Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
883 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.41% | — | Beijing Founder Electronics Founder Enjoys All-media Acquisition AND Editing SystemAI | 9/3/2025 | 17/6/2026 | A vulnerability has been found in Beijing Founder Electronics Founder Enjoys All-Media Acquisition and Editing System 3.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /newsedit/newsedit/xy/imageProxy.do of the component File Protocol Handler. The manipulation of… | |
| Aplazada | Media (5.3) | 0.38% | — | Wpchill Strong TestimonialsAI | 25/2/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Strong Testimonials: from n/a through <= 3.2.3. | |
| Aplazada | Alta (7.5) | 0.77% | — | Deetronix Affiliate CouponsAI | 25/2/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Deetronix Affiliate Coupons affiliate-coupons allows PHP Local File Inclusion.This issue affects Affiliate Coupons: from n/a through <= 1.7.3. | |
| Aplazada | Baja (2) | 0.32% | — | Amauri TarteaucitronjsAI | 23/2/2025 | 17/6/2026 | Versions of the package tarteaucitronjs before 1.17.0 are vulnerable to Cross-site Scripting (XSS) via the getElemWidth() and getElemHeight(). This is related to [SNYK-JS-TARTEAUCITRONJS-8366541](https://security.snyk.io/vuln/SNYK-JS-TARTEAUCITRONJS-8366541) | |
| Aplazada | Alta (7.1) | 0.29% | — | Pengutronix BareboxAI | 19/2/2025 | 17/6/2026 | In barebox before 2025.01.0, ext4fs_read_symlink has an integer overflow for zalloc (adding one to an le32 variable) via a crafted ext4 filesystem with an inode size of 0xffffffff, resulting in a malloc of zero and resultant memory overwrite, a related issue to CVE-2024-57256. | |
| Aplazada | Alta (7.1) | 0.29% | — | Pengutronix BareboxAI | 19/2/2025 | 17/6/2026 | In barebox before 2025.01.0, request2size in common/dlmalloc.c has an integer overflow, a related issue to CVE-2024-57258. | |
| Aplazada | Alta (8.4) | 0.46% | 💥 PoC | Strongkey Fido ServerAI | 14/2/2025 | 17/6/2026 | StrongKey FIDO Server before 4.15.1 treats a non-discoverable (namedcredential) flow as a discoverable transaction. | |
| Aplazada | Alta (7.3) | 0.17% | — | Electronic Arts Dragon AGE OriginsAI | 27/1/2025 | 17/6/2026 | In Electronic Arts Dragon Age Origins 1.05, the DAUpdaterSVC service contains an unquoted service path vulnerability. This service is configured with insecure permissions, allowing users to modify the executable file path used by the service. The service runs with NT AUTHORITY\SYSTEM privileges, enabling attackers to… | |
| Analizada | Media (4.8) | 0.24% | — | Kleegroup Tarte AU Citron | 9/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Tarte au Citron allows Cross-Site Scripting (XSS).This issue affects Tarte au Citron: from 2.0.0 before 2.0.5. | |
| Aplazada | Media (5.4) | 0.18% | — | Zookatron MybooktableAI | 7/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in zookatron MyBookTable Bookstore mybooktable allows Cross Site Request Forgery.This issue affects MyBookTable Bookstore: from n/a through <= 3.5.3. | |
| Aplazada | Media (5.3) | 0.32% | — | Unigroup Electronic Archives SystemAI | 5/1/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). This affects an unknown part of the file /Logs/Annals/downLoad.html. The manipulation of the argument path leads to information disclosure. It is possible to initiate the attack remotely.… | |
| Aplazada | Media (5.3) | 0.42% | — | Unigroup Electronic Archives SystemAI | 5/1/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this issue is the function download of the file /collect/PortV4/downLoad.html. The manipulation of the argument path leads to information disclosure. The attack may be… | |
| Aplazada | Media (5.3) | 0.47% | — | Unigroup Electronic Archives SystemAI | 5/1/2025 | 17/6/2026 | A vulnerability classified as problematic was found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this vulnerability is an unknown functionality of the file /setting/ClassFy/exampleDownload.html. The manipulation of the argument name leads to path traversal: '/../filedir'. The attack… | |
