Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2806▲ 5 respecto a la semana anterior
Críticas / altas1465▲ 246 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)77▼ 441 respecto a la semana anterior
–

869 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.4)0.29%—Flexible PDF CouponsAI30/9/202630/9/2026
Contributor Insecure Direct Object References (IDOR) in Flexible PDF Coupons <= 1.14.11 versions.
AplazadaMedia (4.3)0.43%—Flex ImportAI19/9/202621/9/2026
The Flex Import plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0. This is due to the license_activate_fleximp() and license_deactivate_fleximp() functions, hooked to the wp_ajax_license_activate_fleximp and wp_ajax_license_deactivate_fleximp AJAX actions, lacking…
AplazadaMedia (4.8)0.10%—Veritas Netbackup Flex OSAI18/9/202618/9/2026
An authenticated user with access to the NetBackup Flex OS management shell could read arbitrary files from the underlying operating system by supplying a specially crafted path argument to a diagnostic command. Successful exploitation could expose sensitive system configuration and credential material stored on the…
AplazadaCrítica (9.4)0.34%—Veritas Netbackup FlexAI18/9/202618/9/2026
An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptographic signature verification step of a privileged support command by supplying a specially formed access credential. Successful exploitation grants the attacker an unrestricted root shell with full…
AplazadaCrítica (9.4)0.67%—Veritas Netbackup FlexAI18/9/202618/9/2026
An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could supply a specially crafted input to a privileged administrative command, causing it to execute arbitrary code with root-level permissions. Successful exploitation grants the attacker unrestricted control over the Flex…
AplazadaAlta (7.2)0.54%—Flextype CMSAI15/9/202616/9/2026
Flextype CMS through 1.0.0-alpha.3 fails to properly validate id and new_id parameters in the Entries REST API, allowing API token holders to read, create, or overwrite files outside the entries directory. Attackers can use traversal sequences in API requests to escape the project entries directory and manipulate…
AplazadaMedia (5.3)0.29%—Flexible Quantity Measurement Price CalculatorAI11/9/202611/9/2026
Unauthenticated Broken Access Control in Flexible Quantity – Measurement Price Calculator for WooCommerce <= 2.3.21 versions.
AplazadaBaja (2.4)0.18%—Flextype CMSAI11/9/202624/9/2026
Flextype CMS versions 0.9.9 through 1.0.0-alpha.3 fail to HTML-escape plugin directory names in the dependency error page rendered by getValidPluginsDependencies(). Attackers with write access to the plugins directory can create a plugin with HTML characters in its name to execute arbitrary scripts in users' browsers…
AplazadaAlta (8.2)0.56%—Flextype CMSAI10/9/202615/9/2026
Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes. Attackers with access to web server, proxy, or monitoring logs can recover valid API token pairs that grant full API access.
AplazadaAlta (8.6)0.19%—Siemens Desigo CC Clickonce ClientAISiemens Desigo CC Flex ClientAISiemens Desigo CC Installed ClientAISiemens Desigo CCAI8/9/202614/9/2026
A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CC family V8 (All versions), Desigo CC family V9 (All versions), Desigo CC Flex Client V6 (All versions), Desigo CC Flex Client V7 (All versions), Desigo CC Installed Client V6 (All…
AplazadaAlta (7.1)0.61%—Flextype CMSAI28/8/20268/9/2026
Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that allows authenticated attackers with a valid API token to read arbitrary files by passing unsanitized user-supplied input to the Symfony ExpressionLanguage engine via the POST /api/v1/query endpoint. Attackers can leverage…
AplazadaAlta (8.3)0.38%—Grav Flex ObjectsAI25/8/202631/8/2026
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability in the flex-objects shortcode that allows users with page-edit access to render any registered Flex collection without permission checks. Attackers can place the shortcode in published pages to expose sensitive…
AplazadaAlta (7.7)0.44%—PTC Windchill PdmlinkAIPTC FlexplmAI20/8/20269/9/2026
A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.
AplazadaCrítica (9.2)0.56%—PTC WindchillAIPTC FlexplmAI20/8/20269/9/2026
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.
AplazadaMedia (6.3)0.33%—Getgrav Flex ObjectsAI19/8/20269/9/2026
Grav Flex Objects Plugin allows you to build custom collections of objects. Prior to 1.4.3, the Grav Flex Objects Admin Next API requireFlexPermission() method in classes/Api/FlexApiController.php returns without denying access when a directory blueprint omits config.admin.permissions. An authenticated account with…
AplazadaCrítica (9.8)0.56%—Flexible SubscriptionsAI19/8/202620/8/2026
Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.
Pendiente de análisisAlta (7.3)0.17%—Dell AppsyncAIDell Metro NodeAIDell UCC EdgeAIDell VxrailAI+518/8/202620/8/2026
Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00 and Dell PowerFlex Rack version 4.5.4…
AplazadaAlta (8.7)0.56%—Getgrav Flex ObjectsAIGetgrav GravAI14/8/202631/8/2026
The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerability in its Flex Objects API. FlexApiController::update() checks only the general Flex directory permission and does not apply the additional target/field/super-admin checks enforced by the dedicated Users and…
AplazadaAlta (8.7)0.90%—Getgrav GravAIGetgrav Flex ObjectsAI14/8/20268/9/2026
Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by uploading a ZIP file containing PHP code. Attackers can bypass routine name validation by using array notation instead of string notation,…
AnalizadaAlta (8.3)0.14%—Thermofisher ABI Prism 310 Data Collection SoftwareThermofisher ABI Prism 3100/3100-avant Data Collection SoftwareThermofisher Applied Biosystems 3130 Series Data Collection SoftwareThermofisher Applied Biosystems 3500/3500xl Series Data Collection Software+45/8/202626/8/2026
The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes.
Pendiente de análisisAlta (7.2)0.57%—Zyxel ATP Series FirmwareAIZyxel USG Flex Series FirmwareAIZyxel USG Flex 50 Series FirmwareAIZyxel Usg20 VPN Series FirmwareAI4/8/20264/8/2026
A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 through V5.42 Patch 1, USG FLEX series firmware versions from V4.50 through V5.42 Patch 1, USG FLEX 50(W) series firmware versions from V4.16 through V5.42 Patch 1, and USG20(W)-VPN…
AplazadaMedia (4.3)0.41%—Uni-yaz FlexcityAI21/7/202628/7/2026
Improper restriction of excessive authentication attempts vulnerability in Universal Software Inc. FlexCity allows Excessive Allocation. This issue affects FlexCity: from 5.536.0 before 5.542.0.
AplazadaMedia (6.1)0.24%—Uni-yaz FlexcityAI21/7/202628/7/2026
URL redirection to untrusted site ('open redirect') vulnerability in Universal Software Inc. FlexCity allows Input Data Manipulation. This issue affects FlexCity: from 5.536.0 before 5.542.0.
AplazadaMedia (6.5)0.34%—Uni-yaz FlexcityAI21/7/202628/7/2026
Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FlexCity: from 5.536.0 before 5.542.0.
AplazadaBaja (2.3)0.29%—Getgrav GravAIGetgrav Flex-objectsAI17/7/202617/7/2026
Grav Flex-Objects before version 1.4.3 contains a broken access control vulnerability in the admin-next REST API that allows authenticated users with only api.access permission to perform unauthorized CRUD operations on permission-less directories. Attackers with api.access credentials can create, read, update,…