Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

397 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (9.3)22%💥 ExploitSchneider-electric ConceptSchneider-electric Modbus Serial DriverSchneider-electric Modbuscommdtm SLSchneider-electric OPC Factory Server+91/4/201416/6/2026
Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow remote attackers to execute arbitrary code via a large buffer-size value in a Modbus Application Header.
ModificadaAlta (7.8)2.1%—HP Storeonce 2610 Iscsi Backup SystemHP Storeonce 2620 Iscsi Backup SystemHP Storeonce 4210 FC Backup SystemHP Storeonce 4210 Iscsi Backup System+429/3/201417/6/2026
Unspecified vulnerability in HP StoreOnce Virtual Storage Appliance (VSA) before 3.7.2, StoreOnce 26xx and 4210 iSCSI Backup System before 3.9.0, StoreOnce 4210 FC Backup System before 3.9.0, and StoreOnce 4xxx Backup System before 3.9.0 allows remote attackers to obtain sensitive information or cause a denial of…
ModificadaMedia (6.8)11%💥 ExploitConceptronic Cipcamptiwl 1.0 FirmwareConceptronic Cipcamptiwl17/1/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in set_users.cgi in Conceptronic CIPCAMPTIWL Camera 1.0 with firmware 21.37.2.49 allows remote attackers to hijack the authentication of administrators for requests that add arbitrary users.
ModificadaAlta (7.8)1.5%—Conceptronic C54apm FirmwareConceptronic C54apm10/1/201417/6/2026
The Conceptronic C54APM access point with runtime code 1.26 has a default password of admin for the admin account, which makes it easier for remote attackers to obtain access via an HTTP request, as demonstrated by stored XSS attacks.
ModificadaMedia (4.3)1.2%—Conceptronic C54apm FirmwareConceptronic C54apm10/1/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities on the Conceptronic C54APM access point with runtime code 1.26 allow remote attackers to inject arbitrary web script or HTML via (1) the submit-url parameter in a Refresh action to goform/formWlSiteSurvey or (2) the wlan-url parameter to goform/formWlanSetup.
ModificadaMedia (4.3)0.98%—Conceptronic C54apm FirmwareConceptronic C54apm10/1/201417/6/2026
CRLF injection vulnerability in goform/formWlSiteSurvey on the Conceptronic C54APM access point with runtime code 1.26 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the submit-url parameter in a Refresh action.
ModificadaMedia (5.8)1.2%—Conceptronic C54apm FirmwareConceptronic C54apm10/1/201417/6/2026
Multiple open redirect vulnerabilities on the Conceptronic C54APM access point with runtime code 1.26 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the submit-url parameter in a Refresh action to goform/formWlSiteSurvey or (2) the wlan-url parameter to…
ModificadaMedia (4.7)0.30%—Cooperindustries SMP 16 Gateway (data Concentrator)Cooperindustries SMP 4/dp Gateway (data Concentrator)Cooperindustries SMP 4 Gateway (data Concentrator)17/12/201316/6/2026
The DNP3 component in Cooper Power Systems SMP 4, 4/DP, and 16 gateways allows physically proximate attackers to cause a denial of service (reboot or link outage) via crafted input over a serial line.
ModificadaAlta (7.1)1.3%—Cooperindustries SMP 16 Gateway (data Concentrator)Cooperindustries SMP 4/dp Gateway (data Concentrator)Cooperindustries SMP 4 Gateway (data Concentrator)17/12/201316/6/2026
The DNP3 component in Cooper Power Systems SMP 4, 4/DP, and 16 gateways allows remote attackers to cause a denial of service (reboot or link outage) via a crafted DNP3 TCP packet.
ModificadaBaja (3.5)0.76%—IBM Rational Quality ManagerIBM Rational Requirements ComposerIBM Rational Team Concert10/12/201316/6/2026
Cross-site scripting (XSS) vulnerability in the search implementation in IBM Rational Quality Manager (RQM) 2.0 through 2.0.1.1, 3.x before 3.0.1.6 iFix 1, and 4.x before 4.0.5, as used in Rational Team Concert, Rational Requirements Composer, and other products, allows remote authenticated users to inject arbitrary…
ModificadaAlta (7.8)2.5%—HP Storeonce D2D28/8/201316/6/2026
Unspecified vulnerability in HP StoreOnce D2D Backup System 1.x before 1.2.19 and 2.x before 2.3.0 allows remote attackers to cause a denial of service via unknown vectors.
