Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1920 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.17% | — | Bitdefender AntivirusBitdefender Antivirus PlusBitdefender Endpoint Security ToolsBitdefender Internet Security+1 | 10/12/2025 | 17/6/2026 | A local privilege escalation vulnerability in Bitdefender Total Security versions prior to 27.0.47.241 allows low-privileged attackers to elevate privileges. The issue arises from bdservicehost.exe deleting files from a user-writable directory (C:\ProgramData\Atc\Feedback) without proper symbolic link validation,… | |
| Aplazada | Media (5.5) | 0.30% | — | Chanjet TplusAI | 7/12/2025 | 17/6/2026 | A flaw has been found in Chanjet TPlus up to 20251121. Affected by this vulnerability is an unknown functionality of the file /tplus/ajaxpro/Ufida.T.SM.UIP.MultiCompanySettingController,Ufida.T.SM.UIP.ashx?method=Load. This manipulation of the argument currentAccId causes sql injection. It is possible to initiate the… | |
| Aplazada | Alta (8.8) | 0.55% | — | Kraftplugins Demo Importer PlusAI | 5/12/2025 | 25/9/2026 | The Demo Importer Plus plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2.0.6. This is due to insufficient file type validation detecting WXR files, allowing double extension files to bypass sanitization while being accepted as a valid WXR file. This makes it possible… | |
| Analizada | Media (5.3) | 0.24% | — | Compassplustechnologies Tranzaxis | 4/12/2025 | 17/6/2026 | TranzAxis 3.2.41.10.26 allows authenticated users to inject cross-site scripting via the `Open Object in Tree` endpoint, allowing attackers to steal session cookies and potentially escalate privileges. | |
| Analizada | Media (6.5) | 0.35% | 💥 PoC | Edupluscampus | 4/12/2025 | 17/6/2026 | An Insecure Direct Object Reference (IDOR) vulnerability in the EduplusCampus 3.0.1 Student Payment API allows authenticated users to access other students personal and financial records by modifying the 'rec_no' parameter in the /student/get-receipt endpoint. | |
| Analizada | Media (6.5) | 0.16% | — | Magewell Ultra Encode Hdmi FirmwareMagewell Ultra Encode SDI FirmwareMagewell Ultra Encode Hdmi Plus FirmwareMagewell Ultra Encode SDI Plus Firmware+1 | 24/11/2025 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the /usapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request. | |
| Analizada | Media (5.7) | 0.16% | — | Magewell PRO Convert Hdmi 4K Plus FirmwareMagewell PRO Convert Hdmi Plus FirmwareMagewell PRO Convert Hdmi TX FirmwareMagewell PRO Convert 12G SDI 4K Plus Firmware+9 | 24/11/2025 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request. | |
| Analizada | Media (5.1) | 0.28% | — | Iest Winplus | 18/11/2025 | 17/6/2026 | Stored Cross-site Scripting (XSS)vylnerability type in WinPlus v24.11.27 byInformática del Este that consist of an stored XSS of a stored XSS due to a lack of proper validation of user input by sending a POST request using the 'descripcion' parameter in '/WinplusPortal/ws/sWinplus.svc/json/savesoldoc_post'. This… | |
| Analizada | Media (5.1) | 0.35% | — | Iest Winplus | 18/11/2025 | 17/6/2026 | Stored Cross-site Scripting (XSS)vylnerability type in WinPlus v24.11.27 byInformática del Este that consist of an stored XSS of a stored XSS due to a lack of proper validation of user input by sending a POST request using the 'descripcion' parameter in '/WinplusPortal/ws/sWinplus. svc/json/savesolpla_post'. This… | |
| Analizada | Alta (8.7) | 0.54% | — | Iest Winplus | 18/11/2025 | 17/6/2026 | SQL injection vulnerability in WinPlus v24.11.27 by Informática del Este. This vulnerability allows an attacker recover, create, update an delete databases by sendng a POST request using the parameters 'val1' and 'cont in '/WinplusPortal/ws/sWinplus.svc/json/getacumper_post'. | |
| Analizada | Alta (8.7) | 0.34% | — | Iest Winplus | 18/11/2025 | 17/6/2026 | Unlimited upload vulnerability for dangerous file types in WinPlus v24.11.27 from Informática del Este. This vulnerability allows an attacker to upload a 'webshell' by sending a POST request to '/WinplusPortal/ws/sWinplus.svc/json/uploadfile'. | |
