Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
822 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.98% | — | Pistar Pi-star Digital Voice Dashboard | 11/11/2022 | 17/6/2026 | Pi-Star_DV_Dash (for Pi-Star DV) before 5aa194d mishandles the module parameter. | |
| Modificada | Alta (8.7) | 1.4% | — | Siemens Nucleus NETSiemens Nucleus Readystart V3Siemens Nucleus Source CodeSiemens Apogee Modular Building Controller Firmware+17 | 11/10/2022 | 17/6/2026 | A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions < V3.5.7), APOGEE PXC Compact (P2 Ethernet) (All versions <… | |
| Modificada | Alta (8.8) | 1.1% | — | Supremainc Biostar 2 | 19/9/2022 | 17/6/2026 | A vulnerability in Suprema BioStar (aka Bio Star) 2 v2.8.16 allows attackers to escalate privileges to System Administrator via a crafted PUT request to the update profile page. | |
| Modificada | Crítica (9.8) | 0.93% | — | Globalnorthstar Northstar Club Management | 16/9/2022 | 17/6/2026 | There are two full (read/write) Blind/Time-based SQL injection vulnerabilities in the Northstar Club Management version 6.3 application. The vulnerabilities exist in the userName parameter of the processlogin.jsp page in the /northstar/Portal/ directory and the userID parameter of the login.jsp page in the… | |
| Modificada | Media (5.5) | 0.25% | — | MSI Micro-star International Feature Navigator | 12/9/2022 | 9/7/2026 | An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to download arbitrary files regardless of file type or size. | |
| Modificada | Alta (7.1) | 0.26% | — | MSI Micro-star International Feature Navigator | 12/9/2022 | 9/7/2026 | An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to write arbitrary files to the directory \PromoPhoto\, regardless of file type or size. | |
| Modificada | Alta (7.1) | 0.28% | — | MSI Micro-star International Feature Navigator | 12/9/2022 | 9/7/2026 | An issue in the Feature Navigator of Micro-Star International MSI Feature Nagivator v1.0.1808.0901 allows attackers to cause a Denial of Service (DoS) via a crafted image or video file. | |
| Modificada | Crítica (9.8) | 2.1% | — | Johnsoncontrols Istar Ultra Firmware | 31/8/2022 | 17/6/2026 | All versions of iSTAR Ultra prior to version 6.8.9.CU01 are vulnerable to a command injection that could allow an unauthenticated user root access to the system. | |
| Modificada | Media (5.4) | 0.68% | — | Getkirby Starterkit | 18/8/2022 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in Kirby's Starterkit v3.7.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Tags field. | |
| Modificada | Media (6.9) | 0.64% | — | Siemens Simcenter Star-ccm+ Viewer | 10/8/2022 | 14/7/2026 | A vulnerability has been identified in Simcenter STAR-CCM+ (All versions only if the Power-on-Demand public license server is used). Affected applications expose user, host and display name of users, when the public license server is used. This could allow an attacker to retrieve this information. | |
| Modificada | Media (4.3) | 0.31% | — | Starfish Rich Review | 5/8/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Rich Reviews by Starfish plugin <= 1.9.14 at WordPress allows an attacker to delete reviews. | |
| Modificada | Alta (8.8) | 1.6% | — | Novastar Novaicare | 12/7/2022 | 17/6/2026 | An issue has been discovered in Novastar-VNNOX-iCare Novaicare 7.16.0 that gives attacker privilege escalation and allows attackers to view corporate information and SMTP server details, delete users, view roles, and other unspecified impacts. NOTE: As of April 2026, the vendor has officially decommissioned the… | |
| Modificada | Alta (7.2) | 1.6% | — | Yokogawa Stardom FCJ FirmwareYokogawa Stardom FCN Firmware | 28/6/2022 | 17/6/2026 | Use of hard-coded credentials vulnerability exists in STARDOM FCN Controller and FCJ Controller R4.10 to R4.31, which may allow an attacker with an administrative privilege to read/change configuration settings or update the controller with tampered firmware. | |
| Modificada | Alta (7.5) | 0.38% | — | Yokogawa Stardom FCJ FirmwareYokogawa Stardom FCN Firmware | 28/6/2022 | 17/6/2026 | Cleartext transmission of sensitive information vulnerability exists in STARDOM FCN Controller and FCJ Controller R1.01 to R4.31, which may allow an adjacent attacker to login the affected products and alter device configuration settings or tamper with device firmware. | |
