Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▲ 460 respecto a la semana anterior
Críticas / altas1445▲ 228 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 156 respecto a la semana anterior
31 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.39% | — | Trex Digital Trex MESAI | 30/9/2026 | 30/9/2026 | Missing authentication for critical function vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Authentication Bypass. This issue affects Trex MES: through 2026-09-29. | |
| Aplazada | Crítica (9.8) | 0.58% | — | Trex Digital Smart Manufacturing Systems Trex MESAI | 30/9/2026 | 30/9/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection. This issue affects Trex MES: through 2026-09-29. | |
| Aplazada | Alta (8.1) | 0.56% | — | Themetrex OzistiAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Ozisti ozisti allows PHP Local File Inclusion.This issue affects Ozisti: from n/a through <= 1.1.10. | |
| Aplazada | Alta (8.1) | 0.56% | — | Themetrex MaxifyAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Maxify maxify allows PHP Local File Inclusion.This issue affects Maxify: from n/a through <= 1.0.16. | |
| Aplazada | Alta (8.1) | 0.56% | — | Themetrex THE QleanAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX The Qlean the-qlean allows PHP Local File Inclusion.This issue affects The Qlean: from n/a through <= 2.12. | |
| Aplazada | Alta (8.1) | 0.53% | — | Themetrex YokooAI | 20/2/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Yokoo yokoo allows PHP Local File Inclusion.This issue affects Yokoo: from n/a through <= 1.1.11. | |
| Analizada | Media (5.4) | 0.24% | — | Intrexx | 2/5/2025 | 17/6/2026 | In Intrexx Portal Server before 12.0.4, multiple Velocity-Scripts are susceptible to the execution of unrequested JavaScript code in HTML, aka XSS. | |
| Aplazada | Media (6.1) | 0.23% | — | Intrexx Portal ServerAI | 19/3/2025 | 17/6/2026 | Intrexx Portal Server 12.x <= 12.0.2 and 11.x <= 11.9.2 allows XSS in multiple Velocity scripts. | |
| Aplazada | Media (6.5) | 0.34% | — | Intrexx Portal ServerAI | 19/3/2025 | 17/6/2026 | A vulnerability in Intrexx Portal Server 12.0.2 and earlier which was classified as problematic potentially allows users with particular permissions under certain conditions to see potentially sensitive data from a different user context. | |
| Aplazada | Media (5.4) | 0.22% | — | Intrexx Portal ServerAI | 16/12/2024 | 17/6/2026 | Intrexx Portal Server before 12.0.2 allows XSS via a user-defined portlet. | |
| Modificada | Media (6.1) | 0.83% | — | Unitedplanet Intrexx | 14/10/2020 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the search functionality in Intrexx before 9.4.0 allows remote attackers to inject arbitrary web script or HTML via the request parameter. | |
| Modificada | Crítica (9.8) | 4.0% | — | Unitedplanet Intrexx | 31/1/2020 | 17/6/2026 | Unrestricted file upload vulnerability in an unspecified third party tool in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unknown vectors. | |
| Modificada | Crítica (9.8) | 2.4% | — | SAP Trex | 25/7/2017 | 17/6/2026 | SAP TREX 7.10 allows remote attackers to (1) read arbitrary files via an fget command or (2) write to arbitrary files and consequently execute arbitrary code via an fdir command, aka SAP Security Note 2419592. | |
| Modificada | Crítica (9.8) | 1.6% | — | SAP Trex | 11/4/2017 | 17/6/2026 | A code injection vulnerability exists in SAP TREX / Business Warehouse Accelerator (BWA). The vendor response is SAP Security Note 2419592. | |
| Modificada | Media (5.3) | 2.0% | — | SAP Trex | 27/9/2016 | 17/6/2026 | The NameServer in SAP TREX 7.10 Revision 63 allows remote attackers to obtain sensitive TNS information via an unspecified query, aka SAP Security Note 2234226. | |
| Modificada | Crítica (9.8) | 4.7% | — | SAP Trex | 27/9/2016 | 17/6/2026 | An unspecified function in SAP TREX 7.10 Revision 63 allows remote attackers to execute arbitrary OS commands via unknown vectors, aka SAP Security Note 2203591. | |
| Modificada | Crítica (9.8) | 4.5% | — | SAP Trex | 5/8/2016 | 17/6/2026 | An unspecified interface in SAP TREX 7.10 Revision 63 allows remote attackers to execute arbitrary OS commands with SIDadm privileges via unspecified vectors, aka SAP Security Note 2234226. | |
| Modificada | Crítica (9.8) | 5.5% | — | SAP Trex | 5/8/2016 | 17/6/2026 | SAP TREX 7.10 Revision 63 allows remote attackers to write to arbitrary files via vectors related to RFC-Gateway, aka SAP Security Note 2203591. | |
| Modificada | Crítica (9.8) | 4.2% | — | SAP Trex | 5/8/2016 | 17/6/2026 | SAP TREX 7.10 Revision 63 allows remote attackers to read arbitrary files via unspecified vectors, aka SAP Security Note 2203591. | |
| Modificada | Crítica (9.8) | 5.8% | — | SAP Trex | 5/8/2016 | 17/6/2026 | Directory traversal vulnerability in SAP TREX 7.10 Revision 63 allows remote attackers to read arbitrary files via unspecified vectors, aka SAP Security Note 2203591. | |
| Modificada | Media (4.3) | 1.9% | — | Unitedplanet Intrexx | 19/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the search functionality in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to inject arbitrary web script or HTML via the request parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Trexart Campaignmonitor | 31/10/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the administrative interface in the Campaign Monitor module before 6.x-2.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this refers to an issue in an independently developed Drupal module, and NOT an issue in the… | |
| Modificada | Media (4.3) | 1.8% | — | Timetrex | 27/10/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in interface/Login.php in TimeTrex 2.2.11 allow remote attackers to inject arbitrary web script or HTML via the (1) password and (2) user_name parameters. | |
| Modificada | Alta (7.1) | 1.8% | — | Nortel Business Communications ManagerNortel Centrex IP Client ManagerNortel Centrex IP Element ManagerNortel Meridian Option 11C+5 | 23/10/2007 | 16/6/2026 | The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), Mobile Voice Client, and other product lines, allow remote attackers to block calls and force re-registration via a resume message to the Signaling Server that has a spoofed… | |
| Modificada | Media (4.3) | 3.1% | — | Nortel Business Communications ManagerNortel Centrex IP Client ManagerNortel Centrex IP Element ManagerNortel Meridian Option 11C+5 | 23/10/2007 | 16/6/2026 | The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), and other product lines allow remote attackers to eavesdrop on the physical environment via an Open Audio Stream message that enables "surveillance mode." NOTE: issues relating… |