Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

883 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.41%—Beijing Founder Electronics Founder Enjoys All-media Acquisition AND Editing SystemAI9/3/202517/6/2026
A vulnerability has been found in Beijing Founder Electronics Founder Enjoys All-Media Acquisition and Editing System 3.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /newsedit/newsedit/xy/imageProxy.do of the component File Protocol Handler. The manipulation of…
AplazadaMedia (5.3)0.38%—Wpchill Strong TestimonialsAI25/2/202517/6/2026
Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Strong Testimonials: from n/a through <= 3.2.3.
AplazadaAlta (7.5)0.77%—Deetronix Affiliate CouponsAI25/2/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Deetronix Affiliate Coupons affiliate-coupons allows PHP Local File Inclusion.This issue affects Affiliate Coupons: from n/a through <= 1.7.3.
AplazadaBaja (2)0.32%—Amauri TarteaucitronjsAI23/2/202517/6/2026
Versions of the package tarteaucitronjs before 1.17.0 are vulnerable to Cross-site Scripting (XSS) via the getElemWidth() and getElemHeight(). This is related to [SNYK-JS-TARTEAUCITRONJS-8366541](https://security.snyk.io/vuln/SNYK-JS-TARTEAUCITRONJS-8366541)
AplazadaAlta (7.1)0.29%—Pengutronix BareboxAI19/2/202517/6/2026
In barebox before 2025.01.0, ext4fs_read_symlink has an integer overflow for zalloc (adding one to an le32 variable) via a crafted ext4 filesystem with an inode size of 0xffffffff, resulting in a malloc of zero and resultant memory overwrite, a related issue to CVE-2024-57256.
AplazadaAlta (7.1)0.29%—Pengutronix BareboxAI19/2/202517/6/2026
In barebox before 2025.01.0, request2size in common/dlmalloc.c has an integer overflow, a related issue to CVE-2024-57258.
AplazadaAlta (8.4)0.46%💥 PoCStrongkey Fido ServerAI14/2/202517/6/2026
StrongKey FIDO Server before 4.15.1 treats a non-discoverable (namedcredential) flow as a discoverable transaction.
AplazadaAlta (7.3)0.17%—Electronic Arts Dragon AGE OriginsAI27/1/202517/6/2026
In Electronic Arts Dragon Age Origins 1.05, the DAUpdaterSVC service contains an unquoted service path vulnerability. This service is configured with insecure permissions, allowing users to modify the executable file path used by the service. The service runs with NT AUTHORITY\SYSTEM privileges, enabling attackers to…
AnalizadaMedia (4.8)0.24%—Kleegroup Tarte AU Citron9/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Tarte au Citron allows Cross-Site Scripting (XSS).This issue affects Tarte au Citron: from 2.0.0 before 2.0.5.
AplazadaMedia (5.4)0.18%—Zookatron MybooktableAI7/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in zookatron MyBookTable Bookstore mybooktable allows Cross Site Request Forgery.This issue affects MyBookTable Bookstore: from n/a through <= 3.5.3.
