Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
2344 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.44% | — | Disable-right-click-powered-by-pixtermeAIPixter-image-digital-licenseAI | 14/8/2025 | 17/6/2026 | The disable-right-click-powered-by-pixterme through v1.2 and pixter-image-digital-license thtough v1.0 WordPress plugins load a JavaScript file which has been compromised from an apparent abandoned S3 bucket. It can be used as a backdoor by those who control it, but it currently displays an alert marketing security… | |
| Analizada | Alta (7.8) | 0.52% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Powerpoint | 12/8/2025 | 17/6/2026 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | |
| Aplazada | Media (6.8) | 0.10% | — | Siemens Power Meter Sicam Q100AISiemens Power Meter Sicam Q200AI | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA01-2AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA31-0AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA31-2AA1) (All… | |
| Aplazada | Media (5.3) | 0.83% | — | Powered Blue 870AI | 8/8/2025 | 17/6/2026 | Powered BLUE 870 versions 0.20130927 and prior contain an OS command injection vulnerability. If this vulnerability is exploited, arbitrary OS commands may be executed on the affected product. | |
| Analizada | Media (5.1) | 0.22% | — | Alfasado Powercms | 31/7/2025 | 17/6/2026 | Multiple versions of PowerCMS allow unrestricted upload of dangerous files. If a product administrator accesses a malicious file uploaded by a product user, an arbitrary script may be executed on the browser. | |
| Analizada | Media (4.8) | 0.25% | — | Alfasado Powercms | 31/7/2025 | 17/6/2026 | Multiple versions of PowerCMS improperly neutralize formula elements in a CSV file. If a product user creates a malformed entry and a victim user downloads it as a CSV file and opens it in the user's environment, the embedded code may be executed. | |
| Analizada | Alta (8.6) | 0.58% | 💥 PoC | Alfasado Powercms | 31/7/2025 | 17/6/2026 | A path traversal issue exists in backup and restore feature of multiple versions of PowerCMS. A product administrator may execute arbitrary code by restoring a crafted backup file. | |
| Analizada | Media (5.3) | 0.38% | — | Alfasado Powercms | 31/7/2025 | 17/6/2026 | A path traversal issue exists in file uploading feature of multiple versions of PowerCMS. Arbitrary files may be overwritten by a product user. | |
| Analizada | Media (5.1) | 0.18% | — | Alfasado Powercms | 31/7/2025 | 17/6/2026 | Stored cross-site scripting vulnerability exists in multiple versions of PowerCMS. If a product user accesses a malicious page, an arbitrary script may be executed on the browser. | |
| Analizada | Media (5.3) | 0.19% | — | Alfasado Powercms | 31/7/2025 | 17/6/2026 | Reflected cross-site scripting vulnerability exists in multiple versions of PowerCMS. If a product administrator accesses a crafted URL, an arbitrary script may be executed on the browser. | |
| Analizada | Media (6.5) | 0.35% | — | Dell Powerprotect Data Manager | 30/7/2025 | 17/6/2026 | Dell PowerProtect Data Manager, versions prior to 19.19, contain(s) an Improper Input Validation vulnerability in PowerProtect Data Manager. A low privileged attacker with remote access could potentially exploit this vulnerability to read arbitrary files. | |
| Aplazada | Alta (8.8) | 0.61% | — | Powerstick Wave Dual-band Wifi ExtenderAI | 28/7/2025 | 5/7/2026 | An authenticated remote code execution vulnerability in PowerStick Wave Dual-Band Wifi Extender V1.0 allows an attacker with valid credentials to execute arbitrary commands with root privileges. The issue stems from insufficient sanitization of user-supplied input in the /cgi-bin/cgi_vista.cgi executable, which is… | |
| Aplazada | Media (6) | 0.28% | — | Typo3 PowermailAI | 22/7/2025 | 17/6/2026 | The powermail extension for TYPO3 allows Insecure Direct Object Reference resulting in download of arbitrary files from the webserver. This issue affects powermail version 12.0.0 up to 12.5.2 and version 13.0.0 | |
| Analizada | Media (4.9) | 0.21% | — | Dell Powerscale Onefs | 21/7/2025 | 17/6/2026 | Dell PowerScale OneFS, versions prior to 9.11.0.0, contains a use of a broken or risky cryptographic algorithm vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Aplazada | Alta (7.5) | 0.24% | — | Powerdns RecursorAI | 21/7/2025 | 17/6/2026 | An attacker spoofing answers to ECS enabled requests sent out by the Recursor has a chance of success higher than non-ECS enabled queries. The updated version include various mitigations against spoofing attempts of ECS enabled queries by chaining ECS enabled requests and enforcing stricter validation of the received… | |
| Analizada | Media (6.5) | 0.27% | — | Dell Powerflex Manager | 9/7/2025 | 17/6/2026 | Dell PowerFlex Manager VM, versions prior to 4.6.2.1, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed… | |
| Analizada | Alta (7.8) | 0.41% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Powerpoint | 8/7/2025 | 17/6/2026 | Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7) | 0.35% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Outlook+2 | 8/7/2025 | 17/6/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (5.4) | 0.26% | — | Pwrplugins Powerfolio | 4/7/2025 | 17/6/2026 | The Portfolio for Elementor & Image Gallery | PowerFolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom JS Attributes of Plugin's widgets in all versions up to, and including, 3.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Analizada | Alta (7.2) | 0.65% | — | Dell Solutions Enabler Virtual ApplianceDell Unisphere FOR Powermax Virtual Appliance | 27/6/2025 | 17/6/2026 | Dell Unisphere for PowerMax vApp, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. | |
| Analizada | Alta (7.5) | 0.48% | — | Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+5 | 25/6/2025 | 17/6/2026 | Autel MaxiCharger AC Wallbox Commercial PIN Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. Authentication is not required to exploit this… | |
| Analizada | Alta (8.8) | 0.39% | — | Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+5 | 25/6/2025 | 17/6/2026 | Autel MaxiCharger AC Wallbox Commercial DLB_SlaveRegister Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Wallbox Commercial EV chargers. Authentication is not required to… | |
| Analizada | Media (6.8) | 0.34% | — | Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+5 | 25/6/2025 | 17/6/2026 | Autel MaxiCharger AC Wallbox Commercial autocharge Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected affected installations of Autel MaxiCharger AC Wallbox Commercial EV chargers. Authentication is not required… | |
| Analizada | Media (6.8) | 0.34% | — | Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+5 | 25/6/2025 | 17/6/2026 | Autel MaxiCharger AC Wallbox Commercial wLength Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Wallbox Commercial EV chargers. Authentication is not required to exploit this… | |
| Analizada | Alta (8.8) | 0.39% | — | Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+5 | 25/6/2025 | 17/6/2026 | Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Wallbox Commercial EV chargers. Authentication is not required… |