Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

822 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.2)0.58%—Modstart Mostartcms27/9/202417/6/2026
ModStartCMS v8.8.0 was discovered to contain an open redirect vulnerability in the redirect parameter at /admin/login. This vulnerability allows attackers to redirect users to an arbitrary website via a crafted URL.
AplazadaMedia (5.3)0.36%—Stylemixthemes Masterstudy LMS StarterAI25/9/202417/6/2026
Insertion of Sensitive Information into Log File vulnerability in StylemixThemes Masterstudy LMS Starter.This issue affects Masterstudy LMS Starter: from n/a through 1.1.8.
ModificadaMedia (6.1)0.27%—Spicethemes Spice Starter Sites18/9/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in spicethemes Spice Starter Sites spice-starter-sites allows Reflected XSS.This issue affects Spice Starter Sites: from n/a through <= 1.2.5.
AplazadaMedia (5.3)0.39%—Shandong Star Measurement AND Control Equipment Heating Network Wireless Monitoring SystemAI11/9/202417/6/2026
A vulnerability was found in Shandong Star Measurement and Control Equipment Heating Network Wireless Monitoring System 5.6.2 and classified as critical. Affected by this issue is the function GetDataKindByType of the file /DataSrvs/UCCGSrv.asmx. The manipulation leads to sql injection. The attack may be launched…
AnalizadaCrítica (9.3)0.56%—Reedos Aim-star11/9/202417/6/2026
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack against legitimate user passwords, which could lead to gain unauthorized…
AnalizadaMedia (6.9)0.22%—Reedos Aim-star11/9/202417/6/2026
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper validation of the ‘mode’ parameter in the API endpoint used during the registration process. An authenticated remote attacker could exploit this vulnerability by manipulating parameter in the API request body on the vulnerable application.…
AnalizadaAlta (8.7)0.50%—Reedos Aim-star11/9/202417/6/2026
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing rate limiting on OTP requests in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoints which could lead to the OTP bombing/flooding on the…
AnalizadaAlta (8.7)0.44%—Reedos Aim-star11/9/202417/6/2026
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to transmission of sensitive information in plain text in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter through API request URL and intercepting response of the API request leading to…
AnalizadaAlta (8.7)0.39%—Reedos Aim-star11/9/202417/6/2026
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper access controls on its certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter through API request URL which could lead to gain unauthorized access to sensitive information belonging…
AnalizadaMedia (4.8)0.40%—Squirrly Starbox10/9/202417/6/2026
The Starbox WordPress plugin before 3.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
AnalizadaMedia (4.8)0.35%—Ronvalstar Pocket Widget9/9/202417/6/2026
The Pocket Widget WordPress plugin through 0.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
AnalizadaAlta (7.1)0.30%—Echostar Fusion5/9/202417/6/2026
Credentials to access device configuration were transmitted using an unencrypted protocol. These credentials would allow read-only access to network configuration information and terminal configuration data.
AnalizadaMedia (4.1)0.20%—Echostar Fusion5/9/202417/6/2026
Credentials to access device configuration information stored unencrypted in flash memory. These credentials would allow read-only access to network configuration information and terminal configuration data.
AnalizadaMedia (4.8)0.28%—Starkdigital WP Testimonial Widget26/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Stark Digital WP Testimonial Widget allows Stored XSS.This issue affects WP Testimonial Widget: from n/a through 3.1.
AnalizadaAlta (7.2)0.44%—Starkdigital WP Testimonial Widget26/8/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stark Digital WP Testimonial Widget.This issue affects WP Testimonial Widget: from n/a through 3.1.
ModificadaMedia (5.3)0.34%—Starkdigital WP Testimonial Widget21/8/202417/6/2026
The WP Testimonial Widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnSaveTestimonailOrder function in all versions up to, and including, 3.1. This makes it possible for unauthenticated attackers to change the order of testimonials.
AplazadaMedia (6.5)0.25%—Visualcomposer Visual Composer StarterAI18/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Visual Composer Visual Composer Starter allows Stored XSS.This issue affects Visual Composer Starter: from n/a through 3.3.
AplazadaMedia (6.4)0.50%—InstarisacsAI13/8/202417/6/2026
This vulnerability exists in InstaRISPACS software due to insufficient validation of user supplied input for the loginTo parameter in user login module of the web interface of the application. A remote attacker could exploit this vulnerability by sending a specially crafted input to the vulnerable parameter to perform…
AplazadaAlta (8.2)0.68%💥 PoCMicro-star International Z590 MotherboardAIMicro-star International Z490 MotherboardAIMicro-star International Z790 MotherboardAIMicro-star International B760 MotherboardAI+312/8/202417/6/2026
Micro-Star International Z-series motherboards (Z590, Z490, and Z790) and B-series motherboards (B760, B560, B660, and B460) with firmware 7D25v14, 7D25v17 to 7D25v19, and 7D25v1A to 7D25v1H was discovered to contain a write-what-where condition in the in the SW handler for SMI 0xE3. Motherboard's with the following…
AplazadaAlta (8.3)0.65%💥 PoCLitestarAI12/8/202417/6/2026
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions 2.10.0 and prior, Litestar's `docs-preview.yml` workflow is vulnerable to Environment Variable injection which may lead to secret exfiltration and repository manipulation. This issue grants a malicious actor the permission to write…
AnalizadaCrítica (9.3)0.48%—Hamastar Meetinghub Paperless Meetings5/8/202417/6/2026
A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtain the other users’ credentials and gain access to the product via an XML file.
AnalizadaCrítica (9.3)0.52%—Hamastar Meetinghub Paperless Meetings5/8/202417/6/2026
A Unrestricted upload of file with dangerous type vulnerability in meeting management function in Hamastar MeetingHub Paperless Meetings 2021 allows remote authenticated users to perform arbitrary system commands via a crafted ASP file.
ModificadaMedia (4.8)0.26%—5starplugins Pretty Simple Popup Builder1/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rob @ 5 Star Plugins Pretty Simple Popup Builder pretty-simple-popup-builder allows Stored XSS.This issue affects Pretty Simple Popup Builder: from n/a through <= 1.0.9.
AplazadaMedia (6.4)0.33%—Athemes Starter SitesAI27/7/202417/6/2026
The aThemes Starter Sites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.53 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject…
ModificadaAlta (7)0.46%—Starship26/7/202417/6/2026
Starship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. This issue only affects users with custom commands, so the…
Orbitaley — Vulnerabilidades