Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.6) | 0.47% | — | Acer Connect M6E 5G Firmware | 4/6/2026 | 22/7/2026 | The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +) to enumerate hidden network devices or publish rogue control commands. | |
| Analizada | Crítica (10) | 0.56% | — | Acer Connect M6E 5G Firmware | 4/6/2026 | 22/7/2026 | The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection. | |
| Modificada | Media (5.4) | 0.68% | — | Braekling Connect Matomo | 22/9/2023 | 17/6/2026 | The WP-Matomo Integration (WP-Piwik) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wp-piwik' shortcode in versions up to, and including, 1.0.28 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Media (4.3) | 0.28% | — | Mitel Connect Mobility Router | 14/9/2023 | 17/6/2026 | A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2304.102 could allow an unauthenticated attacker to perform a Cross Site Request Forgery (CSRF) attack due to insufficient request validation. A successful exploit could allow an attacker to provide a modified URL,… | |
| Modificada | Media (5.5) | 0.17% | — | Intel Connect M | 10/5/2023 | 17/6/2026 | Uncontrolled resource consumption in the Intel(R) Connect M Android application before version 1.82 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Alta (7.8) | 0.16% | — | Intel Connect M | 10/5/2023 | 17/6/2026 | Improper access control in the Intel(R) Connect M Android application before version 1.82 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.19% | — | Intel Connect M | 18/8/2022 | 17/6/2026 | Incorrect default permissions for the Intel(R) Connect M Android application before version 1.7.4 may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Alta (7.8) | 1.4% | — | Connect-multiparty Project Connect-multiparty | 16/5/2022 | 17/6/2026 | An arbitrary file upload vulnerability in the file upload module of Express Connect-Multiparty 2.2.0 allows attackers to execute arbitrary code via a crafted PDF file. NOTE: the Supplier has not verified this vulnerability report. | |
| Modificada | Media (6.5) | 0.65% | — | Dell EMC Powerconnect 8024 FirmwareDell EMC Powerconnect 7000 FirmwareDell EMC Powerconnect M6348 FirmwareDell EMC Powerconnect M6220 Firmware+2 | 20/8/2019 | 17/6/2026 | Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability. TACACS\Radius credentials are stored in plain text in the system settings menu. An authenticated malicious user with access to the system settings menu may… | |
| Modificada | Media (5.4) | 0.27% | — | Healthways Well-being Connect Mobile | 27/9/2014 | 17/6/2026 | The Well-Being Connect Mobile (aka com.healthways.wellbeinggo) application 2.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |