Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2723▼ 319 respecto a la semana anterior
Críticas / altas1277▼ 191 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)210▼ 117 respecto a la semana anterior
–

883 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.83%—Suntront Smart Table Integrated Management System1/9/202317/6/2026
Se ha encontrado una vulnerabilidad, clasificada como crítica, en Xintian Smart Table Integrated Management System v5.6.9. Afecta a una parte desconocida del archivo "/SysManage/AddUpdateRole.aspx". La manipulación del argumento "txtRoleName" conduce a una inyección SQL. El exploit ha sido revelado al público y puede…
ModificadaMedia (6.1)0.38%—Codebard's Patron Button AND Widgets FOR Patreon5/8/202317/6/2026
Vulnerabilidad de Cross-Site Scripting (XSS) reflejado sin necesidad de autenticación en el plugin CodeBard CodeBard's Patron Button and Widgets for Patreon en versiones anteriores, e incluyendo, la 2.1.8.
ModificadaAlta (8.8)0.88%—Istrong Four Mountain Torrent Disaster Prevention, Control Monitoring AND Early Warning System20/7/202317/6/2026
A vulnerability, which was classified as critical, was found in Gen Technology Four Mountain Torrent Disaster Prevention and Control of Monitoring and Early Warning System up to 20230712. This affects an unknown part of the file /Duty/AjaxHandle/UploadFloodPlanFileUpdate.ashx. The manipulation of the argument Filedata…
ModificadaAlta (7.5)0.62%—Crestron Cp3n 6505417 FirmwareCrestron CP3 6504877 FirmwareCrestron Cp3-gv 6506034 Firmware17/7/202317/6/2026
On Crestron 3-Series Control Systems before 1.8001.0187, crafting and sending a specific BACnet packet can cause a crash.
AnalizadaCrítica (9.8)0.92%—Unitronics Vision1210 Firmware13/7/202317/6/2026
Embedded malicious code vulnerability in Vision1210, in the build 5 of operating system version 4.3, which could allow a remote attacker to store base64-encoded malicious code in the device's data tables via the PCOM protocol, which can then be retrieved by a client and executed on the device.
ModificadaCrítica (9.8)1.1%—Voltronicpower Snmp WEB PRO12/7/202317/6/2026
The authentication mechanism in PowerShield SNMP Web Pro 1.1 contains a vulnerability that allows unauthenticated users to directly access Common Gateway Interface (CGI) scripts without proper identification or authorization. This vulnerability arises from a lack of proper cookie verification and affects all instances…
ModificadaCrítica (9.8)0.96%—Istrong Mountain Flood Disaster Prevention Monitoring AND Early Warning System11/7/202317/6/2026
A vulnerability, which was classified as critical, has been found in Suncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System up to 20230706. This issue affects some unknown processing of the file /Duty/AjaxHandle/UpLoadFloodPlanFile.ashx of the component UpLoadFloodPlanFile. The manipulation…
ModificadaCrítica (9.8)0.96%—Istrong Mountain Flood Disaster Prevention Monitoring AND Early Warning System11/7/202317/6/2026
A vulnerability classified as critical was found in Suncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System up to 20230706. This vulnerability affects unknown code of the file /Duty/AjaxHandle/Write/UploadFile.ashx of the component Duty Write-UploadFile. The manipulation of the argument…
ModificadaCrítica (9.8)0.91%—Istrong Mountain Flood Disaster Prevention Monitoring AND Early Warning System11/7/202317/6/2026
A vulnerability was found in Suncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System up to 20230704. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Duty/AjaxHandle/UploadHandler.ashx of the component Duty Module. The manipulation of the…
ModificadaMedia (5.4)0.54%—Tarteaucitron11/7/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository amauric/tarteaucitron.js prior to v1.13.1.
ModificadaMedia (6.1)0.49%—Softmedyazilim Selfpatron10/7/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Softmed SelfPatron allows Reflected XSS. This issue affects SelfPatron : before 2.0.
