Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

2287 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.33%—Open-metadata Openmetadata8/8/202517/6/2026
OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO interface. The entityType parameter can be used to build a SQL query.
AnalizadaAlta (8.8)0.32%—Open-metadata Openmetadata8/8/202517/6/2026
OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO interface. The testPlatform parameter can be used to build a SQL query.
AplazadaMedia (4.4)0.25%—Shortpixel Adaptive ImagesAI2/8/202517/6/2026
The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the API URL Setting in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
AnalizadaMedia (5.4)0.21%—IBM Qradar Security Information AND Event Manager1/8/202517/6/2026
IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 12 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AnalizadaCrítica (9.8)0.52%—Iroadau FX2 Firmware28/7/202517/6/2026
An issue was discovered on IROAD Dashcam FX2 devices. Bypass of Device Pairing/Registration can occur. It requires device registration via the "IROAD X View" app for authentication, but its HTTP server lacks this restriction. Once connected to the dashcam's Wi-Fi network via the default password ("qwertyuiop"), an…
AnalizadaCrítica (9.4)0.55%—Iroadau FX2 Firmware25/7/202517/6/2026
An issue was discovered on IROAD Dashcam FX2 devices. Dumping Files Over HTTP and RTSP Without Authentication can occur. It lacks authentication controls on its HTTP and RTSP interfaces, allowing attackers to retrieve sensitive files and video recordings. By connecting to http://192.168.10.1/mnt/extsd/event/, an…
AplazadaCrítica (9.8)0.66%💥 PoCBayraktar Solar Energies Scadawatt OtopilotAI24/7/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bayraktar Solar Energies ScadaWatt Otopilot allows SQL Injection. This issue affects ScadaWatt Otopilot: before 27.05.2025.
AnalizadaMedia (4.5)0.18%—IBM Qradar Network Threat Analytics22/7/202517/6/2026
IBM Security QRadar Network Threat Analytics 1.0.0 through 1.3.1 could allow a privileged user to cause a denial of service due to improper allocation of resources.
AplazadaCrítica (9.1)0.88%—Madara CoreAI17/7/202517/6/2026
The Madara - Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wp_manga_delete_zip() function in all versions up to, and including, 2.2.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead…
AnalizadaBaja (2)0.31%—Scada-lts17/7/202517/6/2026
A vulnerability classified as problematic was found in Scada-LTS up to 2.7.8.1. Affected by this vulnerability is an unknown functionality of the file usersProfiles.shtm. The manipulation of the argument Username leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the…
AnalizadaBaja (2)0.31%—Scada-lts17/7/202517/6/2026
A vulnerability classified as problematic has been found in Scada-LTS up to 2.7.8.1. Affected is an unknown function of the file users.shtm. The manipulation of the argument Username leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be…
AplazadaMedia (6.4)0.20%—Avada Fusion BuilderAI16/7/202517/6/2026
The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fusion_map' shortcode in all versions up to, and including, 3.12.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…
AnalizadaMedia (5.4)0.19%—IBM Qradar Security Information AND Event Manager15/7/202517/6/2026
IBM QRadar SIEM 7.5 - 7.5.0 UP12 IF02 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AplazadaMedia (5.3)0.25%—Kamleshyadav CF7 7 Mailchimp Add-onAI4/7/202517/6/2026
Missing Authorization vulnerability in kamleshyadav CF7 7 Mailchimp Add-on CF7-mailchimp-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CF7 7 Mailchimp Add-on: from n/a through < 2.4.
AplazadaMedia (5.3)0.26%—Theme-fusion AvadaAI4/7/202517/6/2026
Missing Authorization vulnerability in ThemeFusion Avada avada.This issue affects Avada: from n/a through <= 7.11.10.
AplazadaCrítica (9.8)1.1%—Mitsubishielectric G-50AIMitsubishielectric G-50-wAIMitsubishielectric G-50aAIMitsubishielectric Gb-50AI+2326/6/202517/6/2026
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation G-50 all versions, G-50-W all versions, G-50A all versions, GB-50 all versions, GB-50A all versions, GB-24A all versions, G-150AD all versions, AG-150A-A all versions, AG-150A-J all versions, GB-50AD all versions, GB-50ADA-A…
AnalizadaCrítica (9.8)0.68%—Iroadau FX2 Firmware26/6/202517/6/2026
An issue was discovered on IROAD Dashcam FX2 devices. An unauthenticated file upload endpoint can be leveraged to execute arbitrary commands by uploading a CGI-based webshell. Once a file is uploaded, the attacker can execute commands with root privileges, gaining full control over the dashcam. Additionally, by…
AnalizadaAlta (7.1)0.20%—Hitachienergy Microscada X Sys60024/6/202517/6/2026
A vulnerability exists in the IEC 61850 in MicroSCADA X SYS600 product. The certificate validation of the TLS protocol allows remote Man-in-the-Middle attack due to missing proper validation.
AnalizadaAlta (8.5)0.36%—Hitachienergy Microscada X Sys60024/6/202517/6/2026
A vulnerability exists in the Web interface of the MicroSCADA X SYS600 product. The filtering query in the Web interface can be malformed, so returning data can leak unauthorized information to the user.
AnalizadaAlta (7.1)0.22%—Hitachienergy Microscada X Sys60024/6/202517/6/2026
A vulnerability exists in the IEC 61850 of the MicroSCADA X SYS600 product. An IEC 61850-8 crafted message content from IED or remote system can cause a denial of service resulting in disconnection loop.
AnalizadaAlta (8.3)0.23%—Hitachienergy Microscada X Sys60024/6/202517/6/2026
A vulnerability exists in in the Monitor Pro interface of the MicroSCADA X SYS600 product. An authenticated user with low privileges can see and overwrite files causing information leak and data corruption.
AnalizadaMedia (6.9)0.13%—Hitachienergy Microscada X Sys60024/6/202517/6/2026
A vulnerability exists in MicroSCADA X SYS600 product. If exploited this could allow a local unauthenticated attacker to tamper a system file, making denial of Notify service.
AnalizadaMedia (6.2)0.17%—IBM Qradar Security Information AND Event Manager19/6/202517/6/2026
IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 stores potentially sensitive information in log files that could be read by a local user.
AnalizadaAlta (7.1)0.48%—IBM Qradar Security Information AND Event Manager19/6/202517/6/2026
IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
AnalizadaCrítica (9.1)0.55%—IBM Qradar Security Information AND Event Manager19/6/202517/6/2026
IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 could allow a privileged user to modify configuration files that would allow the upload of a malicious autoupdate file to execute arbitrary commands.