ModificadaAlta (7.1)1.4%—Moxa Oncell Gateway FirmwareMoxa Oncell Gateway G3111Moxa Oncell Gateway G3151Moxa Oncell Gateway G3211+19/8/201316/6/2026
Moxa OnCell Gateway G3111, G3151, G3211, and G3251 devices with firmware before 1.4 do not use a sufficient source of entropy for SSH and SSL keys, which makes it easier for remote attackers to obtain access by leveraging knowledge of a key from a product installation elsewhere.
ModificadaAlta (7.7)0.82%—HP Storeonce D2D30/6/201316/6/2026
The HP StoreOnce D2D backup system with software before 3.0.0 has a default password of badg3r5 for the HPSupport account, which allows remote attackers to obtain administrative access and delete data via an SSH session.
ModificadaMedia (5.8)0.57%—Harald Ponce DE Leon Authorize.netOscommerce4/11/201216/6/2026
The Authorize.Net module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
ModificadaMedia (6.8)0.64%—IBM Rational Team Concert1/10/201216/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in unspecified services in IBM Rational Team Concert (RTC) 4.x before 4.0.0.1 allow remote attackers to hijack the authentication of arbitrary users for requests that modify work items.
ModificadaMedia (5)1.4%—Conceptcms23/9/201116/6/2026
conceptcms 5.3.1, 5.3.3, and possibly other versions allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by sys_libs/umlib/um_authserver.inc.php and certain other files.
ModificadaMedia (4.3)1.1%—IBM Rational Team Concert30/6/201116/6/2026
Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert (RTC) 3.0 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Work Item 165513.
ModificadaMedia (4.3)1.1%—IBM Rational Team Concert30/6/201116/6/2026
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Rational Team Concert (RTC) 3.0 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Work Item 165511.
ModificadaBaja (3.5)0.89%—IBM Rational Team Concert14/2/201116/6/2026
Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert (RTC) 2.0.0.x allows remote authenticated users to inject arbitrary web script or HTML via the name of a shared report.
ModificadaMedia (5)1.6%—Cisco ASA 5500Cisco PIX 500Cisco VPN 3000 ConcentratorCisco VPN 3005 Concentrator+530/11/201016/6/2026
The remote-access IPSec VPN implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices, PIX Security Appliances 500 series devices, and VPN Concentrators 3000 series devices responds to an Aggressive Mode IKE Phase I message only when the group name is configured on the device, which allows remote…
ModificadaAlta (7.5)0.96%💥 ExploitRuncms Myannonces24/7/200916/6/2026
SQL injection vulnerability in the MyAnnonces module for E-Xoopport 3.1 allows remote attackers to execute arbitrary SQL commands via the lid parameter in a viewannonces action to index.php.
ModificadaAlta (7.5)0.97%💥 ExploitCms.brdconcept Cms-brd24/6/200816/6/2026
SQL injection vulnerability in index.php in CMS-BRD allows remote attackers to execute arbitrary SQL commands via the menuclick parameter.
ModificadaAlta (7.5)1.0%💥 ExploitRuncms Myannonces21/2/200816/6/2026
SQL injection vulnerability in index.php in the MyAnnonces 1.7 and earlier module for RunCMS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view action.
ModificadaAlta (7.5)2.4%💥 ExploitDivideconcept VHD WEB Pack6/2/200816/6/2026
Directory traversal vulnerability in index.php in DivideConcept VHD Web Pack 2.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.
ModificadaMedia (6.8)3.5%💥 ExploitCJG Explorer PROVincent Blavet Phpconcept Library14/5/200716/6/2026
PHP remote file inclusion vulnerability in pcltrace.lib.php in the PclTar module in Vincent Blavet PhpConcept Library, as used in CJG EXPLORER PRO 3.3 and earlier and probably other products, allows remote attackers to execute arbitrary PHP code via a URL in the g_pcltar_lib_dir parameter. NOTE: CVE disputes this…
Orbitaley — Vulnerabilidades