Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2950▲ 8 respecto a la semana anterior
Críticas / altas1450▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
252 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.47% | — | Openairinterface | 30/3/2026 | 17/6/2026 | OpenAirInterface V2.2.0 AMF crashes when it fails to decode the message. Not all decode failures result in a crash. But the crash is consistent for particular inputs. An example input in hex stream is 80 00 00 0E 00 00 01 00 0F 80 02 02 40 00 58 00 01 88. | |
| Analizada | Alta (8.9) | 1.8% | — | Pi-hole WEB Interface | 27/3/2026 | 17/6/2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions prior to 6.0 have a critical OS Command Injection vulnerability in the savesettings.php file. The application takes the user-controlled $_POST['webtheme'] parameter and concatenates… | |
| Aplazada | Media (6.5) | 0.22% | — | Northernbeacheswebsites WP Custom Admin InterfaceAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface allows DOM-Based XSS.This issue affects WP Custom Admin Interface: from n/a through <= 7.42. | |
| Pendiente de análisis | Media (6.9) | 0.11% | — | Asus Business System Control Interface DriverAI | 12/3/2026 | 17/6/2026 | An Out-of-Bounds Read vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a specially crafted IOCTL request, potentially leading to a disclosure of kernel information or a system crash. Refer to the "Security Update for… | |
| Pendiente de análisis | Media (6.8) | 0.10% | — | Asus Business System Control Interface DriverAI | 12/3/2026 | 17/6/2026 | An Incorrect Permission Assignment vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a specially crafted IOCTL request, potentially leading to unauthorized access to sensitive hardware resources and kernel information… | |
| Analizada | Alta (7.5) | 0.18% | — | Nexusinterface | 9/3/2026 | 17/6/2026 | An issue pertaining to CWE-319: Cleartext Transmission of Sensitive Information was discovered in Nexusoft NexusInterface v3.2.0-beta.2. | |
| Analizada | Alta (7.5) | 0.35% | — | Nexusinterface | 9/3/2026 | 17/6/2026 | An issue pertaining to CWE-400: Uncontrolled Resource Consumption was discovered in Nexusoft NexusInterface v3.2.0-beta.2. | |
| Analizada | Alta (7.5) | 0.51% | — | Github Copilot Command Line Interface | 6/3/2026 | 17/6/2026 | The shell tool within GitHub Copilot CLI versions prior to and including 0.0.422 can allow arbitrary code execution through crafted bash parameter expansion patterns. An attacker who can influence the commands executed by the agent (e.g., via prompt injection through repository files, MCP server responses, or user… | |
| Modificada | Alta (7) | 0.49% | — | Docker Command Line Interface | 4/3/2026 | 15/7/2026 | Docker CLI for Windows searches for plugin binaries in C:\ProgramData\Docker\cli-plugins, a directory that does not exist by default. A low-privileged attacker can create this directory and place malicious CLI plugin binaries (docker-compose.exe, docker-buildx.exe, etc.) that are executed when a victim user opens… | |
| Modificada | Alta (7.1) | 0.56% | — | Spip Interface Traduction Objets | 25/2/2026 | 17/6/2026 | The SPIP interface_traduction_objets plugin versions prior to 2.2.2 contain an authenticated SQL injection vulnerability in interface_traduction_objets_pipelines.php. When handling translation requests, the plugin reads the id_parent parameter from user-supplied input and concatenates it directly into a SQL WHERE… | |
| Analizada | Alta (8.7) | 1.1% | — | Spip Interface Traduction Objets | 25/2/2026 | 17/6/2026 | The SPIP interface_traduction_objets plugin versions prior to 2.2.2 contain an authenticated remote code execution vulnerability in the translation interface workflow. The plugin incorporates untrusted request data into a hidden form field that is rendered without SPIP output filtering. Because fields prefixed with an… | |
| Analizada | Media (5.4) | 0.42% | — | Pi-hole WEB Interface | 19/2/2026 | 17/6/2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions 6.0 and above have a Stored HTML Injection vulnerability in the active sessions table located on the API settings page, allowing an attacker with valid credentials to inject arbitrary… | |
