Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

610 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.43%—Pluginus Wordpress Currency Switcher Professional9/6/202317/6/2026
The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create function in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with subscriber-level permissions and above,…
ModificadaAlta (8.8)1.4%—WP User Switch Project WP User Switch6/6/202317/6/2026
The WP User Switch plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0.2. This is due to incorrect authentication checking in the 'wpus_allow_user_to_admin_bar_menu' function with the 'wpus_who_switch' cookie value. This makes it possible for authenticated attackers, with…
ModificadaCrítica (9.8)0.59%—Draytek MyvigorDraytek Vigorswitch Pq2200xb FirmwareDraytek Vigorswitch Pq2121x FirmwareDraytek Vigorswitch P2540xs Firmware+681/6/202317/6/2026
Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and Myvigor firmware versions below 2.3.2 were discovered to use hardcoded encryption keys which allows attackers to bind any affected device to their own account. Attackers…
ModificadaMedia (6.1)0.38%—Fugu Maintenance Switch10/5/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Fugu Maintenance Switch plugin <= 1.5.2 versions.
ModificadaCrítica (9.8)0.71%—Home.cern White Rabbit Switch Firmware24/4/202317/6/2026
White Rabbit Switch contains a vulnerability which makes it possible for an attacker to perform system commands under the context of the web application (the default installation makes the webserver run as the root user).
ModificadaAlta (7.5)0.75%—Home.cern White Rabbit Switch Firmware24/4/202317/6/2026
Within White Rabbit Switch it's possible as an unauthenticated user to retrieve sensitive information such as password hashes and the SNMP community strings.
ModificadaAlta (8.2)1.2%—Cloudbase Open VswitchDebian LinuxRedhat Openshift Container PlatformRedhat Openstack Platform+210/4/202317/6/2026
A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nw_proto is wildcarded) for this flow,…
ModificadaMedia (6.5)0.47%—Fortinet FortianalyzerFortinet FortimanagerFortinet FortiportalFortinet Fortiswitch7/3/202317/6/2026
A exposure of sensitive information to an unauthorized actor in Fortinet FortiManager version 6.0.0 through 6.0.4, FortiAnalyzer version 6.0.0 through 6.0.4, FortiPortal version 6.0.0 through 6.0.9, 5.3.0 through 5.3.8, 5.2.x, 5.1.0, 5.0.x, 4.2.x, 4.1.x, FortiSwitch version 7.0.0 through 7.0.4, 6.4.0 through 6.4.10,…
ModificadaAlta (7.5)1.1%—Hitachienergy Sys600 FirmwareHitachienergy Rtu500 FirmwareHitachienergy Reb500 FirmwareHitachienergy Pwc600 Firmware+921/2/202317/6/2026
A vulnerability exists in the IEC 61850 communication stack that affects multiple Hitachi Energy products. An attacker could exploit the vulnerability by using a specially crafted message sequence, to force the IEC 61850 MMS-server communication stack, to stop accepting new MMS-client connections. Already…
ModificadaAlta (8.1)0.93%—Fortinet FortiswitchmanagerFortinet FortiproxyFortinet Fortios16/2/202317/6/2026
A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.10, FortiProxy version 7.2.0 through 7.2.1, 7.0.0 through 7.0.7 and before 2.0.10, FortiSwitchManager 7.2.0 and before 7.0.0 allows an authenticated attacker to read and write files on…
ModificadaMedia (4.3)0.29%—Fortinet FortiproxyFortinet FortiwebFortinet FortiosFortinet Fortiswitch16/2/202317/6/2026
An improper verification of cryptographic signature vulnerability [CWE-347] in FortiWeb 6.4 all versions, 6.3.16 and below, 6.2 all versions, 6.1 all versions, 6.0 all versions; FortiOS 7.0.3 and below, 6.4.8 and below, 6.2 all versions, 6.0 all versions; FortiSwitch 7.0.3 and below, 6.4.10 and below, 6.2 all…
ModificadaAlta (7.5)0.54%—Switcherapi Switcher Client3/2/202317/6/2026
Switcher Client is a JavaScript SDK to work with Switcher API which is cloud-based Feature Flag. Unsanitized input flows into Strategy match operation (EXIST), where it is used to build a regular expression. This may result in a Regular expression Denial of Service attack (reDOS). This issue has been patched in…
ModificadaCrítica (9.8)39%💥 ExploitWp-buy Login AS User OR Customer (user Switching)23/1/202317/6/2026
The Login as User or Customer WordPress plugin before 3.3 lacks authorization checks to ensure that users are allowed to log in as another one, which could allow unauthenticated attackers to obtain a valid admin session.
