Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
71 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 0.46% | — | Sound4 First Firmware | 19/11/2025 | 17/6/2026 | The Sound4 FIRST web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware update package. The update mechanism fails to validate the integrity of manual.sh, allowing an attacker to inject arbitrary commands by modifying this script and repackaging the firmware. | |
| Aplazada | Media (6.5) | 0.24% | — | Firstnum Jc21a-04AI | 5/8/2025 | 17/6/2026 | An issue was discovered on FIRSTNUM JC21A-04 devices through 2.01ME/FN. They enable the SSH service by default with the credentials of root/admin. The GUI doesn't offer a way to disable the account. | |
| Aplazada | Alta (7.4) | 6.5% | — | Firstnum Jc21a-04AI | 5/8/2025 | 17/6/2026 | An issue was discovered on FIRSTNUM JC21A-04 devices through 2.01ME/FN that allows authenticated attackers to execute arbitrary OS system commands with root privileges via crafted payloads to the xml_action.cgi?method= endpoint. | |
| Aplazada | Alta (7.1) | 0.39% | — | Robin90 First Comment RedirectAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robin90 First Comment Redirect first-comment-redirect allows Reflected XSS.This issue affects First Comment Redirect: from n/a through <= 1.0.3. | |
| Modificada | Alta (7.5) | 1.4% | — | Automaticsystems SOC Fl9600 Firstlane Firmware | 3/1/2024 | 9/7/2026 | Directory Traversal in Automatic Systems SOC FL9600 FirstLane V06 lego_T04E00 allows a remote attacker to obtain sensitive information via csvServer.php?file= with a .. in the dir parameter. | |
| Modificada | Alta (7.5) | 0.86% | — | Automaticsystems SOC Fl9600 Firstlane Firmware | 3/1/2024 | 9/7/2026 | An issue in Automatic Systems SOC FL9600 FirstLane V06 lego_T04E00 allows a remote attacker to obtain sensitive information because there is an automaticsystems super admin account with astech as its hardcoded password. | |
| Modificada | Alta (8.8) | 0.25% | — | Quanticedge First Order Discount Woocommerce | 18/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in QuanticEdge First Order Discount Woocommerce.This issue affects First Order Discount Woocommerce: from n/a through 1.21. | |
| Modificada | Crítica (9.8) | 1.3% | — | C-first Cfr-1004ea FirmwareC-first Cfr-1008ea FirmwareC-first Cfr-1016ea FirmwareC-first Cfr-16eaa Firmware+24 | 16/11/2023 | 17/6/2026 | Missing authentication for critical function vulnerability in First Corporation's DVRs allows a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB, MD-404AB, and… | |
| Modificada | Crítica (9.8) | 1.1% | — | C-first Cfr-1004ea FirmwareC-first Cfr-1008ea FirmwareC-first Cfr-1016ea FirmwareC-first Cfr-16eaa Firmware+24 | 16/11/2023 | 17/6/2026 | First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB, MD-404AB, and MD-808AB. As for the other… | |
| Analizada | Crítica (9.8) | 0.72% | — | Objectfirst Ootbi | 7/11/2022 | 17/6/2026 | An issue was discovered in Object First Ootbi BETA build 1.0.7.712. The authorization service has a flow that allows getting access to the Web UI without knowing credentials. For signing, the JWT token uses a secret key that is generated through a function that doesn't produce cryptographically strong sequences. An… | |
| Analizada | Media (6.5) | 0.56% | — | Objectfirst Ootbi | 7/11/2022 | 17/6/2026 | An issue was discovered in Object First Ootbi BETA build 1.0.7.712. A flaw was found in the Web Service, which could lead to local information disclosure. The command that creates the URL for the support bundle uses an insecure RNG. That can lead to prediction of the generated URL. As a result, an attacker can get… | |
| Analizada | Alta (8.8) | 1.0% | — | Objectfirst Ootbi | 7/11/2022 | 17/6/2026 | An issue was discovered in Object First Ootbi BETA build 1.0.7.712. Management protocol has a flow which allows a remote attacker to execute arbitrary Bash code with root privileges. The command that sets the hostname doesn't validate input parameters. As a result, arbitrary data goes directly to the Bash interpreter.… | |
