Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

50 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.63%—Teknogis Informatics Closed Circuit Vehicle Tracking SoftwareAI21/11/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknogis Informatics Closed Circuit Vehicle Tracking Software allows SQL Injection, Blind SQL Injection. This issue affects Closed Circuit Vehicle Tracking Software: through 21.11.2024. NOTE: The vendor was contacted…
AnalizadaMedia (5.3)0.31%—Circutor Q-smt Firmware18/9/202417/6/2026
An attacker with no knowledge of the current users in the web application, could build a dictionary of potential users and check the server responses as it indicates whether or not the user is present in CIRCUTOR Q-SMT in its firmware version 1.0.4.
AnalizadaCrítica (9.1)0.34%—Circutor Tcp2rs+ Firmware18/9/202417/6/2026
Vulnerability in CIRCUTOR TCP2RS+ firmware version 1.3b, which could allow an attacker to modify any configuration value, even if the device has the user/password authentication option enabled, without authentication by sending packets through the UDP protocol and port 2000, deconfiguring the device and thus disabling…
AnalizadaAlta (8.8)0.40%—Circutor Q-smt Firmware18/9/202417/6/2026
An attacker with access to the network where the CIRCUTOR Q-SMT is located in its firmware version 1.0.4, could obtain legitimate credentials or steal sessions due to the fact that the device only implements the HTTP protocol. This fact prevents a secure communication channel from being established.
AnalizadaCrítica (9.1)0.43%—Circutor Tcp2rs+ Firmware18/9/202417/6/2026
Vulnerability in CIRCUTOR TCP2RS+ firmware version 1.3b, which could allow an attacker to modify any configuration value, even if the device has the user/password authentication option enabled, without authentication by sending packets through the UDP protocol and port 2000, deconfiguring the device and thus disabling…
AnalizadaAlta (7.5)0.42%—Circutor Q-smt Firmware18/9/202417/6/2026
An attacker with access to the network where CIRCUTOR Q-SMT is located in its firmware version 1.0.4, could steal the tokens used on the web, since these have no expiration date to access the web application without restrictions. Token theft can originate from different methods such as network captures, locally stored…
AnalizadaAlta (8.6)0.56%—Circutor Q-smt Firmware18/9/202417/6/2026
CIRCUTOR Q-SMT in its firmware version 1.0.4, could be affected by a denial of service (DoS) attack if an attacker with access to the web service bypasses the authentication mechanisms on the login page, allowing the attacker to use all the functionalities implemented at web level that allow interacting with the…
ModificadaAlta (7.5)0.80%—UI Edgemax Edgerouter FirmwareUI Aircube Firmware18/7/202317/6/2026
A heap overflow vulnerability found in EdgeRouters and Aircubes allows a malicious actor to interrupt UPnP service to said devices.
ModificadaAlta (7.8)1.1%—Circuitverse6/9/202217/6/2026
CircuitVerse is an open-source platform which allows users to construct digital logic circuits online. A remote code execution (RCE) vulnerability in CircuitVerse allows authenticated attackers to execute arbitrary code via specially crafted JSON payloads. This issue may lead to Remote Code Execution (RCE). A patch is…
ModificadaAlta (8.1)0.80%—Circutor Compact Dc-s Basic Firmware24/5/202217/6/2026
A buffer overflow vulnerability has been detected in the firewall function of the device management web portal. The device runs a CGI binary (index.cgi) to offer a management web application. Once authenticated with valid credentials in this web portal, a potential attacker could submit any "Address" value and it…
ModificadaCrítica (9.8)2.5%—Circutor Compact Dc-s Basic Firmware2/12/202117/6/2026
Buffer overflow vulnerability in function SetFirewall in index.cgi in CIRCUTOR COMPACT DC-S BASIC smart metering concentrator Firwmare version CIR_CDC_v1.2.17, allows attackers to execute arbitrary code.
ModificadaAlta (8.8)0.43%—Circutor Sge-plc1000 Firmware9/6/202117/6/2026
Improper Authentication vulnerability in the cookie parameter of Circutor SGE-PLC1000 firmware version 0.9.2b allows an attacker to perform operations as an authenticated user. In order to exploit this vulnerability, the attacker must be within the network where the device affected is located.
