Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
46 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.25% | — | Magnigenie RestropressAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Magnigenie RestroPress restropress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RestroPress: from n/a through <= 3.2.8. | |
| Modificada | Media (5.4) | 0.28% | — | Magnigenie Restropress | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MagniGenie RestroPress allows Stored XSS.This issue affects RestroPress: from n/a through 3.1.2.1. | |
| Aplazada | Crítica (9.9) | 25% | 💥 PoC | Netgear GenieAI | 14/5/2024 | 17/6/2026 | A path traversal issue potentially leading to remote code execution in Genie for all versions prior to 4.3.18 | |
| Aplazada | Media (5.4) | 0.21% | — | Magnigenie RestropressAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in MagniGenie RestroPress.This issue affects RestroPress: from n/a through 3.1.2. | |
| Modificada | Alta (8.2) | 0.60% | — | Geniecompany Aladdin Connect Garage Door Opener Firmware | 3/1/2024 | 17/6/2026 | Unauthenticated access permitted to web interface page The Genie Company Aladdin Connect (Retrofit-Kit Model ALDCM) "Garage Door Control Module Setup" and modify the Garage door's SSID settings. | |
| Modificada | Alta (8.8) | 0.55% | — | Geniecompany Aladdin Connect Garage Door Opener Firmware | 3/1/2024 | 17/6/2026 | When the Genie Company Aladdin Connect garage door opener (Retrofit-Kit Model ALDCM) is placed into configuration mode the web servers “Garage Door Control Module Setup” page is vulnerable to XSS via a broadcast SSID name containing malicious code with client side Java Script and/or HTML. This allows the attacker to… | |
| Modificada | Media (6.8) | 0.42% | — | Geniecompany Aladdin Connect | 3/1/2024 | 17/6/2026 | Users’ product account authentication data was stored in clear text in The Genie Company Aladdin Connect Mobile Application Version 5.65 Build 2075 (and below) on Android Devices. This allows the attacker, with access to the android device, to potentially retrieve users' clear text authentication credentials. | |
| Modificada | Media (6.1) | 0.39% | — | Bugfinder Icogenie | 22/7/2023 | 17/6/2026 | A vulnerability was found in Bug Finder ICOGenie 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /user/ticket/create of the component Support Ticket Handler. The manipulation of the argument message leads to cross site scripting. The attack can be initiated remotely.… | |
| Modificada | Media (4.3) | 0.42% | — | Jenkins Opsgenie | 30/6/2022 | 17/6/2026 | Jenkins OpsGenie Plugin 1.9 and earlier transmits API keys in plain text as part of the global Jenkins configuration form and job configuration forms, potentially resulting in their exposure. | |
| Modificada | Media (4.3) | 0.59% | — | Jenkins Opsgenie | 30/6/2022 | 17/6/2026 | Jenkins OpsGenie Plugin 1.9 and earlier stores API keys unencrypted in its global configuration file and in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission (config.xml), or access to the Jenkins controller file system. | |
| Modificada | Crítica (9.8) | 22% | 💥 Exploit | Genieacs | 6/3/2022 | 17/6/2026 | In GenieACS 1.2.x before 1.2.8, the UI interface API is vulnerable to unauthenticated OS command injection via the ping host argument (lib/ui/api.ts and lib/ping.ts). The vulnerability arises from insufficient input validation combined with a missing authorization check. | |
| Modificada | Media (5.4) | 0.60% | — | Magnigenie WP Responsive Menu | 28/2/2022 | 17/6/2026 | The WP Responsive Menu WordPress plugin before 3.1.7.1 does not have capability and CSRF checks in the wpr_live_update AJAX action, as well as do not sanitise and escape some of the data submitted. As a result, any authenticated, such as subscriber could update the plugin's settings and perform Cross-Site Scripting… | |
| Modificada | Alta (7.8) | 0.29% | — | Netgear Genie Installer | 30/12/2021 | 17/6/2026 | All known versions of the Netgear Genie Installer for macOS contain a local privilege escalation vulnerability. The installer of the macOS version of Netgear Genie handles certain files in an insecure way. A malicious actor who has local access to the endpoint on which the software is going to be installed may… | |
| Modificada | Media (6.5) | 0.55% | — | Genie WP Favicon Project Genie WP Favicon | 8/11/2021 | 17/6/2026 | The Genie WP Favicon WordPress plugin through 0.5.2 does not have CSRF in place when updating the favicon, which could allow attackers to make a logged in admin change it via a CSRF attack | |
| Modificada | Media (6.1) | 6.9% | 💥 Exploit | Cyberoamworks Netgenie C0101b1-20141120-ng11vo Firmware | 17/8/2021 | 17/6/2026 | Cyberoam NetGenie C0101B1-20141120-NG11VO devices through 2021-08-14 allow tweb/ft.php?u=[XSS] attacks. | |
| Modificada | Alta (7.5) | 1.2% | — | Netgear Genie | 28/4/2020 | 17/6/2026 | The NETGEAR genie application before 2.4.34 for Android is affected by mishandling of hard-coded API keys and session IDs. | |
| Modificada | Media (6.1) | 1.1% | — | Thebuggenie THE BUG Genie | 11/2/2020 | 16/6/2026 | The Bug Genie before 3.2.6 has Multiple XSS and HTML Injection Vulnerabilities | |
| Modificada | Alta (7.5) | 11% | 💥 Exploit | Genieaccess Wip3bvaf Firmware | 17/6/2019 | 17/6/2026 | Genie Access WIP3BVAF WISH IP 3MP IR Auto Focus Bullet Camera devices through 3.x are vulnerable to directory traversal via the web interface, as demonstrated by reading /etc/shadow. NOTE: this product is discontinued, and its final firmware version has this vulnerability (4.x versions exist only for other Genie… | |
| Modificada | Media (5.4) | 0.27% | — | Elokence Akinator THE Genie Free | 9/9/2014 | 17/6/2026 | The Akinator the Genie FREE (aka com.digidust.elokence.akinator.freemium) application 2.46 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5) | 1.2% | — | Thebuggenie THE BUG Genie | 24/9/2011 | 16/6/2026 | The Bug Genie 2.1.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/svn_integration/config.inc.php and certain other files. | |
| Modificada | Media (6.5) | 2.3% | — | Nilesh Dosooye Phpcodegenie | 31/12/2004 | 16/6/2026 | Direct static code injection vulnerability in the PCG simple application generation in phpCodeGenie before 3.0.2 allows remote authenticated users to execute arbitrary code via the (1) header or (2) footer. |