Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

160 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.3)1.0%—Blackbeartechhive Atop Ehg2408 FirmwareBlackbeartechhive Atop Ehg2408-2sfp Firmware9/3/20267/7/2026
EHG2408 series switch developed by Atop Technologies has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and execute arbitrary code.
AplazadaBaja (1.7)0.19%—MKJ DropbearAI8/3/202617/6/2026
A vulnerability was determined in mkj Dropbear up to 2025.89. Impacted is the function unpackneg of the file src/curve25519.c of the component S Range Check. This manipulation causes improper verification of cryptographic signature. The attack can be initiated remotely. The attack is considered to have high…
AplazadaMedia (5.4)0.38%—DropbearAI12/2/202617/6/2026
A flaw was found in Dropbear. When running in multi-user mode and authenticating users, the dropbear ssh server does the socket forwardings requested by the remote client as root, only switching to the logged-in user upon spawning a shell or performing some operations like reading the user's files. With the recent…
AplazadaAlta (8.2)0.69%—Ziroom Zhome A0101AIDropbear SSHAI3/2/202617/6/2026
A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the component Dropbear SSH Service. This manipulation causes use of default credentials. Remote exploitation of the attack is possible. The complexity of an attack is rather high. The exploitability is considered…
AplazadaCrítica (9.3)2.6%—SickbeardAI30/1/202617/6/2026
Sickbeard alpha contains a remote command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands through the extra scripts configuration. Attackers can set malicious commands in the extra scripts field and trigger processing to execute remote code on the vulnerable Sickbeard…
AplazadaMedia (5.1)0.20%—SickbeardAI30/1/202617/6/2026
Sickbeard alpha contains a cross-site request forgery vulnerability that allows attackers to disable authentication by submitting crafted configuration parameters. Attackers can trick users into submitting a malicious form that clears web username and password, effectively removing authentication protection.
AplazadaAlta (8.4)0.48%—Bearshare LiteAI29/1/202617/6/2026
BearShare Lite 5.2.5 contains a buffer overflow vulnerability in the Advanced Search keywords input that allows attackers to execute arbitrary code. Attackers can craft a specially designed payload to overwrite the EIP register and execute shellcode by pasting malicious content into the search keywords field.
AplazadaMedia (5.5)0.38%—Ywxbear Php-bookstore-website-exampleAIYwxbear PHP Basic Bookstore WebsiteAI11/10/202517/6/2026
A vulnerability has been found in ywxbear PHP-Bookstore-Website-Example and PHP Basic BookStore Website up to 0e0b9f542f7a2d90a8d7f8c83caca69294e234e4. This issue affects some unknown processing of the file /index.php of the component Quantity Handler. Such manipulation leads to improper validation of specified…
AplazadaCrítica (9.8)0.66%—Beardev JoomsportAI3/10/202517/6/2026
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.7.3 via the task parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the…
AnalizadaMedia (6.5)0.53%—Smartbear Swagger Petstore25/9/202517/6/2026
An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server returns a 404-error page exposing sensitive information including the Servlet name (default) and server version
AnalizadaMedia (6.1)0.38%—Smartbear Swagger Petstore25/9/202517/6/2026
Cross Site Scripting vulnerability in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via a crafted script to the /api/v3/pet
AnalizadaMedia (6.5)0.43%—Smartbear Swagger Petstore25/9/202517/6/2026
An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpoint
AplazadaCrítica (9.8)0.76%—Bears BackupAI17/7/202517/6/2026
The Bears Backup plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.0. This is due to the bbackup_ajax_handle() function not having a capability check, nor validating user supplied input passed directly to call_user_func(). This makes it possible for unauthenticated…
AplazadaMedia (6.5)0.30%—NET DropbearAILibtommathAI16/7/202517/6/2026
Net::Dropbear versions through 0.16 for Perl contains a dependency that may be susceptible to an integer overflow. Net::Dropbear embeds a version of the libtommath library that is susceptible to an integer overflow associated with CVE-2023-36328.
AplazadaMedia (4.5)0.59%—Dropbear SSHAI7/5/202517/6/2026
dbclient in Dropbear SSH before 2025.88 allows command injection via an untrusted hostname argument, because a shell is used.
AnalizadaMedia (5.1)0.60%—Mirweiye Seven Bears Library CMS16/4/202517/6/2026
A vulnerability was found in mirweiye Seven Bears Library CMS 2023. It has been classified as problematic. Affected is an unknown function of the component Add Link Handler. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public…
AplazadaMedia (4.8)0.33%—Mirweiye Seven Bears Library CMSAI16/4/202517/6/2026
A vulnerability, which was classified as problematic, was found in mirweiye Seven Bears Library CMS 2023. This affects an unknown part of the component Background Management Page. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the…
AplazadaCrítica (9)0.49%—VyosAIDropbearAI31/3/202517/6/2026
VyOS 1.3 through 1.5 (fixed in 1.4.2) or any Debian-based system using dropbear in combination with live-build has the same Dropbear private host keys across different installations. Thus, an attacker can conduct active man-in-the-middle attacks against SSH connections if Dropbear is enabled as the SSH daemon. I n…
ModificadaMedia (4.8)0.25%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional17/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 BEAR woo-bulk-editor allows Stored XSS.This issue affects BEAR: from n/a through <= 1.1.4.4.
AplazadaMedia (6.5)0.23%—Paul Bearne Author AvatarsAI9/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Bearne Author Avatars List/Block author-avatars allows Stored XSS.This issue affects Author Avatars List/Block: from n/a through <= 2.1.23.
AplazadaAlta (7.1)0.29%—Beardev JoomsportAI7/1/202517/6/2026
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page parameter in all versions up to, and including, 5.6.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
AnalizadaAlta (7.8)1.0%—Smartbear Soapui22/11/202417/6/2026
SMARTBEAR SoapUI unpackageAll Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of SMARTBEAR SoapUI. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a…
ModificadaAlta (8.8)0.36%—Beardev Joomsport1/11/202417/6/2026
Missing Authorization vulnerability in beardev JoomSport joomsport-sports-league-results-management.This issue affects JoomSport: from n/a through <= 5.6.3.
AnalizadaAlta (8.8)0.42%—Beardev Joomsport1/11/202417/6/2026
Missing Authorization vulnerability in BearDev JoomSport allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JoomSport: from n/a through 5.3.0.
AplazadaMedia (6.5)0.26%—Paul Bearne Author Avatars List BlockAI5/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Bearne Author Avatars List/Block author-avatars allows Stored XSS.This issue affects Author Avatars List/Block: from n/a through <= 2.1.21.
Orbitaley — Vulnerabilidades