ModificadaCrítica (9.8)0.88%—Softmedyazilim Selfpatron10/7/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Softmed SelfPatron allows SQL Injection. This issue affects SelfPatron : before 2.0.
ModificadaAlta (8.8)0.79%💥 PoCHeroelectronix Qubo Hcd01 FirmwareHeroelectronix Qubo Hcd02 Firmware4/7/202317/6/2026
Hero Qubo HCD01_02_V1.38_20220125 devices allow TELNET access with root privileges by default, without a password.
ModificadaAlta (8.8)28%—Medtronic Paceart Optima29/6/202317/6/2026
Deserialization of untrusted data in Microsoft Messaging Queuing Service in Medtronic's Paceart Optima versions 1.11 and earlier on Windows allows an unauthorized user to impact a healthcare delivery organization’s Paceart Optima system cardiac device causing data to be deleted, stolen, or modified, or the Paceart…
ModificadaMedia (5.4)0.37%—Wpchill Strong Testimonials16/6/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WPChill Strong Testimonials plugin <= 3.0.2 versions.
ModificadaCrítica (9.8)0.93%—Hitrontech Coda-5310 Firmware2/6/202317/6/2026
It is identified a vulnerability of insufficient authentication in the system configuration interface of Hitron Technologies CODA-5310. An unauthorized remote attacker can exploit this vulnerability to access system configuration interface, resulting in performing arbitrary system operation or disrupt service.
ModificadaCrítica (9.8)0.85%—Hitrontech Coda-5310 Firmware2/6/202317/6/2026
Hitron Technologies CODA-5310 Telnet function with the default account and password, and there is no warning or prompt to ask users to change the default password and account. An unauthenticated remote attackers can exploit this vulnerability to obtain the administrator’s privilege, resulting in performing arbitrary…
ModificadaAlta (7.5)0.49%—Hitrontech Coda-5310 Firmware2/6/202317/6/2026
Hitron Technologies CODA-5310’s Telnet function transfers sensitive data in plaintext. An unauthenticated remote attacker can exploit this vulnerability to access credentials of normal users and administrator.
ModificadaAlta (7.2)0.51%—Hitrontech Coda-5310 Firmware2/6/202317/6/2026
Hitron CODA-5310 has hard-coded encryption/decryption keys in the program code. A remote attacker authenticated as an administrator can decrypt system files using the hard-coded keys for file access, modification, and cause service disruption.
ModificadaAlta (7.2)1.3%—Hitrontech Coda-5310 Firmware2/6/202317/6/2026
Hitron CODA-5310 has insufficient filtering for specific parameters in the connection test function. A remote attacker authenticated as an administrator, can use the management page to perform command injection attacks, to execute arbitrary system command, manipulate system or disrupt service.
ModificadaCrítica (9.8)0.71%—Agtteknik Ceppatron25/5/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AGT Tech Ceppatron allows Command Line Execution through SQL Injection, SQL Injection. This issue affects all versions of the sofware also EOS when CVE-ID assigned.
ModificadaMedia (5.5)0.33%—Electronic Flexihub24/5/202317/6/2026
A vulnerability classified as problematic has been found in FlexiHub 5.5.14691.0. This affects the function 0x220088 in the library fusbhub.sys of the component IoControlCode Handler. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the…
ModificadaAlta (8.8)0.26%—Trinitronic Nice Paypal Button Lite23/4/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in TriniTronic Nice PayPal Button Lite plugin <= 1.3.5 versions.
ModificadaCrítica (9.8)2.3%—Strongswan15/4/202317/6/2026
strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two different purposes within the same function. There is initially incorrect access control, later followed by an expired pointer dereference. One attack vector is sending an untrusted client certificate…
ModificadaMedia (6.5)0.64%—Wisdomgarden Tronclass Ilearn27/3/202317/6/2026
WisdomGarden Tronclass has improper access control when uploading file. An authenticated remote attacker with general user privilege can exploit this vulnerability to access files belonging to other users by modifying the file ID within URL.