Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

121 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.50%—Admin Safety GuardAI8/8/202626/8/2026
The Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin before 1.4.0 does not perform any capability check on one of its REST API endpoints, allowing unauthenticated attackers to retrieve the full list of registered users including their usernames, email addresses, roles,…
Pendiente de análisisAlta (8.2)0.61%—Nasa Core Flight SystemAINasa Health AND SafetyAI30/7/202631/8/2026
An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a separate NULL pointer dereference reachable in versions through 7.0.1. An attacker who can trigger the affected command under specific conditions could cause the HS application to crash, resulting in a…
Pendiente de análisisAlta (8.2)0.61%—Nasa Core Flight SystemAINasa Health AND SafetyAI16/7/202617/7/2026
A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the application to crash via segmentation fault when processing a routine Housekeeping Telemetry request, leading to denial of service.
AplazadaBaja (2.1)0.45%—Sourcecodester Safety Anger PADAI28/4/202617/6/2026
A vulnerability was found in SourceCodester Safety Anger Pad 1.0. The affected element is an unknown function. The manipulation of the argument angerDisplay results in cross site scripting. The attack may be performed from remote. The exploit has been made public and could be used.
AplazadaAlta (8.1)0.48%—Themepaste Admin Safety GuardAI19/3/202617/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Themepaste Admin Safety Guard admin-safety-guard allows Password Recovery Exploitation.This issue affects Admin Safety Guard: from n/a through <= 1.2.6.
AnalizadaMedia (5.1)0.35%—Etaplighting Etap Safety Manager30/12/202517/6/2026
ETAP Safety Manager 1.0.0.32 contains a cross-site scripting vulnerability in the 'action' GET parameter that allows unauthenticated attackers to inject malicious HTML and JavaScript. Attackers can craft specially formed requests to execute arbitrary scripts in victim browser sessions, potentially stealing credentials…
AnalizadaAlta (7.5)0.31%—Flocksafety License Plate Reader Firmware2/10/202517/6/2026
Flock Safety Falcon and Sparrow License Plate Readers OPM1.171019.026 ship with development Wi-Fi credentials (test_flck) stored in cleartext in production firmware.
AnalizadaCrítica (9.8)0.67%—Flocksafety Flock Safety2/10/202517/6/2026
The Flock Safety DetectionProcessing com.flocksafety.android.objects application 6.35.33 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) bundles a Java Keystore (flock_rye.bks) along with its hardcoded password (flockhibiki17) in its code. The keystore contains a…
AnalizadaMedia (6.2)0.17%—Flocksafety Flock Safety2/10/202517/6/2026
The Flock Safety Pisco com.flocksafety.android.pisco application 6.21.11 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) has a cleartext Auth0 client secret in its codebase. Because application binaries can be trivially decompiled or inspected, attackers can…
AnalizadaAlta (7.5)0.47%—Flocksafety Flock Safety2/10/202517/6/2026
The Flock Safety Peripheral com.flocksafety.android.peripheral application 7.38.3 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) contains a cleartext DataDog API key within in its codebase. Because application binaries can be trivially decompiled or inspected,…
ModificadaCrítica (9.8)1.1%—Flocksafety Flock Safety2/10/202517/6/2026
The Flock Safety Android Collins application (aka com.flocksafety.android.collins) 6.35.31 for Android lacks authentication. It is responsible for the camera feed on Falcon, Sparrow, and Bravo devices, but exposes administrative API endpoints on port 8080 without authentication. Endpoints include but are not limited…
AnalizadaAlta (7.3)0.25%—Flocksafety Bravo Compute BOX Firmware25/9/202517/6/2026
Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 ships with Secure Boot disabled. This allows an attacker to flash modified firmware with no cryptographic protections.
AnalizadaAlta (7.5)0.43%—Flocksafety Bravo Compute BOX Firmware25/9/202517/6/2026
Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 ships with its bootloader unlocked. This permits bypass of Android Verified Boot (AVB) and allows direct modification of partitions.
AnalizadaMedia (5.4)0.23%—Flocksafety Bravo Compute BOX Firmware25/9/202517/6/2026
Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 accepts the default Thundercomm TurboX 6490 Firehose loader in EDL/QDL mode. This enables attackers with physical access to flash arbitrary firmware, dump partitions, and bypass bootloader and OS security controls.
AplazadaMedia (5.9)0.22%—Tomas Cordero Safety ExitAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tomas Cordero Safety Exit safety-exit allows Stored XSS.This issue affects Safety Exit: from n/a through <= 1.8.0.
AplazadaAlta (8.5)0.18%—Siemens Simatic S7-plcsimAISiemens Simatic Step 7AISiemens Simatic WinccAISiemens Simocode ESAI+512/8/202517/6/2026
A vulnerability has been identified in SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 V17 (All versions < V17 Update 9), SIMATIC STEP 7 V18 (All versions), SIMATIC STEP 7 V19 (All versions < V19 Update 4), SIMATIC STEP 7 V20 (All versions < V20 Update 4), SIMATIC WinCC V17 (All versions < V17 Update 9), SIMATIC…
AplazadaAlta (8.6)0.17%—Siemens Simatic PCS NEOAISiemens Simatic S7-plcsimAISiemens Simatic Step 7AISiemens Simatic WinccAI+712/8/202517/6/2026
A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions < V6.0 SP1 Update 1), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 V17 (All versions < V17 Update 9), SIMATIC STEP 7 V18 (All versions), SIMATIC STEP 7 V19 (All…
AnalizadaBaja (2.4)0.15%—Flocksafety License Plate Reader Firmware27/6/202517/6/2026
Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have cleartext storage of code.
AnalizadaMedia (4.6)0.24%—Flocksafety License Plate Reader Firmware27/6/202517/6/2026
Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have a hardcoded password for a system.
AnalizadaMedia (6.8)0.25%—Flocksafety License Plate Reader Firmware27/6/202517/6/2026
Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have an on-chip debug interface with improper access control.
AnalizadaMedia (4.6)0.23%—Flocksafety Gunshot Detection Firmware27/6/202517/6/2026
Flock Safety Gunshot Detection devices before 1.3 have a hardcoded password for a system.
AnalizadaBaja (2.4)0.16%—Flocksafety Gunshot Detection Firmware27/6/202517/6/2026
Flock Safety Gunshot Detection devices before 1.3 have cleartext storage of code.
AnalizadaMedia (6.8)0.26%—Flocksafety Gunshot Detection Firmware27/6/202517/6/2026
Flock Safety Gunshot Detection devices before 1.3 have an on-chip debug interface with improper access control.
AnalizadaMedia (4.6)0.24%—Flocksafety Gunshot Detection Firmware27/6/202517/6/2026
Flock Safety Gunshot Detection devices before 1.3 have a hard-coded password for a connection.
AplazadaAlta (8.2)0.41%—Siemens Sirius 3rk3 Modular Safety SystemAISiemens Sirius 3sk2 Safety RelaysAI13/5/202517/6/2026
A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2 (All versions). The affected devices do not require authentication to access critical resources. An attacker with network access could retrieve sensitive information from certain data records,…
Orbitaley — Vulnerabilidades