Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
26 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 1.2% | — | Chengdu Feiyuxing Technology Feiyu Star Router B-mb5e202AI | 21/9/2026 | 22/9/2026 | A weakness has been identified in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. Affected is an unknown function of the file /send_order.cgi?parameter=loginout of the component Cookie Handler. This manipulation of the argument session_id causes command injection. Remote exploitation of the… | |
| Aplazada | Baja (2) | 2.1% | — | Chengdu Feiyuxing Technology Feiyu Star Router B-mb5e202-210322-r11656AI | 21/9/2026 | 21/9/2026 | A security flaw has been discovered in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. This impacts an unknown function of the file /send_order.cgi?parameter=del_expmac. The manipulation of the argument mac results in command injection. The attack may be launched remotely. The exploit has been… | |
| Aplazada | Crítica (9.3) | 0.52% | — | Xing Cptrans-me-xAI | 4/9/2026 | 8/9/2026 | XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the credential may log in to the affected device. | |
| Aplazada | Crítica (9.3) | 0.52% | — | Xing Cptrans-me-xAI | 4/9/2026 | 8/9/2026 | XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the credential may log in to the affected device. | |
| Aplazada | Alta (8.7) | 0.44% | — | Xing Cptrans-me-xAI | 4/9/2026 | 8/9/2026 | XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497). Sensitive system information may be leaked. | |
| Aplazada | Crítica (9.3) | 2.0% | — | Xing Cptrans-me-xAI | 4/9/2026 | 8/9/2026 | XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected. | |
| Aplazada | Crítica (9.8) | 0.43% | — | Zuoxingdong LagomAI | 17/6/2026 | 6/10/2026 | Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection. This issue affects Lagom: from n/a through 2.0. | |
| Aplazada | Baja (1.9) | 0.38% | — | Xingfuggz BaykeshopAI | 23/2/2026 | 17/6/2026 | A security vulnerability has been detected in xingfuggz BaykeShop up to 1.3.20. Impacted is an unknown function of the file src/baykeshop/contrib/article/templates/baykeshop/sidebar/custom.html of the component Article Sidebar Module. Such manipulation of the argument sidebar.content leads to cross site scripting. The… | |
| Analizada | Alta (7.5) | 0.57% | — | Axing Dev7113 Firmware | 26/12/2025 | 17/6/2026 | Incorrect access control in DEV Systemtechnik GmbH DEV 7113 RF over Fiber Distribution System 32-0078 H.01 allows unauthenticated attackers to access an administrative endpoint. | |
| Aplazada | Baja (2.1) | 0.31% | — | Guanxinglu VlarlAIZeromqAI | 25/9/2025 | 17/6/2026 | A vulnerability was found in GuanxingLu vlarl up to 31abc0baf53ef8f5db666a1c882e1ea64def2997. This vulnerability affects the function experiments.robot.bridge.reasoning_server::run_reasoning_server of the file experiments/robot/bridge/reasoning_server.py of the component ZeroMQ. Performing manipulation of the argument… | |
| Analizada | Alta (7.5) | 0.38% | — | Zykzhangyukang Xinguan | 5/5/2025 | 17/6/2026 | Incorrect access control in the /system/user/findUserList API of Xinguan v0.0.1-SNAPSHOT allows attackers to access sensitive information via a crafted payload. | |
| Aplazada | Crítica (9.8) | 0.76% | — | Wanxing Technology Yitu Project Management Kirin EditionAI | 15/10/2024 | 17/6/2026 | An issue in Wanxing Technology Yitu Project Management Kirin Edition 2.3.6 allows a remote attacker to execute arbitrary code via a specially constructed so file/opt/EdrawProj-2/plugins/imageformat. | |
| Aplazada | Crítica (9.8) | 0.81% | — | Wanxing Technology Yitu Project Management SoftwareAI | 15/10/2024 | 17/6/2026 | An issue in Wanxing Technology's Yitu project Management Software 3.2.2 allows a remote attacker to execute arbitrary code via the platformpluginpath parameter to specify that the qt plugin loads the directory. | |
