Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2764▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)245▼ 256 respecto a la semana anterior
–

686 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)2.1%💥 ExploitHypercommentsAI5/6/202517/6/2026
The HyperComments plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the hc_request_handler function in all versions up to, and including, 1.2.2. This makes it possible for unauthenticated attackers to update arbitrary…
AplazadaMedia (6.5)0.22%—Mitsubishielectric Genesis64AIMitsubishielectric Iconics SuiteAIMitsubishielectric MobilehmiAIMitsubishielectric Hyper HistorianAI+615/5/202517/6/2026
Execution with Unnecessary Privileges vulnerability in multiple services of Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric MobileHMI versions 10.97.3 and prior, Mitsubishi Electric Hyper Historian versions 10.97.3 and prior,…
AplazadaAlta (8.7)0.28%—Hyperledger BesuAIHyperledger Besu-nativeAI7/5/202517/6/2026
Besu Native contains scripts and tooling that is used to build and package the native libraries used by the Ethereum client Hyperledger Besu. Besu 24.7.1 through 25.2.2, corresponding to besu-native versions 0.9.0 through 1.2.1, have a potential consensus bug for the precompiles ALTBN128_ADD (0x06), ALTBN128_MUL…
AplazadaMedia (6.5)0.27%—Studio Hyperset THE Great Firewords OF ChinaAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Studio Hyperset The Great Firewords of China sensitive-chinese-words-scanner allows Stored XSS.This issue affects The Great Firewords of China: from n/a through <= 1.2.
AplazadaMedia (6.5)0.22%—Daniel Floeter Hyperlink Group BlockAI1/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniel Floeter Hyperlink Group Block hyperlink-group-block allows DOM-Based XSS.This issue affects Hyperlink Group Block: from n/a through <= 2.0.1.
AnalizadaMedia (4.4)0.13%—IBM Powervm Hypervisor28/3/202517/6/2026
IBM PowerVM Hypervisor FW1050.00 through FW1050.30 and FW1060.00 through FW1060.20 could allow a local user, under certain Linux processor combability mode configurations, to cause undetected data loss or errors when performing gzip compression using HW acceleration.
AplazadaAlta (7.1)0.39%—Atelierhyper AumenuAI26/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in atelierhyper AuMenu aumenu allows Reflected XSS.This issue affects AuMenu: from n/a through <= 1.1.5.
AplazadaAlta (7.5)0.52%—Szad670401 HyperlprAI20/3/202517/6/2026
A vulnerability in szad670401/hyperlpr v3.0 allows for a Denial of Service (DoS) attack. The server fails to handle excessive characters appended to the end of multipart boundaries, regardless of the character used. This flaw can be exploited by sending malformed multipart requests with arbitrary characters at the end…
AplazadaCrítica (9.3)0.32%—Hyperbridge Ismp-grandpaAI28/1/202517/6/2026
Hyperbridge is a hyper-scalable coprocessor for verifiable, cross-chain interoperability. A critical vulnerability was discovered in the ismp-grandpa crate, that allowed a malicious prover easily convince the verifier of the finality of arbitrary headers. This could be used to steal funds or compromise other kinds of…
AplazadaAlta (7.1)0.39%—Siteheart HypercommentsAI22/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in siteheart HyperComments comments-with-hypercommentscom allows Reflected XSS.This issue affects HyperComments: from n/a through <= 0.9.6.
