Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

2344 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.3)0.27%—Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+525/6/202517/6/2026
Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Misinterpretation of Input Vulnerability. This vulnerability allows network-adjacent attackers to inject arbitrary AT commands on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. Authentication is not required to exploit…
AnalizadaAlta (7.5)0.28%—Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+525/6/202517/6/2026
Autel MaxiCharger AC Wallbox Commercial Firmware Downgrade Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. An attacker must first obtain the ability to pair a…
AnalizadaAlta (7.5)0.17%—Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+525/6/202517/6/2026
Autel MaxiCharger AC Wallbox Commercial Origin Validation Error Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Autel MaxiCharger AC Wallbox Commercial. An attacker must first obtain the ability to pair a malicious…
AnalizadaMedia (6.5)0.55%—Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+525/6/202517/6/2026
Autel MaxiCharger AC Wallbox Commercial Serial Number Exposed Dangerous Method Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Autel MaxiCharger AC Wallbox Commercial EV chargers. Authentication is required to exploit this…
AnalizadaAlta (8.8)0.41%—Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+525/6/202517/6/2026
Autel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. An attacker must first obtain a low-privileged…
AplazadaMedia (4.9)0.20%—Blubrry Powerpress PodcastingAI20/6/202517/6/2026
Server-Side Request Forgery (SSRF) vulnerability in blubrry PowerPress Podcasting powerpress allows Server Side Request Forgery.This issue affects PowerPress Podcasting: from n/a through <= 11.13.11.
AnalizadaAlta (7.8)0.19%—Dell Powerscale Onefs20/6/202517/6/2026
Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.1, contains an improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service, information disclosure, and…
AnalizadaCrítica (9.8)0.50%—Dell Powerscale Onefs20/6/202517/6/2026
Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.1, contains a missing authorization vulnerability in the NFS export. An unauthenticated attacker with remote access could potentially exploit this vulnerability leading to unauthorized filesystem access. The attacker may be able to read, modify, and delete…
AnalizadaAlta (7.5)1.1%—Microsoft Visual Studio 2022Microsoft .netMicrosoft Powershell13/6/202517/6/2026
Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
ModificadaAlta (7.5)1.4%—Xmlsoft Libxml2Redhat Jboss Core ServicesRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR Arm64+1612/6/202518/9/2026
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.
AplazadaAlta (8.3)0.25%—Sungrowpower IsolarcloudAI11/6/202517/6/2026
SunGrow's back end users system iSolarCloud https://isolarcloud.com uses an MQTT service to transport data from the user's connected devices to the user's web browser. The MQTT server however did not have sufficient restrictions in place to limit the topics that a user could subscribe to. While the data that is…
AnalizadaAlta (7.8)2.4%💥 ExploitMicrosoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Powerpoint10/6/202517/6/2026
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
AnalizadaCrítica (9.8)1.2%—Microsoft Power Automate FOR Desktop5/6/202517/6/2026
Exposure of sensitive information to an unauthorized actor in Power Automate allows an unauthorized attacker to elevate privileges over a network.
AplazadaMedia (4.8)0.23%—Techpowerup Gpu-zAI29/5/202517/6/2026
A vulnerability, which was classified as problematic, was found in TechPowerUp GPU-Z 2.23.0. Affected is the function sub_140001880 in the library GPU-Z.sys of the component 0x8000645C IOCTL Handler. The manipulation leads to memory leak. It is possible to launch the attack on the local host. The exploit has been…
AnalizadaMedia (6.5)0.31%—Dell Powerstoreos28/5/202511/9/2026
Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privileged attacker with remote access, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to gain unauthorized access based on the hardcoded…
AplazadaBaja (2.1)1.2%—Netcore Nbr1005gpev2AINetcore B6v2AINetcore Cover5AINetcore Nap830AI+425/5/202517/6/2026
A vulnerability, which was classified as critical, was found in Netcore NBR1005GPEV2, B6V2, COVER5, NAP830, NAP930, NBR100V2, NBR200V2 and POWER13 up to 20250508. This affects an unknown part of the file /www/cgi-bin/ of the component Query String Handler. The manipulation leads to command injection. It is possible to…
AplazadaAlta (7.5)0.61%—Powerdns DnsdistAI20/5/202517/6/2026
In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a single, incoming TCP connection from a client, an attacker can cause a denial of service by crafting a TCP exchange that triggers an exhaustion of the stack and a crash of DNSdist, causing a denial of service. The remedy is:…
AnalizadaMedia (4.8)0.31%—Blubrry Powerpress15/5/202517/6/2026
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its settings when adding a podcast, which could allow admin users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
AnalizadaAlta (7.5)0.48%—Dell Powerscale Onefs15/5/202517/6/2026
Dell PowerScale OneFS, versions 9.4.0.0 through 9.9.0.0, contains an uncontrolled resource consumption vulnerability. A remote unprivileged attacker could potentially exploit this vulnerability, leading to denial of service.
AnalizadaMedia (6.1)0.42%—Lichess Powertip.ts15/5/202517/6/2026
powertip.ts in Lila (for Lichess) before ab0beaf allows XSS in some applications because of an innerHTML usage pattern in which text is extracted from a DOM node and interpreted as HTML.
AnalizadaAlta (7.5)2.0%—Microsoft Power Apps8/5/202517/6/2026
Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network
AnalizadaMedia (5.5)0.22%—Dell Powerscale Onefs8/5/202517/6/2026
Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.1.0, contains an out-of-bounds write vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to denial of service.
AnalizadaMedia (6.3)0.16%—Dell Powerscale Onefs8/5/202517/6/2026
Dell PowerScale OneFS, versions 9.8.0.0 through 9.10.1.0, contain a time-of-check time-of-use (TOCTOU) race condition vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to denial of service and information tampering.
AplazadaAlta (7.5)2.3%—Nghttp2AIH2OAIPowerdns DnsdistAI29/4/202517/6/2026
When DNSdist is configured to provide DoH via the nghttp2 provider, an attacker can cause a denial of service by crafting a DoH exchange that triggers an illegal memory access (double-free) and crash of DNSdist, causing a denial of service. The remedy is: upgrade to the patched 1.9.9 version. A workaround is to…
AnalizadaBaja (3.4)0.15%—Dell Powerprotect Data Manager28/4/202517/6/2026
Dell PowerProtect Data Manager Reporting, version(s) 19.17, 19.18 contain(s) an Improper Encoding or Escaping of Output vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to inject arbitrary web script or html in reporting outputs.