Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

1720 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.6)1.1%—H3C Magic Nx15AIH3C Magic Nx400AIH3C Magic R3010AI14/4/202517/6/2026
A vulnerability, which was classified as critical, was found in H3C Magic NX15, Magic NX400 and Magic R3010 up to V100R014. This affects the function FCGI_WizardProtoProcess of the file /api/wizard/getsyncpppoecfg of the component HTTP POST Request Handler. The manipulation leads to command injection. The attack needs…
AplazadaAlta (8.6)1.1%—H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI13/4/202517/6/2026
A vulnerability, which was classified as critical, has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400 and Magic R3010 up to V100R014. Affected by this issue is the function FCGI_WizardProtoProcess of the file /api/wizard/getSpecs of the component HTTP POST Request Handler. The manipulation leads to command…
AplazadaAlta (8.6)1.1%—H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI13/4/202517/6/2026
A vulnerability classified as critical was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400 and Magic R3010 up to V100R014. Affected by this vulnerability is the function FCGI_WizardProtoProcess of the file /api/wizard/getCapability of the component HTTP POST Request Handler. The manipulation leads to command…
AplazadaAlta (8.6)1.1%—H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+113/4/202517/6/2026
A vulnerability classified as critical has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. Affected is the function FCGI_CheckStringIfContainsSemicolon of the file /api/wizard/getBasicInfo of the component HTTP POST Request Handler. The manipulation leads to…
AnalizadaCrítica (9.1)0.35%—Graphicsmagick9/4/202517/6/2026
GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in coders/jxl.c, related to an ImportViewPixelArea call.
AplazadaMedia (6.4)0.33%—Metagauss RegistrationmagicAI4/4/202517/6/2026
The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘payment_method’ parameter in all versions up to, and including, 6.0.4.3 due to insufficient input sanitization and output escaping. This makes it…
AplazadaMedia (6.5)0.31%—Matthewrubin Local MagicAI3/4/202517/6/2026
Missing Authorization vulnerability in matthewrubin Local Magic local-magic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Local Magic: from n/a through <= 2.9.0.
AplazadaMedia (6.5)0.36%—Noor Alam Magical-blocksAI1/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Magical Blocks magical-blocks allows Stored XSS.This issue affects Magical Blocks: from n/a through <= 1.0.12.
AplazadaMedia (6.5)0.21%—Wpembedfb Magic EmbedsAI28/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Miguel Sirvent Magic Embeds wp-embed-facebook allows Stored XSS.This issue affects Magic Embeds: from n/a through <= 3.1.2.
AplazadaAlta (8.6)1.0%—H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+125/3/202517/6/2026
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/wizard/getWifiNeighbour of the component HTTP POST Request Handler. The manipulation leads to…
AplazadaAlta (8.6)1.0%—H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+125/3/202517/6/2026
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /api/wizard/getDualbandSync of the component HTTP POST Request Handler. The manipulation leads…
AplazadaAlta (8.6)1.0%—H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+125/3/202517/6/2026
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been classified as critical. Affected is an unknown function of the file /api/wizard/getssidname of the component HTTP POST Request Handler. The manipulation leads to command injection. The…
AplazadaAlta (8.6)1.0%—H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+125/3/202517/6/2026
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014 and classified as critical. This issue affects some unknown processing of the file /api/wizard/networkSetup of the component HTTP POST Request Handler. The manipulation leads to command injection. The…
AplazadaAlta (8.6)1.0%—H3C Magic Nx30 PROAIH3C Magic Nx400AI25/3/202517/6/2026
A vulnerability has been found in H3C Magic NX30 Pro and Magic NX400 up to V100R014 and classified as critical. This vulnerability affects unknown code of the file /api/wizard/getNetworkConf. The manipulation leads to command injection. The attack needs to be approached within the local network. It is recommended to…
AplazadaAlta (8.6)1.0%—H3C Magic Nx30 PROAI25/3/202517/6/2026
A vulnerability, which was classified as critical, was found in H3C Magic NX30 Pro up to V100R007. This affects an unknown part of the file /api/wizard/getNetworkStatus of the component HTTP POST Request Handler. The manipulation leads to command injection. Access to the local network is required for this attack to…
AplazadaAlta (8.6)1.0%—H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+125/3/202517/6/2026
A vulnerability, which was classified as critical, has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. Affected by this issue is some unknown functionality of the file /api/esps of the component HTTP POST Request Handler. The manipulation leads to command…
AplazadaAlta (8.6)8.3%—H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+125/3/202517/6/2026
A vulnerability classified as critical was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. Affected by this vulnerability is an unknown functionality of the file /api/login/auth of the component HTTP POST Request Handler. The manipulation leads to command injection.…
AnalizadaCrítica (9.8)0.39%—Graphicsmagick7/3/202517/6/2026
ReadWPGImage in WPG in GraphicsMagick before 1.3.46 mishandles palette buffer allocation, resulting in out-of-bounds access to heap memory in ReadBlob.
AnalizadaAlta (7.5)0.45%—Graphicsmagick7/3/202517/6/2026
ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits.
AplazadaAlta (7.1)0.24%—Grimdonkey Magic THE Gathering Card TooltipsAI22/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in grimdonkey Magic the Gathering Card Tooltips magic-the-gathering-card-tooltips allows Stored XSS.This issue affects Magic the Gathering Card Tooltips: from n/a through <= 3.5.0.
AnalizadaMedia (6.3)0.30%—Dcooperman Magicform1/2/202517/6/2026
The MagicForm plugin for WordPress is vulnerable to access and modification of data due to a missing capability check on the plugin's AJAX actions in all versions up to, and including, 1.6.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to invoke those actions in order to…
ModificadaMedia (6.1)0.26%—Metagauss Registrationmagic31/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Reflected XSS.This issue affects RegistrationMagic: from n/a through <= 6.0.3.3.
AplazadaMedia (6.5)0.37%—Grimdonkey Magic THE Gathering Card TooltipsAI24/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in grimdonkey Magic the Gathering Card Tooltips magic-the-gathering-card-tooltips allows Stored XSS.This issue affects Magic the Gathering Card Tooltips: from n/a through <= 3.4.0.
AplazadaMedia (6.5)0.23%—Fengler Magic Google MapsAI16/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fengler Magic Google Maps magic-google-maps allows Stored XSS.This issue affects Magic Google Maps: from n/a through <= 1.0.4.
AplazadaAlta (7.1)0.41%—Straps Strx Magic Floating Sidebar MakerAI16/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in straps Strx Magic Floating Sidebar Maker strx-magic-floating-sidebar-maker allows Stored XSS.This issue affects Strx Magic Floating Sidebar Maker: from n/a through <= 1.4.1.