Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

822 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.60%—Supremainc Biostar 23/8/202317/6/2026
A SQL injection vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows authenticated users to inject arbitrary SQL directives into an SQL statement and execute arbitrary SQL commands.
ModificadaAlta (7.5)0.73%—Supremainc Biostar 23/8/202317/6/2026
A path traversal vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated attackers to fetch arbitrary files from the server's web server.
ModificadaAlta (8.8)1.6%—Supremainc Biostar 23/8/202317/6/2026
An OS Command injection vulnerability exists in Suprema BioStar 2 before V2.9.1, which allows authenticated users to execute arbitrary OS commands on the BioStar 2 server.
ModificadaAlta (7.5)0.56%—Supremainc Biostar 23/8/202317/6/2026
An authentication bypass vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated users to access some functionality on BioStar 2 servers.
ModificadaMedia (6.1)0.41%—Fivestarplugins Five Star Restaurant Menu25/7/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FiveStarPlugins Five Star Restaurant Reservations plugin <= 2.6.7 versions.
ModificadaAlta (8.8)0.26%—Fivestarplugins Five Star Restaurant Menu17/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in FiveStarPlugins Restaurant Menu and Food Ordering plugin <= 2.4.6 versions.
ModificadaMedia (6.1)0.60%—Instareza Mail Control12/7/202317/6/2026
The Mail Control plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 0.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute…
ModificadaCrítica (9.8)0.56%—Johnsoncontrols Istar Ultra FirmwareJohnsoncontrols Istar Ultra LT FirmwareJohnsoncontrols Istar Ultra G2 FirmwareJohnsoncontrols Edge G2 Firmware11/7/202317/6/2026
An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.
ModificadaAlta (8.1)4.4%💥 ExploitStarface15/6/202317/6/2026
RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the SHA512 hash of the password instead of the cleartext password. While storing password hashes instead of cleartext passwords in an application's database generally has become best practice to protect…
ModificadaMedia (6.1)0.38%—Zestard Admin Side Data Storage FOR Contact Form 715/6/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Zestard Technologies Admin side data storage for Contact Form 7 plugin <= 1.1.1 versions.
ModificadaAlta (7.2)22%💥 PoCMitrastar Gpt-2741gnac Firmware6/6/20239/7/2026
A command injection vulnerability was found in the ping functionality of the MitraStar GPT-2741GNAC router (firmware version AR_g5.8_110WVN0b7_2). The vulnerability allows an authenticated user to execute arbitrary OS commands by sending specially crafted input to the router via the ping function.
ModificadaAlta (7.5)2.0%—Encode Starlette1/6/202317/6/2026
Directory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthenticated attacker to view files in a web service which was built using Starlette.
ModificadaAlta (8.8)0.26%—Brainstormforce Starter Templates23/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Starter Templates plugin <= 3.1.20 versions.
ModificadaAlta (8.8)0.86%—Supremainc Biostar 222/5/202317/6/2026
Suprema BioStar 2 before 2022 Q4, v2.9.1 has Insecure Permissions. A vulnerability in the web application allows an authenticated attacker with "User Operator" privileges to create a highly privileged user account. The vulnerability is caused by missing server-side validation, which can be exploited to gain full…
ModificadaBaja (3.3)0.49%—Microsoft Azure ARC Jumpstart18/5/202317/6/2026
Azure Arc Jumpstart Information Disclosure Vulnerability
ModificadaAlta (7.1)0.49%—Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware11/5/202317/6/2026
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User interaction, such as a phishing attack, is required for successful exploitation of this vulnerability.
ModificadaAlta (7.1)0.49%—Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware11/5/202317/6/2026
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User interaction, such as a phishing attack, is required for successful exploitation of this vulnerability.
ModificadaMedia (5.9)0.62%—Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware11/5/202317/6/2026
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the…
ModificadaMedia (5.9)0.62%—Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware11/5/202317/6/2026
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the…
ModificadaMedia (5.9)0.62%—Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware11/5/202317/6/2026
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the…
ModificadaMedia (5.9)0.62%—Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware11/5/202317/6/2026
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the…
ModificadaMedia (5.9)0.62%—Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware11/5/202317/6/2026
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the…
ModificadaMedia (6.5)0.62%—Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware11/5/202317/6/2026
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product A cross site scripting vulnerability was discovered that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User interaction, such as a phishing attack, is…
ModificadaMedia (6.1)0.49%—Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware11/5/202317/6/2026
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User interaction, such as a phishing attack, is required for successful exploitation of this vulnerability.
ModificadaMedia (5.9)0.62%—Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware11/5/202317/6/2026
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the…