| Modificada | Crítica (9.8) | 1.3% | — | Firstmall | 25/2/2022 | 17/6/2026 | This issues due to insufficient verification of the various input values from user’s input. The vulnerability allows remote attackers to execute malicious code in Firstmall via navercheckout_add function. | |
| Modificada | Crítica (9.8) | 1.4% | — | Jupyterhub First USE Authenticator | 28/10/2021 | 17/6/2026 | FirstUseAuthenticator is a JupyterHub authenticator that helps new users set their password on their first login to JupyterHub. When JupyterHub is used with FirstUseAuthenticator, a vulnerability in versions prior to 1.0.0 allows unauthorized access to any user's account if `create_users=True` and the username is… | |
| Modificada | Media (6.1) | 1.2% | — | Targetfirst Watcheezy | 24/5/2021 | 17/6/2026 | The Target First WordPress Plugin v2.0, also previously known as Watcheezy, suffers from a critical unauthenticated stored XSS vulnerability. An attacker could change the licence key value through a POST on any URL with the 'weeWzKey' parameter that will be save as the 'weeID option and is not sanitized. | |
| Modificada | Alta (7.5) | 1.3% | — | IBM Mobilefirst Platform Foundation | 27/5/2020 | 17/6/2026 | IBM MobileFirst Platform Foundation 8.0.0.0 stores highly sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 175207. | |
| Modificada | Alta (7.5) | 1.2% | — | Smartmesh Project SmartmeshUgtoken Project UgtokenGG Token Project GG TokenFirst Project First+2 | 10/8/2018 | 17/6/2026 | The transferProxy and approveProxy functions of a smart contract implementation for SmartMesh (SMT), an Ethereum ERC20 token, allow attackers to accomplish an unauthorized transfer of digital assets because replay attacks can occur with the same-named functions (with the same signatures) in other tokens: First (FST),… | |
| Modificada | Media (6.1) | 1.3% | — | IBM Mobilefirst Platform Foundation | 4/4/2018 | 17/6/2026 | IBM Worklight (IBM MobileFirst Platform Foundation 6.3, 7.0, 7.1, and 8.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force… | |
| Modificada | Media (6.4) | 1.2% | — | Oracle Hospitality Simphony First Edition Venue Management | 8/8/2017 | 17/6/2026 | Vulnerability in the Oracle Hospitality Simphony First Edition Venue Management component of Oracle Hospitality Applications (subcomponent: Core). The supported version that is affected is 3.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality… | |
| Modificada | Media (6.1) | 0.78% | — | IBM Mobilefirst Platform FoundationIBM Worklight | 1/8/2017 | 17/6/2026 | A Reflected Cross Site Scripting (XSS) vulnerability exists in the authorization function exposed by RESTful Web Api of IBM Worklight Framework 6.1, 6.2, 6.3, 7.0, 7.1, and 8.0. The vulnerable parameter is "scope"; if you set as its value a "realm" not defined in authenticationConfig.xml, you get an HTTP 403 Forbidden… | |
| Modificada | Media (5.9) | 0.49% | — | Fsbbigfork First State Bank OF Bigfork Mobile Banking | 16/6/2017 | 17/6/2026 | The "First State Bank of Bigfork Mobile Banking" by First State Bank of Bigfork app 4.0.3 -- aka first-state-bank-of-bigfork-mobile-banking/id1133969876 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted… | |
| Modificada | Media (5.9) | 0.49% | — | Fcbl First Citizens Bank-mobile | 16/6/2017 | 17/6/2026 | The "First Citizens Bank-Mobile Banking" by First Citizens Bank (AL) app 3.0.0 -- aka first-citizens-bank-mobile-banking/id566037101 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.9) | 0.49% | — | Meafinancial First Security Bank Sleepy EYE Mobile | 16/6/2017 | 17/6/2026 | The first-security-bank-sleepy-eye-mobile/id870531890 app 3.0.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.9) | 0.49% | — | America's First Federal Credit Union America's First FCU Mobile Banking | 5/5/2017 | 17/6/2026 | The America's First Federal Credit Union (FCU) Mobile Banking app 3.1.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Subsplash First Assembly NLR | 29/9/2014 | 17/6/2026 | The First Assembly NLR (aka com.subsplash.thechurchapp.firstassemblynlr) application 2.8.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |