Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

396 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.69%—Online Examination System Project Online Examination System24/5/202117/6/2026
Project Worlds Online Examination System 1.0 is affected by Cross Site Scripting (XSS) via account.php.
ModificadaMedia (6.5)0.66%—Online Examination System Project Online Examination System24/5/202117/6/2026
Projectworlds Online Examination System 1.0 is vulnerable to CSRF, which allows a remote attacker to delete the existing user.
ModificadaAlta (7.5)3.6%—AVE DominaplusAVE 53ab-wbs FirmwareAVE Ts01 FirmwareAVE Ts03x-v Firmware+328/4/202117/6/2026
AVE DOMINAplus <=1.10.x suffers from an unauthenticated reboot command execution. Attackers can exploit this issue to cause a denial of service scenario.
ModificadaCrítica (9.8)3.7%—AVE DominaplusAVE 53ab-wbs FirmwareAVE Ts01 FirmwareAVE Ts03x-v Firmware+328/4/202117/6/2026
AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an unprotected directory that hosts an XML file '/xml/authClients.xml' and obtain administrative login information that allows for a successful authentication bypass attack.
ModificadaCrítica (9.8)2.9%—AVE DominaplusAVE 53ab-wbs FirmwareAVE Ts01 FirmwareAVE Ts03x-v Firmware+328/4/202117/6/2026
AVE DOMINAplus <=1.10.x suffers from an authentication bypass vulnerability due to missing control check when directly calling the autologin GET parameter in changeparams.php script. Setting the autologin value to 1 allows an unauthenticated attacker to permanently disable the authentication security control and…
ModificadaAlta (7.5)1.8%💥 PoCXn--b1agzlht FX Aggregator Terminal Client12/2/202117/6/2026
The Sovremennye Delovye Tekhnologii FX Aggregator terminal client 1 allows attackers to cause a denial of service (access suspended for five hours) by making five invalid login attempts to a victim's account.
ModificadaAlta (7.5)2.0%💥 PoCXn--b1agzlht FX Aggregator Terminal Client12/2/202117/6/2026
The Sovremennye Delovye Tekhnologii FX Aggregator terminal client 1 stores authentication credentials in cleartext in login.sav when the Save Password box is checked.
ModificadaCrítica (9.8)2.1%—Schneider-electric Ecostruxure Operator Terminal ExpertSchneider-electric Pro-face Blue26/1/202117/6/2026
A CWE-20: Improper Input Validation vulnerability exists in EcoStruxure™ Operator Terminal Expert and Pro-face BLUE (version details in the notification) that could cause arbitrary code execution when the Ethernet Download feature is enable on the HMI.
ModificadaCrítica (9.8)75%💥 ExploitGetlaminas Laminas-httpZend Framework4/1/202117/6/2026
Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execution if the content is controllable, related to the __destruct method of the Zend\Http\Response\Stream class in Stream.php. NOTE: Zend Framework is no longer supported by the…
ModificadaCrítica (9.1)0.90%—Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact FL Mguard Rs4004 Tx/dtx FirmwarePhoenixcontact FL Mguard Rs4004 Tx/dtx VPN Firmware+517/12/202017/6/2026
On Phoenix Contact mGuard Devices versions before 8.8.3 LAN ports get functional after reboot even if they are disabled in the device configuration. For mGuard devices with integrated switch on the LAN side, single switch ports can be disabled by device configuration. After a reboot these ports get functional…
ModificadaCrítica (9.8)12%💥 ExploitMobileviewpoint Wireless Multiplex Terminal Playout Server14/12/202017/6/2026
The Web Administrative Interface in Mobile Viewpoint Wireless Multiplex Terminal (WMT) Playout Server 20.2.8 and earlier has a default account with a password of "pokon."
ModificadaMedia (5.4)0.67%—Online Examination System Project Online Examination System9/12/202017/6/2026
Cross-site scripting (XSS) vulnerability in Online Examination System 1.0 via the subject or feedback parameter to feedback.php.
ModificadaMedia (6.1)0.69%—Online Examination System Project Online Examination System9/12/202017/6/2026
Cross-site scripting (XSS) vulnerability in Online Examination System 1.0 via the w parameter to index.php.
ModificadaMedia (6.1)0.70%—Online Examination System Project Online Examination System9/12/202017/6/2026
Cross-site scripting (XSS) vulnerability in Online Examination System 1.0 via the q parameter to feedback.php.
ModificadaMedia (5.5)0.45%—Antiy Zhijia Terminal Defense System3/12/202017/6/2026
There is a local denial of service vulnerability in the Antiy Zhijia Terminal Defense System 5.0.2.10121559 and an attacker can cause a computer crash (BSOD).
ModificadaAlta (7.8)0.31%—Schneider-electric Operator Terminal Expert Runtime19/11/202017/6/2026
A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD) that could cause privilege escalation on the workstation when interacting directly with a driver installed by the runtime software of EcoStruxureª Operator Terminal Expert.
ModificadaAlta (8.1)3.4%💥 ExploitBT Ctroms Terminal Project BT Ctroms Terminal19/6/202017/6/2026
An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-reset feature discloses the verification token. Upon a getverificationcode.jsp request, this token is transmitted not only to the registered phone number of the user account, but is also transmitted to…
ModificadaCrítica (9.8)2.3%—Schneider-electric Ecostruxure Operator Terminal Expert16/6/202017/6/2026
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD)which could cause arbitrary application execution when the computer starts.
ModificadaAlta (7.8)0.86%—SE Ecostruxure Operator Terminal Expert16/6/202017/6/2026
A CWE-88: Argument Injection or Modification vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD)which could cause unauthorized write access when opening the project file.
ModificadaMedia (5.5)0.88%—Schneider-electric Ecostruxure Operator Terminal Expert16/6/202017/6/2026
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability during zip file extraction exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause unauthorized write access outside of expected path folder when…
ModificadaAlta (7.8)1.3%—Schneider-electric Ecostruxure Operator Terminal Expert16/6/202017/6/2026
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause malicious code execution when opening the project file.
ModificadaAlta (7.8)1.1%—Schneider-electric Ecostruxure Operator Terminal Expert16/6/202017/6/2026
A CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause malicious code execution when opening the project file.
ModificadaMedia (6.1)1.5%—Kaminari Project KaminariDebian Linux28/5/202017/6/2026
In Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1.
ModificadaCrítica (9.8)7.9%—Tellabs Optical Line Terminal 1150 Firmware20/3/202017/6/2026
Tellabs Optical Line Terminal (OLT) 1150 devices allow Remote Command Execution via the -l option to TELNET or SSH. Tellabs has addressed this issue in the SR30.1 and SR31.1 release on February 18, 2020.
ModificadaAlta (7.5)4.7%💥 PoCGolang GODebian LinuxFedoraproject FedoraRedhat Developer Tools+724/10/201917/6/2026
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.
Orbitaley — Vulnerabilidades