ModificadaMedia (5.4)0.50%—Pluginus FOX - Currency Switcher Professional FOR Woocommerce16/1/202317/6/2026
The WOOCS WordPress plugin before 1.3.9.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
ModificadaCrítica (9.8)1.3%—OpenvswitchDebian Linux10/1/202317/6/2026
An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch.
ModificadaCrítica (9.8)1.3%—OpenvswitchDebian Linux10/1/202317/6/2026
An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.
ModificadaMedia (6.1)0.64%—Webdevstudios Taxonomy Switcher5/1/202317/6/2026
A vulnerability was found in WebDevStudios taxonomy-switcher Plugin up to 1.0.3 on WordPress. It has been classified as problematic. Affected is the function taxonomy_switcher_init of the file taxonomy-switcher.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading…
ModificadaAlta (7.5)1.8%—HP Officeconnect 1820 24G Poe+ (185w) Switch J9983a FirmwareHP Officeconnect 1820 48G Poe+ (370w) Switch J9984a FirmwareHP Officeconnect 1820 8G Poe+ (65w) Switch J9982a FirmwareHP Officeconnect 1820 8G Switch J9979a Firmware+65/1/202317/6/2026
A potential security vulnerability has been identified in HPE OfficeConnect 1820, and 1850 switch series. The vulnerability could be remotely exploited to allow remote directory traversal in HPE OfficeConnect 1820 switch series version PT.02.17 and below, HPE OfficeConnect 1850 switch series version PC.01.23 and…
ModificadaCrítica (9.8)23%—Nintendo Animal Crossing\Nintendo ArmsNintendo Mario Kart 7Nintendo Mario Kart 8+524/12/202217/6/2026
The Nintendo NetworkBuffer class, as used in Animal Crossing: New Horizons before 2.0.6 and other products, allows remote attackers to execute arbitrary code via a large UDP packet that causes a buffer overflow, aka ENLBufferPwn. The victim must join a game session with the attacker. Other affected products include…
ModificadaMedia (6.5)0.36%—Addify Automatic User Roles Switcher31/10/202217/6/2026
The Automatic User Roles Switcher WordPress plugin before 1.1.2 does not have authorisation and proper CSRF checks, allowing any authenticated users like subscriber to add any role to themselves, such as administrator
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitFortinet FortiproxyFortinet FortiswitchmanagerFortinet Fortios18/10/20226/8/2026
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the…
ModificadaAlta (7.8)0.17%—AsusswitchAsus System Control Interface18/10/202217/6/2026
AsusSwitch.exe on ASUS personal computers (running Windows) sets weak file permissions, leading to local privilege escalation (this also can be used to delete files within the system arbitrarily). This affects ASUS System Control Interface 3 before 3.1.5.0, and AsusSwitch.exe before 1.0.10.0.
ModificadaMedia (6.1)0.61%—Cloudbase Open VswitchDebian Linux28/9/202217/6/2026
In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minimasks” function could lead access to an unmapped region of memory. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.
ModificadaMedia (4.3)0.31%—Sedlex Favicon-switcher21/9/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in SedLex FavIcon Switcher plugin <= 1.2.11 at WordPress allows plugin settings change.
ModificadaMedia (4.8)0.60%—Woobewoo WBW Currency Switcher FOR Woocommerce16/9/202217/6/2026
The WBW Currency Switcher for WooCommerce WordPress plugin before 1.6.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)