Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1459 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.5) | 0.14% | — | Siemens TIA Administrator | 8/7/2025 | 17/6/2026 | A vulnerability has been identified in TIA Administrator (All versions < V3.0.6). The affected application allows low-privileged users to trigger installations by overwriting cache files and modifying the downloads path. This would allow an attacker to escalate privilege and exceute arbitrary code. | |
| Analizada | Media (6.9) | 0.07% | — | Siemens TIA Administrator | 8/7/2025 | 17/6/2026 | A vulnerability has been identified in TIA Administrator (All versions < V3.0.6). The affected application improperly validates code signing certificates. This could allow an attacker to bypass the check and exceute arbitrary code during installations. | |
| Aplazada | Media (6.1) | 0.25% | — | SAP Businessobjects Content Administrator WorkbenchAI | 8/7/2025 | 17/6/2026 | Due to insufficient sanitization in the SAP BusinessObjects Content Administrator Workbench, attackers could craft malicious URLs and execute scripts in a victim�s browser. This could potentially lead to the exposure or modification of web client data, resulting in low impact on confidentiality and integrity, with no… | |
| Analizada | Media (4.8) | 0.24% | — | Miniorange 2FA | 26/6/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.8.0, from 5.2.0 before 5.2.1, from 0.0.0 before 5.0.*, from 0.0.0 before 5.1.*. | |
| Analizada | Alta (8.2) | 0.25% | — | IBM Process Mining | 21/6/2025 | 17/6/2026 | IBM Process Mining 2.0.1 IF001 and 2.0.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that… | |
| Modificada | Crítica (9.4) | 3.4% | — | Edimax Ew-7438rpn Mini Firmware | 20/6/2025 | 17/6/2026 | An OS command injection vulnerability exists in the Edimax EW-7438RPn Mini firmware version 1.13 and prior via the syscmd.asp form handler. The /goform/formSysCmd endpoint exposes a system command interface through the sysCmd parameter. A remote authenticated attacker can submit arbitrary shell commands directly,… | |
| Modificada | Crítica (9.4) | 3.8% | — | Edimax Ew-7438rpn Mini Firmware | 20/6/2025 | 17/6/2026 | An OS command injection vulnerability exists in the Edimax EW-7438RPn firmware version 1.13 and prior via the mp.asp form handler. The /goform/mp endpoint improperly handles user-supplied input to the command parameter. An authenticated attacker can inject shell commands using shell metacharacters to achieve arbitrary… | |
| Analizada | Crítica (9.3) | 5.5% | — | Minidvblinux | 20/6/2025 | 17/6/2026 | An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system’s web-based management interface fails to properly sanitize user-supplied input before passing it to operating system commands. A remote unauthenticated attacker can exploit this vulnerability to execute arbitrary commands… | |
| Analizada | Media (5.9) | 0.37% | — | Heavenspell Minitcg | 18/6/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in miniTCG v1.3.1 beta allows attackers to execute abritrary web scripts or HTML via injecting a crafted payload into the id parameter at /members/edit.php. | |
| Aplazada | Alta (8.8) | 0.58% | — | Miniorange Password Policy ManagerAI | 9/6/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Password Policy Manager password-policy-manager allows Authentication Abuse.This issue affects Password Policy Manager: from n/a through <= 2.0.4. | |
| Aplazada | Alta (7.8) | 0.23% | — | Solarwinds Dameware Mini Remote ControlAI | 2/6/2025 | 17/6/2026 | The SolarWinds Dameware Mini Remote Control was determined to be affected by Incorrect Permissions Local Privilege Escalation Vulnerability. This vulnerability requires local access and a valid low privilege account to be susceptible to this vulnerability. | |
| Aplazada | Media (6.4) | 0.30% | — | Minimal Share ButtonsAI | 30/5/2025 | 17/6/2026 | The Minimal Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ parameter in all versions up to, and including, 1.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Alta (8.1) | 0.64% | — | Miniorange Discord IntegrationAI | 23/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in miniOrange miniOrange Discord Integration miniorange-discord-integration allows PHP Local File Inclusion.This issue affects miniOrange Discord Integration: from n/a through <= 2.2.2. | |
| Aplazada | Alta (8.1) | 0.64% | — | Miniorange Wordpress Social Login AND RegisterAI | 23/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in miniOrange WordPress Social Login and Register miniorange-login-openid allows PHP Local File Inclusion.This issue affects WordPress Social Login and Register: from n/a through <= 7.6.10. | |
| Aplazada | Alta (7) | 0.36% | — | Tibco Activematrix AdministratorAI | 21/5/2025 | 17/6/2026 | Stored XSS in TIBCO ActiveMatrix Administrator allows malicious data to appear to be part of the website and run within user's browser under the privileges of the web application. | |
| Analizada | Alta (7.4) | 0.37% | — | Miniorange 2FA | 14/5/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0. | |
| Analizada | Media (6.5) | 0.24% | — | Miniorange 2FA | 14/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Forceful Browsing.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0. | |
| Analizada | Alta (8.8) | 0.19% | — | Miniorange 2FA | 14/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Cross Site Request Forgery.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0. | |
| Analizada | Alta (7.5) | 0.41% | — | Miniorange 2FA | 14/5/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0. | |
| Analizada | Media (4.8) | 0.27% | — | Miniorange 2FA | 14/5/2025 | 17/6/2026 | Authentication Bypass by Capture-replay vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Remote Services with Stolen Credentials.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0. | |
| Aplazada | Media (5.4) | 0.14% | — | Intel Network Adapters Administrative ToolsAI | 13/5/2025 | 17/6/2026 | Race condition in some Administrative Tools for some Intel(R) Network Adapters package before version 29.4 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7) | 0.22% | — | Conda-forge MiniforgeConda-forge Openssl-feedstock | 13/5/2025 | 17/6/2026 | conda-forge openssl-feedstock before 066e83c (2024-05-20), on Microsoft Windows, configures OpenSSL to use an OPENSSLDIR file path that can be written to by non-privilged local users. By writing a specially crafted openssl.cnf file in OPENSSLDIR, a non-privileged local user can execute arbitrary code with the… | |
| Aplazada | Media (5.3) | 0.22% | — | ABB ANCAIABB Anc-lAIABB Anc-miniAI | 30/4/2025 | 17/6/2026 | : Use of GET Request Method With Sensitive Query Strings vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC: through 1.1.4; ANC-L: through 1.1.4; ANC-mini: through 1.1.4. | |
| Aplazada | Alta (8.5) | 0.25% | — | ABB ANCAIABB Anc-lAIABB Anc-miniAI | 30/4/2025 | 17/6/2026 | : Modification of Assumed-Immutable Data (MAID) vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC: through 1.1.4; ANC-L: through 1.1.4; ANC-mini: through 1.1.4. | |
| Aplazada | Media (6.5) | 0.26% | — | Oniswap Mini Twitter FeedAI | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in oniswap Mini twitter feed mini-twitter-feed allows Stored XSS.This issue affects Mini twitter feed: from n/a through <= 3.0. |