Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

822 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.98%—Pistar Pi-star Digital Voice Dashboard11/11/202217/6/2026
Pi-Star_DV_Dash (for Pi-Star DV) before 5aa194d mishandles the module parameter.
ModificadaAlta (8.7)1.4%—Siemens Nucleus NETSiemens Nucleus Readystart V3Siemens Nucleus Source CodeSiemens Apogee Modular Building Controller Firmware+1711/10/202217/6/2026
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions < V3.5.7), APOGEE PXC Compact (P2 Ethernet) (All versions <…
ModificadaAlta (8.8)1.1%—Supremainc Biostar 219/9/202217/6/2026
A vulnerability in Suprema BioStar (aka Bio Star) 2 v2.8.16 allows attackers to escalate privileges to System Administrator via a crafted PUT request to the update profile page.
ModificadaCrítica (9.8)0.93%—Globalnorthstar Northstar Club Management16/9/202217/6/2026
There are two full (read/write) Blind/Time-based SQL injection vulnerabilities in the Northstar Club Management version 6.3 application. The vulnerabilities exist in the userName parameter of the processlogin.jsp page in the /northstar/Portal/ directory and the userID parameter of the login.jsp page in the…
ModificadaMedia (5.5)0.25%—MSI Micro-star International Feature Navigator12/9/20229/7/2026
An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to download arbitrary files regardless of file type or size.
ModificadaAlta (7.1)0.26%—MSI Micro-star International Feature Navigator12/9/20229/7/2026
An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to write arbitrary files to the directory \PromoPhoto\, regardless of file type or size.
ModificadaAlta (7.1)0.28%—MSI Micro-star International Feature Navigator12/9/20229/7/2026
An issue in the Feature Navigator of Micro-Star International MSI Feature Nagivator v1.0.1808.0901 allows attackers to cause a Denial of Service (DoS) via a crafted image or video file.
ModificadaCrítica (9.8)2.1%—Johnsoncontrols Istar Ultra Firmware31/8/202217/6/2026
All versions of iSTAR Ultra prior to version 6.8.9.CU01 are vulnerable to a command injection that could allow an unauthenticated user root access to the system.
ModificadaMedia (5.4)0.68%—Getkirby Starterkit18/8/202217/6/2026
A stored cross-site scripting (XSS) vulnerability in Kirby's Starterkit v3.7.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Tags field.
ModificadaMedia (6.9)0.64%—Siemens Simcenter Star-ccm+ Viewer10/8/202214/7/2026
A vulnerability has been identified in Simcenter STAR-CCM+ (All versions only if the Power-on-Demand public license server is used). Affected applications expose user, host and display name of users, when the public license server is used. This could allow an attacker to retrieve this information.
ModificadaMedia (4.3)0.31%—Starfish Rich Review5/8/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Rich Reviews by Starfish plugin <= 1.9.14 at WordPress allows an attacker to delete reviews.
ModificadaAlta (8.8)1.6%—Novastar Novaicare12/7/202217/6/2026
An issue has been discovered in Novastar-VNNOX-iCare Novaicare 7.16.0 that gives attacker privilege escalation and allows attackers to view corporate information and SMTP server details, delete users, view roles, and other unspecified impacts. NOTE: As of April 2026, the vendor has officially decommissioned the…
ModificadaAlta (7.2)1.6%—Yokogawa Stardom FCJ FirmwareYokogawa Stardom FCN Firmware28/6/202217/6/2026
Use of hard-coded credentials vulnerability exists in STARDOM FCN Controller and FCJ Controller R4.10 to R4.31, which may allow an attacker with an administrative privilege to read/change configuration settings or update the controller with tampered firmware.
ModificadaAlta (7.5)0.38%—Yokogawa Stardom FCJ FirmwareYokogawa Stardom FCN Firmware28/6/202217/6/2026
Cleartext transmission of sensitive information vulnerability exists in STARDOM FCN Controller and FCJ Controller R1.01 to R4.31, which may allow an adjacent attacker to login the affected products and alter device configuration settings or tamper with device firmware.
