Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

883 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.29%—Strongtestimonials Strong TestimonialsAI6/11/20257/10/2026
The Strong Testimonials plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.2.16. This is due to the software allowing users to submit a testimonial in which a value is not properly validated or sanitized prior to being passed to a do_shortcode call. This makes…
AplazadaCrítica (10)0.36%—Deepseaelectronics Dse855AI31/10/202517/6/2026
Incorrect access control in the realtime.cgi endpoint of Deep Sea Electronics devices DSE855 v1.1.0 to v1.1.26 allows attackers to gain access to the admin panel and complete control of the device.
AplazadaAlta (7.5)0.35%—CBK Soft Software Hardware Electronic Computer Systems Industry AND Trade INC EnvisionAI24/10/202517/6/2026
Observable Discrepancy, Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in CBK Soft Software Hardware Electronic Computer Systems Industry and Trade Inc. EnVision allows Account Footprinting. This issue affects enVision: before…
AplazadaMedia (5.5)0.17%—VHS Electronic Software ACE CenterAI20/10/202517/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in VHS Electronic Software Ltd. Co. ACE Center allows Privilege Abuse, Exploitation of Trusted Identifiers. This issue affects ACE Center: from 3.10.100.1768 before 3.10.161.2255.
AplazadaMedia (4.3)0.28%—Webmaniabr Nota Fiscal Eletronica WoocommerceAI26/9/202517/6/2026
Missing Authorization vulnerability in webmaniabr Nota Fiscal Eletrônica WooCommerce nota-fiscal-eletronica-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Nota Fiscal Eletrônica WooCommerce: from n/a through <= 3.4.0.9.
AplazadaMedia (5.9)0.24%—Webmaniabr Nota Fiscal Eletronica WoocommerceAI26/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webmaniabr Nota Fiscal Eletrônica WooCommerce nota-fiscal-eletronica-woocommerce allows Stored XSS.This issue affects Nota Fiscal Eletrônica WooCommerce: from n/a through <= 3.4.0.9.
AnalizadaAlta (7.8)0.24%—Nvidia Megatron-lm24/9/202517/6/2026
NVIDIA Megatron-LM for all platforms contains a vulnerability in the ensemble_classifer script where malicious data created by an attacker may cause an injection. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, Information disclosure, and data tampering.
AnalizadaAlta (7.8)0.24%—Nvidia Megatron-lm24/9/202517/6/2026
NVIDIA Megatron-LM for all platforms contains a vulnerability in the msdp preprocessing script where malicious data created by an attacker may cause an injection. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, Information disclosure, and data tampering.
AnalizadaAlta (7.8)0.24%—Nvidia Megatron-lm24/9/202517/6/2026
NVIDIA Megatron-LM for all platforms contains a vulnerability in the tasks/orqa/unsupervised/nq.py component, where an attacker may cause a code injection. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and data tampering.
AnalizadaAlta (7.8)0.24%—Nvidia Megatron-lm24/9/202517/6/2026
NVIDIA Megatron-LM for all platforms contains a vulnerability in the pretrain_gpt script, where malicious data created by an attacker may cause a code injection issue. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and data tampering.
AplazadaMedia (5.3)0.27%—Wisdomgarden TronclassAI19/9/202517/6/2026
Tronclass developed by WisdomGarden has an Insecure Direct object Reference vulnerability, allowing remote attackers with regular privilege to modify a specific parameter to access other users' files.
