Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
2139 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.97% | — | Sony Bravia Signage | 6/1/2026 | 17/6/2026 | Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization controls. Attackers can access hidden system resources like '/#/content-creation' by manipulating client-side access restrictions. | |
| Analizada | Media (6.9) | 0.64% | — | Sony Bravia Signage | 6/1/2026 | 17/6/2026 | Sony BRAVIA Digital Signage 1.7.8 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive system details through API endpoints. Attackers can retrieve network interface information, server configurations, and system metadata by sending requests to the exposed system… | |
| Aplazada | Media (6.9) | 0.43% | — | Red-v Super Digital Signage SystemAI | 6/1/2026 | 17/6/2026 | RED-V Super Digital Signage System 5.1.1 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive webserver log files. Attackers can visit multiple endpoints to retrieve system resources and debug log information without authentication. | |
| Aplazada | Alta (8.7) | 0.37% | — | Ids6 Dsspro Digital Signage SystemAI | 6/1/2026 | 17/6/2026 | iDS6 DSSPro Digital Signage System 6.2 contains an improper access control vulnerability that allows authenticated users to elevate privileges through console JavaScript functions. Attackers can create users, modify roles and permissions, and potentially achieve full application takeover by exploiting insecure direct… | |
| Aplazada | Media (5.1) | 0.17% | — | Ids6 Dsspro Digital Signage SystemAI | 6/1/2026 | 17/6/2026 | iDS6 DSSPro Digital Signage System 6.2 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without request validation. Attackers can craft malicious web pages to trick logged-in administrators into adding unauthorized users by exploiting the lack of CSRF… | |
| Aplazada | Alta (8.6) | 0.31% | — | Ids6 Dsspro Digital Signage SystemAI | 6/1/2026 | 17/6/2026 | iDS6 DSSPro Digital Signage System 6.2 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept authentication credentials through cleartext cookie transmission. Attackers can exploit the autoSave feature to capture user passwords during man-in-the-middle attacks on HTTP… | |
| Aplazada | Alta (8.5) | 0.26% | — | TDM Digital Signage PC PlayerAI | 6/1/2026 | 17/6/2026 | TDM Digital Signage PC Player 4.1.0.4 contains an elevation of privileges vulnerability that allows authenticated users to modify executable files. Attackers can leverage the 'Modify' permissions for authenticated users to replace executable files with malicious binaries and gain elevated system access. | |
| Aplazada | Alta (8.7) | 0.39% | — | Adtec Digital Signedje Digital Signage PlayerAI | 6/1/2026 | 17/6/2026 | Adtec Digital SignEdje Digital Signage Player v2.08.28 contains multiple hardcoded default credentials that allow unauthenticated remote access to web, telnet, and SSH interfaces. Attackers can exploit these credentials to gain root-level access and execute system commands across multiple Adtec Digital product… | |
| Aplazada | Alta (8.6) | 0.31% | — | Qihang Media WEB Digital SignageAI | 6/1/2026 | 17/6/2026 | QiHang Media Web Digital Signage 3.0.9 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept user authentication credentials through cleartext cookie transmission. Attackers can perform man-in-the-middle attacks to capture and potentially misuse stored authentication… | |
| Aplazada | Media (5.1) | 0.43% | — | Plexus Anblick Digital Signage ManagementAI | 6/1/2026 | 17/6/2026 | Plexus anblick Digital Signage Management 3.1.13 contains an open redirect vulnerability in the 'PantallaLogin' script that allows attackers to manipulate the 'pagina' GET parameter. Attackers can craft malicious links that redirect users to arbitrary websites by exploiting improper input validation in the parameter. | |
| Aplazada | Alta (8.7) | 1.4% | — | Cayin Signage Media PlayerAI | 6/1/2026 | 17/6/2026 | Cayin Signage Media Player 3.0 contains an authenticated remote command injection vulnerability in system.cgi and wizard_system.cgi pages. Attackers can exploit the 'NTP_Server_IP' parameter with default credentials to execute arbitrary shell commands as root. | |
| Aplazada | Media (5.4) | 0.20% | — | Buddhathemes Wedesigntech Ultimate Booking AddonAI | 6/1/2026 | 7/10/2026 | Missing Authorization vulnerability in BuddhaThemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WeDesignTech Ultimate Booking Addon: from n/a through <= 1.0.3. | |
