Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

2344 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.1)0.16%—Dell Powerstoreos1/4/202611/9/2026
PowerStore, contains a Path Traversal vulnerability in the Service user. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modification of arbitrary system files.
AnalizadaAlta (7.5)1.3%—Powerdns Dnsdist31/3/202625/7/2026
An attacker might be able to trigger a use-after-free by sending crafted DNS queries to a DNSdist using the DNSQuestion:getEDNSOptions method in custom Lua code. In some cases DNSQuestion:getEDNSOptions might refer to a version of the DNS packet that has been modified, thus triggering a use-after-free and potentially…
AnalizadaAlta (7.5)1.5%—Powerdns Dnsdist31/3/202625/7/2026
An attacker might be able to trigger an out-of-bounds write by sending crafted DNS responses to a DNSdist using the DNSQuestion:changeName or DNSResponse:changeName methods in custom Lua code. In some cases the rewritten packet might become larger than the initial response and even exceed 65535 bytes, potentially…
AnalizadaAlta (7.5)0.54%—Powerdns Dnsdist31/3/202625/7/2026
An attacker might be able to trick DNSdist into allocating too much memory while processing DNS over QUIC or DNS over HTTP/3 payloads, resulting in a denial of service. In setups with a large quantity of memory available this usually results in an exception and the QUIC connection is properly closed, but in some cases…
AnalizadaMedia (6.5)0.15%—Powerdns Dnsdist31/3/202625/7/2026
When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using the nghttp2 provider, the ACL check is skipped, allowing all clients to send DoH queries regardless of the configured ACL.
AnalizadaAlta (8.2)1.0%—Powerdns Dnsdist31/3/202625/7/2026
An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to parse DNS packets. The out-of-bounds read might trigger a crash, leading to a denial of service, or access unrelated memory, leading to potential information disclosure.
AnalizadaMedia (4.3)0.16%—Powerdns Dnsdist31/3/202625/7/2026
When the internal webserver is enabled (default is disabled), an attacker might be able to trick an administrator logged to the dashboard into visiting a malicious website and extract information about the running configuration from the dashboard. The root cause of the issue is a misconfiguration of the Cross-Origin…
AnalizadaMedia (4.3)0.14%—Powerdns Dnsdist31/3/202625/7/2026
An attacker might be able to inject HTML content into the internal web dashboard by sending crafted DNS queries to a DNSdist instance where domain-based dynamic rules have been enabled via either DynBlockRulesGroup:setSuffixMatchRule or DynBlockRulesGroup:setSuffixMatchRuleFFI.
AnalizadaMedia (6.9)0.18%—Powersoftware Anyburn26/3/202617/6/2026
AnyBurn 4.3 contains a local buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the image file name field. Attackers can paste a 10000-byte payload into the 'Image file name' parameter during the 'Copy disk to Image' operation to trigger a…
AplazadaAlta (7.4)3.8%—Netcore Power 15axAI26/3/202617/6/2026
A security flaw has been discovered in Netcore Power 15AX up to 3.0.0.6938. Affected by this issue is the function setTools of the file /bin/netis.cgi of the component Diagnostic Tool Interface. Performing a manipulation of the argument IpAddr results in os command injection. Remote exploitation of the attack is…
ModificadaAlta (7.5)1.1%—LibarchiveRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR Arm64+319/3/202628/9/2026
A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the…
AnalizadaAlta (8.3)0.38%—Ironmansoftware Powershell Universal17/3/202617/6/2026
Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authenticated user with any valid token to bypass role-based access controls and perform privileged operations — including reading sensitive data, creating or deleting resources, and disrupting service…
AnalizadaMedia (5.5)0.40%—Ironmansoftware Powershell Universal17/3/202617/6/2026
Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an authenticated user with permissions to create or modify Apps or Endpoints to override existing application or system routes, resulting in unintended request routing and denial of service via a…
ModificadaAlta (7.1)0.54%—Microsoft 365 CopilotMicrosoft EdgeMicrosoft ExcelMicrosoft Loop+616/3/202617/6/2026
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
AplazadaMedia (6.5)0.22%—Ideabox Creations Powerpack Addons FOR ElementorAI13/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IdeaBox Creations PowerPack Addons for Elementor powerpack-lite-for-elementor allows Stored XSS.This issue affects PowerPack Addons for Elementor: from n/a through <= 2.9.9.
AplazadaMedia (5.9)0.24%—Blubrry PowerpressAI13/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in blubrry PowerPress Podcasting powerpress allows Stored XSS.This issue affects PowerPress Podcasting: from n/a through <= 11.15.13.
AnalizadaAlta (8.5)0.19%—Schneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Ecostruxure Power Operation10/3/202624/6/2026
CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges when a locally authenticated attacker sends a crafted data stream, triggering unsafe deserialization.
AplazadaMedia (6.5)0.35%—Powersync ServiceAI10/3/202617/6/2026
PowerSync Service is the server-side component of the PowerSync sync engine. In version 1.20.0, when using new sync streams with config.edition: 3, certain subquery filters were ignored when determining which data to sync to users. Depending on the sync stream configuration, this could result in authenticated users…
ModificadaAlta (8.3)0.21%—Taipower APP9/3/202617/6/2026
Taipower APP for Andorid developed by Taipower has an Improper Certificate Validation vulnerability. When establishing an HTTPS connection with the server, the application fails to verify the server-side TLS/SSL certificate. This flaw allows an unauthenticated remote attackers to exploit the vulnerability to perform a…
AplazadaCrítica (9.8)0.41%—Powerpack FOR LearndashAI6/3/202617/6/2026
The PowerPack for LearnDash WordPress plugin before 1.3.0 does not have authorization and CRSF checks in an AJAX action, allowing unauthenticated users to update arbitrary WordPress options (such as default_role etc) and create arbitrary admin users
AnalizadaAlta (8.7)0.81%💥 PoCEpower.ie6/3/202617/6/2026
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct brute-force attacks to gain unauthorized access.
AnalizadaMedia (6.9)0.40%—Epower.ie6/3/202617/6/2026
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the most recent connection displaces the…
AnalizadaCrítica (9.3)0.92%—Epower.ie6/3/202617/6/2026
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then issue or receive OCPP…
AplazadaAlta (8.8)0.50%—Blubrry PowerpressAI5/3/202617/6/2026
Deserialization of Untrusted Data vulnerability in blubrry PowerPress Podcasting powerpress allows Object Injection.This issue affects PowerPress Podcasting: from n/a through <= 11.15.10.
AnalizadaCrítica (9.6)0.48%—Pebblepower Pebble Prism Ultra Firmware4/3/202617/6/2026
A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd Pebble Prism Ultra v2.9.2 allows attackers to reverse engineer the protocol and execute arbitrary commands on the device without establishing a connection. This is exploitable over…