Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

374 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.21%—Amazon Aws-sigv419/4/202317/6/2026
aws-sigv4 is a rust library for low level request signing in the aws cloud platform. The `aws_sigv4::SigningParams` struct had a derived `Debug` implementation. When debug-formatted, it would include a user's AWS access key, AWS secret key, and security token in plaintext. When TRACE-level logging is enabled for an…
ModificadaAlta (8.8)0.79%—Gnome Gvariant Database26/12/202217/6/2026
A vulnerability was found in GNOME gvdb. It has been classified as critical. This affects the function gvdb_table_write_contents_async of the file gvdb-builder.c. The manipulation leads to use after free. It is possible to initiate the attack remotely. The name of the patch is d83587b2a364eb9a9a53be7e6a708074e252de14.…
ModificadaAlta (7.5)1.3%—Enumstringvalues Project Enumstringvalues21/12/202217/6/2026
A vulnerability was found in Brondahl EnumStringValues up to 4.0.0. It has been declared as problematic. This vulnerability affects the function GetStringValuesWithPreferences_Uncache of the file EnumStringValues/EnumExtensions.cs. The manipulation leads to resource consumption. Upgrading to version 4.0.1 is able to…
ModificadaAlta (8.8)0.66%—Gvectors Wpdiscuz18/11/202217/6/2026
Auth. (subscriber+) Insecure Direct Object References (IDOR) vulnerability in Comments – wpDiscuz plugin 7.4.2 on WordPress.
ModificadaAlta (8.8)0.96%—Gvectors Wpforo Forum17/11/202217/6/2026
Auth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.
ModificadaAlta (8.8)0.47%—Gvectors Wpforo Forum17/11/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.
ModificadaAlta (8.1)1.1%—Nagvis13/11/202217/6/2026
A vulnerability was found in NagVis up to 1.9.33 and classified as problematic. This issue affects the function checkAuthCookie of the file share/server/core/classes/CoreLogonMultisite.php. The manipulation of the argument hash leads to incorrect type conversion. The attack may be initiated remotely. The complexity of…
ModificadaCrítica (9.8)0.97%—Mitsubishielectric Mac-557if-e FirmwareMitsubishielectric Mac-557if-e1 FirmwareMitsubishielectric Pac-wf010-e FirmwareMitsubishielectric Mac-566ifb-e Firmware+1748/11/202217/6/2026
Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Electric consumer electronics products (PHOTOVOLTAIC COLOR MONITOR ECO-GUIDE, HEMS adapter, Wi-Fi Interface, Air Conditioning, Induction hob, Mitsubishi Electric HEMS Energy…
ModificadaMedia (5.4)0.28%—Gvectors Wpforo Forum8/11/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 on WordPress leading to topic deletion.
ModificadaMedia (4.3)0.50%—Gvectors Wpforo Forum8/11/202217/6/2026
Insecure direct object references (IDOR) vulnerability in the wpForo Forum plugin <= 2.0.5 on WordPress allows attackers with subscriber or higher user roles to mark any forum post as private/public.
ModificadaMedia (4.3)0.53%—Gvectors Wpforo Forum8/11/202217/6/2026
Insecure direct object references (IDOR) vulnerability in the wpForo Forum plugin <= 2.0.5 on WordPress allows attackers with subscriber or higher user roles to mark any forum post as solved/unsolved.
ModificadaMedia (4.8)0.68%—Dsgvo-for-wp Dsgvo ALL IN ONE FOR WP3/10/202217/6/2026
The DSGVO All in one for WP WordPress plugin before 4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaCrítica (9.1)0.77%—ZTE Zxa10 B76hv3 FirmwareZTE Zxa10 B766v2 FirmwareZTE Zxa10 B800v2 FirmwareZTE Zxa10 B860av2.1 Firmware+1123/9/202217/6/2026
There is a broken access control vulnerability in ZTE ZXvSTB product. Due to improper permission control, attackers could use this vulnerability to delete the default application type, which affects normal use of system.
ModificadaAlta (8.8)0.51%—Gvectors Wpforo Forum9/9/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 at WordPress.
ModificadaAlta (7.8)0.41%—Gvim30/8/202217/6/2026
An issue in the installer of gvim 9.0.0000 allows authenticated attackers to execute arbitrary code via a binary hijacking attack on C:\Program.exe.
ModificadaCrítica (9.8)0.85%—Mitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data TransferMitsubishielectric EM Configurator+2519/5/202217/6/2026
Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software Products of various versions could allow an attacker to escalate privilege and execute malicious programs, which could cause a denial-of-service condition, and allow information to be disclosed,…
ModificadaAlta (7.5)1.1%—Gvectors Wpdiscuz21/2/202217/6/2026
Sensitive information disclosure discovered in wpDiscuz WordPress plugin (versions <= 7.3.11).
ModificadaCrítica (9.8)1.3%—Mitsubishielectric C Controller Interface Module UtilityMitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric Cc-link IE Control Network Data CollectorMitsubishielectric Cc-link IE Field Network Data Collector+4211/2/202217/6/2026
Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition.
ModificadaCrítica (9.8)3.7%—Dlink Di-7200gv2 Firmware4/2/202217/6/2026
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function msp_info.htm. This vulnerability allows attackers to execute arbitrary commands via the cmd parameter.
ModificadaCrítica (9.8)3.7%—Dlink Di-7200gv2 Firmware4/2/202217/6/2026
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function version_upgrade.asp. This vulnerability allows attackers to execute arbitrary commands via the path parameter.
ModificadaCrítica (9.8)3.7%—Dlink Di-7200gv2 Firmware4/2/202217/6/2026
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function urlrd_opt.asp. This vulnerability allows attackers to execute arbitrary commands via the url_en parameter.
ModificadaCrítica (9.8)3.7%—Dlink Di-7200gv2 Firmware4/2/202217/6/2026
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function upgrade_filter. This vulnerability allows attackers to execute arbitrary commands via the path and time parameters.
ModificadaCrítica (9.8)4.4%—Dlink Di-7200gv2 Firmware4/2/202217/6/2026
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function usb_paswd.asp. This vulnerability allows attackers to execute arbitrary commands via the name parameter.
ModificadaCrítica (9.8)3.7%—Dlink Di-7200gv2 Firmware4/2/202217/6/2026
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function httpd_debug.asp. This vulnerability allows attackers to execute arbitrary commands via the time parameter.
ModificadaCrítica (9.8)4.7%—Dlink Di-7200gv2 Firmware4/2/202217/6/2026
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function proxy_client.asp. This vulnerability allows attackers to execute arbitrary commands via the proxy_srv, proxy_srvport, proxy_lanip, proxy_lanport parameters.