ModificadaAlta (8.1)2.0%💥 PoCCaphyon Advanced Installer3CX Call Flow Designer3CX CRM Template GeneratorBoomtv Streamer Portal+666/6/20229/7/2026
Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected…
ModificadaAlta (8.8)2.3%—Starwindsoftware Starwind SAN & NAS3/6/202217/6/2026
StarWind SAN and NAS v0.2 build 1914 allow remote code execution. A flaw was found in REST API in StarWind Stack. REST command, which allows changing the hostname, doesn’t check a new hostname parameter. It goes directly to bash as part of a script. An attacker with non-root user access can inject arbitrary data into…
ModificadaAlta (7.5)1.3%—Chainsafe Lodestar24/5/202217/6/2026
Lodestar is a TypeScript implementation of the Ethereum Consensus specification. Prior to version 0.36.0, there is a possible consensus split given maliciously-crafted `AttesterSlashing` or `ProposerSlashing` being included on-chain. Because the developers represent `uint64` values as native javascript `number`s,…
ModificadaAlta (7.8)0.39%—Needrestart Project NeedrestartDebian Linux17/5/202217/6/2026
needrestart 0.8 through 3.5 before 3.6 is prone to local privilege escalation. Regexes to detect the Perl, Python, and Ruby interpreters are not anchored, allowing a local user to escalate privileges when needrestart tries to detect if interpreters are using old source files.
ModificadaAlta (8.8)14%💥 ExploitMitrastar Gpt-2541gnac-n1 Firmware3/5/202217/6/2026
MitraStar GPT-2541GNAC-N1 (HGU) 100VNZ0b33 devices allow remote authenticated users to obtain root access by executing command "deviceinfo show file &&/bin/bash" because of incorrect sanitization of parameter "path".
ModificadaCrítica (9.8)1.7%—5 Stars Rating Funnel Project 5 Stars Rating Funnel25/4/202217/6/2026
The 5 Stars Rating Funnel WordPress Plugin | RRatingg WordPress plugin before 1.2.54 does not properly sanitise, validate and escape lead ids before using them in a SQL statement via the rrtngg_delete_leads AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue. There is an…
ModificadaMedia (6.7)0.31%—Cisco Staros6/4/202217/6/2026
A vulnerability in the CLI of Cisco StarOS could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient input validation of CLI commands. An attacker could exploit this vulnerability by sending crafted commands to the CLI. A successful exploit…
ModificadaAlta (7.2)1.6%—Bosch Autodome IP 4000i FirmwareBosch Autodome IP 5000i FirmwareBosch Autodome IP Starlight 5000i FirmwareBosch Autodome IP Starlight 7000i Firmware+6430/3/202217/6/2026
A specially crafted TCP/IP packet may cause the camera recovery image web interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can only be booted with administrative rights or with physical access to the camera and allows the upload of a new firmware in…
ModificadaAlta (7.2)1.6%—Bosch Autodome IP 4000i FirmwareBosch Autodome IP 5000i FirmwareBosch Autodome IP Starlight 5000i FirmwareBosch Autodome IP Starlight 7000i Firmware+6430/3/202217/6/2026
A specially crafted TCP/IP packet may cause a camera recovery image telnet interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can only be booted with administrative rights or with physical access to the camera and allows the upload of a new firmware in…
ModificadaAlta (7.8)0.81%—Siemens Simcenter Star-ccm+ Viewer8/3/202217/6/2026
A vulnerability has been identified in Simcenter STAR-CCM+ Viewer (All versions < V2022.1). The starview+.exe contains a memory corruption vulnerability while parsing specially crafted .SCE files. This could allow an attacker to execute code in the context of the current process.
ModificadaMedia (5.4)0.60%—Fivestarplugins Five Star Business Profile AND Schema21/2/202217/6/2026
The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its bpfwp_welcome_add_contact_page and bpfwp_welcome_set_contact_information AJAX action, allowing any authenticated users, such as subscribers, to call them. Furthermore, due to the lack of…