Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

73 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.3)3.4%—Sound4 Impact FirmwareSound4 Pulse FirmwareSound4 First FirmwareSound4 Impact ECO Firmware+522/12/202517/6/2026
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands through the 'password' parameter. Attackers can exploit the login.php and index.php scripts by injecting shell commands via the 'password' POST parameter to…
ModificadaAlta (8.8)1.2%—Sound4 Impact FirmwareSound4 Pulse FirmwareSound4 First FirmwareSound4 Stream Extension+522/12/202517/6/2026
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated directory traversal vulnerability that allows remote attackers to write arbitrary files through the 'upgfile' parameter in upload.cgi. Attackers can exploit the vulnerability by sending crafted multipart form-data POST requests with directory traversal…
ModificadaMedia (5.1)0.19%—Sound4 Impact FirmwareSound4 Pulse FirmwareSound4 First FirmwareSound4 Impact ECO Firmware+522/12/202517/6/2026
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages that submit HTTP requests to the radio processing interface, triggering unintended administrative operations when…
ModificadaCrítica (9.3)0.74%—Sound4 First FirmwareSound4 Impact ECO FirmwareSound4 Pulse ECO FirmwareSound4 BIG Voice4 Firmware+522/12/202517/6/2026
SOUND4 IMPACT/FIRST/PULSE/Eco version 2.x contains an SQL injection vulnerability in the 'index.php' authentication mechanism that allows attackers to manipulate login credentials. Attackers can inject malicious SQL code through the 'password' POST parameter to bypass authentication and potentially gain unauthorized…
AnalizadaCrítica (9.3)0.85%—Sound4 Stream ExtensionSound4 WM2 FirmwareSound4 BIG Voice2 FirmwareSound4 BIG Voice4 Firmware+522/12/202517/6/2026
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access hidden system resources. Attackers can exploit the vulnerability by manipulating user-supplied input to execute privileged functionalities without proper authentication.
AnalizadaAlta (7.2)0.46%—Sound4 Impact Firmware18/11/202517/6/2026
The Sound4 IMPACT web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware update package. The update mechanism fails to validate the integrity of manual.sh, allowing an attacker to inject arbitrary commands by modifying this script and repackaging the firmware.
AplazadaMedia (6.5)0.28%—Wired Impact Volunteer ManagementAI25/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wired Impact Wired Impact Volunteer Management wired-impact-volunteer-management allows Stored XSS.This issue affects Wired Impact Volunteer Management: from n/a through <= 2.5.
AnalizadaAlta (8.2)1.1%💥 PoCCs-grp NEO ImpactGreenware GreenguardHowyar SysreturnRadix Smart Recovery+314/1/202517/6/2026
Howyar UEFI Application "Reloader" (32-bit and 64-bit) is vulnerable to execution of unsigned software in a hardcoded path.
AplazadaCrítica (9.2)1.0%—Comfyui Impact PackAI12/12/202417/6/2026
ComfyUI-Impact-Pack is vulnerable to Path Traversal. The issue stems from missing validation of the `image.filename` field in a POST request sent to the `/upload/temp` endpoint added by the extension to the server. This results in writing arbitrary files to the file system which may, under some conditions, result in…
ModificadaMedia (4.8)0.31%—Impactpixel ADS Invalid Click Protection8/1/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Impactpixel Ads Invalid Click Protection allows Stored XSS.This issue affects Ads Invalid Click Protection: from n/a through 1.0.
ModificadaAlta (7.5)0.71%—IBM Tivoli Netcool/impact12/7/202117/6/2026
IBM Tivoli Netcool/Impact 7.1.0.20 and 7.1.0.21 uses an insecure SSH server configuration which enables weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 203556.
ModificadaMedia (6.1)0.81%—IBM Tivoli Netcool/impact15/12/202017/6/2026
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.19 Interim Fix 7 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vulnerability and redirect a vitcim to a phishing site. IBM X-Force ID: 190294.
ModificadaAlta (8.8)0.69%—Verint Impact 36014/7/202017/6/2026
An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the login form can accept submissions from external websites. In conjunction with CVE-2019-12783, this can be used by attackers to "crowdsource" bruteforce login attempts on the target site, allowing them to guess and potentially compromise…
ModificadaMedia (6.1)0.86%—Verint Impact 36014/7/202017/6/2026
An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the rd parameter can accept a URL, to which users will be redirected after a successful login. In conjunction with CVE-2019-12784, this can be used by attackers to "crowdsource" bruteforce login attempts on the target site, allowing them to…
ModificadaMedia (6.1)0.84%—Verint Impact 36014/7/202017/6/2026
An issue was discovered in Verint Impact 360 15.1. At wfo/help/help_popup.jsp, the helpURL parameter can be changed to embed arbitrary content inside of an iFrame. Attackers may use this in conjunction with social engineering to embed malicious scripts or phishing pages on a site where this product is installed, given…
ModificadaMedia (5.3)1.8%—IBM Tivoli Netcool/impact31/3/202017/6/2026
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 175412.
ModificadaAlta (8.8)0.53%—IBM Tivoli Netcool/impact31/3/202017/6/2026
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 175411.
ModificadaAlta (8.8)0.53%—IBM Tivoli Netcool/impact31/3/202017/6/2026
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 175410.
ModificadaMedia (6.5)1.4%—IBM Tivoli Netcool/impact31/3/202017/6/2026
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 could allow an authenticated user to cause a denial of service due to improper content parsing in the project management module. IBM X-Force ID: 175409.
ModificadaMedia (5.4)0.67%—IBM Tivoli Netcool/impact31/3/202017/6/2026
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 175408.
ModificadaMedia (6.1)0.73%—IBM Tivoli Netcool/impact24/3/202017/6/2026
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 171734.
ModificadaCrítica (9.8)8.9%💥 ExploitThemerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+5910/3/202017/6/2026
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
ModificadaMedia (5.3)1.1%—Nokia Impact25/11/201917/6/2026
Nokia IMPACT < 18A has path traversal that may lead to RCE if chained with CVE-2019-1743
ModificadaMedia (6.1)0.71%—Nokia Impact25/11/201917/6/2026
Nokia IMPACT < 18A: has Reflected self XSS
ModificadaMedia (4.3)0.97%—Nokia Impact25/11/201917/6/2026
Nokia IMPACT < 18A: allows full path disclosure
Orbitaley — Vulnerabilidades