. No authentication, session, or credentials are… | |
| Analizada | Crítica (9.4) | 0.55% | — | Altium On-prem Enterprise Server | 5/6/2026 | 23/7/2026 | A path traversal vulnerability exists in the Altium Enterprise Server Vault Service UploadController due to improper validation of a user-controlled path component in image upload requests. An authenticated user can supply a crafted absolute path so that the configured storage root is discarded, allowing arbitrary… | |
| Analizada | Crítica (10) | 0.48% | — | Altium On-prem Enterprise Server | 5/6/2026 | 17/6/2026 | A hard-coded cryptographic key is used by Altium Enterprise Server to sign file download URLs in the Vault service. Because the key is identical across all installations, an unauthenticated network attacker who can reach the server can forge valid download signatures and retrieve files from the Vault storage area… | |
| Aplazada | Crítica (10) | 0.54% | — | Altium 365AI | 21/5/2026 | 23/7/2026 | A missing authentication vulnerability exists in the Altium 365 SearchService. A legacy SOAP endpoint exposes search index operations without requiring authentication, session tokens, or any form of identity verification. An unauthenticated network attacker who can reference a target workspace's identifier can… | |
| Aplazada | Crítica (9.4) | 0.33% | — | Altium Enterprise Server ViewerAI | 20/5/2026 | 23/7/2026 | A path traversal vulnerability exists in the Altium Enterprise Server Viewer StorageController due to improper handling of file path route parameters. On on-premise deployments that use local filesystem storage, a regular authenticated user can supply a URL-encoded absolute path (such as an encoded drive letter) in a… | |
| Aplazada | Crítica (9.4) | 0.80% | — | Altium Enterprise ServerAI | 20/5/2026 | 23/7/2026 | A path traversal vulnerability exists in the Altium Enterprise Server ComparisonService due to missing filename sanitization in the Gerber file upload APIs. A regular authenticated workspace user can supply a crafted filename in the multipart Content-Disposition header to escape the intended temporary upload directory… | |
| Analizada | Alta (7.6) | 0.27% | — | Altium On-prem Enterprise Server | 22/1/2026 | 17/6/2026 | HTML injection in Project Release in Altium Enterprise Server (AES) 7.0.3 on all platforms allows an authenticated attacker to execute arbitrary JavaScript in the victim’s browser via crafted HTML content. | |
| Analizada | Media (4.6) | 0.23% | — | Altium On-prem Enterprise Server | 22/1/2026 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the BOM Viewer in Altium AES 7.0.3 allows an authenticated attacker to inject arbitrary JavaScript into the Description field of a schematic, which is executed when the BOM Viewer renders the affected content. | |
| Analizada | Crítica (9.8) | 0.39% | — | Altium On-prem Enterprise Server | 22/1/2026 | 17/6/2026 | AES contains a SQL injection vulnerability due to an inactive configuration that prevents the latest SQL parsing logic from being applied. When this configuration is not enabled, crafted input may be improperly handled, allowing attackers to inject and execute arbitrary SQL queries. | |
| Analizada | Media (5.3) | 0.19% | — | Altium Designer | 22/1/2026 | 17/6/2026 | Altium Designer version 24.9.0 does not validate self-signed server certificates for cloud connections. An attacker capable of performing a man-in-the-middle (MITM) attack could exploit this issue to intercept or manipulate network traffic, potentially exposing authentication credentials or sensitive design data. | |
| Aplazada | Crítica (9) | 0.36% | — | Altium 365AI | 19/1/2026 | 17/6/2026 | Altium 365 workspace endpoints were configured with an overly permissive Cross-Origin Resource Sharing (CORS) policy that allowed credentialed cross-origin requests from other Altium-controlled subdomains, including forum.live.altium.com. As a result, JavaScript executing on those origins could access authenticated… | |
| Analizada | Media (6.1) | 0.29% | — | Altium Live | 16/1/2026 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in the Altium Support Center AddComment endpoint due to missing server-side input sanitization. Although the client interface applies HTML escaping, the backend accepts and stores arbitrary HTML and JavaScript supplied via modified POST requests. The injected… | |
| Analizada | Media (5.4) | 0.34% | — | Altium On-prem Enterprise Server | 15/1/2026 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in the Altium Workflow Engine due to missing server-side input sanitization in workflow form submission APIs. A regular authenticated user can inject arbitrary JavaScript into workflow data. When an administrator views the affected workflow, the injected payload… | |
| Analizada | Media (5.4) | 0.24% | — | Altium Live | 15/1/2026 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in the Altium Forum due to missing server-side input sanitization in forum post content. An authenticated attacker can inject arbitrary JavaScript into forum posts, which is stored and executed when other users view the affected post. Successful exploitation… | |
| Analizada | Media (5.4) | 0.24% | — | Altium Live | 15/1/2026 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in the user profile text fields of Altium 365. Insufficient server-side input sanitization allows authenticated users to inject arbitrary HTML and JavaScript payloads using whitespace-based attribute parsing bypass techniques. The injected payload is persisted… |