Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2750▲ 27 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
33 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.6) | 0.14% | — | Gallagher Active Directory SyncGallagher Cardholder Sync UtilityGallagher Command CentreGallagher Diagnostics Service+11 | 25/5/2026 | 17/8/2026 | Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted.… | |
| Aplazada | Baja (1.3) | 0.24% | — | Realcetecnologia Queue Ticket KioskAI | 11/9/2025 | 17/6/2026 | A flaw has been found in SEAT Queue Ticket Kiosk up to 20250827. This affects an unknown part of the component Java RMI Registry Handler. This manipulation causes deserialization. The attack can only be done within the local network. The attack is considered to have high complexity. It is indicated that the… | |
| Aplazada | Alta (8.5) | 0.14% | — | Bluebird KioskAI | 17/7/2025 | 17/6/2026 | Bluebird devices contain a pre-loaded kiosk application. This application exposes an unsecured service provider "com.bluebird.kiosk.launcher.IpartnerKioskRemoteService". A local attacker can bind to the AIDL-type service to modify device's global settings and wallpaper image. This issue affects all versions before… | |
| Analizada | Media (4.8) | 0.34% | — | Realcetecnologia Queue Ticket Kiosk | 26/5/2025 | 17/6/2026 | A vulnerability classified as problematic was found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. Affected by this vulnerability is an unknown functionality of the file /adm/index.php of the component Cadastro de Administrador Page. The manipulation of the argument Name/Usuário leads to cross site scripting.… | |
| Analizada | Media (5.3) | 0.50% | — | Realcetecnologia Queue Ticket Kiosk | 26/5/2025 | 17/6/2026 | A vulnerability classified as critical has been found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. Affected is an unknown function of the file /adm/ajax.php of the component Image File Handler. The manipulation of the argument files[] leads to unrestricted upload. It is possible to launch the attack… | |
| Analizada | Media (5.3) | 0.57% | — | Realcetecnologia Queue Ticket Kiosk | 26/5/2025 | 17/6/2026 | A vulnerability was found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. It has been rated as problematic. This issue affects some unknown processing of the file /adm/index.php of the component Admin Login Page. The manipulation of the argument Usuário leads to cross site scripting. The attack may be… | |
| Analizada | Media (6.9) | 0.45% | — | Realcetecnologia Queue Ticket Kiosk | 26/5/2025 | 17/6/2026 | A vulnerability was found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. It has been declared as critical. This vulnerability affects unknown code of the file /adm/index.php of the component Admin Login Page. The manipulation of the argument Usuário leads to sql injection. The attack can be initiated… | |
| Aplazada | Media (6.8) | 0.32% | — | Opswat Metadefender KioskAI | 26/2/2025 | 17/6/2026 | In OPSWAT MetaDefender Kiosk before 4.7.0, arbitrary code execution can be performed by an attacker via the MD Kiosk Unlock Device feature for software encrypted USB drives. | |
| Aplazada | Media (6.5) | 0.39% | — | Figoliquinn Mobile KioskAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in figoliquinn Mobile Kiosk mobile-kiosk allows Stored XSS.This issue affects Mobile Kiosk: from n/a through <= 1.3.0. | |
| Aplazada | Alta (7.5) | 0.37% | — | Newland Nquire 1000 Interactive KioskAI | 9/3/2024 | 17/6/2026 | An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to obtain sensitive information via cleartext credential storage in backup.htm component. | |
| Aplazada | Crítica (9.8) | 0.86% | — | Newland Nquire 1000 Interactive KioskAI | 9/3/2024 | 17/6/2026 | An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to escalate privileges and bypass authentication via incorrect access control in the web management portal. | |
