Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3040▲ 560 respecto a la semana anterior
Críticas / altas1452▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.4) | 0.53% | — | Rockwellautomation Factorytalk Datamosaix Private CloudAI | 14/7/2026 | 14/7/2026 | A Stored Cross-Site Scripting security issue exists within FactoryTalk® DataMosaix™ Private Cloud. The vulnerability stems from improper neutralization of user-supplied input within the Workflows configuration. An authenticated attacker with high privileges can inject malicious scripts that are permanently stored on… | |
| Analizada | Media (6.5) | 0.27% | — | Apple Private Cloud Compute | 18/5/2026 | 30/6/2026 | An attacker in a privileged network position may be able to leak sensitive information. A path handling issue was addressed with improved validation. This issue is fixed in PCC Release 5E290.3. | |
| Aplazada | Alta (7.1) | 0.30% | — | SAP S/4 Hana Private CloudAI | 9/12/2025 | 17/6/2026 | Due to a Missing Authorization Check vulnerability in SAP S/4 HANA Private Cloud (Financials General Ledger), an authenticated attacker with authorization limited to a single company code could read sensitive data and post or modify documents across all company codes. Successful exploitation could result in a high… | |
| Aplazada | Alta (8.7) | 0.43% | — | Datamosaix Private CloudAI | 9/12/2025 | 17/6/2026 | A security issue was discovered in DataMosaix Private Cloud, allowing users with low privilege to perform sensitive database operations through exposed API endpoints. | |
| Aplazada | Alta (8.6) | 0.35% | — | Datamosaix Private CloudAI | 11/11/2025 | 17/6/2026 | A security issue exists within DataMosaix™ Private Cloud allowing for Persistent XSS. This vulnerability can result in the execution of malicious JavaScript, allowing for account takeover, credential theft, or redirection to a malicious website. | |
| Aplazada | Alta (7.6) | 0.15% | — | Datamosaix Private CloudAI | 11/11/2025 | 17/6/2026 | A security issue exists within DataMosaix™ Private Cloud, allowing attackers to bypass MFA during setup and obtain a valid login-token cookie without knowing the users password. This vulnerability occurs when MFA is enabled but not completed within a 7-day period. | |
| Analizada | Alta (7.5) | 0.82% | — | ClamavCisco Secure EndpointCisco Secure Endpoint Private Cloud | 18/6/2025 | 17/6/2026 | A vulnerability in Universal Disk Format (UDF) processing of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a memory overread during UDF file scanning. An attacker could exploit this vulnerability by submitting a… | |
| Aplazada | Media (5.3) | 0.51% | — | Kingdee Cloud Galaxy Private Cloud BBC SystemAI | 21/5/2025 | 17/6/2026 | A vulnerability has been found in Kingdee Cloud Galaxy Private Cloud BBC System up to 9.0 Patch April 2025 and classified as critical. Affected by this vulnerability is the function BaseServiceFactory.getFileUploadService.deleteFileAction of the file fileUpload/deleteFileAction.jhtml of the component File Handler. The… | |
| Aplazada | Alta (7) | 0.39% | — | Rockwellautomation Datamosaix Private CloudAI | 28/1/2025 | 17/6/2026 | A path traversal vulnerability exists in the Rockwell Automation DataEdge Platform DataMosaix Private Cloud. By specifying the character sequence in the body of the vulnerable endpoint, it is possible to overwrite files outside of the intended directory. A threat actor with admin privileges could leverage this… | |
| Modificada | Alta (7.5) | 1.6% | — | ClamavCisco Secure EndpointCisco Secure Endpoint Private Cloud | 22/1/2025 | 17/6/2026 | A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an integer underflow in a bounds check that allows for a heap buffer overflow read.… | |
| Aplazada | Media (5.1) | 1.9% | — | Huashi Private Cloud CDN Live Streaming Acceleration ServerAI | 23/5/2024 | 17/6/2026 | A vulnerability was found in Huashi Private Cloud CDN Live Streaming Acceleration Server up to 20240520. It has been classified as critical. Affected is an unknown function of the file /manager/ipconfig_new.php. The manipulation of the argument dev leads to os command injection. It is possible to launch the attack… | |
| Aplazada | Crítica (9.8) | 1.1% | — | Huashi Private Cloud CDN Live Streaming Acceleration Server Hgateway-sixportAI | 29/3/2024 | 17/6/2026 | An issue in Huashi Private Cloud CDN Live Streaming Acceleration Server hgateway-sixport v.1.1.2 allows a remote attacker to execute arbitrary code via the manager/ipping.php component. | |
| Modificada | Alta (7.5) | 33% | — | Cisco Secure EndpointCisco Secure Endpoint Private CloudFedoraproject Fedora | 7/2/2024 | 17/6/2026 | A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for end-of-string values during scanning, which may result in a heap buffer over-read. An attacker… | |
| Modificada | Media (5.4) | 0.42% | — | Qualys Private Cloud Platform | 8/12/2023 | 17/6/2026 | A Qualys web application was found to have a stored XSS vulnerability resulting from the absence of HTML encoding in the presentation of logging information to users. This vulnerability allowed a user with login access to the application to introduce XSS payload via browser details. | |
| Modificada | Media (4.4) | 0.17% | — | Cisco Secure EndpointCisco Secure Endpoint Private Cloud | 22/11/2023 | 17/6/2026 | A vulnerability in the endpoint software of Cisco Secure Endpoint for Windows could allow an authenticated, local attacker to evade endpoint protection within a limited time window. This vulnerability is due to a timing issue that occurs between various software components. An attacker could exploit this vulnerability… | |
| Modificada | Alta (7.5) | 3.4% | — | Cisco Secure EndpointCisco Secure Endpoint Private Cloud | 18/8/2023 | 17/6/2026 | A vulnerability in the AutoIt module of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a logic error in the memory management of an affected device. An attacker could exploit this vulnerability by submitting a… | |
| Modificada | Alta (7.5) | 1.2% | — | Cisco Secure EndpointCisco Secure Endpoint Private CloudFedoraproject Fedora | 16/8/2023 | 17/6/2026 | A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for completion when a file is decompressed, which may… | |
| Modificada | Media (5.3) | 7.0% | — | Cisco Secure EndpointCisco Secure Endpoint Private CloudClamavStormshield Network Security | 1/3/2023 | 17/6/2026 | On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to access sensitive information on an affected device.… | |
| Modificada | Crítica (9.8) | 29% | — | Cisco Secure EndpointCisco Secure Endpoint Private CloudCisco WEB Security ApplianceClamav+1 | 1/3/2023 | 17/6/2026 | On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to execute arbitrary code. This vulnerability… | |
| Modificada | Crítica (9.8) | 0.69% | — | Private Cloud Management Platform Project Private Cloud Management Platform | 5/8/2022 | 17/6/2026 | A vulnerability classified as critical has been found in Private Cloud Management Platform. Affected is an unknown function of the file /management/api/rcx_management/global_config_query of the component POST Request Handler. The manipulation leads to improper authentication. It is possible to launch the attack… | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… |