Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2750▲ 27 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.28% | — | Genexis Platinum-4410AI | 21/1/2026 | 17/6/2026 | Genexis Platinum-4410 P4410-V2-1.31A contains a stored cross-site scripting vulnerability in the 'start_addr' parameter of the Security Management interface. Attackers can inject malicious scripts through the start source address field that will persist and trigger for privileged users when they access the security… | |
| Analizada | Alta (8.4) | 0.38% | — | Genexis Platinum 4410 Firmware | 4/12/2025 | 17/6/2026 | A vulnerability has been identified in Genexis Platinum P4410 router (Firmware P4410-V2–1.41) that allows a local network attacker to achieve Remote Code Execution (RCE) with root privileges. The issue occurs due to improper session invalidation after administrator logout. When an administrator logs out, the session… | |
| Aplazada | Alta (8.7) | 0.36% | — | Avid NexisAIAvid Nexis AgentAIAvid System Director ApplianceAIGenivia GsoapAI | 14/7/2025 | 17/6/2026 | The Avid Nexis Agent uses a vulnerable gSOAP version. An undocumented vulnerability impacting gSOAP v2.8 makes the application vulnerable to an Unauthenticated Path Traversal vulnerability. This issue affects Avid NEXIS E-series: before 2025.5.1; Avid NEXIS F-series: before 2025.5.1; Avid NEXIS PRO+: before 2025.5.1;… | |
| Aplazada | Alta (7.1) | 0.37% | — | Avid Nexis E-seriesAIAvid Nexis F-seriesAIAvid Nexis Pro+AIAvid System Director ApplianceAI | 14/7/2025 | 17/6/2026 | An authenticated Arbitrary File Deletion vulnerability enables an attacker to delete critical files. This issue affects Avid NEXIS E-series: before 2025.5.1; Avid NEXIS F-series: before 2025.5.1; Avid NEXIS PRO+: before 2025.5.1; System Director Appliance (SDA+): before 2025.5.1. | |
| Aplazada | Alta (8.7) | 1.1% | — | Avid Nexis E-seriesAIAvid Nexis F-seriesAIAvid Nexis Pro+AIAvid System Director ApplianceAI | 14/7/2025 | 17/6/2026 | An Unauthenticated Arbitrary File Read vulnerability affects the Agent when installed on a system. The parameter filename does not validate the path thus allowing users to read arbitrary files. As the application runs with the highest privileges (root/NT_AUTHORITY SYSTEM) by default attackers are able to obtain… | |
| Aplazada | Alta (8.7) | 0.52% | — | Avid Nexis E-seriesAIAvid Nexis F-seriesAIAvid Nexis Pro+AIAvid System Director ApplianceAI | 12/3/2025 | 17/6/2026 | Improper Input Validation vulnerability in Avid Avid NEXIS E-series on Linux, Avid Avid NEXIS F-series on Linux, Avid Avid NEXIS PRO+ on Linux, Avid System Director Appliance (SDA+) on Linux allows code execution on underlying operating system with root permissions.This issue affects Avid NEXIS E-series: before… | |
| Aplazada | Media (5.3) | 0.36% | — | Genexis Tilgin Home GatewayAI | 21/8/2024 | 17/6/2026 | A vulnerability was found in Genexis Tilgin Home Gateway 322_AS0500-03_05_13_05. It has been rated as problematic. This issue affects some unknown processing of the file /vood/cgi-bin/vood_view.cgi?lang=EN&act=user/spec_conf&sessionId=86213915328111654515&user=A&message2user=Account%20updated. The manipulation of the… | |
| Aplazada | Media (6.9) | 0.43% | — | Genexis Tilgin Fiber Home Gateway Hg1522AI | 26/6/2024 | 17/6/2026 | A vulnerability was found in Genexis Tilgin Fiber Home Gateway HG1522 CSx000-01_09_01_12. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /status/product_info/. The manipulation of the argument product_info leads to cross site scripting. The attack can be… | |