| Analizada | Alta (8.8) | 0.30% | — | Signalk Signal K Server | 1/1/2026 | 7/10/2026 | Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the access request system have two related features that when combined by themselves and with an information disclosure vulnerability enable convincing social engineering attacks against administrators. When a… | |
| Analizada | Crítica (9.1) | 0.54% | — | Signalk Signal K Server | 1/1/2026 | 7/10/2026 | Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 expose two features that can be chained together to steal JWT authentication tokens without any prior authentication. The attack combines WebSocket-based request enumeration with unauthenticated polling of access… | |
| Analizada | Alta (7.3) | 0.71% | — | Signalk Signal K Server | 1/1/2026 | 7/10/2026 | Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the appstore interface allow administrators to install npm packages through a REST API endpoint. While the endpoint validates that the package name exists in the npm registry as a known plugin or webapp, the… | |
| Analizada | Media (5.3) | 0.82% | 💥 Exploit | Signalk Signal K Server | 1/1/2026 | 7/10/2026 | Signal K Server is a server application that runs on a central hub in a boat. An unauthenticated information disclosure vulnerability in versions prior to 2.19.0 allows any user to retrieve sensitive system information, including the full SignalK data schema, connected serial devices, and installed analyzer tools.… | |
| Analizada | Alta (7.5) | 0.56% | — | Signalk Signal K Server | 1/1/2026 | 7/10/2026 | Signal K Server is a server application that runs on a central hub in a boat. A Denial of Service (DoS) vulnerability in versions prior to 2.19.0 allows an unauthenticated attacker to crash the SignalK Server by flooding the access request endpoint (`/signalk/v1/access/requests`). This causes a "JavaScript heap out of… | |
| Analizada | Alta (8.8) | 20% | 💥 PoC | Signalk Signal K Server | 1/1/2026 | 7/10/2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the internal state (`restoreFilePath`) of the server via the `/skServer/validateBackup` endpoint. This allows the attacker to hijack the administrator's "Restore" functionality… | |
| Aplazada | Alta (7.1) | 0.18% | — | Terry Zielke Zielke Design Project GalleryAI | 31/12/2025 | 23/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Terry Zielke Zielke Design Project Gallery zielke-design-project-gallery allows Reflected XSS.This issue affects Zielke Design Project Gallery: from n/a through <= 2.5.0. | |
| Aplazada | Media (4.3) | 0.22% | — | Gravityforms Signature Add-onAI | 31/12/2025 | 28/9/2026 | Missing Authorization vulnerability in approveme Signature Add-On for Gravity Forms gravity-signature-forms-add-on allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Signature Add-On for Gravity Forms: from n/a through <= 1.8.6. | |
| Aplazada | Media (5.9) | 0.21% | — | Soli WP Post SignatureAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Soli WP Post Signature wp-post-signature allows Stored XSS.This issue affects WP Post Signature: from n/a through <= 0.4.1. | |
| Aplazada | Media (6.5) | 0.19% | — | Webmandesign Webman AmplifierAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebMan Design | Oliver Juhas WebMan Amplifier webman-amplifier allows DOM-Based XSS.This issue affects WebMan Amplifier: from n/a through <= 1.5.12. | |
| Aplazada | Baja (3.8) | 0.37% | 💥 PoC | Automattic Crowdsignal FormsAI | 30/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Automattic Crowdsignal Forms crowdsignal-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Crowdsignal Forms: from n/a through <= 1.7.2. | |
| Aplazada | Media (5.9) | 0.21% | — | Inboxify Sign UP FormAI | 30/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Inboxify Inboxify Sign Up Form inboxify-sign-up-form allows Stored XSS.This issue affects Inboxify Sign Up Form: from n/a through <= 1.0.4. | |
| Aplazada | Media (5.3) | 0.25% | — | Designthemes LMS AddonAI | 30/12/2025 | 7/10/2026 | Missing Authorization vulnerability in designthemes DesignThemes LMS Addon designthemes-lms-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DesignThemes LMS Addon: from n/a through <= 2.6. |