Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
2344 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.16% | — | Dell Powerstoreos | 1/4/2026 | 11/9/2026 | PowerStore, contains a Path Traversal vulnerability in the Service user. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modification of arbitrary system files. | |
| Analizada | Alta (7.5) | 1.3% | — | Powerdns Dnsdist | 31/3/2026 | 25/7/2026 | An attacker might be able to trigger a use-after-free by sending crafted DNS queries to a DNSdist using the DNSQuestion:getEDNSOptions method in custom Lua code. In some cases DNSQuestion:getEDNSOptions might refer to a version of the DNS packet that has been modified, thus triggering a use-after-free and potentially… | |
| Analizada | Alta (7.5) | 1.5% | — | Powerdns Dnsdist | 31/3/2026 | 25/7/2026 | An attacker might be able to trigger an out-of-bounds write by sending crafted DNS responses to a DNSdist using the DNSQuestion:changeName or DNSResponse:changeName methods in custom Lua code. In some cases the rewritten packet might become larger than the initial response and even exceed 65535 bytes, potentially… | |
| Analizada | Alta (7.5) | 0.54% | — | Powerdns Dnsdist | 31/3/2026 | 25/7/2026 | An attacker might be able to trick DNSdist into allocating too much memory while processing DNS over QUIC or DNS over HTTP/3 payloads, resulting in a denial of service. In setups with a large quantity of memory available this usually results in an exception and the QUIC connection is properly closed, but in some cases… | |
| Analizada | Media (6.5) | 0.15% | — | Powerdns Dnsdist | 31/3/2026 | 25/7/2026 | When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using the nghttp2 provider, the ACL check is skipped, allowing all clients to send DoH queries regardless of the configured ACL. | |
| Analizada | Alta (8.2) | 1.0% | — | Powerdns Dnsdist | 31/3/2026 | 25/7/2026 | An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to parse DNS packets. The out-of-bounds read might trigger a crash, leading to a denial of service, or access unrelated memory, leading to potential information disclosure. | |
| Analizada | Media (4.3) | 0.16% | — | Powerdns Dnsdist | 31/3/2026 | 25/7/2026 | When the internal webserver is enabled (default is disabled), an attacker might be able to trick an administrator logged to the dashboard into visiting a malicious website and extract information about the running configuration from the dashboard. The root cause of the issue is a misconfiguration of the Cross-Origin… | |
| Analizada | Media (4.3) | 0.14% | — | Powerdns Dnsdist | 31/3/2026 | 25/7/2026 | An attacker might be able to inject HTML content into the internal web dashboard by sending crafted DNS queries to a DNSdist instance where domain-based dynamic rules have been enabled via either DynBlockRulesGroup:setSuffixMatchRule or DynBlockRulesGroup:setSuffixMatchRuleFFI. | |
| Analizada | Media (6.9) | 0.18% | — | Powersoftware Anyburn | 26/3/2026 | 17/6/2026 | AnyBurn 4.3 contains a local buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the image file name field. Attackers can paste a 10000-byte payload into the 'Image file name' parameter during the 'Copy disk to Image' operation to trigger a… | |
| Aplazada | Alta (7.4) | 3.8% | — | Netcore Power 15axAI | 26/3/2026 | 17/6/2026 | A security flaw has been discovered in Netcore Power 15AX up to 3.0.0.6938. Affected by this issue is the function setTools of the file /bin/netis.cgi of the component Diagnostic Tool Interface. Performing a manipulation of the argument IpAddr results in os command injection. Remote exploitation of the attack is… | |
| Modificada | Alta (7.5) | 1.1% | — | LibarchiveRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR Arm64+3 | 19/3/2026 | 28/9/2026 | A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the… | |
| Analizada | Alta (8.3) | 0.38% | — | Ironmansoftware Powershell Universal | 17/3/2026 | 17/6/2026 | Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authenticated user with any valid token to bypass role-based access controls and perform privileged operations — including reading sensitive data, creating or deleting resources, and disrupting service… | |
| Analizada | Media (5.5) | 0.40% | — | Ironmansoftware Powershell Universal | 17/3/2026 | 17/6/2026 | Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an authenticated user with permissions to create or modify Apps or Endpoints to override existing application or system routes, resulting in unintended request routing and denial of service via a… | |
| Modificada | Alta (7.1) | 0.54% | — | Microsoft 365 CopilotMicrosoft EdgeMicrosoft ExcelMicrosoft Loop+6 | 16/3/2026 | 17/6/2026 | AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. | |
| Aplazada | Media (6.5) | 0.22% | — | Ideabox Creations Powerpack Addons FOR ElementorAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IdeaBox Creations PowerPack Addons for Elementor powerpack-lite-for-elementor allows Stored XSS.This issue affects PowerPack Addons for Elementor: from n/a through <= 2.9.9. | |
| Aplazada | Media (5.9) | 0.24% | — | Blubrry PowerpressAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in blubrry PowerPress Podcasting powerpress allows Stored XSS.This issue affects PowerPress Podcasting: from n/a through <= 11.15.13. | |
| Analizada | Alta (8.5) | 0.19% | — | Schneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Ecostruxure Power Operation | 10/3/2026 | 24/6/2026 | CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges when a locally authenticated attacker sends a crafted data stream, triggering unsafe deserialization. | |
| Aplazada | Media (6.5) | 0.35% | — | Powersync ServiceAI | 10/3/2026 | 17/6/2026 | PowerSync Service is the server-side component of the PowerSync sync engine. In version 1.20.0, when using new sync streams with config.edition: 3, certain subquery filters were ignored when determining which data to sync to users. Depending on the sync stream configuration, this could result in authenticated users… | |
| Modificada | Alta (8.3) | 0.21% | — | Taipower APP | 9/3/2026 | 17/6/2026 | Taipower APP for Andorid developed by Taipower has an Improper Certificate Validation vulnerability. When establishing an HTTPS connection with the server, the application fails to verify the server-side TLS/SSL certificate. This flaw allows an unauthenticated remote attackers to exploit the vulnerability to perform a… | |
| Aplazada | Crítica (9.8) | 0.41% | — | Powerpack FOR LearndashAI | 6/3/2026 | 17/6/2026 | The PowerPack for LearnDash WordPress plugin before 1.3.0 does not have authorization and CRSF checks in an AJAX action, allowing unauthenticated users to update arbitrary WordPress options (such as default_role etc) and create arbitrary admin users | |
| Analizada | Alta (8.7) | 0.81% | 💥 PoC | Epower.ie | 6/3/2026 | 17/6/2026 | The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct brute-force attacks to gain unauthorized access. | |
| Analizada | Media (6.9) | 0.40% | — | Epower.ie | 6/3/2026 | 17/6/2026 | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the most recent connection displaces the… | |
| Analizada | Crítica (9.3) | 0.92% | — | Epower.ie | 6/3/2026 | 17/6/2026 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then issue or receive OCPP… | |
| Aplazada | Alta (8.8) | 0.50% | — | Blubrry PowerpressAI | 5/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in blubrry PowerPress Podcasting powerpress allows Object Injection.This issue affects PowerPress Podcasting: from n/a through <= 11.15.10. | |
| Analizada | Crítica (9.6) | 0.48% | — | Pebblepower Pebble Prism Ultra Firmware | 4/3/2026 | 17/6/2026 | A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd Pebble Prism Ultra v2.9.2 allows attackers to reverse engineer the protocol and execute arbitrary commands on the device without establishing a connection. This is exploitable over… |