AnalizadaMedia (6.6)0.49%—Oracle Hyperion Data Relationship Management21/1/202517/6/2026
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Web Services). The supported version that is affected is 11.2.19.0.000. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Data…
AnalizadaMedia (4.5)0.44%—Oracle Hyperion Data Relationship Management21/1/202517/6/2026
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and Security). The supported version that is affected is 11.2.19.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Data…
AplazadaMedia (4.8)0.44%—Softiron HypercloudAIVM SquaredAI30/12/202417/6/2026
An issue exists in SoftIron HyperCloud where authenticated, but non-admin users can create data pools, which could potentially impact the performance and availability of the backend software-defined storage subsystem. This issue only impacts SoftIron HyperCloud and related software products (such as VM Squared)…
AnalizadaMedia (6.7)0.13%—Dell Vxrail Hyperconverged Infrastructure11/12/202417/6/2026
Dell VxVerify, versions prior to x.40.405, contain a Plain-text Password Storage Vulnerability in the shell wrapper. A local high privileged attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access…
AplazadaAlta (7.8)0.24%—Mitsubishi Electric Iconics Digital Solutions Genesis64AIMitsubishi Electric Iconics Digital Solutions Iconics SuiteAIMitsubishielectric Genesis64AIMitsubishielectric Iconics SuiteAI+528/11/202417/6/2026
Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric Hyper Historian versions 10.97.3 and prior, Mitsubishi Electric GENESIS32 all versions, Mitsubishi Electric MC Works64 all…
AplazadaAlta (7.8)0.24%—Mitsubishielectric Genesis64AIMitsubishielectric Iconics SuiteAIMitsubishielectric Hyper HistorianAIMitsubishielectric Genesis32AI+528/11/202417/6/2026
Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric Hyper Historian versions 10.97.3 and prior, Mitsubishi Electric GENESIS32 all versions, Mitsubishi Electric MC Works64 all…
AnalizadaMedia (5.9)0.35%—IBM Powervm Hypervisor22/11/202417/6/2026
IBM PowerVM Platform KeyStore (IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1030.00 through FW1030.60, FW1050.00 through FW1050.20, and FW1060.00 through FW1060.10 functionality can be compromised if an attacker gains service access to the HMC. An attacker that gains service access to the HMC can locate and…
AplazadaMedia (6.5)0.27%—Daniel Floeter Hyperlink Group BlockAI17/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniel Floeter Hyperlink Group Block hyperlink-group-block allows Stored XSS.This issue affects Hyperlink Group Block: from n/a through <= 1.17.5.
AnalizadaBaja (3)0.37%—Oracle Hyperion BI+15/10/202417/6/2026
Vulnerability in the Oracle Hyperion BI+ product of Oracle Hyperion (component: UI and Visualization). The supported version that is affected is 11.2.18.0.000. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle…
ModificadaAlta (7.2)44%💥 ExploitKemptechnologies LoadmasterKemptechnologies Multi-tenant Hypervisor Firmware5/9/202417/6/2026
Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects: * LoadMaster: 7.2.40.0 and above * ECS: All versions * Multi-Tenancy: 7.1.35.4 and above
AnalizadaMedia (5.3)0.32%—Hyperview Geoportal Toolkit28/8/202417/6/2026
HyperView Geoportal Toolkit in versions lower than 8.5.0 is vulnerable to Reflected Cross-Site Scripting (XSS). An unauthenticated attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser.
AnalizadaMedia (5.3)0.35%—Hyperview Geoportal Toolkit28/8/202417/6/2026
HyperView Geoportal Toolkit in versions lower than 8.5.0 does not restrict cross-domain requests when fetching remote content pointed by one of GET request parameters. An unauthenticated remote attacker can prepare links, which upon opening will load scripts from a remote location controlled by the attacker and…
ModificadaMedia (5.3)0.59%💥 PoCHyperledger Fabric25/8/202417/6/2026
Hyperledger Fabric through 3.0.0 and 2.5.x through 2.5.9 do not verify that a request has a timestamp within the expected time window.
AplazadaMedia (6.7)0.19%—Mitsubishielectric Genesis64AIMitsubishielectric Iconics SuiteAIMitsubishielectric Hyper HistorianAIMitsubishielectric MobilehmiAI+44/7/202417/6/2026
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in the licensing feature of Mitsubishi Electric GENESIS64 versions 10.97.2 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.2 and prior, Mitsubishi Electric Hyper Historian versions 10.97.2 and prior, Mitsubishi…
AplazadaMedia (5.9)0.59%—Mitsubishielectric Genesis64AIMitsubishielectric Iconics SuiteAIMitsubishielectric Hyper HistorianAIMitsubishielectric AnalyticxAI+34/7/202417/6/2026
Missing Authentication for Critical Function vulnerability in the mobile monitoring feature of Mitsubishi Electric GENESIS64 versions 10.97.2 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.2 and prior, Mitsubishi Electric Hyper Historian versions 10.97.2 and prior, Mitsubishi Electric AnalytiX versions…
Orbitaley — Vulnerabilidades