AnalizadaMedia (6.8)0.29%—Positron Px360bt Firmware15/9/202517/6/2026
The Positron PX360BT SW REV 8 car alarm system is vulnerable to a replay attack due to a failure in implementing rolling code security. The alarm system does not properly rotate or invalidate used codes, allowing repeated reuse of captured transmissions. This exposes users to significant security risks, including…
AplazadaMedia (6.8)0.46%—Crestron Touchscreens X70AI9/9/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CRESTRON TOUCHSCREENS x70 allows Relative Path Traversal.This issue affects TOUCHSCREENS x70: from 3.000.0110.001 before 3.001.0031.001. Confirmed Affected Hardware: TSW-760, TSW-1060 Confirmed Affected Firmware: 3.002.1061…
AplazadaMedia (5.9)0.37%—Crestron Tsw-760AICrestron Tsw-1060AI9/9/202517/6/2026
A vulnerability exists in the ConsoleFindCommandMatchList function in libsymproc. so imported by ctpd that may lead to unauthorized execution of an attacker-defined file that gets prioritized by the ConsoleFindCommandMatchList. A third-party researcher discovered that the ConsoleFindCommandMatchList enumerates the…
AplazadaMedia (6.1)0.27%—ElectronAI4/9/202517/6/2026
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions below 35.7.5, 36.0.0-alpha.1 through 36.8.0, 37.0.0-alpha.1 through 37.3.1 and 38.0.0-alpha.1 through 38.0.0-beta.6, ASAR Integrity Bypass via resource modification. This only impacts apps that have the…
AplazadaMedia (6.5)0.17%—Deetronix Booking Ultra PROAI3/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Deetronix Booking Ultra Pro booking-ultra-pro allows Stored XSS.This issue affects Booking Ultra Pro: from n/a through <= 1.1.21.
AplazadaAlta (8.6)0.37%—Crestron Touchscreens X70AICrestron Tsw-x70AICrestron Tsw-x60AICrestron Tst-1080AI+93/9/202517/6/2026
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in CRESTRON TOUCHSCREENS x70 allows Argument Injection.This issue affects TOUCHSCREENS x70: from 3.001.0031.001 through 3.001.0034.001. A specially crafted SCP command sent via SSH login string can lead a valid…
AplazadaMedia (5.9)0.16%—Delta Electronics DiaviewAI1/9/202517/6/2026
Delta Electronics DIAView has an authentication bypass vulnerability.
AplazadaMedia (5.5)0.18%—Delta Electronics EIP BuilderAI26/8/202517/6/2026
Delta Electronics EIP Builder version 1.11 is vulnerable to a File Parsing XML External Entity Processing Information Disclosure Vulnerability.
AplazadaAlta (7.8)0.21%—Delta Electronics CommgrAI26/8/202517/6/2026
Delta Electronics COMMGR has Code Injection vulnerability.
AplazadaAlta (8.6)0.40%—Delta Electronics CommgrAI26/8/202517/6/2026
Delta Electronics COMMGR has Stack-based Buffer Overflow vulnerability.
AplazadaMedia (6.5)0.82%—Hitron Cgnf-twnAI25/8/202517/6/2026
Hitron CGNF-TWN 3.1.1.43-TWN-pre3 contains a command injection vulnerability in the telnet service. The issue arises due to improper input validation within the telnet command handling mechanism. An attacker can exploit this vulnerability by injecting arbitrary commands through the telnet interface when prompted for…
AplazadaCrítica (9.8)0.66%💥 PoCVoltronicpower ViewpowerAIVoltronicpower Powershield NetguardAI22/8/202517/6/2026
Voltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292 allows a remote attacker to configure the system via an unspecified web interface. An unauthenticated remote attacker can make changes to the system including: changing the web interface admin password, view/change system…
AplazadaCrítica (10)0.80%💥 PoCVoltronicpower ViewpowerAIVoltronicpower Viewpower PROAIVoltronicpower Powershield NetguardAI22/8/202517/6/2026
Voltronic Power ViewPower through 1.04-24215, ViewPower Pro through 2.0-22165, and PowerShield Netguard before 1.04-23292 allows a remote attacker to run arbitrary code via an unspecified web interface related to detection of a managed UPS shutting down. An unauthenticated attacker can use this to run arbitrary code…
AplazadaAlta (7)0.16%—Strongdm Macos ClientAI20/8/202517/6/2026
The StrongDM macOS client incorrectly processed JSON-formatted messages. Attackers could potentially modify macOS system configuration by crafting a malicious JSON message.