Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

822 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.86%—Cisco Staros9/5/202317/6/2026
A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of user-supplied credentials. An attacker could exploit this vulnerability by sending a…
ModificadaAlta (8.8)1.3%—Mitrastar Gpt-2741gnac-n2 Firmware5/5/202317/6/2026
MitraStar GPT-2741GNAC-N2 with firmware BR_g5.9_1.11(WVK.0)b32 was discovered to contain a remote code execution (RCE) vulnerability in the ping function.
ModificadaAlta (7.8)0.43%—Serenity SereneSerenity Startsharp27/4/202317/6/2026
An issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. Password reset links are sent by email. A link contains a token that is used to reset the password. This token remains valid even after the password reset and can be used a second time to change the password of the corresponding user. The token…
ModificadaMedia (5.3)1.0%—Serenity SereneSerenity Startsharp27/4/202317/6/2026
An issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. When a password reset request occurs, the server response leaks the existence of users. If one tries to reset a password of a non-existent user, an error message indicates that this user does not exist.
ModificadaMedia (6.1)0.78%—Serenity SereneSerenity Startsharp27/4/202317/6/2026
An XSS issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. When users upload temporary files, some specific file endings are not allowed, but it is possible to upload .html or .htm files containing an XSS payload. The resulting link can be sent to an administrator user.
ModificadaAlta (7.5)1.3%—Encode Starlette21/4/202315/7/2026
There MultipartParser usage in Encode's Starlette python framework before versions 0.25.0 allows an unauthenticated and remote attacker to specify any number of form fields or files which can cause excessive memory usage resulting in denial of service of the HTTP service.
ModificadaMedia (5.3)0.47%—Stargate-bukkit Project Stargate-bukkit19/4/202317/6/2026
Stargate-Bukkit is a mod for the minecraft video game which adds a portal focused environment. In affected versions Minecarts with chests will drop their items when teleporting through a portal; when they reappear, they will still have their items impacting the integrity of the game world. The teleport code has since…
ModificadaMedia (6.5)7.6%💥 ExploitSupremainc Biostar 229/3/20239/7/2026
Suprema BioStar 2 v2.8.16 was discovered to contain a SQL injection vulnerability via the values parameter at /users/absence?search_month=1.
ModificadaAlta (8.8)0.27%—Universal Star Rating Project Universal Star Rating17/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Chasil Universal Star Rating plugin <= 2.1.0 version.
ModificadaMedia (6.1)0.38%—Yasr - YET Another Stars Rating Project Yasr - YET Another Stars Rating16/3/202317/6/2026
Cross-Site Scripting (XSS) vulnerability in Dario Curvino Yasr – Yet Another Stars Rating plugin <= 3.1.2 versions.
ModificadaAlta (7.5)0.60%—Saysis Starcities10/3/202317/6/2026
Files or Directories Accessible to External Parties vulnerability in Saysis Starcities allows Collect Data from Common Resource Locations. This issue affects Starcities: through 1.3.
ModificadaCrítica (9.8)0.66%—Saysis Starcities10/3/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saysis Starcities allows SQL Injection. This issue affects Starcities: through 1.3.
ModificadaMedia (6.1)0.38%—Saysis Starcities6/3/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saysis Computer Starcities allows Cross-Site Scripting (XSS). This issue affects Starcities: before 1.1.
ModificadaAlta (7.8)0.42%💥 PoCStarsoftcomm Coocare3/3/202317/6/2026
starsoftcomm CooCare 5.304 allows local attackers to escalate privileges and execute arbitrary commands via a crafted file upload.
ModificadaAlta (7.5)1.0%—Starliteproject Starlite15/2/202317/6/2026
Starlite is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 1.5.2, the request body parsing in `starlite` allows a potentially unauthenticated attacker to consume a large amount of CPU time and RAM. The multipart body parser processes an unlimited number of file parts and an unlimited…
ModificadaAlta (7.3)1.5%💥 PoCRockstargames Grand Theft Auto V22/1/202317/6/2026
Grand Theft Auto V for PC allows attackers to achieve partial remote code execution or modify files on a PC, as exploited in the wild in January 2023.
ModificadaAlta (7.5)0.54%—Yeastar N824 FirmwareYeastar N412 Firmware20/1/202317/6/2026
In Yeastar N412 and N824 Configuration Panel 42.x and 45.x, an unauthenticated attacker can create backup file and download it, revealing admin hash, allowing, once cracked, to login inside the Configuration Panel, otherwise, replacing the hash in the archive and restoring it on the device which will change admin…
ModificadaMedia (4.8)0.53%—404 TO Start Project 404 TO Start9/1/202317/6/2026
The 404 to Start WordPress plugin through 1.6.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
ModificadaAlta (8.8)0.92%—Kadencewp Starter Templates9/1/202317/6/2026
The Starter Templates by Kadence WP WordPress plugin before 1.2.17 unserialises the content of an imported file, which could lead to PHP object injection issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.
ModificadaCrítica (9.8)1.1%—Starcounter-jack Json-patch25/12/202217/6/2026
A vulnerability has been found in Starcounter-Jack JSON-Patch up to 3.1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). The attack can be initiated remotely. The exploit has…
ModificadaMedia (6.1)0.53%—Starter-public-edition-4 Project Starter-public-edition-417/12/202217/6/2026
A vulnerability was found in starter-public-edition-4 up to 4.6.10. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 4.6.11 is able to address this issue. The name of the patch is…
ModificadaAlta (7.8)0.21%—Siemens Star-ccm+13/12/202217/6/2026
A vulnerability has been identified in Simcenter STAR-CCM+ (All versions < V2306). The affected application improperly assigns file permissions to installation folders. This could allow a local attacker with an unprivileged account to override or modify the service executables and subsequently gain elevated privileges.
ModificadaAlta (7.8)0.19%—HP Jumpstart12/12/202217/6/2026
A potential security vulnerability has been identified in the HP Jumpstart software, which might allow escalation of privilege. HP is recommending that customers uninstall HP Jumpstart and use myHP software.
ModificadaMedia (5.4)0.50%—Dinstar Dag2000-16o Firmware28/11/202217/6/2026
Dinstar FXO Analog VoIP Gateway DAG2000-16O is vulnerable to Cross Site Scripting (XSS).
ModificadaMedia (6.1)0.55%—Fivestarplugins Five Star Restaurant Reservations21/11/202217/6/2026
The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated users to change the payment status of arbitrary bookings. Furthermore, due to the lack of sanitisation and escaping, attackers could…
Orbitaley — Vulnerabilidades