Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

1459 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.5%—Mbconnectline Mbnet.mini FirmwareHelmholz REX 100 Firmware15/10/202417/6/2026
An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.
ModificadaAlta (7.8)0.09%—Mbconnectline Mbnet.mini FirmwareHelmholz Myrex24 V2 Virtual ServerHelmholz REX 300 FirmwareHelmholz REX 200 Firmware+1115/10/202417/6/2026
An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.
ModificadaAlta (7.8)0.31%—Mbconnectline Mbnet.mini FirmwareHelmholz REX 100 Firmware15/10/202417/6/2026
An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.
AnalizadaMedia (6.9)0.32%—1234n Minicms27/9/202417/6/2026
A vulnerability was found in bg5sbk MiniCMS 1.11. It has been classified as problematic. Affected is an unknown function of the file page-edit.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The…
AnalizadaMedia (6.9)0.36%—1234n Minicms27/9/202417/6/2026
A vulnerability was found in bg5sbk MiniCMS up to 1.11 and classified as problematic. This issue affects some unknown processing of the file post-edit.php. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The…
ModificadaCrítica (9.8)0.59%—Jianbo Rest API TO Miniprogram25/9/202417/6/2026
The REST API TO MiniProgram plugin for WordPress is vulnerable to privilege escalation via account takeovr in all versions up to, and including, 4.7.1 via the updateUserInfo() due to missing validation on the 'openid' user controlled key that determines what user will be updated. This makes it possible for…
ModificadaAlta (7.5)3.8%💥 ExploitJianbo Rest API TO Miniprogram25/9/202417/6/2026
The REST API TO MiniProgram plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/watch-life-net/v1/comment/getcomments REST API endpoint in all versions up to, and including, 4.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…
AnalizadaMedia (6.5)0.20%—Lenovo Xclarity Administrator13/9/202417/6/2026
A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device through a specially crafted web API call.
AnalizadaMedia (4.3)0.34%—Lenovo Xclarity Administrator13/9/202417/6/2026
A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privileges.
AnalizadaMedia (6.5)0.73%—Haxx CurlDebian LinuxNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility+611/9/202417/6/2026
When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine. If the returned status reports another error than 'revoked' (like for…
ModificadaAlta (7.5)67%—OpensslNetapp Active IQ Unified ManagerManagement Services FOR Element Software AND Netapp HCINetapp Ontap 9+153/9/202417/6/2026
Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service.…
AnalizadaMedia (5.3)0.63%💥 PoCMiniorange WEB Application Firewall31/8/202417/6/2026
The Web Application Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.1.2. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header…
AplazadaMedia (5.4)0.25%—Mini Inventory AND Sales Management SystemAI21/8/202417/6/2026
A cross-site scripting (XSS) vulnerability in the component /email/welcome.php of Mini Inventory and Sales Management System commit 18aa3d allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter.
ModificadaMedia (5.9)0.19%—Google Nest Mini FirmwareHaxx Libcurl19/8/202417/6/2026
The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-middle attack on requests to Google cloud services by any host the traffic was routed through.
ModificadaAlta (7.5)0.63%—Rust-bitcoin Miniscript19/8/202417/6/2026
The Miniscript (aka rust-miniscript) library before 12.2.0 for Rust allows stack consumption because it does not properly track tree depth.
AnalizadaMedia (6.9)0.55%—Forip Administracao Pabx5/8/202417/6/2026
A vulnerability was found in ForIP Tecnologia Administração PABX 1.x. It has been rated as critical. Affected by this issue is some unknown functionality of the file /authMonitCallcenter of the component monitcallcenter. The manipulation of the argument user leads to sql injection. The attack may be launched remotely.…
ModificadaCrítica (9.8)0.97%—Alykoshin Mini-deep-assign30/7/202417/6/2026
Prototype Pollution in alykoshin mini-deep-assign v0.0.8 allows an attacker to execute arbitrary code or cause a Denial of Service (DoS) and cause other impacts via the _assign() method at (/lib/index.js:91)
ModificadaMedia (5.3)0.40%—Forip Administracao Pabx25/7/202417/6/2026
A vulnerability classified as critical has been found in ForIP Tecnologia Administração PABX 1.x. Affected is an unknown function of the file /detalheIdUra of the component Lista Ura Page. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been…
AplazadaMedia (6.9)0.45%—Forip Administracao PabxAI25/7/202417/6/2026
A vulnerability, which was classified as critical, has been found in ForIP Tecnologia Administração PABX 1.x. This issue affects some unknown processing of the file /login of the component Authentication Form. The manipulation of the argument usuario leads to sql injection. The attack may be initiated remotely. The…
AplazadaMedia (6.3)0.28%—Opentext Netiq Directory AND Resource AdministratorAI16/7/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Access vulnerability in OpenText NetIQ Directory and Resource Administrator. This issue affects NetIQ Directory and Resource Administrator versions prior to 10.0.2 and prior to 9.2.1 Patch 10.
ModificadaAlta (7.5)1.0%💥 PoCCertifiManagement Services FOR Element Software AND Netapp HCINetapp Ontap Select Deploy Administration UtilityNetapp Ontap Tools5/7/202417/6/2026
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.5.30 and prior to 2024.7.4 recognized root certificates from `GLOBALTRUST`. Certifi 2024.7.04 removes root certificates from `GLOBALTRUST` from…
ModificadaAlta (8.1)100%💥 ExploitSonicwall SMA 6200 FirmwareSonicwall SMA 7200 FirmwareArista EOSCanonical Ubuntu Linux+491/7/20241/9/2026
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.
AnalizadaAlta (7.8)0.12%—HP Elitebook 745 G4 FirmwareHP Elitebook 745 G5 FirmwareHP Elitebook 745 G6 FirmwareHP Elitebook 755 G4 Firmware+34928/6/202417/6/2026
A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability.
ModificadaMedia (5.5)0.16%—Monoprice Select Mini 3D Printer V2 Firmware12/6/202417/6/2026
Improper input validation of printing files in Monoprice Select Mini V2 V37.115.32 allows attackers to instruct the device's movable parts to destinations that exceed the devices' maximum coordinates via the printing of a malicious .gcode file.
AnalizadaMedia (4.8)0.15%—Siemens TIA Administrator11/6/202417/6/2026
A vulnerability has been identified in TIA Administrator (All versions < V3 SP2). The affected component creates temporary download files in a directory with insecure permissions. This could allow any authenticated attacker on Windows to disrupt the update process.