Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
49 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.38% | — | Fs-code BookneticAI | 6/10/2026 | 6/10/2026 | Unauthenticated SQL Injection in Booknetic <= 4.8.5 versions. | |
| Aplazada | Media (6.9) | 0.17% | — | DarknetAI | 27/8/2026 | 24/9/2026 | darknet subscripts its layer array with an index taken from a configuration file without checking it against the array's length. The array is allocated in src-lib/darknet_network.cpp as xcalloc(net.n, sizeof(Darknet::Layer)), sized to exactly the number of layer sections the file declares. The shortcut, scale_channels… | |
| Aplazada | Alta (8.5) | 0.21% | — | Hank-ai DarknetAI | 20/8/2026 | 24/9/2026 | hank-ai/darknet sizes a convolutional layer's weight and output heap buffers by multiplying configuration fields taken from a .cfg file in unchecked 32-bit int arithmetic. In src-lib/convolutional_layer.cpp, l.nweights is computed as (c / groups) * n * size * size and l.outputs as l.out_h * l.out_w * l.out_c, and both… | |
| Aplazada | Alta (8.1) | 0.46% | — | Fs-code BookneticAI | 17/6/2026 | 17/6/2026 | Unauthenticated Broken Authentication in Booknetic <= 4.8.5 versions. | |
| Aplazada | Media (6.1) | 0.19% | — | Aryom Software High Technology Systems INC KvknetAI | 11/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Aryom Software High Technology Systems Inc. KVKNET allows Reflected XSS. This issue affects KVKNET: before 2.1.8. | |
| Aplazada | Media (5.3) | 0.29% | — | Desknets NEOAI | 16/10/2025 | 17/6/2026 | Improper Protection of Alternate Path (CWE-424) in the AppSuite of desknet's NEO V4.0R1.0 to V9.0R2.0 allows an attacker to create malicious AppSuite applications. | |
| Aplazada | Media (4.8) | 0.29% | — | Desknet NEOAI | 16/10/2025 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in desknet's NEO V2.0R1.0 to V9.0R2.0 allow execution of arbitrary JavaScript in a user’s web browser. | |
| Aplazada | Media (4.6) | 0.30% | — | Desknet NEOAI | 16/10/2025 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in desknet's NEO V9.0R2.0 and earlier allow execution of arbitrary JavaScript in a user’s web browser. | |
| Aplazada | Media (4.8) | 0.29% | — | Desknet NEOAI | 16/10/2025 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in desknet's NEO V9.0R2.0 and earlier allow execution of arbitrary JavaScript in a user’s web browser. | |
| Aplazada | Media (5.1) | 0.32% | — | Desknet WEB ServerAI | 16/10/2025 | 17/6/2026 | Reflected cross-site scripting (XSS) vulnerability in desknet's Web Server allows execution of arbitrary JavaScript in a user’s web browser. | |
| Aplazada | Media (4.8) | 0.29% | — | Desknets NEOAI | 16/10/2025 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in desknet's NEO versions V4.0R1.0–V9.0R2.0 allow execution of arbitrary JavaScript in a user’s web browser. | |
| Aplazada | Media (5.3) | 0.27% | — | Desknet NEOAI | 16/10/2025 | 30/9/2026 | desknet's NEO V4.0R1.0 to V9.0R2.0 contains a hard-coded cryptographic key, which allows an attacker to create malicious AppSuite applications. | |
| Analizada | Alta (8.8) | 0.24% | — | Fs-code Booknetic | 26/3/2025 | 17/6/2026 | The Booknetic WordPress plugin before 4.1.5 does not have CSRF check when creating Staff accounts, which could allow attackers to make logged in admin add arbitrary Staff members via a CSRF attack | |
| Aplazada | Media (4.3) | 0.16% | — | Fs-code BookneticAI | 25/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in fs-code Booknetic booknetic.This issue affects Booknetic: from n/a through <= 4.0.9. | |
| Aplazada | Media (5.3) | 0.53% | — | Yunknet Online School SystemAI | 12/9/2024 | 17/6/2026 | A vulnerability was found in 云课网络科技有限公司 Yunke Online School System up to 3.0.6. It has been declared as problematic. This vulnerability affects the function downfile of the file application/admin/controller/Appadmin.php. The manipulation of the argument url leads to path traversal. The attack can be initiated… | |
| Modificada | Baja (2.3) | 0.73% | — | Yunknet Online School System | 4/9/2024 | 17/6/2026 | A vulnerability was found in 云课网络科技有限公司 Yunke Online School System up to 1.5.5. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/educloud/videobind.html. The manipulation leads to inclusion of sensitive information in source code. The attack can be initiated remotely. The… | |
| Modificada | Media (6.1) | 0.51% | — | Teknet Project Teknet | 2/1/2023 | 17/6/2026 | A vulnerability was found in kirill2485 TekNet. It has been classified as problematic. Affected is an unknown function of the file pages/loggedin.php. The manipulation of the argument statusentery leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is… | |
| Modificada | Alta (8.8) | 0.57% | 💥 PoC | Optilinknetwork Op-xt71000n Firmware | 23/11/2022 | 17/6/2026 | A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to Reset ONU to Factory Default through ' /mgm_dev_reset.asp.' Resetting to default leads to Escalation of Privileges by… | |
| Modificada | Crítica (9.8) | 1.2% | 💥 PoC | Optilinknetwork Op-xt71000n Firmware | 23/11/2022 | 17/6/2026 | A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an attacker to upload arbitrary files through " /mgm_dev_upgrade.asp " which can "delete every file for Denial of Service (using 'rm -rf *.*' in the code), reverse connection (using '.asp' webshell), backdoor. | |
| Modificada | Media (6.5) | 0.45% | 💥 PoC | Optilinknetwork Op-xt71000n Firmware | 23/11/2022 | 17/6/2026 | A vulnerability in Optilink OP-XT71000N Hardware version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated remote attacker to conduct a cross-site request forgery (CSRF) attack to change the Password for "WLAN SSID" through "wlwpa.asp". | |
| Modificada | Media (6.5) | 0.48% | 💥 PoC | Optilinknetwork Op-xt71000n Firmware | 23/11/2022 | 17/6/2026 | A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to cause a Denial of Service by Rebooting the router through " /mgm_dev_reboot.asp." | |
| Modificada | Media (4.3) | 0.40% | 💥 PoC | Optilinknetwork Op-xt71000n Firmware | 23/11/2022 | 17/6/2026 | A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to "Enable or Disable Ports" and to "Change port number" through " /rmtacc.asp ". | |
| Modificada | Baja (3.1) | 0.33% | 💥 PoC | Optilinknetwork Op-xt71000n Firmware | 23/11/2022 | 17/6/2026 | A vulnerability found in the OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to men in the middle attack by adding New Routes in RoutingConfiguration on " /routing.asp ". | |
| Modificada | Media (4.3) | 0.37% | 💥 PoC | Optilinknetwork Op-xt71000n Firmware | 23/11/2022 | 17/6/2026 | A vulnerability found in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to Add Network Traffic Control Type Rule. | |
| Modificada | Crítica (9.8) | 41% | 💥 PoC | Optilinknetwork Op-xt71000n Firmware | 23/11/2022 | 17/6/2026 | Unauthenticated remote code execution in OPTILINK OP-XT71000N, Hardware Version: V2.2 occurs when the attacker passes arbitrary commands with IP-ADDRESS using " | " to execute commands on " /diag_tracert_admin.asp " in the "PingTest" parameter that leads to command execution. |