Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1804 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.47% | — | Lucky Lm-520-scAILucky Lm-520-fscAILucky Lm-520-fsc-samAI | 9/6/2025 | 17/6/2026 | A vulnerability classified as problematic was found in Lucky LM-520-SC, LM-520-FSC and LM-520-FSC-SAM up to 20250321. Affected by this vulnerability is an unknown functionality. The manipulation leads to missing authentication. The attack can be launched remotely. The exploit has been disclosed to the public and may… | |
| Aplazada | Alta (8.7) | 0.58% | — | Tar-fsAI | 2/6/2025 | 17/6/2026 | tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.0.9, 2.1.3, and 1.16.5 have an issue where an extract can write outside the specified dir with a specific tarball. This has been patched in versions 3.0.9, 2.1.3, and 1.16.5. As a workaround, use the ignore option to ignore non files/directories. | |
| Aplazada | Alta (8.8) | 0.43% | — | Offsprout Page BuilderAI | 31/5/2025 | 17/6/2026 | The Offsprout Page Builder plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization placed on the permission_callback() function in versions 2.2.1 to 2.15.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to read, create, update or delete… | |
| Aplazada | Alta (7.1) | 0.28% | — | Reifsnyderb Document Management SystemAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reifsnyderb Document Management System dms allows Reflected XSS.This issue affects Document Management System: from n/a through <= 1.24. | |
| Aplazada | Alta (7.1) | 0.22% | — | Thewebhunter Offset WritingAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in twh offset writing allows Reflected XSS.This issue affects offset writing: from n/a through 1.2. | |
| Analizada | Media (6.5) | 0.25% | — | Seaweedfs | 16/5/2025 | 17/6/2026 | seaweedfs v3.68 was discovered to contain a SQL injection vulnerability via the component /abstract_sql/abstract_sql_store.go. | |
| Analizada | Alta (7.5) | 0.48% | — | Dell Powerscale Onefs | 15/5/2025 | 17/6/2026 | Dell PowerScale OneFS, versions 9.4.0.0 through 9.9.0.0, contains an uncontrolled resource consumption vulnerability. A remote unprivileged attacker could potentially exploit this vulnerability, leading to denial of service. | |
| Modificada | Media (5.4) | 1.3% | — | Netgate Pfsense CENetgate Pfsense Plus | 14/5/2025 | 5/7/2026 | Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross-site scripting (XSS) in the Automatic Configuration Backup (ACB) service, allowing remote attackers to execute arbitrary JavaScript, delete backups, or leak sensitive information via an unsanitized "reason" field and… | |
| Analizada | Alta (8.8) | 12% | — | Netgate Pfsense CENetgate Pfsense Plus | 14/5/2025 | 17/6/2026 | Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to improper sanitization of user-supplied input to the OpenVPN management interface. An authenticated attacker can exploit this vulnerability by injecting arbitrary OpenVPN… | |
| Analizada | Media (5.4) | 8.5% | — | Netgate Pfsense CENetgate Pfsense Plus | 14/5/2025 | 17/6/2026 | Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XSS) in widgets/log.widget.php. | |
| Analizada | Alta (8.1) | 45% | — | Zohocorp Manageengine Adselfservice Plus | 14/5/2025 | 17/6/2026 | Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports. | |
| Analizada | Media (5.5) | 0.22% | — | Dell Powerscale Onefs | 8/5/2025 | 17/6/2026 | Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.1.0, contains an out-of-bounds write vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to denial of service. | |
| Analizada | Media (6.3) | 0.16% | — | Dell Powerscale Onefs | 8/5/2025 | 17/6/2026 | Dell PowerScale OneFS, versions 9.8.0.0 through 9.10.1.0, contain a time-of-check time-of-use (TOCTOU) race condition vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to denial of service and information tampering. | |
| Aplazada | Baja (2.9) | 0.17% | — | ObfstrAI | 2/5/2025 | 17/6/2026 | In the obfstr crate before 0.4.4 for Rust, the obfstr! argument type is not restricted to string slices, leading to invalid UTF-8 conversion that produces an invalid value. | |
| Aplazada | Alta (7.1) | 0.14% | — | Offshorewebmaster Availability CalendarAI | 24/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Steve Availability Calendar availability allows Stored XSS.This issue affects Availability Calendar: from n/a through <= 0.2.4. | |
| Aplazada | Media (4.7) | 0.14% | — | Arctera Veritas Data InsightAIDell Isilon OnefsAI | 16/4/2025 | 17/6/2026 | Arctera/Veritas Data Insight before 7.1.2 can send cleartext credentials when configured to use HTTP Basic Authentication to a Dell Isilon OneFS server. | |
| Aplazada | Alta (8.3) | 0.31% | — | Fs-code FS PosterAI | 16/4/2025 | 17/6/2026 | Missing Authorization vulnerability in fs-code FS Poster fs-poster.This issue affects FS Poster: from n/a through <= 6.5.8. | |
| Aplazada | Alta (7.1) | 0.23% | — | Fs-code FS PosterAI | 15/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fs-code FS Poster fs-poster allows Reflected XSS.This issue affects FS Poster: from n/a through <= 6.5.8. | |
| Analizada | Crítica (9.8) | 0.47% | — | Dell Powerscale Onefs | 10/4/2025 | 17/6/2026 | Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.0, contains a use of default password vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to the takeover of a high privileged user account. | |
| Analizada | Alta (7.5) | 0.45% | — | Dell Powerscale Onefs | 10/4/2025 | 17/6/2026 | Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.0, contains an uncontrolled resource consumption vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service. | |
| Analizada | Baja (3.1) | 0.25% | — | Dell Powerscale Onefs | 10/4/2025 | 17/6/2026 | Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an out-of-bounds write vulnerability. An attacker could potentially exploit this vulnerability in NFS workflows, leading to data integrity issues. | |
| Analizada | Alta (7) | 0.15% | — | Dell Powerscale Onefs | 10/4/2025 | 17/6/2026 | Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an incorrect authorization vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability to access the cluster with previous privileges of a disabled user account. | |
| Analizada | Baja (3.3) | 0.16% | — | Dell Powerscale Onefs | 10/4/2025 | 17/6/2026 | Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an exposure of information through directory listing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure. | |
| Analizada | Media (6.5) | 0.37% | — | Dell Powerscale Onefs | 10/4/2025 | 17/6/2026 | Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an integer overflow or wraparound vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service. | |
| Aplazada | Media (5.4) | 0.15% | — | Elfsight Testimonials SliderAI | 31/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in elfsight Elfsight Testimonials Slider elfsight-testimonials-slider allows Cross Site Request Forgery.This issue affects Elfsight Testimonials Slider: from n/a through <= 1.0.1. |