| Aplazada | Crítica (9.8) | 1.3% | — | 2100 Technology Electronic Official Document Management SystemAI | 31/12/2024 | 17/6/2026 | The Electronic Official Document Management System from 2100 Technology has an Authentication Bypass vulnerability. Although the product enforces an IP whitelist for the API used to query user tokens, unauthenticated remote attackers can still deceive the server to obtain tokens of arbitrary users, which can then be… | |
| Aplazada | Media (5.3) | 0.38% | — | Tsinghua Unigroup Electronic Archives Management SystemAI | 30/12/2024 | 17/6/2026 | A vulnerability was found in Tsinghua Unigroup Electronic Archives Management System 3.2.210802(62532). It has been classified as problematic. Affected is the function download of the file /Searchnew/Subject/download.html. The manipulation of the argument path leads to information disclosure. It is possible to launch… | |
| Aplazada | Alta (8.5) | 0.33% | — | Delta Electronics DTM SoftAI | 20/12/2024 | 17/6/2026 | Delta Electronics DTM Soft deserializes objects, which could allow an attacker to execute arbitrary code. | |
| Aplazada | Crítica (10) | 0.66% | — | HK Digital Agency LLC TAX Service Electronic HDMAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in HK Digital Agency LLC TAX SERVICE Electronic HDM virtual-hdm-for-taxservice-am allows SQL Injection.This issue affects TAX SERVICE Electronic HDM: from n/a through <= 1.2.2. | |
| Aplazada | Crítica (9.8) | 0.46% | — | Stmicroelectronics Spc58AI | 5/12/2024 | 17/6/2026 | STMicroelectronics SPC58 is vulnerable to Missing Protection Mechanism for Alternate Hardware Interface. Code running as Supervisor on the SPC58 PowerPC microcontrollers may disable the System Memory Protection Unit and gain unabridged read/write access to protected assets. | |
| Aplazada | Media (5.3) | 0.55% | — | Kekotron AI QuizAI | 2/12/2024 | 17/6/2026 | Missing Authorization vulnerability in kekotron AI Quiz ai-quiz allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects AI Quiz: from n/a through <= 1.1. | |
| Aplazada | Alta (7.5) | 0.71% | — | Openstack NeutronAI | 25/11/2024 | 17/6/2026 | In OpenStack Neutron before 25.0.1, neutron/extensions/tagging.py can use an incorrect ID during policy enforcement. It does not apply the proper policy check for changing network tags. An unprivileged tenant is able to change (add and clear) tags on network objects that do not belong to the tenant, and this action is… | |
| Analizada | Alta (8.8) | 0.75% | — | Devtron | 7/11/2024 | 17/6/2026 | devtron is an open source tool integration platform for Kubernetes. In affected versions an authenticated user (with minimum permission) could utilize and exploit SQL Injection to allow the execution of malicious SQL queries via CreateUser API (/orchestrator/user). This issue has been addressed in version 0.7.2 and… | |
| Modificada | Alta (8.8) | 0.40% | — | Wpchill Strong Testimonials | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials.This issue affects Strong Testimonials: from n/a through <= 3.1.16. | |
| Aplazada | Media (5.2) | 0.47% | — | Hitron Coda-4582AIHitron Coda-4589AI | 30/10/2024 | 17/6/2026 | Hitron CODA-4582 2AHKM-CODA4589 7.2.4.5.1b8 devices allow a remote attacker within Wi-Fi proximity to conduct stored XSS attacks via the 'Network Name (SSID)' input fields to the /index.html#wireless_basic page. | |
| Aplazada | Crítica (9.3) | 18% | — | Delta Electronics Infrasuite Device MasterAI | 30/10/2024 | 17/6/2026 | Delta Electronics InfraSuite Device Master versions prior to 1.0.12 are affected by a deserialization vulnerability that targets the Device-Gateway, which could allow deserialization of arbitrary .NET objects prior to authentication. | |
| Aplazada | Media (5.9) | 0.30% | — | Inatronic BMWAI | 14/10/2024 | 17/6/2026 | An issue in INATRONIC com.inatronic.bmw 2.7.1 allows a remote attacker to obtain sensitive information via the firmware update process. |