| Aplazada | Media (6.9) | 0.43% | — | Genexis Tilgin Home GatewayAI | 18/6/2024 | 17/6/2026 | A vulnerability was found in Genexis Tilgin Home Gateway 322_AS0500-03_05_13_05. It has been classified as problematic. Affected is an unknown function of the file /vood/cgi-bin/vood_view.cgi?act=index&lang=EN# of the component Login. The manipulation of the argument errmsg leads to basic cross site scripting. It is… | |
| Modificada | Media (6.5) | 0.18% | — | Assaabloy Yale Conexis L1 Firmware | 5/12/2023 | 17/6/2026 | Weak encryption mechanisms in RFID Tags in Yale Conexis L1 v1.1.0 allows attackers to create a cloned tag via physical proximity to the original. | |
| Modificada | Media (6.5) | 0.56% | — | Genexis Platinum 4410 Firmware | 10/11/2021 | 17/6/2026 | Cross site request forgery (CSRF) in Genexis Platinum 4410 V2-1.28, allows attackers to cause a denial of service by continuously restarting the router. | |
| Modificada | Crítica (9.8) | 45% | — | Genexis Platinum 4410 Firmware | 13/4/2021 | 17/6/2026 | Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacters to sys_config_valid.xgi, as demonstrated by the sys_config_valid.xgi?exeshell=%60telnetd%20%26%60 URI. | |
| Modificada | Media (6.5) | 3.1% | — | Genexis Platinum 4410 Firmware | 17/11/2020 | 17/6/2026 | UPNP Service listening on port 5555 in Genexis Platinum 4410 Router V2.1 (P4410-V2–1.34H) has an action 'X_GetAccess' which leaks the credentials of 'admin', provided that the attacker is network adjacent. | |
| Modificada | Media (5.4) | 0.76% | — | Genexis Platinum-4410 Firmware | 28/10/2020 | 17/6/2026 | Genexis Platinum-4410 P4410-V2-1.28 devices allow stored XSS in the WLAN SSID parameter. This could allow an attacker to perform malicious actions in which the XSS popup will affect all privileged users. | |
| Modificada | Media (6.5) | 3.1% | — | Genexis Platinum 4410 Firmware | 16/9/2020 | 17/6/2026 | A specific router allows changing the Wi-Fi password remotely. Genexis Platinum 4410 V2-1.28, a compact router generally used at homes and offices was found to be vulnerable to Broken Access Control and CSRF which could be combined to remotely change the WIFI access point’s password. | |
| Modificada | Crítica (9.8) | 7.3% | — | Genexis Platinum-4410 Firmware | 8/1/2020 | 17/6/2026 | An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cleartext credentials from the HTML source code of the cgi-bin/index2.asp URI. | |
| Modificada | Crítica (9.8) | 1.2% | — | Genexis Gaps | 20/12/2017 | 17/6/2026 | CPEs used by subscribers on the access network receive their individual configuration settings from a central GAPS instance. A CPE identifies itself by the MAC address of its WAN interface and a certain "chk" value (48bit) derived from the MAC. The algorithm used to compute the "chk" was disclosed by reverse… | |
| Modificada | Alta (7.5) | 1.1% | — | Sonexis Conferencemanager | 27/9/2011 | 16/6/2026 | Multiple SQL injection vulnerabilities in Sonexis ConferenceManager 9.3.14.0 allow remote attackers to execute arbitrary SQL commands via (1) the g parameter to Conference/Audio/AudioResourceContainer.asp or (2) the txtConferenceID parameter to Login/HostLogin.asp. | |
| Modificada | Media (4.3) | 1.3% | — | Sonexis Conferencemanager | 27/9/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Sonexis ConferenceManager 9.2.11.0 allow remote attackers to inject arbitrary web script or HTML via (1) the txtConferenceID parameter to HostLogin.asp, (2) the txtConferenceID parameter to ParticipantLogin.asp, (3) the acp parameter to ForgotPIN.asp, or the (4)… | |
| Modificada | Media (4.3) | 1.3% | — | Sonexis Conferencemanager | 27/9/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in myAddressBook.asp in Sonexis ConferenceManager 9.2.11.0 and 9.3.14.0 allow remote attackers to inject arbitrary web script or HTML via the (1) fname, (2) lname, (3) email_edit, (4) email, (5) email2, (6) email3, (7) sms, (8) sms_id, or (9) work parameter. |