| Aplazada | Crítica (9.1) | 0.37% | — | Renwoxing Enterprise Intelligent Management SystemAI | 10/9/2024 | 17/6/2026 | Renwoxing Enterprise Intelligent Management System before v3.0 was discovered to contain a SQL injection vulnerability via the parid parameter at /fx/baseinfo/SearchInfo. | |
| Aplazada | Alta (8) | 0.54% | — | Shenzhen Haichangxing Technology HCX H822 4G LTE RouterAI | 10/9/2024 | 5/7/2026 | Shenzhen Haichangxing Technology Co., Ltd HCX H822 4G LTE Router M7628NNxISPxUIv2_v1.0.1557.15.35_P0 is vulnerable to Incorrect Access Control. Unauthenticated factory mode reset and command injection leads to information exposure and root shell access. | |
| Aplazada | Crítica (9.8) | 0.61% | — | Tongtianxing Technology CO LTD Cmsv6AI | 29/3/2024 | 17/6/2026 | SQL Injection vulnerability in Tongtianxing Technology Co., Ltd CMSV6 v.7.31.0.2 through v.7.31.0.3 allows a remote attacker to escalate privileges and obtain sensitive information via the ids parameter. | |
| Analizada | Media (6.6) | 0.31% | — | Zuoxingdong Lagom | 21/3/2024 | 17/6/2026 | An issue in zuoxingdong lagom v.0.1.2 allows a local attacker to execute arbitrary code via the pickle_load function of the serialize.py file. | |
| Modificada | Crítica (9.8) | 0.71% | — | Ontall Longxing Industrial Development Zone Project | 27/10/2023 | 17/6/2026 | A vulnerability was found in Nanning Ontall Longxing Industrial Development Zone Project Construction and Installation Management System up to 20231026. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file login.aspx. The manipulation of the argument tbxUserName… | |
| Modificada | Alta (7.5) | 19% | — | Feiyuxing Vec40g Firmware | 12/6/2023 | 17/6/2026 | A vulnerability classified as problematic was found in Chengdu VEC40G 3.0. Affected by this vulnerability is an unknown functionality of the file /send_order.cgi?parameter=restart. The manipulation of the argument restart with the input reboot leads to denial of service. The attack can be launched remotely. The… | |
| Modificada | Alta (7.2) | 34% | — | Feiyuxing Vec40g Firmware | 4/5/2023 | 17/6/2026 | A vulnerability was found in Chengdu VEC40G 3.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /send_order.cgi?parameter=access_detect of the component Network Detection. The manipulation of the argument COUNT with the input 3 | netstat -an leads to os command… | |
| Modificada | Media (5.4) | 0.60% | — | Kluks Xingwall | 6/1/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in kassi xingwall. This issue affects some unknown processing of the file app/controllers/oauth.js. The manipulation leads to session fixiation. The patch is named e9f0d509e1408743048e29d9c099d36e0e1f6ae7. It is recommended to apply a patch to fix this… | |
| Modificada | Media (4.3) | 1.1% | — | Peter Proell Xing | 7/10/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the XING Button (xing) extension before 1.0.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (10) | 97% | 💥 Exploit | Microsoft Index ServerMicrosoft Indexing ServiceMicrosoft Internet Information Server | 21/7/2001 | 16/6/2026 | Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to execute arbitrary commands via a long argument to Internet Data Administration (.ida) and Internet Data Query (.idq) files such as default.ida, as commonly exploited by Code… | |
| Modificada | Media (5) | 14% | — | Microsoft Index ServerMicrosoft Indexing Service | 27/6/2001 | 16/6/2026 | Microsoft Index Server 2.0 in Windows NT 4.0, and Indexing Service in Windows 2000, allows remote attackers to read server-side include files via a malformed search request, aka a new variant of the "Malformed Hit-Highlighting" vulnerability. | |
| Modificada | Media (4.3) | 11% | 💥 Exploit | Microsoft Indexing Service | 9/1/2001 | 16/6/2026 | The ixsso.query ActiveX Object is marked as safe for scripting, which allows malicious web site operators to embed a script that remotely determines the existence of files on visiting Windows 2000 systems that have Indexing Services enabled. |