AplazadaMedia (5.3)0.32%—Unigroup Electronic Archives SystemAI5/1/202517/6/2026
A vulnerability, which was classified as problematic, was found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). This affects an unknown part of the file /Logs/Annals/downLoad.html. The manipulation of the argument path leads to information disclosure. It is possible to initiate the attack remotely.…
AplazadaMedia (5.3)0.42%—Unigroup Electronic Archives SystemAI5/1/202517/6/2026
A vulnerability, which was classified as problematic, has been found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this issue is the function download of the file /collect/PortV4/downLoad.html. The manipulation of the argument path leads to information disclosure. The attack may be…
AplazadaMedia (5.3)0.47%—Unigroup Electronic Archives SystemAI5/1/202517/6/2026
A vulnerability classified as problematic was found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this vulnerability is an unknown functionality of the file /setting/ClassFy/exampleDownload.html. The manipulation of the argument name leads to path traversal: '/../filedir'. The attack…
AplazadaCrítica (9.8)1.3%—2100 Technology Electronic Official Document Management SystemAI31/12/202417/6/2026
The Electronic Official Document Management System from 2100 Technology has an Authentication Bypass vulnerability. Although the product enforces an IP whitelist for the API used to query user tokens, unauthenticated remote attackers can still deceive the server to obtain tokens of arbitrary users, which can then be…
AplazadaMedia (5.3)0.38%—Tsinghua Unigroup Electronic Archives Management SystemAI30/12/202417/6/2026
A vulnerability was found in Tsinghua Unigroup Electronic Archives Management System 3.2.210802(62532). It has been classified as problematic. Affected is the function download of the file /Searchnew/Subject/download.html. The manipulation of the argument path leads to information disclosure. It is possible to launch…
AplazadaAlta (8.5)0.33%—Delta Electronics DTM SoftAI20/12/202417/6/2026
Delta Electronics DTM Soft deserializes objects, which could allow an attacker to execute arbitrary code.
AplazadaCrítica (10)0.66%—HK Digital Agency LLC TAX Service Electronic HDMAI13/12/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in HK Digital Agency LLC TAX SERVICE Electronic HDM virtual-hdm-for-taxservice-am allows SQL Injection.This issue affects TAX SERVICE Electronic HDM: from n/a through <= 1.2.2.
AplazadaCrítica (9.8)0.46%—Stmicroelectronics Spc58AI5/12/202417/6/2026
STMicroelectronics SPC58 is vulnerable to Missing Protection Mechanism for Alternate Hardware Interface. Code running as Supervisor on the SPC58 PowerPC microcontrollers may disable the System Memory Protection Unit and gain unabridged read/write access to protected assets.
AplazadaMedia (5.3)0.55%—Kekotron AI QuizAI2/12/202417/6/2026
Missing Authorization vulnerability in kekotron AI Quiz ai-quiz allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects AI Quiz: from n/a through <= 1.1.
AplazadaAlta (7.5)0.71%—Openstack NeutronAI25/11/202417/6/2026
In OpenStack Neutron before 25.0.1, neutron/extensions/tagging.py can use an incorrect ID during policy enforcement. It does not apply the proper policy check for changing network tags. An unprivileged tenant is able to change (add and clear) tags on network objects that do not belong to the tenant, and this action is…
AnalizadaAlta (8.8)0.75%—Devtron7/11/202417/6/2026
devtron is an open source tool integration platform for Kubernetes. In affected versions an authenticated user (with minimum permission) could utilize and exploit SQL Injection to allow the execution of malicious SQL queries via CreateUser API (/orchestrator/user). This issue has been addressed in version 0.7.2 and…
ModificadaAlta (8.8)0.40%—Wpchill Strong Testimonials1/11/202417/6/2026
Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials.This issue affects Strong Testimonials: from n/a through <= 3.1.16.
AplazadaMedia (5.2)0.47%—Hitron Coda-4582AIHitron Coda-4589AI30/10/202417/6/2026
Hitron CODA-4582 2AHKM-CODA4589 7.2.4.5.1b8 devices allow a remote attacker within Wi-Fi proximity to conduct stored XSS attacks via the 'Network Name (SSID)' input fields to the /index.html#wireless_basic page.
AplazadaCrítica (9.3)18%—Delta Electronics Infrasuite Device MasterAI30/10/202417/6/2026
Delta Electronics InfraSuite Device Master versions prior to 1.0.12 are affected by a deserialization vulnerability that targets the Device-Gateway, which could allow deserialization of arbitrary .NET objects prior to authentication.
AplazadaMedia (5.9)0.30%—Inatronic BMWAI14/10/202417/6/2026
An issue in INATRONIC com.inatronic.bmw 2.7.1 allows a remote attacker to obtain sensitive information via the firmware update process.