Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
396 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.8% | — | Illumina Local RUN Manager | 24/6/2022 | 17/6/2026 | LRM utilizes elevated privileges. An unauthenticated malicious actor can upload and execute code remotely at the operating system level, which can allow an attacker to change settings, configurations, software, or access sensitive data on the affected produc. An attacker could also exploit this vulnerability to access… | |
| Modificada | Media (6.1) | 0.46% | — | Arista TerminattrArista EOS | 26/5/2022 | 17/6/2026 | This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig transport protocols. The impact of this vulnerability is that, in certain conditions, TerminAttr might leak MACsec sensitive data in clear text in CVP to other authorized… | |
| Modificada | Media (6.1) | 0.51% | — | Arista TerminattrArista EOS | 26/5/2022 | 17/6/2026 | This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig transport protocols. The impact of this vulnerability is that, in certain conditions, TerminAttr might leak IPsec sensitive data in clear text in CVP to other authorized… | |
| Modificada | Media (6.1) | 1.0% | — | Terminalfour | 16/5/2022 | 17/6/2026 | Terminalfour versions 8.3.7, 8.3.x versions prior to version 8.3.8 and r 8.2.x versions prior to version 8.2.18.5 or 8.2.18.2.1 are vulnerable to (XSS) vulnerability that could be exploited by an attacker to mislead an administrator and steal their credentials. | |
| Modificada | Media (6.1) | 0.99% | — | Getlaminas Laminas-formFedoraproject Fedora | 28/1/2022 | 17/6/2026 | laminas-form is a package for validating and displaying simple and complex forms. When rendering validation error messages via the `formElementErrors()` view helper shipped with laminas-form, many messages will contain the submitted value. However, in laminas-form prior to version 3.1.1, the value was not being… | |
| Modificada | Crítica (9.8) | 1.6% | — | Projectworlds Online Examination System | 21/1/2022 | 17/6/2026 | An SQL Injection vulnerability exists in Projectworlds Online Examination System 1.0 via the eid parameter in account.php. | |
| Modificada | Alta (7.8) | 0.84% | — | Arista Terminattr | 14/1/2022 | 17/6/2026 | An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration. | |
| Modificada | Crítica (9) | 0.45% | — | SUN Moon Jingyao Network Computer Terminal Protection System Firmware | 3/1/2022 | 17/6/2026 | The server-request receiver function of Shockwall system has an improper authentication vulnerability. An authenticated attacker of an agent computer within the local area network can use the local registry information to launch server-side request forgery (SSRF) attack on another agent computer, resulting in… | |
| Modificada | Media (5.4) | 1.0% | — | Jquery.terminal Project Jquery.terminal | 30/12/2021 | 17/6/2026 | jQuery Terminal Emulator is a plugin for creating command line interpreters in your applications. Versions prior to 2.31.1 contain a low impact and limited cross-site scripting (XSS) vulnerability. The code for XSS payload is always visible, but an attacker can use other techniques to hide the code the victim sees. If… | |
| Modificada | Alta (8.8) | 1.3% | — | SSH & WEB Terminal Project SSH & WEB Terminal | 16/12/2021 | 17/6/2026 | The addon.stdin service in addon-ssh (aka Home Assistant Community Add-on: SSH & Web Terminal) before 10.0.0 has an attack surface that requires social engineering. NOTE: the vendor does not agree that this is a vulnerability; however, addon.stdin was removed as a defense-in-depth measure against complex social… | |
| Modificada | Media (4.8) | 0.62% | — | Incsub Forminator | 23/11/2021 | 17/6/2026 | The Forminator WordPress plugin before 1.15.4 does not sanitize and escape the email field label, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed | |
| Modificada | Media (6.5) | 4.6% | — | Apache MinaOracle Banking PaymentsOracle Banking Trade Finance Process ManagementOracle Banking Treasury Management+5 | 1/11/2021 | 17/6/2026 | In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update MINA to 2.1.5 or greater. | |
| Modificada | Alta (7.3) | 0.43% | — | Ecoa ECS Router Controller-ecs FirmwareEcoa Riskbuster FirmwareEcoa Riskterminator | 30/9/2021 | 17/6/2026 | ECOA BAS controller stores sensitive data (backup exports) in clear-text, thus the unauthenticated attacker can remotely query user password and obtain user’s privilege. | |
