Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 80 respecto a la semana anterior
Críticas / altas1442▲ 302 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
156 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.30% | — | Wellav WES Emergency Broadcast TerminalAI | 25/9/2026 | 30/9/2026 | An issue in Wellav Technologies Co., Ltd Wellav WES Emergency Broadcast Terminal WES100, WES270, WES280, and WES290 before 08-08-2023 allows a remote attacker to obtain sensitive information via the global API request wrapper function | |
| Aplazada | Media (6.7) | 0.18% | — | Keyence XG VisionterminalAIKeyence Xg-x VisionterminalAI | 3/9/2026 | 15/9/2026 | XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporation improperly restrict XML external entity references. If a user opens a specially crafted setting file, the sensitive information stored in the system where XG VisionTerminal or XG-X VisionTerminal is installed may be disclosed. | |
| Aplazada | Media (5.3) | 0.29% | — | Next TerminalAI | 17/8/2026 | 24/9/2026 | Next Terminal fails to enforce per-asset authorization checks on the portal ping and wake-on-LAN endpoints, allowing any authenticated user to probe and wake assets they are not granted access to. Attackers can call these endpoints with arbitrary asset identifiers to retrieve asset information including display names,… | |
| Pendiente de análisis | Media (5) | 0.35% | — | Cisco Terminal Service AgentAI | 5/8/2026 | 6/8/2026 | A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker to bypass firewall rules that are associated with the account of the attacker. This vulnerability is due to an incorrect mapping of network connections to user accounts. An attacker with at least… | |
| Analizada | Alta (7.5) | 0.61% | — | Microsoft Terminal | 16/7/2026 | 30/7/2026 | Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft TerminalMicrosoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 24h2+4 | 14/7/2026 | 22/7/2026 | Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.6) | 0.19% | — | Lizardsystems Terminal Services Manager | 22/4/2026 | 17/6/2026 | Terminal Services Manager 3.1 contains a stack-based buffer overflow vulnerability in the computer names field that allows local attackers to execute arbitrary code by triggering structured exception handling. Attackers can craft a malicious input file with shellcode and jump instructions that overwrite the SEH… | |
| Analizada | Media (6.4) | 0.16% | — | Redhat WEB Terminal | 8/4/2026 | 24/7/2026 | A container privilege escalation flaw was found in certain Web Terminal images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can leverage… | |
| Analizada | Media (6.9) | 0.19% | — | Lizardsystems Terminal Services Manager | 21/3/2026 | 17/6/2026 | Terminal Services Manager 3.2.1 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying an excessively long string in the computer name field. Attackers can input a 5000-byte buffer of data into the 'Computer name or IP address' field during computer addition, causing… | |
| Aplazada | Media (6.7) | 0.38% | — | ZOC TerminalAI | 5/2/2026 | 17/6/2026 | ZOC Terminal 7.25.5 contains a denial of service vulnerability in the private key file input field that allows attackers to crash the application. Attackers can overwrite the private key file input with a 2000-byte buffer, causing the application to become unresponsive when attempting to create SSH key files. | |
| Aplazada | Media (6.7) | 0.18% | — | ZOC TerminalAI | 5/2/2026 | 17/6/2026 | ZOC Terminal 7.25.5 contains a script processing vulnerability that allows local attackers to crash the application by loading a maliciously crafted REXX script file. Attackers can generate an oversized script with 20,000 repeated characters to trigger an application crash and cause a denial of service. | |
| Analizada | Crítica (10) | 2.2% | — | Gongrzhe Terminal-controller-mcp | 7/1/2026 | 17/6/2026 | A command injection vulnerability in the execute_command function of terminal-controller-mcp 0.1.7 allows attackers to execute arbitrary commands via a crafted input. | |
| Aplazada | Media (6.5) | 0.12% | — | Identity Agent FOR Terminal ServicesAI | 22/12/2025 | 17/6/2026 | An authenticated local user can obtain information that allows claiming security policy rules of another user due to sensitive information being printed in plaintext in Identity Agent for Terminal Services debug files. | |
| Analizada | Media (6.9) | 0.21% | — | Waveterm Wave Terminal | 12/12/2025 | 17/6/2026 | Code Injection using Electron Fuses in waveterm on MacOS allows TCC Bypass. This issue affects waveterm: 0.12.2. | |
| Analizada | Crítica (9.8) | 0.34% | — | Terminalfour | 2/12/2025 | 17/6/2026 | In Terminalfour 8 through 8.4.1.1, the userLevel parameter in the user management function is not subject to proper server-side authorization checks. A Power User can intercept and modify this parameter to assign the Administrator role to other existing lower-privileged accounts, or invite a new lower-privileged… | |
| Aplazada | Alta (8.8) | 0.29% | — | NCR Atleos Terminal ManagerAI | 29/10/2025 | 17/6/2026 | An issue in NCR Atleos Terminal Manager (ConfigApp) v3.4.0 allows attackers to escalate privileges via a crafted request. | |
| Aplazada | Media (6.6) | 0.35% | — | Minecraft Rcon TerminalAIMicrosoft Visual Studio CodeAI | 3/10/2025 | 17/6/2026 | Minecraft RCON Terminal is a VS Code extension that streamlines Minecraft server management. Versions 0.1.0 through 2.0.6 stores passwords using VS Code's configuration API which writes to settings.json in plaintext. This issue is fixed in version 2.1.0. | |
| Aplazada | Media (6.5) | 0.44% | — | Asna RegistrarAIAsna Datagate FOR SQL ServerAIAsna Datagate Component SuiteAIAsna Datagate MonitorAI+13 | 3/7/2025 | 17/6/2026 | ASNA Assist and ASNA Registrar before 2025-03-31 allow deserialization attacks against .NET remoting. These are Windows system services that support license key management and deprecated Windows network authentication. The services are implemented with .NET remoting and can be exploited via well-known deserialization… | |
| Aplazada | Crítica (9.8) | 0.40% | — | Mobilteg Mikro Hand Terminal - MikrodbAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mobilteg Mobile Informatics Mikro Hand Terminal - MikroDB allows SQL Injection. This issue affects Mikro Hand Terminal - MikroDB. NOTE: The vendor did not inform about the completion of the fixing process within the… | |
| Analizada | Crítica (9.8) | 0.73% | — | NCR Terminal Handler | 23/6/2025 | 17/6/2026 | An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via a GET request to a UserService SOAP API endpoint to validate if a user exists. | |
| Analizada | Crítica (9.8) | 0.72% | — | NCR Terminal Handler | 23/6/2025 | 17/6/2026 | An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted POST request to the UserService component | |
| Modificada | Crítica (9.8) | 0.62% | — | NCR Terminal Handler | 23/6/2025 | 5/7/2026 | An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to escalate privileges via a crafted POST request to the grantRolesToUsers, grantRolesToGroups, and grantRolesToOrganization SOAP API component. | |
| Analizada | Crítica (9.8) | 0.60% | — | NCR Terminal Handler | 23/6/2025 | 17/6/2026 | A CSV injection vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands via injecting a crafted payload into any text field that accepts strings. | |
| Analizada | Alta (8.1) | 0.33% | — | NCR Terminal Handler | 23/6/2025 | 17/6/2026 | An issue in NCR Terminal Handler v1.5.1 allows low-level privileged authenticated attackers to arbitrarily deactivate, lock, and delete user accounts via a crafted session cookie. | |
| Analizada | Crítica (9.8) | 0.82% | — | NCR Terminal Handler | 23/6/2025 | 17/6/2026 | Password Vulnerability in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code via a crafted script to the UserService SOAP API function. |