Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

2493 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.37%—Cisco Iec6400 Wireless Backhaul Edge Compute SoftwareAI21/1/202617/6/2026
A vulnerability in the SSH service of Cisco IEC6400 Wireless Backhaul Edge Compute Software could allow an unauthenticated, remote attacker to cause the SSH service to stop responding. This vulnerability exists because the SSH service lacks effective flood protection. An attacker could exploit this vulnerability by…
ModificadaAlta (7.1)0.28%—Microsoft Edge Chromium16/1/202617/6/2026
Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.
AnalizadaMedia (4.8)0.27%—Arubanetworks Edgeconnect Sd-wan Orchestrator14/1/202617/6/2026
Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attacks against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a…
ModificadaCrítica (9.8)0.66%—Arubanetworks Edgeconnect Sd-wan Orchestrator14/1/202617/6/2026
A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-factor authentication requirements. Successful exploitation could allow an attacker to create an admin user account without the necessary multi-factor authentication, thereby compromising the integrity…
AnalizadaAlta (7.2)0.47%—Arubanetworks Edgeconnect Sd-wan Orchestrator14/1/202617/6/2026
Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, potentially leading to unauthorized data…
AnalizadaAlta (7.2)0.47%—Arubanetworks Edgeconnect Sd-wan Orchestrator14/1/202617/6/2026
Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, potentially leading to unauthorized data…
AnalizadaAlta (7.2)0.47%—Arubanetworks Edgeconnect Sd-wan Orchestrator14/1/202617/6/2026
Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, potentially leading to unauthorized data…
ModificadaCrítica (9.8)40%💥 ExploitAdvantech IOT Edge Linux DockerAdvantech IOT Edge WindowsAdvantech Iotsuite Growth Linux DockerAdvantech Iotsuite Saas Composer+112/1/202617/6/2026
Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability. Users and administrators of affected product…
AnalizadaBaja (3.5)0.26%—Microsoft Edge7/1/20267/10/2026
User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an authorized attacker to perform spoofing over a network.
AplazadaMedia (6.5)0.17%—Basepress Knowledge Base Documentation & Wiki PluginAI31/12/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BasePress Knowledge Base documentation & wiki plugin – BasePress basepress allows Stored XSS.This issue affects Knowledge Base documentation & wiki plugin – BasePress: from n/a through <= 2.17.0.1.
AnalizadaMedia (5.5)0.33%—Linuxfoundation Wasmedge30/12/202517/6/2026
WasmEdge is a WebAssembly runtime. Prior to version 0.16.0-alpha.3, a multiplication in `WasmEdge/include/runtime/instance/memory.h` can wrap, causing `checkAccessBound()` to incorrectly allow the access. This leads to a segmentation fault. Version 0.16.0-alpha.3 contains a patch for the issue.
AplazadaMedia (6.5)0.19%—Xenioushk BWL Knowledge Base ManagerAI30/12/20257/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xenioushk BWL Knowledge Base Manager bwl-kb-manager allows Stored XSS.This issue affects BWL Knowledge Base Manager: from n/a through <= 1.6.3.
AplazadaAlta (7.5)0.46%—Edge-themes CineramaAI30/12/20257/10/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Cinerama cinerama allows PHP Local File Inclusion.This issue affects Cinerama: from n/a through <= 2.9.
AplazadaMedia (5.1)0.16%—Ecessa Edge Ev150AI24/12/202517/6/2026
Ecessa Edge EV150 10.7.4 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without authentication. Attackers can craft a malicious web page with a form that submits requests to the /cgi-bin/pl_web.cgi/util_configlogin_act endpoint to add superuser accounts…
AnalizadaAlta (7.5)0.29%—Gtedge GT Edge AI22/12/202517/6/2026
Incorrect access control in the /api/v1/conversations/*/messages API of GT Edge AI Platform before v2.0.10-dev allows unauthorized attackers to access other users' message history with AI agents.
AnalizadaAlta (7.5)0.29%—Gtedge GT Edge AI22/12/202517/6/2026
Incorrect access control in the /api/v1/conversations/*/files API of GT Edge AI Platform before v2.0.10 allows unauthorized attackers to access other users' uploaded files.
AnalizadaAlta (7.5)0.30%—Gtedge GT Edge AI22/12/202517/6/2026
Insecure permissions in the /api/v1/agents API of GT Edge AI Platform before v2.0.10-dev allows unauthorized attackers to access sensitive information.
AplazadaMedia (4.3)0.23%—Mapro Collins Magazine EdgeAI21/12/202517/6/2026
Missing Authorization vulnerability in Mapro Collins Magazine Edge allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Magazine Edge: from n/a through 1.13.
AnalizadaCrítica (9.8)0.50%—Gtedge GT Edge AI19/12/20255/10/2026
An issue in GT Edge AI Community Edition Versions before v2.0.12 allows attackers to execute arbitrary code via injecting a crafted JSON payload into the Prompt window.
ModificadaBaja (3.1)0.28%—Microsoft Edge Chromium18/12/202530/9/2026
Microsoft Edge (Chromium-based) Spoofing Vulnerability
AnalizadaCrítica (9.8)1.00%—Apache-airflow-providers-edge317/12/202517/6/2026
Edge3 Worker RPC RCE on Airflow 2. This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you installed and configured it on Airflow 2. The Edge3 provider support in Airflow 2 has been always development-only and not officially released, however if you installed and configured Edge3 provider in…
AnalizadaAlta (8.8)22%⚠ Explotación activa💥 PoCGoogle ChromeApple SafariApple IpadosApple Iphone OS+512/12/20257/10/2026
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
AnalizadaMedia (4.8)0.17%—Solaredge Monitoring Platform12/12/20257/10/2026
SolarEdge monitoring platform contains a Cross‑Site Scripting (XSS) flaw that allows an authenticated user to inject payloads into report names, which may execute in a victim’s browser during a deletion attempt.
AnalizadaAlta (7)0.23%—Solaredge Se3680h Firmware12/12/20257/10/2026
SolarEdge SE3680H ships with an outdated Linux kernel containing unpatched vulnerabilities in core subsystems. An attacker with network or local access can exploit these flaws to achieve remote code execution, privilege escalation, or disclosure of sensitive information.
AnalizadaBaja (2.4)0.16%—Solaredge Se3680h Firmware12/12/20257/10/2026
SolarEdge SE3680H has unauthenticated disclosure of sensitive information during the bootloader loop. While the device repeatedly initializes and waits for boot instructions, the bootloader emits diagnostic output this behavior can leak operating system information.