| Analizada | Media (5.4) | 0.35% | — | Pi-hole WEB Interface | 19/2/2026 | 17/6/2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions 6.4 and below are vulnerable to stored HTML injection through the local DNS records configuration page, which allows an authenticated administrator to inject code that is stored in… | |
| Analizada | Media (6) | 0.17% | — | Yokogawa Vnet/ip Interface Package | 13/2/2026 | 17/6/2026 | A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receives maliciously crafted packets, Vnet/IP software stack process may be terminated. The affected products and versions are as follows: Vnet/IP Interface Package (for CENTUM VP R6 VP6C3300,… | |
| Analizada | Media (6) | 0.17% | — | Yokogawa Vnet/ip Interface Package | 13/2/2026 | 17/6/2026 | A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receives maliciously crafted packets, Vnet/IP software stack process may be terminated. The affected products and versions are as follows: Vnet/IP Interface Package (for CENTUM VP R6 VP6C3300,… | |
| Analizada | Media (6) | 0.17% | — | Yokogawa Vnet/ip Interface Package | 13/2/2026 | 17/6/2026 | A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receives maliciously crafted packets, Vnet/IP software stack process may be terminated. The affected products and versions are as follows: Vnet/IP Interface Package (for CENTUM VP R6 VP6C3300,… | |
| Analizada | Media (6) | 0.23% | — | Yokogawa Vnet/ip Interface Package | 13/2/2026 | 17/6/2026 | A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receives maliciously crafted packets, Vnet/IP software stack process may be terminated. The affected products and versions are as follows: Vnet/IP Interface Package (for CENTUM VP R6 VP6C3300,… | |
| Analizada | Media (6) | 0.21% | — | Yokogawa Vnet/ip Interface Package | 13/2/2026 | 17/6/2026 | A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receives maliciously crafted packets, Vnet/IP software stack process may be terminated. The affected products and versions are as follows: Vnet/IP Interface Package (for CENTUM VP R6 VP6C3300,… | |
| Analizada | Media (6) | 0.19% | — | Yokogawa Vnet/ip Interface Package | 13/2/2026 | 17/6/2026 | A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receive maliciously crafted packets, a DoS attack may cause Vnet/IP communication functions to stop or arbitrary programs to be executed. The affected products and versions are as follows: Vnet/IP… | |
| Aplazada | Media (4.3) | 0.19% | — | Northernbeacheswebsites WP Custom Admin InterfaceAI | 3/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through <= 7.41. | |
| Modificada | Crítica (9.8) | 0.45% | — | N3uron WEB User Interface | 29/1/2026 | 5/7/2026 | An issue in N3uron Web User Interface v.1.21.7-240207.1047 allows a remote attacker to escalate privileges via the password hashing on the client side using the MD5 algorithm over a predictable string format | |
| Analizada | Alta (7.5) | 0.37% | — | Openairinterface Oai-cn5g-amf | 7/1/2026 | 17/6/2026 | OpenAirInterface CN5G AMF<=v2.0.1 There is a logical error when processing JSON format requests. Unauthorized remote attackers can send malicious JSON data to AMF's SBI interface to launch a denial-of-service attack. | |
| Analizada | Alta (7.5) | 0.38% | — | Openairinterface Oai-cn5g-amf | 7/1/2026 | 17/6/2026 | OpenAirInterface CN5G AMF<=v2.1.9 has a buffer overflow vulnerability in processing NAS messages. Unauthorized remote attackers can launch a denial-of-service attack and potentially execute malicious code by accessing port N1 and sending an imsi string longer than 1000 to AMF. | |
| Aplazada | Media (4.3) | 0.24% | — | Northernbeacheswebsites WP Custom Admin InterfaceAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through <= 7.40. | |
| Analizada | Alta (8.8) | 0.32% | — | Eaton Xcomfort Ethernet Communication Interface | 23/12/2025 | 17/6/2026 | Improper input validation at one of the endpoints of Eaton xComfort ECI's web interface, could lead into an attacker with network access to the device executing privileged user commands. As cybersecurity standards continue to evolve and to meet our requirements today, Eaton has decided to discontinue the product. Upon… |