Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
160 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.3) | 1.0% | — | Blackbeartechhive Atop Ehg2408 FirmwareBlackbeartechhive Atop Ehg2408-2sfp Firmware | 9/3/2026 | 7/7/2026 | EHG2408 series switch developed by Atop Technologies has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and execute arbitrary code. | |
| Aplazada | Baja (1.7) | 0.19% | — | MKJ DropbearAI | 8/3/2026 | 17/6/2026 | A vulnerability was determined in mkj Dropbear up to 2025.89. Impacted is the function unpackneg of the file src/curve25519.c of the component S Range Check. This manipulation causes improper verification of cryptographic signature. The attack can be initiated remotely. The attack is considered to have high… | |
| Aplazada | Media (5.4) | 0.38% | — | DropbearAI | 12/2/2026 | 17/6/2026 | A flaw was found in Dropbear. When running in multi-user mode and authenticating users, the dropbear ssh server does the socket forwardings requested by the remote client as root, only switching to the logged-in user upon spawning a shell or performing some operations like reading the user's files. With the recent… | |
| Aplazada | Alta (8.2) | 0.69% | — | Ziroom Zhome A0101AIDropbear SSHAI | 3/2/2026 | 17/6/2026 | A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the component Dropbear SSH Service. This manipulation causes use of default credentials. Remote exploitation of the attack is possible. The complexity of an attack is rather high. The exploitability is considered… | |
| Aplazada | Crítica (9.3) | 2.6% | — | SickbeardAI | 30/1/2026 | 17/6/2026 | Sickbeard alpha contains a remote command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands through the extra scripts configuration. Attackers can set malicious commands in the extra scripts field and trigger processing to execute remote code on the vulnerable Sickbeard… | |
| Aplazada | Media (5.1) | 0.20% | — | SickbeardAI | 30/1/2026 | 17/6/2026 | Sickbeard alpha contains a cross-site request forgery vulnerability that allows attackers to disable authentication by submitting crafted configuration parameters. Attackers can trick users into submitting a malicious form that clears web username and password, effectively removing authentication protection. | |
| Aplazada | Alta (8.4) | 0.48% | — | Bearshare LiteAI | 29/1/2026 | 17/6/2026 | BearShare Lite 5.2.5 contains a buffer overflow vulnerability in the Advanced Search keywords input that allows attackers to execute arbitrary code. Attackers can craft a specially designed payload to overwrite the EIP register and execute shellcode by pasting malicious content into the search keywords field. | |
| Aplazada | Media (5.5) | 0.38% | — | Ywxbear Php-bookstore-website-exampleAIYwxbear PHP Basic Bookstore WebsiteAI | 11/10/2025 | 17/6/2026 | A vulnerability has been found in ywxbear PHP-Bookstore-Website-Example and PHP Basic BookStore Website up to 0e0b9f542f7a2d90a8d7f8c83caca69294e234e4. This issue affects some unknown processing of the file /index.php of the component Quantity Handler. Such manipulation leads to improper validation of specified… | |
| Aplazada | Crítica (9.8) | 0.66% | — | Beardev JoomsportAI | 3/10/2025 | 17/6/2026 | The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.7.3 via the task parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the… | |
| Analizada | Media (6.5) | 0.53% | — | Smartbear Swagger Petstore | 25/9/2025 | 17/6/2026 | An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server returns a 404-error page exposing sensitive information including the Servlet name (default) and server version | |
| Analizada | Media (6.1) | 0.38% | — | Smartbear Swagger Petstore | 25/9/2025 | 17/6/2026 | Cross Site Scripting vulnerability in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via a crafted script to the /api/v3/pet | |
| Analizada | Media (6.5) | 0.43% | — | Smartbear Swagger Petstore | 25/9/2025 | 17/6/2026 | An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpoint | |
| Aplazada | Crítica (9.8) | 0.76% | — | Bears BackupAI | 17/7/2025 | 17/6/2026 | The Bears Backup plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.0. This is due to the bbackup_ajax_handle() function not having a capability check, nor validating user supplied input passed directly to call_user_func(). This makes it possible for unauthenticated… | |
| Aplazada | Media (6.5) | 0.30% | — | NET DropbearAILibtommathAI | 16/7/2025 | 17/6/2026 | Net::Dropbear versions through 0.16 for Perl contains a dependency that may be susceptible to an integer overflow. Net::Dropbear embeds a version of the libtommath library that is susceptible to an integer overflow associated with CVE-2023-36328. | |
| Aplazada | Media (4.5) | 0.59% | — | Dropbear SSHAI | 7/5/2025 | 17/6/2026 | dbclient in Dropbear SSH before 2025.88 allows command injection via an untrusted hostname argument, because a shell is used. | |
| Analizada | Media (5.1) | 0.60% | — | Mirweiye Seven Bears Library CMS | 16/4/2025 | 17/6/2026 | A vulnerability was found in mirweiye Seven Bears Library CMS 2023. It has been classified as problematic. Affected is an unknown function of the component Add Link Handler. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Aplazada | Media (4.8) | 0.33% | — | Mirweiye Seven Bears Library CMSAI | 16/4/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in mirweiye Seven Bears Library CMS 2023. This affects an unknown part of the component Background Management Page. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Aplazada | Crítica (9) | 0.49% | — | VyosAIDropbearAI | 31/3/2025 | 17/6/2026 | VyOS 1.3 through 1.5 (fixed in 1.4.2) or any Debian-based system using dropbear in combination with live-build has the same Dropbear private host keys across different installations. Thus, an attacker can conduct active man-in-the-middle attacks against SSH connections if Dropbear is enabled as the SSH daemon. I n… | |
| Modificada | Media (4.8) | 0.25% | — | Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional | 17/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 BEAR woo-bulk-editor allows Stored XSS.This issue affects BEAR: from n/a through <= 1.1.4.4. | |
| Aplazada | Media (6.5) | 0.23% | — | Paul Bearne Author AvatarsAI | 9/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Bearne Author Avatars List/Block author-avatars allows Stored XSS.This issue affects Author Avatars List/Block: from n/a through <= 2.1.23. | |
| Aplazada | Alta (7.1) | 0.29% | — | Beardev JoomsportAI | 7/1/2025 | 17/6/2026 | The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page parameter in all versions up to, and including, 5.6.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers… | |
| Analizada | Alta (7.8) | 1.0% | — | Smartbear Soapui | 22/11/2024 | 17/6/2026 | SMARTBEAR SoapUI unpackageAll Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of SMARTBEAR SoapUI. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a… | |
| Modificada | Alta (8.8) | 0.36% | — | Beardev Joomsport | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in beardev JoomSport joomsport-sports-league-results-management.This issue affects JoomSport: from n/a through <= 5.6.3. | |
| Analizada | Alta (8.8) | 0.42% | — | Beardev Joomsport | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in BearDev JoomSport allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JoomSport: from n/a through 5.3.0. | |
| Aplazada | Media (6.5) | 0.26% | — | Paul Bearne Author Avatars List BlockAI | 5/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Bearne Author Avatars List/Block author-avatars allows Stored XSS.This issue affects Author Avatars List/Block: from n/a through <= 2.1.21. |