Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.33% | — | Rafalautopilot Ortto AutopilotAI | 2/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rafalautopilot Ortto autopilot allows Reflected XSS.This issue affects Ortto: from n/a through <= 1.0.19. | |
| Analizada | Alta (7.5) | 0.70% | — | Dronecode PX4 Drone Autopilot | 25/6/2024 | 17/6/2026 | PX4-Autopilot v1.14.3 was discovered to contain a buffer overflow via the topic_name parameter at /logger/logged_topics.cpp. | |
| Analizada | Media (6.5) | 0.53% | — | Dronecode PX4 Drone Autopilot | 25/6/2024 | 17/6/2026 | A buffer overflow in PX4-Autopilot v1.12.3 allows attackers to cause a Denial of Service (DoS) via a crafted MavLink message. | |
| Analizada | Media (5.6) | 0.21% | — | Dronecode PX4 Drone Autopilot | 23/4/2024 | 17/6/2026 | PX4 Autopilot v.1.14 allows an attacker to fly the drone into no-fly zones by breaching the geofence using flaws in the function. | |
| Analizada | Media (4.4) | 0.26% | — | Dronecode PX4 Drone Autopilot | 22/4/2024 | 17/6/2026 | An issue in PX4 Autopilot v1.14 and before allows a remote attacker to execute arbitrary code and cause a denial of service via the Breach Return Point function. | |
| Analizada | Media (6.6) | 0.24% | — | Dronecode PX4 Drone Autopilot | 10/4/2024 | 17/6/2026 | An issue in PX4 Autopilot v.1.14.0 allows an attacker to manipulate the flight path allowing for crashes of the drone via the home point location of the mission_block.cpp component. | |
| Modificada | Media (4.2) | 0.34% | — | Dronecode PX4 Drone Autopilot | 6/2/2024 | 17/6/2026 | A Race Condition discovered in geofence.cpp and mission_feasibility_checker.cpp in PX4 Autopilot 1.14 and earlier allows attackers to send drones on unintended missions. | |
| Modificada | Media (4.2) | 0.36% | — | Dronecode PX4 Drone Autopilot | 6/2/2024 | 17/6/2026 | PX4 Autopilot 1.14 and earlier, due to the lack of synchronization mechanism for loading geofence data, has a Race Condition vulnerability in the geofence.cpp and mission_feasibility_checker.cpp. This will result in the drone uploading overlapping geofences and mission routes. | |
| Modificada | Media (4.3) | 0.52% | — | Dronecode PX4 Drone Autopilot | 13/11/2023 | 17/6/2026 | PX4 autopilot is a flight control solution for drones. In affected versions a global buffer overflow vulnerability exists in the CrsfParser_TryParseCrsfPacket function in /src/drivers/rc/crsf_rc/CrsfParser.cpp:298 due to the invalid size check. A malicious user may create an RC packet remotely and that packet goes… | |
| Modificada | Crítica (9.8) | 0.63% | — | Dronecode PX4 Drone Autopilot | 31/10/2023 | 17/6/2026 | PX4-Autopilot provides PX4 flight control solution for drones. In versions 1.14.0-rc1 and prior, PX4-Autopilot has a heap buffer overflow vulnerability in the parser function due to the absence of `parserbuf_index` value checking. A malfunction of the sensor device can cause a heap buffer overflow with leading… | |
| Modificada | Media (5.4) | 0.36% | — | Palantir Apollo Autopilot | 27/9/2023 | 17/6/2026 | In Apollo change requests, comments added by users could contain a javascript URI link that when rendered will result in an XSS that require user interaction. | |
| Modificada | Alta (7.5) | 0.81% | — | Dronecode PX4 Drone Autopilot | 6/7/2023 | 17/6/2026 | Buffer Overflow vulnerability in PX4-Autopilot allows attackers to cause a denial of service via handler function handling msgid 332. | |
| Modificada | Alta (8.8) | 1.3% | — | Xforwoocommerce ADD Product TabsXforwoocommerce Autopilot SEOXforwoocommerce Bulk ADD TO CartXforwoocommerce Comment AND Review Spam Control+12 | 7/6/2023 | 17/6/2026 | Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax_factory function in various versions listed below. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to read, edit, or… | |
| Modificada | Alta (7.5) | 0.96% | — | Dronecode PX4 Drone AutopilotYuneec Mantis Q Firmware | 9/3/2023 | 17/6/2026 | An issue discovered in Yuneec Mantis Q and PX4-Autopilot v 1.11.3 and below allow attacker to gain access to sensitive information via various nuttx commands. | |
| Modificada | Media (5) | 1.0% | — | WHM AutopilotAI | 19/11/2005 | 16/6/2026 | cancel_account.php in WHM AutoPilot 2.5.30 and earlier allows remote attackers to cancel requests for arbitrary accounts via a modified c parameter. | |
| Modificada | Media (4.3) | 4.0% | — | WHM Autopilot | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in header.php in WHM AutoPilot 2.4.6.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) site_title or (2) http_images parameter. | |
| Modificada | Alta (7.5) | 4.2% | — | WHM Autopilot | 31/12/2004 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities (1) step_one.php, (2) step_one_tables.php, (3) step_two_tables.php in WHM AutoPilot 2.4.6.5 and earlier allow remote attackers to execute arbitrary PHP code by modifying the server_inc parameter to reference a URL on a remote web server that contains the code. | |
| Modificada | Media (5) | 7.9% | — | WHM Autopilot | 31/12/2004 | 16/6/2026 | WHM AutoPilot 2.4.6.5 and earlier allows remote attackers to gain sensitive information via phpinfo, which reveals php settings. | |
| Modificada | Media (5) | 1.7% | — | WHM Autopilot | 31/12/2004 | 16/6/2026 | clogin.php in Benchmark Designs' WHM AutoPilot 2.4.5 and earlier allows remote attackers to obtain plaintext username and password credentials by using the clogin_e and base64_encode functions to encode the desired user ID in the c parameter, then read the plaintext values in the resulting form. |