Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
933 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.76% | — | Zabbix | 12/8/2024 | 17/6/2026 | Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine. | |
| Modificada | Alta (8.1) | 0.61% | — | Zabbix | 12/8/2024 | 17/6/2026 | The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text. | |
| Modificada | Baja (2.7) | 0.57% | — | Zabbix | 12/8/2024 | 17/6/2026 | Setting SMS media allows to set GSM modem file. Later this file is used as Linux device. But due everything is a file for Linux, it is possible to set another file, e.g. log file and zabbix_server will try to communicate with it as modem. As a result, log file will be broken with AT commands and small part for log… | |
| Modificada | Crítica (9.1) | 1.6% | — | Zabbix | 12/8/2024 | 17/6/2026 | Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web nor on Zabbix server side. Attacker can run test of SMS providing specially crafted phone number and execute additional AT commands on modem. | |
| Analizada | Media (6.1) | 0.23% | — | Zabbix | 12/8/2024 | 17/6/2026 | A non-admin user can change or remove important features within the Zabbix Agent application, thus impacting the integrity and availability of the application. | |
| Modificada | Alta (7.2) | 1.6% | — | Zabbix | 12/8/2024 | 17/6/2026 | An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section. The lack of default escaping for script parameters enabled this user ability to execute arbitrary code via the Ping script, thereby compromising infrastructure. | |
| Modificada | Media (4.3) | 0.59% | — | Zabbix | 12/8/2024 | 17/6/2026 | User with no permission to any of the Hosts can access and view host count & other statistics through System Information Widget in Global View Dashboard. | |
| Analizada | Media (5.9) | 0.33% | — | Devsabbirahmed Simple Form | 30/7/2024 | 17/6/2026 | The FormFlow: WhatsApp Social and Advanced Form Builder with Easy Lead Collection WordPress plugin before 2.12.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed… | |
| Analizada | Alta (8.8) | 0.37% | — | ABB Advabuild | 23/7/2024 | 17/6/2026 | AdvaBuild uses a command queue to launch certain operations. An attacker who gains access to the command queue can use it to launch an attack by running any executable on the AdvaBuild node. The executables that can be run are not limited to AdvaBuild specific executables. Improper Privilege Management vulnerability… | |
| Analizada | Alta (7.8) | 0.13% | — | ABB Advabuild | 23/7/2024 | 17/6/2026 | An attacker could exploit the vulnerability by injecting garbage data or specially crafted data. Depending on the data injected each process might be affected differently. The process could crash or cause communication issues on the affected node, effectively causing a denial-of-service attack. The attacker could… | |
| Modificada | Media (6.2) | 0.18% | — | ABB Mint Workbench | 15/7/2024 | 17/6/2026 | Unquoted Search Path or Element vulnerability in ABB Mint Workbench. A local attacker who successfully exploited this vulnerability could gain elevated privileges by inserting an executable file in the path of the affected service. This issue affects Mint Workbench I versions: from 5866 before 5868. | |
| Modificada | Crítica (9.4) | 19% | 💥 Exploit | ABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+15 | 5/7/2024 | 17/6/2026 | Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to execute arbitrary code remotely | |
| Modificada | Crítica (9.4) | 17% | 💥 Exploit | ABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+15 | 5/7/2024 | 17/6/2026 | Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to access files unauthorized | |
| Analizada | Alta (8.7) | 1.5% | 💥 Exploit | ABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+9 | 1/7/2024 | 17/6/2026 | Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured. | |
| Analizada | Media (6.9) | 0.26% | — | ABB 800xa Base System | 21/6/2024 | 17/6/2026 | Improper Input Validation vulnerability in ABB 800xA Base. An attacker who successfully exploited this vulnerability could cause services to crash by sending specifically crafted messages. This issue affects 800xA Base: from 6.0.0 through 6.1.1-2. | |
| Analizada | Media (6.3) | 0.30% | — | Softlabbd Integrate Google Drive | 12/6/2024 | 17/6/2026 | Missing Authorization vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.3. | |
| Modificada | Media (5.3) | 0.34% | — | Softlabbd Radio Player | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73. | |
| Modificada | Alta (8.8) | 0.33% | — | Yoginetwork Rabbitloader | 10/6/2024 | 17/6/2026 | Missing Authorization vulnerability in RabbitLoader.This issue affects RabbitLoader: from n/a through 2.19.13. | |
| Modificada | Crítica (9.8) | 0.36% | — | Softlabbd Upload Fields FOR Wpforms | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in SoftLab Upload Fields for WPForms.This issue affects Upload Fields for WPForms: from n/a through 1.0.2. | |
| Aplazada | Media (5.3) | 0.33% | — | Softlabbd Integrate Google DriveAI | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.9. | |
| Modificada | Alta (7.3) | 0.14% | — | ABB 2tma310010b0001 FirmwareABB 2tma310011b0001 FirmwareABB 2tma310011b0002 FirmwareABB 2tma310010b0003 Firmware+1 | 5/6/2024 | 17/6/2026 | Replay Attack in ABB, Busch-Jaeger, FTS Display (version 1.00) and BCU (version 1.3.0.33) allows attacker to capture/replay KNX telegram to local KNX Bus-System | |
| Modificada | Alta (7.3) | 0.27% | — | ABB 2tma310010b0001 FirmwareABB 2tma310011b0001 FirmwareABB 2tma310011b0002 FirmwareABB 2tma310010b0003 Firmware+1 | 5/6/2024 | 17/6/2026 | FDSK Leak in ABB, Busch-Jaeger, FTS Display (version 1.00) and BCU (version 1.3.0.33) allows attacker to take control via access to local KNX Bus-System | |
| Modificada | Crítica (9.8) | 0.41% | — | Softlabbd Integrate Google Drive | 4/6/2024 | 17/6/2026 | Broken Authentication vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.93. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Sc8380xp Firmware+9 | 3/6/2024 | 17/6/2026 | Memory corruption while creating a LPAC client as LPAC engine was allowed to access GPU registers. | |
| Analizada | Alta (8.8) | 0.10% | — | Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+64 | 3/6/2024 | 17/6/2026 | Memory corruption in Hypervisor when platform information mentioned is not aligned. |