Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
1459 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.5% | — | Mbconnectline Mbnet.mini FirmwareHelmholz REX 100 Firmware | 15/10/2024 | 17/6/2026 | An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication. | |
| Modificada | Alta (7.8) | 0.09% | — | Mbconnectline Mbnet.mini FirmwareHelmholz Myrex24 V2 Virtual ServerHelmholz REX 300 FirmwareHelmholz REX 200 Firmware+11 | 15/10/2024 | 17/6/2026 | An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used. | |
| Modificada | Alta (7.8) | 0.31% | — | Mbconnectline Mbnet.mini FirmwareHelmholz REX 100 Firmware | 15/10/2024 | 17/6/2026 | An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation. | |
| Analizada | Media (6.9) | 0.32% | — | 1234n Minicms | 27/9/2024 | 17/6/2026 | A vulnerability was found in bg5sbk MiniCMS 1.11. It has been classified as problematic. Affected is an unknown function of the file page-edit.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The… | |
| Analizada | Media (6.9) | 0.36% | — | 1234n Minicms | 27/9/2024 | 17/6/2026 | A vulnerability was found in bg5sbk MiniCMS up to 1.11 and classified as problematic. This issue affects some unknown processing of the file post-edit.php. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Crítica (9.8) | 0.59% | — | Jianbo Rest API TO Miniprogram | 25/9/2024 | 17/6/2026 | The REST API TO MiniProgram plugin for WordPress is vulnerable to privilege escalation via account takeovr in all versions up to, and including, 4.7.1 via the updateUserInfo() due to missing validation on the 'openid' user controlled key that determines what user will be updated. This makes it possible for… | |
| Modificada | Alta (7.5) | 3.8% | 💥 Exploit | Jianbo Rest API TO Miniprogram | 25/9/2024 | 17/6/2026 | The REST API TO MiniProgram plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/watch-life-net/v1/comment/getcomments REST API endpoint in all versions up to, and including, 4.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on… | |
| Analizada | Media (6.5) | 0.20% | — | Lenovo Xclarity Administrator | 13/9/2024 | 17/6/2026 | A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device through a specially crafted web API call. | |
| Analizada | Media (4.3) | 0.34% | — | Lenovo Xclarity Administrator | 13/9/2024 | 17/6/2026 | A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privileges. | |
| Analizada | Media (6.5) | 0.73% | — | Haxx CurlDebian LinuxNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility+6 | 11/9/2024 | 17/6/2026 | When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine. If the returned status reports another error than 'revoked' (like for… | |
| Modificada | Alta (7.5) | 67% | — | OpensslNetapp Active IQ Unified ManagerManagement Services FOR Element Software AND Netapp HCINetapp Ontap 9+15 | 3/9/2024 | 17/6/2026 | Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service.… | |
| Analizada | Media (5.3) | 0.63% | 💥 PoC | Miniorange WEB Application Firewall | 31/8/2024 | 17/6/2026 | The Web Application Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.1.2. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header… | |
| Aplazada | Media (5.4) | 0.25% | — | Mini Inventory AND Sales Management SystemAI | 21/8/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the component /email/welcome.php of Mini Inventory and Sales Management System commit 18aa3d allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter. | |
| Modificada | Media (5.9) | 0.19% | — | Google Nest Mini FirmwareHaxx Libcurl | 19/8/2024 | 17/6/2026 | The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-middle attack on requests to Google cloud services by any host the traffic was routed through. | |
| Modificada | Alta (7.5) | 0.63% | — | Rust-bitcoin Miniscript | 19/8/2024 | 17/6/2026 | The Miniscript (aka rust-miniscript) library before 12.2.0 for Rust allows stack consumption because it does not properly track tree depth. | |
| Analizada | Media (6.9) | 0.55% | — | Forip Administracao Pabx | 5/8/2024 | 17/6/2026 | A vulnerability was found in ForIP Tecnologia Administração PABX 1.x. It has been rated as critical. Affected by this issue is some unknown functionality of the file /authMonitCallcenter of the component monitcallcenter. The manipulation of the argument user leads to sql injection. The attack may be launched remotely.… | |
| Modificada | Crítica (9.8) | 0.97% | — | Alykoshin Mini-deep-assign | 30/7/2024 | 17/6/2026 | Prototype Pollution in alykoshin mini-deep-assign v0.0.8 allows an attacker to execute arbitrary code or cause a Denial of Service (DoS) and cause other impacts via the _assign() method at (/lib/index.js:91) | |
| Modificada | Media (5.3) | 0.40% | — | Forip Administracao Pabx | 25/7/2024 | 17/6/2026 | A vulnerability classified as critical has been found in ForIP Tecnologia Administração PABX 1.x. Affected is an unknown function of the file /detalheIdUra of the component Lista Ura Page. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Aplazada | Media (6.9) | 0.45% | — | Forip Administracao PabxAI | 25/7/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in ForIP Tecnologia Administração PABX 1.x. This issue affects some unknown processing of the file /login of the component Authentication Form. The manipulation of the argument usuario leads to sql injection. The attack may be initiated remotely. The… | |
| Aplazada | Media (6.3) | 0.28% | — | Opentext Netiq Directory AND Resource AdministratorAI | 16/7/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Access vulnerability in OpenText NetIQ Directory and Resource Administrator. This issue affects NetIQ Directory and Resource Administrator versions prior to 10.0.2 and prior to 9.2.1 Patch 10. | |
| Modificada | Alta (7.5) | 1.0% | 💥 PoC | CertifiManagement Services FOR Element Software AND Netapp HCINetapp Ontap Select Deploy Administration UtilityNetapp Ontap Tools | 5/7/2024 | 17/6/2026 | Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.5.30 and prior to 2024.7.4 recognized root certificates from `GLOBALTRUST`. Certifi 2024.7.04 removes root certificates from `GLOBALTRUST` from… | |
| Modificada | Alta (8.1) | 100% | 💥 Exploit | Sonicwall SMA 6200 FirmwareSonicwall SMA 7200 FirmwareArista EOSCanonical Ubuntu Linux+49 | 1/7/2024 | 1/9/2026 | A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period. | |
| Analizada | Alta (7.8) | 0.12% | — | HP Elitebook 745 G4 FirmwareHP Elitebook 745 G5 FirmwareHP Elitebook 745 G6 FirmwareHP Elitebook 755 G4 Firmware+349 | 28/6/2024 | 17/6/2026 | A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability. | |
| Modificada | Media (5.5) | 0.16% | — | Monoprice Select Mini 3D Printer V2 Firmware | 12/6/2024 | 17/6/2026 | Improper input validation of printing files in Monoprice Select Mini V2 V37.115.32 allows attackers to instruct the device's movable parts to destinations that exceed the devices' maximum coordinates via the printing of a malicious .gcode file. | |
| Analizada | Media (4.8) | 0.15% | — | Siemens TIA Administrator | 11/6/2024 | 17/6/2026 | A vulnerability has been identified in TIA Administrator (All versions < V3 SP2). The affected component creates temporary download files in a directory with insecure permissions. This could allow any authenticated attacker on Windows to disrupt the update process. |