ModificadaCrítica (9.8)2.2%—Circutor Sge-plc1000 Firmware9/6/202117/6/2026
SGE-PLC1000 device, in its 0.9.2b firmware version, does not handle some requests correctly, allowing a remote attacker to inject code into the operating system with maximum privileges.
ModificadaMedia (6.4)2.2%💥 ExploitCirculargenius Flat Calendar21/4/200916/6/2026
Flat Calendar 1.1 does not properly restrict access to administrative functions, which allows remote attackers to (1) add new events via calAdd.php, as reachable from admin/add.php, or (2) delete events via admin/deleteEvent.php. NOTE: this is only a vulnerability when the administrator does not follow recommendations…
ModificadaMedia (5)5.2%💥 ExploitIrcuQuakenet Snircd25/3/200816/6/2026
The send_user_mode function in s_user.c in (1) Undernet ircu 2.10.12.12 and earlier, (2) snircd 1.3.4 and earlier, and unspecified other ircu derivatives allows remote attackers to cause a denial of service (daemon crash) via a malformed MODE command.
ModificadaMedia (6)1.1%—Universal Ircd Ircu18/8/200716/6/2026
ircu 2.10.12.05 and earlier does not properly synchronize a kick action in certain cross scenarios, which allows remote authenticated operators to prevent later kick or de-op actions from non-local ops.
ModificadaMedia (5.1)1.3%—Universal Ircd Ircu18/8/200716/6/2026
Race condition in ircu 2.10.12.01 through 2.10.12.05 allows remote attackers to set a new Apass during a netburst by arranging for ops privilege to be granted before the mode arrives.
ModificadaMedia (6.4)1.5%—Universal Ircd Ircu18/8/200716/6/2026
ircu 2.10.12.03 and 2.10.12.04 does not associate a timestamp with ops privilege on an unused channel (zannel), which allows remote attackers to (1) set or remove certain channel modes via a "netriding" attack or (2) take over a channel by joining an unlinked server with the A/Upass and then setting a new Apass.
ModificadaAlta (7.5)1.5%—Universal Ircd Ircu18/8/200716/6/2026
ircu 2.10.12.01 through 2.10.12.04 does not remove ops privilege after a join from a server with an older timestamp (TS), which allows remote attackers to gain control of a channel during a split.
ModificadaMedia (5)1.3%—Universal Ircd Ircu18/8/200716/6/2026
ircu 2.10.12.05 and earlier ignores timestamps in bounces, which allows remote attackers to take over a channel during a netjoin by causing a bounce while a server with an older version of the channel is linking.
ModificadaAlta (7.8)2.4%—Universal Ircd Ircu18/8/200716/6/2026
ircu 2.10.12.01 allows remote attackers to (1) cause a denial of service (flood wallops) by joining two channels with certain long names that differ in the final character, which triggers a protocol violation and (2) cause a denial of service (daemon crash) via a "J 0:#channel" message on a channel without an apass;…
ModificadaAlta (7.8)1.7%—Universal Ircd Ircu18/8/200716/6/2026
ircu 2.10.12.02 through 2.10.12.04 allows remote attackers to cause a denial of service (memory and bandwidth consumption) by creating a large number of unused channels (zannels).
ModificadaMedia (4.3)1.2%—Universal Ircd Ircu18/8/200716/6/2026
ircu 2.10.12.05 and earlier allows remote attackers to discover the hidden IP address of arbitrary +x users via a series of /silence commands with (1) CIDR mask arguments or (2) certain other arguments that represent groups of IP addresses, then monitoring CTCP ping replies.
ModificadaAlta (7.8)1.8%—Avaya Tn2602ap IP Media Resource 320 Circuit Pack4/12/200516/6/2026
Memory leak in Avaya TN2602AP IP Media Resource 320 circuit pack before vintage 9 firmware allows remote attackers to cause a denial of service (memory consumption) via crafted VoIP packets.
ModificadaBaja (2.1)1.9%💥 ExploitFreeform Interactive Purge JihadMonolith Productions Alien Versus PredatorMonolith Productions BloodMonolith Productions Contract Jack+731/12/200416/6/2026
Format string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to cause a denial of service (application crash) via format string specifiers in (1) a nickname or (2) a message.
Orbitaley — Vulnerabilidades