| Modificada | Crítica (9.8) | 0.98% | — | Opswat Metadefender Kiosk | 15/9/2023 | 17/6/2026 | An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. Long inputs were not properly processed, which allows remote attackers to cause a denial of service (loss of communication). | |
| Modificada | Crítica (9.8) | 0.69% | — | Opswat Metadefender Kiosk | 15/9/2023 | 17/6/2026 | An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. Built-in features of Windows (desktop shortcuts, narrator) can be abused for privilege escalation. | |
| Modificada | Alta (7.8) | 0.23% | — | Opswat Media Validation AgentOpswat Metadefender Kiosk | 15/9/2023 | 17/6/2026 | An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. It has an unquoted service path that can be abused locally. | |
| Modificada | Crítica (9.8) | 1.2% | — | Provisio Sitekiosk | 29/3/2019 | 17/6/2026 | An elevation of privilege vulnerability exists in the Call Dispatcher in Provisio SiteKiosk before 9.7.4905. | |
| Modificada | Crítica (9.8) | 2.4% | — | Redswimmer Kiosksimple | 3/7/2018 | 17/6/2026 | KioskSimpleService.exe in RedSwimmer KioskSimple 1.4.7.0 suffers from a privilege escalation vulnerability in the WCF endpoint. The exposed methods allow read and write access to the Windows registry and control of services. These methods may be abused to achieve privilege escalation via execution of attacker… | |
| Modificada | Media (6.6) | 0.42% | — | Norwegian-air Norwegian AIR Kiosk | 9/2/2017 | 17/6/2026 | The Norwegian Air Shuttle (aka norwegian.com) airline kiosk allows physically proximate attackers to bypass the intended "Please select booking identification" UI step, and obtain administrative privileges and network access on the underlying Windows OS, by accessing a touch-screen print icon to manipulate the print… | |
| Modificada | Media (5.4) | 0.27% | — | E-kiosk | 20/10/2014 | 17/6/2026 | The e-Kiosk (aka com.ekioskreader.android.pdfviewer) application 1.74 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.33% | — | Getscoop Kontan Kiosk | 20/10/2014 | 17/6/2026 | The Kontan Kiosk (aka com.appsfoundry.scoopwl.id.kontankiosk) application @7F07025E for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Apps2you Cedar Kiosk | 19/10/2014 | 17/6/2026 | The Cedar Kiosk (aka com.apps2you.cedarkiosk) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5) | 1.7% | — | Agilefleet FleetcommanderAgilefleet Fleetcommander Kiosk | 18/11/2012 | 16/6/2026 | Agile FleetCommander and FleetCommander Kiosk before 4.08 store database credentials in cleartext, which allows remote attackers to obtain sensitive information via requests to unspecified pages. | |
| Modificada | Media (5) | 1.2% | — | Agilefleet FleetcommanderAgilefleet Fleetcommander Kiosk | 18/11/2012 | 16/6/2026 | Agile FleetCommander and FleetCommander Kiosk before 4.08 use an XOR format for password encryption, which makes it easier for context-dependent attackers to obtain sensitive information by reading a key file and the encrypted strings. | |
| Modificada | Alta (7.5) | 1.9% | — | Agilefleet FleetcommanderAgilefleet Fleetcommander Kiosk | 18/11/2012 | 16/6/2026 | Agile FleetCommander and FleetCommander Kiosk before 4.08 allow remote attackers to execute arbitrary commands via unspecified vectors, related to a "command injection" issue. | |
| Modificada | Alta (10) | 3.8% | — | Agilefleet FleetcommanderAgilefleet Fleetcommander Kiosk | 18/11/2012 | 16/6/2026 | Multiple unrestricted file upload vulnerabilities in Agile FleetCommander and FleetCommander Kiosk before 4.08 allow remote attackers to execute arbitrary code by uploading a file via an unspecified page. | |
| Modificada | Media (6.8) | 0.73% | — | Agilefleet FleetcommanderAgilefleet Fleetcommander Kiosk | 18/11/2012 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Agile FleetCommander and FleetCommander Kiosk before 4.08 allow remote attackers to hijack the authentication of arbitrary users for requests that modify (1) passwords, (2) accounts, or (3) permissions. |