| Modificada | Alta (8.1) | 2.0% | 💥 PoC | Caphyon Advanced Installer3CX Call Flow Designer3CX CRM Template GeneratorBoomtv Streamer Portal+66 | 6/6/2022 | 9/7/2026 | Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected… | |
| Modificada | Alta (8.8) | 2.3% | — | Starwindsoftware Starwind SAN & NAS | 3/6/2022 | 17/6/2026 | StarWind SAN and NAS v0.2 build 1914 allow remote code execution. A flaw was found in REST API in StarWind Stack. REST command, which allows changing the hostname, doesn’t check a new hostname parameter. It goes directly to bash as part of a script. An attacker with non-root user access can inject arbitrary data into… | |
| Modificada | Alta (7.5) | 1.3% | — | Chainsafe Lodestar | 24/5/2022 | 17/6/2026 | Lodestar is a TypeScript implementation of the Ethereum Consensus specification. Prior to version 0.36.0, there is a possible consensus split given maliciously-crafted `AttesterSlashing` or `ProposerSlashing` being included on-chain. Because the developers represent `uint64` values as native javascript `number`s,… | |
| Modificada | Alta (7.8) | 0.39% | — | Needrestart Project NeedrestartDebian Linux | 17/5/2022 | 17/6/2026 | needrestart 0.8 through 3.5 before 3.6 is prone to local privilege escalation. Regexes to detect the Perl, Python, and Ruby interpreters are not anchored, allowing a local user to escalate privileges when needrestart tries to detect if interpreters are using old source files. | |
| Modificada | Alta (8.8) | 14% | 💥 Exploit | Mitrastar Gpt-2541gnac-n1 Firmware | 3/5/2022 | 17/6/2026 | MitraStar GPT-2541GNAC-N1 (HGU) 100VNZ0b33 devices allow remote authenticated users to obtain root access by executing command "deviceinfo show file &&/bin/bash" because of incorrect sanitization of parameter "path". | |
| Modificada | Crítica (9.8) | 1.7% | — | 5 Stars Rating Funnel Project 5 Stars Rating Funnel | 25/4/2022 | 17/6/2026 | The 5 Stars Rating Funnel WordPress Plugin | RRatingg WordPress plugin before 1.2.54 does not properly sanitise, validate and escape lead ids before using them in a SQL statement via the rrtngg_delete_leads AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue. There is an… | |
| Modificada | Media (6.7) | 0.31% | — | Cisco Staros | 6/4/2022 | 17/6/2026 | A vulnerability in the CLI of Cisco StarOS could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient input validation of CLI commands. An attacker could exploit this vulnerability by sending crafted commands to the CLI. A successful exploit… | |
| Modificada | Alta (7.2) | 1.6% | — | Bosch Autodome IP 4000i FirmwareBosch Autodome IP 5000i FirmwareBosch Autodome IP Starlight 5000i FirmwareBosch Autodome IP Starlight 7000i Firmware+64 | 30/3/2022 | 17/6/2026 | A specially crafted TCP/IP packet may cause the camera recovery image web interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can only be booted with administrative rights or with physical access to the camera and allows the upload of a new firmware in… | |
| Modificada | Alta (7.2) | 1.6% | — | Bosch Autodome IP 4000i FirmwareBosch Autodome IP 5000i FirmwareBosch Autodome IP Starlight 5000i FirmwareBosch Autodome IP Starlight 7000i Firmware+64 | 30/3/2022 | 17/6/2026 | A specially crafted TCP/IP packet may cause a camera recovery image telnet interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can only be booted with administrative rights or with physical access to the camera and allows the upload of a new firmware in… | |
| Modificada | Alta (7.8) | 0.81% | — | Siemens Simcenter Star-ccm+ Viewer | 8/3/2022 | 17/6/2026 | A vulnerability has been identified in Simcenter STAR-CCM+ Viewer (All versions < V2022.1). The starview+.exe contains a memory corruption vulnerability while parsing specially crafted .SCE files. This could allow an attacker to execute code in the context of the current process. | |
| Modificada | Media (5.4) | 0.60% | — | Fivestarplugins Five Star Business Profile AND Schema | 21/2/2022 | 17/6/2026 | The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its bpfwp_welcome_add_contact_page and bpfwp_welcome_set_contact_information AJAX action, allowing any authenticated users, such as subscribers, to call them. Furthermore, due to the lack of… |