Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

933 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.76%—Zabbix12/8/202417/6/2026
Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine.
ModificadaAlta (8.1)0.61%—Zabbix12/8/202417/6/2026
The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text.
ModificadaBaja (2.7)0.57%—Zabbix12/8/202417/6/2026
Setting SMS media allows to set GSM modem file. Later this file is used as Linux device. But due everything is a file for Linux, it is possible to set another file, e.g. log file and zabbix_server will try to communicate with it as modem. As a result, log file will be broken with AT commands and small part for log…
ModificadaCrítica (9.1)1.6%—Zabbix12/8/202417/6/2026
Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web nor on Zabbix server side. Attacker can run test of SMS providing specially crafted phone number and execute additional AT commands on modem.
AnalizadaMedia (6.1)0.23%—Zabbix12/8/202417/6/2026
A non-admin user can change or remove important features within the Zabbix Agent application, thus impacting the integrity and availability of the application.
ModificadaAlta (7.2)1.6%—Zabbix12/8/202417/6/2026
An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section. The lack of default escaping for script parameters enabled this user ability to execute arbitrary code via the Ping script, thereby compromising infrastructure.
ModificadaMedia (4.3)0.59%—Zabbix12/8/202417/6/2026
User with no permission to any of the Hosts can access and view host count & other statistics through System Information Widget in Global View Dashboard.
AnalizadaMedia (5.9)0.33%—Devsabbirahmed Simple Form30/7/202417/6/2026
The FormFlow: WhatsApp Social and Advanced Form Builder with Easy Lead Collection WordPress plugin before 2.12.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed…
AnalizadaAlta (8.8)0.37%—ABB Advabuild23/7/202417/6/2026
AdvaBuild uses a command queue to launch certain operations. An attacker who gains access to the command queue can use it to launch an attack by running any executable on the AdvaBuild node. The executables that can be run are not limited to AdvaBuild specific executables. Improper Privilege Management vulnerability…
AnalizadaAlta (7.8)0.13%—ABB Advabuild23/7/202417/6/2026
An attacker could exploit the vulnerability by injecting garbage data or specially crafted data. Depending on the data injected each process might be affected differently. The process could crash or cause communication issues on the affected node, effectively causing a denial-of-service attack. The attacker could…
ModificadaMedia (6.2)0.18%—ABB Mint Workbench15/7/202417/6/2026
Unquoted Search Path or Element vulnerability in ABB Mint Workbench. A local attacker who successfully exploited this vulnerability could gain elevated privileges by inserting an executable file in the path of the affected service. This issue affects Mint Workbench I versions: from 5866 before 5868.
ModificadaCrítica (9.4)19%💥 ExploitABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+155/7/202417/6/2026
Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to execute arbitrary code remotely
ModificadaCrítica (9.4)17%💥 ExploitABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+155/7/202417/6/2026
Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to access files unauthorized
AnalizadaAlta (8.7)1.5%💥 ExploitABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+91/7/202417/6/2026
Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured.
AnalizadaMedia (6.9)0.26%—ABB 800xa Base System21/6/202417/6/2026
Improper Input Validation vulnerability in ABB 800xA Base. An attacker who successfully exploited this vulnerability could cause services to crash by sending specifically crafted messages. This issue affects 800xA Base: from 6.0.0 through 6.1.1-2.
AnalizadaMedia (6.3)0.30%—Softlabbd Integrate Google Drive12/6/202417/6/2026
Missing Authorization vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.3.
ModificadaMedia (5.3)0.34%—Softlabbd Radio Player11/6/202417/6/2026
Missing Authorization vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73.
ModificadaAlta (8.8)0.33%—Yoginetwork Rabbitloader10/6/202417/6/2026
Missing Authorization vulnerability in RabbitLoader.This issue affects RabbitLoader: from n/a through 2.19.13.
ModificadaCrítica (9.8)0.36%—Softlabbd Upload Fields FOR Wpforms9/6/202417/6/2026
Missing Authorization vulnerability in SoftLab Upload Fields for WPForms.This issue affects Upload Fields for WPForms: from n/a through 1.0.2.
AplazadaMedia (5.3)0.33%—Softlabbd Integrate Google DriveAI9/6/202417/6/2026
Missing Authorization vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.9.
ModificadaAlta (7.3)0.14%—ABB 2tma310010b0001 FirmwareABB 2tma310011b0001 FirmwareABB 2tma310011b0002 FirmwareABB 2tma310010b0003 Firmware+15/6/202417/6/2026
Replay Attack in ABB, Busch-Jaeger, FTS Display (version 1.00) and BCU (version 1.3.0.33) allows attacker to capture/replay KNX telegram to local KNX Bus-System
ModificadaAlta (7.3)0.27%—ABB 2tma310010b0001 FirmwareABB 2tma310011b0001 FirmwareABB 2tma310011b0002 FirmwareABB 2tma310010b0003 Firmware+15/6/202417/6/2026
FDSK Leak in ABB, Busch-Jaeger, FTS Display (version 1.00) and BCU (version 1.3.0.33) allows attacker to take control via access to local KNX Bus-System
ModificadaCrítica (9.8)0.41%—Softlabbd Integrate Google Drive4/6/202417/6/2026
Broken Authentication vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.93.
AnalizadaAlta (7.8)0.09%—Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Sc8380xp Firmware+93/6/202417/6/2026
Memory corruption while creating a LPAC client as LPAC engine was allowed to access GPU registers.
AnalizadaAlta (8.8)0.10%—Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+643/6/202417/6/2026
Memory corruption in Hypervisor when platform information mentioned is not aligned.
Orbitaley — Vulnerabilidades