| Modificada | Crítica (9.8) | 2.0% | — | Ecoa ECS Router Controller-ecs FirmwareEcoa Riskbuster FirmwareEcoa Riskterminator | 30/9/2021 | 17/6/2026 | ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GET request. This will enable the unauthenticated attacker to remotely disclose sensitive information and help her in authentication bypass, privilege escalation and full system access. | |
| Modificada | Crítica (9.8) | 0.98% | — | Ecoa ECS Router Controller-ecs FirmwareEcoa Riskbuster FirmwareEcoa Riskterminator | 30/9/2021 | 17/6/2026 | ECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can access the page and obtain privilege with full functionality. | |
| Modificada | Crítica (9.8) | 2.1% | — | Ecoa ECS Router Controller-ecs FirmwareEcoa Riskbuster FirmwareEcoa Riskterminator | 30/9/2021 | 17/6/2026 | ECOA BAS controller is vulnerable to hard-coded credentials within its Linux distribution image, thus remote attackers can obtain administrator’s privilege without logging in. | |
| Modificada | Alta (8.8) | 0.87% | — | Ecoa ECS Router Controller-ecs FirmwareEcoa Riskbuster FirmwareEcoa Riskterminator | 30/9/2021 | 17/6/2026 | ECOA BAS controller is vulnerable to insecure direct object references that occur when the application provides direct access to objects based on user-supplied input. As a result of this vulnerability, attackers with general user's privilege can remotely bypass authorization and access the hidden resources in the… | |
| Modificada | Alta (8.8) | 0.74% | — | Ecoa ECS Router Controller-ecs FirmwareEcoa Riskbuster FirmwareEcoa Riskterminator | 30/9/2021 | 17/6/2026 | ECOA BAS controller is vulnerable to weak access control mechanism allowing authenticated user to remotely escalate privileges by disclosing credentials of administrative accounts in plain-text. | |
| Modificada | Crítica (9.8) | 0.95% | — | Ecoa ECS Router Controller-ecs FirmwareEcoa Riskbuster FirmwareEcoa Riskterminator | 30/9/2021 | 17/6/2026 | ECOA BAS controller uses weak set of default administrative credentials that can be easily guessed in remote password attacks and gain full control of the system. | |
| Modificada | Alta (8.8) | 0.43% | — | Ecoa ECS Router Controller-ecs FirmwareEcoa Riskbuster FirmwareEcoa Riskterminator | 30/9/2021 | 17/6/2026 | ECOA BAS controller has a Cross-Site Request Forgery vulnerability, thus authenticated attacker can remotely place a forged request at a malicious web page and execute CRUD commands (GET, POST, PUT, DELETE) to perform arbitrary operations in the system. | |
| Modificada | Crítica (9.1) | 1.2% | — | Ecoa ECS Router Controller-ecs FirmwareEcoa Riskbuster FirmwareEcoa Riskterminator | 30/9/2021 | 17/6/2026 | ECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files deletion. Using the specific GET parameter, unauthenticated attackers can remotely delete arbitrary files on the affected device and cause denial of service scenario. | |
| Modificada | Alta (7.5) | 20% | 💥 Exploit | Ecoa ECS Router Controller-ecs FirmwareEcoa Riskbuster FirmwareEcoa Riskterminator | 30/9/2021 | 17/6/2026 | ECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files disclosure. Using the specific POST parameter, unauthenticated attackers can remotely disclose arbitrary files on the affected device and disclose sensitive and system information. | |
| Modificada | Crítica (9.1) | 1.2% | — | Ecoa ECS Router Controller-ecs FirmwareEcoa Riskbuster FirmwareEcoa Riskterminator | 30/9/2021 | 17/6/2026 | ECOA BAS controller suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie poisoning can remotely bypass authentication and disclose sensitive information and circumvent physical access controls in smart homes and buildings and manipulate HVAC. | |
| Modificada | Alta (7.5) | 83% | 💥 Exploit | Ecoa ECS Router Controller-ecs FirmwareEcoa Riskbuster FirmwareEcoa Riskterminator | 30/9/2021 | 17/6/2026 | ECOA BAS controller suffers from a path traversal content disclosure vulnerability. Using the GET parameter in File Manager, unauthenticated attackers can remotely disclose directory content on the affected device. | |
| Modificada | Crítica (9.8) | 2.3% | — | Ecoa ECS Router Controller-ecs FirmwareEcoa Riskbuster FirmwareEcoa Riskterminator | 30/9/2021 | 17/6/2026 | ECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability. Using the POST parameters, unauthenticated attackers can remotely set arbitrary values for location and content type and gain the possibility to execute arbitrary code on the affected device. |