| Analizada | Crítica (9.3) | 0.32% | — | Iest Winplus | 18/11/2025 | 17/6/2026 | Faulty authorization control in software WinPlus v24.11.27 by Informática del Este that allows another user to be impersonated simply by knowing their 'numerical ID', meaning that an attacker could compromise another user's account, thereby affecting the confidentiality, integrity, and availability of the data stored… | |
| Analizada | Alta (7.5) | 0.31% | — | Zyxel Lte3301-plus FirmwareZyxel Nr5103 FirmwareZyxel Nr5103e FirmwareZyxel Nr5309 Firmware+62 | 18/11/2025 | 17/6/2026 | An uncontrolled resource consumption vulnerability in the web server of Zyxel DX3301-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could allow an attacker to perform Slowloris‑style denial‑of‑service (DoS) attacks. Such attacks may temporarily block legitimate HTTP requests and partially disrupt access to the web… | |
| Aplazada | Alta (8.8) | 0.27% | — | Dell Controlvault3AIDell Controlvault3 PlusAI | 17/11/2025 | 17/6/2026 | A buffer overflow vulnerability exists in the CvManager functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted ControlVault API call can lead to memory corruption. An attacker can issue an api call to trigger this vulnerability. | |
| Aplazada | Alta (7.3) | 0.16% | — | Dell Controlvault3AIDell Controlvault3 PlusAI | 17/11/2025 | 17/6/2026 | Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to memory corruption. An attacker can issue an… | |
| Aplazada | Alta (7.3) | 0.14% | — | Dell Controlvault3AIDell Controlvault3 PlusAI | 17/11/2025 | 17/6/2026 | Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to memory corruption. An attacker can issue an… | |
| Aplazada | Alta (7.3) | 0.14% | — | Dell Controlvault3AIDell Controlvault3 PlusAIBroadcom Storage AdapterAI | 17/11/2025 | 17/6/2026 | Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to memory corruption. An attacker can issue an… | |
| Aplazada | Alta (7.3) | 0.16% | — | Dell Controlvault3AIDell Controlvault3 PlusAIBroadcom Storage AdapterAI | 17/11/2025 | 17/6/2026 | Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to memory corruption. An attacker can issue an… | |
| Aplazada | Alta (8.8) | 0.31% | — | Dell Controlvault3AIDell Controlvault3 PlusAI | 17/11/2025 | 17/6/2026 | A buffer overflow vulnerability exists in the CvManager_SBI functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted ControlVault API call can lead to a arbitrary code execution. An attacker can issue an api call to trigger this vulnerability. | |
| Aplazada | Alta (8.7) | 0.24% | — | Dell Controlvault3AIDell Controlvault3 PlusAI | 17/11/2025 | 17/6/2026 | A hard-coded password vulnerability exists in the ControlVault WBDI Driver functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted ControlVault API call can lead to execute priviledged operation. An attacker can issue an api call to trigger this… | |
| Aplazada | Alta (8.7) | 0.22% | — | Dell Controlvault3AIDell Controlvault3 PlusAI | 17/11/2025 | 17/6/2026 | A privilege escalation vulnerability exists in the ControlVault WBDI Driver WBIO_USH_ADD_RECORD functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to privilege escalation. An attacker can issue an api call to… | |
| Aplazada | Crítica (9.3) | 1.8% | — | ThinplusAI | 17/11/2025 | 17/6/2026 | ThinPLUS developed by ThinPLUS has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. | |
| Aplazada | Alta (8.7) | 0.31% | — | General Industrial Controls Lynx Plus GatewayAI | 14/11/2025 | 7/10/2026 | General Industrial Controls Lynx+ Gateway is vulnerable to a cleartext transmission vulnerability that could allow an attacker to observe network traffic to obtain sensitive information, including plaintext credentials. | |
| Aplazada | Alta (8.8) | 0.28% | — | General Industrial Controls Lynx Plus GatewayAI | 14/11/2025 | 7/10/2026 | General Industrial Controls Lynx+ Gateway is vulnerable to a weak password requirement vulnerability, which may allow an attacker to execute a brute-force attack resulting in unauthorized access and login. | |
| Aplazada | Alta (7.1) | 0.22% | — | Siemens Logo 12 24rceAISiemens Logo 12 24rceoAISiemens Logo 230rceAISiemens Logo 230rceoAI+12 | 11/11/2025 | 17/6/2026 | A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA2) (All versions), LOGO! 230RCE (6ED1052-1FB08-0BA2) (All versions), LOGO! 230RCEo (6ED1052-2FB08-0BA2) (All versions), LOGO! 24CE (6ED1052-1CC08-0BA2) (All versions), LOGO! 24CEo… |