Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
2493 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.37% | — | Cisco Iec6400 Wireless Backhaul Edge Compute SoftwareAI | 21/1/2026 | 17/6/2026 | A vulnerability in the SSH service of Cisco IEC6400 Wireless Backhaul Edge Compute Software could allow an unauthenticated, remote attacker to cause the SSH service to stop responding. This vulnerability exists because the SSH service lacks effective flood protection. An attacker could exploit this vulnerability by… | |
| Modificada | Alta (7.1) | 0.28% | — | Microsoft Edge Chromium | 16/1/2026 | 17/6/2026 | Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally. | |
| Analizada | Media (4.8) | 0.27% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 14/1/2026 | 17/6/2026 | Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attacks against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a… | |
| Modificada | Crítica (9.8) | 0.66% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 14/1/2026 | 17/6/2026 | A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-factor authentication requirements. Successful exploitation could allow an attacker to create an admin user account without the necessary multi-factor authentication, thereby compromising the integrity… | |
| Analizada | Alta (7.2) | 0.47% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 14/1/2026 | 17/6/2026 | Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, potentially leading to unauthorized data… | |
| Analizada | Alta (7.2) | 0.47% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 14/1/2026 | 17/6/2026 | Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, potentially leading to unauthorized data… | |
| Analizada | Alta (7.2) | 0.47% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 14/1/2026 | 17/6/2026 | Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, potentially leading to unauthorized data… | |
| Modificada | Crítica (9.8) | 40% | 💥 Exploit | Advantech IOT Edge Linux DockerAdvantech IOT Edge WindowsAdvantech Iotsuite Growth Linux DockerAdvantech Iotsuite Saas Composer+1 | 12/1/2026 | 17/6/2026 | Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability. Users and administrators of affected product… | |
| Analizada | Baja (3.5) | 0.26% | — | Microsoft Edge | 7/1/2026 | 7/10/2026 | User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an authorized attacker to perform spoofing over a network. | |
| Aplazada | Media (6.5) | 0.17% | — | Basepress Knowledge Base Documentation & Wiki PluginAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BasePress Knowledge Base documentation & wiki plugin – BasePress basepress allows Stored XSS.This issue affects Knowledge Base documentation & wiki plugin – BasePress: from n/a through <= 2.17.0.1. | |
| Analizada | Media (5.5) | 0.33% | — | Linuxfoundation Wasmedge | 30/12/2025 | 17/6/2026 | WasmEdge is a WebAssembly runtime. Prior to version 0.16.0-alpha.3, a multiplication in `WasmEdge/include/runtime/instance/memory.h` can wrap, causing `checkAccessBound()` to incorrectly allow the access. This leads to a segmentation fault. Version 0.16.0-alpha.3 contains a patch for the issue. | |
| Aplazada | Media (6.5) | 0.19% | — | Xenioushk BWL Knowledge Base ManagerAI | 30/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xenioushk BWL Knowledge Base Manager bwl-kb-manager allows Stored XSS.This issue affects BWL Knowledge Base Manager: from n/a through <= 1.6.3. | |
| Aplazada | Alta (7.5) | 0.46% | — | Edge-themes CineramaAI | 30/12/2025 | 7/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Cinerama cinerama allows PHP Local File Inclusion.This issue affects Cinerama: from n/a through <= 2.9. | |
| Aplazada | Media (5.1) | 0.16% | — | Ecessa Edge Ev150AI | 24/12/2025 | 17/6/2026 | Ecessa Edge EV150 10.7.4 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without authentication. Attackers can craft a malicious web page with a form that submits requests to the /cgi-bin/pl_web.cgi/util_configlogin_act endpoint to add superuser accounts… | |
| Analizada | Alta (7.5) | 0.29% | — | Gtedge GT Edge AI | 22/12/2025 | 17/6/2026 | Incorrect access control in the /api/v1/conversations/*/messages API of GT Edge AI Platform before v2.0.10-dev allows unauthorized attackers to access other users' message history with AI agents. | |
| Analizada | Alta (7.5) | 0.29% | — | Gtedge GT Edge AI | 22/12/2025 | 17/6/2026 | Incorrect access control in the /api/v1/conversations/*/files API of GT Edge AI Platform before v2.0.10 allows unauthorized attackers to access other users' uploaded files. | |
| Analizada | Alta (7.5) | 0.30% | — | Gtedge GT Edge AI | 22/12/2025 | 17/6/2026 | Insecure permissions in the /api/v1/agents API of GT Edge AI Platform before v2.0.10-dev allows unauthorized attackers to access sensitive information. | |
| Aplazada | Media (4.3) | 0.23% | — | Mapro Collins Magazine EdgeAI | 21/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Mapro Collins Magazine Edge allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Magazine Edge: from n/a through 1.13. | |
| Analizada | Crítica (9.8) | 0.50% | — | Gtedge GT Edge AI | 19/12/2025 | 5/10/2026 | An issue in GT Edge AI Community Edition Versions before v2.0.12 allows attackers to execute arbitrary code via injecting a crafted JSON payload into the Prompt window. | |
| Modificada | Baja (3.1) | 0.28% | — | Microsoft Edge Chromium | 18/12/2025 | 30/9/2026 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | |
| Analizada | Crítica (9.8) | 1.00% | — | Apache-airflow-providers-edge3 | 17/12/2025 | 17/6/2026 | Edge3 Worker RPC RCE on Airflow 2. This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you installed and configured it on Airflow 2. The Edge3 provider support in Airflow 2 has been always development-only and not officially released, however if you installed and configured Edge3 provider in… | |
| Analizada | Alta (8.8) | 22% | ⚠ Explotación activa💥 PoC | Google ChromeApple SafariApple IpadosApple Iphone OS+5 | 12/12/2025 | 7/10/2026 | Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (4.8) | 0.17% | — | Solaredge Monitoring Platform | 12/12/2025 | 7/10/2026 | SolarEdge monitoring platform contains a Cross‑Site Scripting (XSS) flaw that allows an authenticated user to inject payloads into report names, which may execute in a victim’s browser during a deletion attempt. | |
| Analizada | Alta (7) | 0.23% | — | Solaredge Se3680h Firmware | 12/12/2025 | 7/10/2026 | SolarEdge SE3680H ships with an outdated Linux kernel containing unpatched vulnerabilities in core subsystems. An attacker with network or local access can exploit these flaws to achieve remote code execution, privilege escalation, or disclosure of sensitive information. | |
| Analizada | Baja (2.4) | 0.16% | — | Solaredge Se3680h Firmware | 12/12/2025 | 7/10/2026 | SolarEdge SE3680H has unauthenticated disclosure of sensitive information during the bootloader loop. While the device repeatedly initializes and waits for boot instructions, the bootloader emits diagnostic output this behavior can leak operating system information. |