Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

140 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.65%—Socomec Diris M-70 Firmware1/12/202525/9/2026
A buffer overflow vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted set of network packets can lead to denial of service. An attacker can send a sequence of unauthenticated packets to trigger this vulnerability.
AnalizadaAlta (7.5)0.54%—Socomec Diris M-70 Firmware1/12/202525/9/2026
A denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to denial of service. An attacker can send an unauthenticated packet to trigger this vulnerability.
AnalizadaMedia (6.5)0.34%—Socomec Diris M-70 Firmware1/12/202525/9/2026
A denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to denial of service and weaken credentials resulting in default documented credentials being applied to the device. An attacker can send an…
AnalizadaAlta (8.8)0.24%—Socomec Diris M-70 Firmware1/12/202526/9/2026
A cross-site request forgery (csrf) vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted HTTP request can lead to unauthorized access. An attacker can stage a malicious webpage to trigger this vulnerability.
AnalizadaMedia (6.5)0.34%—Socomec Diris M-70 Firmware1/12/202526/9/2026
A denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to denial of service and weaken credentials resulting in default documented credentials being applied to the device. An attacker can send an unauthenticated packet…
AnalizadaAlta (7.5)1.1%—Socomec Diris M-70 Firmware1/12/202526/9/2026
A cleartext transmission vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can sniff network traffic to trigger this vulnerability.
AnalizadaAlta (7.5)0.54%—Socomec Diris M-70 Firmware1/12/202526/9/2026
A denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to denial of service. An attacker can send an unauthenticated packet to trigger this vulnerability.
AplazadaAlta (8.8)0.12%—Altiris Core Agent UpdaterAI11/9/202530/9/2026
The Altiris Core Agent Updater package (AeXNSC.exe) is prone to an elevation of privileges vulnerability through DLL hijacking.
AplazadaAlta (8.1)0.65%—Cocobsaic CalirisAIPHPAI20/8/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CocoBasic Caliris caliris-wp allows PHP Local File Inclusion.This issue affects Caliris: from n/a through <= 1.5.
AnalizadaMedia (5.3)0.47%—Kirisun Fujian Kelixun23/5/202517/6/2026
A vulnerability was found in Fujian Kelixun 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /app/xml_cdr/xml_cdr_details.php. The manipulation of the argument uuid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and…
AplazadaMedia (6.9)2.1%—Kirisun Fujian KelixunAI23/5/202517/6/2026
A vulnerability was found in Fujian Kelixun 1.0. It has been classified as critical. This affects an unknown part of the file /app/fax/fax_view.php of the component Filename Handler. The manipulation of the argument fax_file leads to os command injection. It is possible to initiate the attack remotely. The exploit has…
AplazadaMedia (5.4)0.15%—Intel Graphics SoftwareAIIntel ARC GraphicsAIIntel Iris XE GraphicsAI13/5/202517/6/2026
Uncontrolled search path for some Intel(R) Graphics software for Intel(R) Arc™ graphics and Intel(R) Iris(R) Xe graphics before version 32.0.101.6325/32.0.101.6252 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (5.4)0.15%—Intel ARC Iris XE Graphics SoftwareAI13/5/202517/6/2026
Uncontrolled search path for some Intel(R) Arc™ &amp; Iris(R) Xe graphics software before version 32.0.101.6083/32.0.101.5736 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (5.2)0.14%—Intel ARC AND Iris XE Graphics SoftwareAI13/5/202517/6/2026
Improper access control for some Intel(R) Arc™ &amp; Iris(R) Xe graphics software before version 32.0.101.6077 may allow an authenticated user to potentially enable denial of service via local access.
AplazadaMedia (5.1)0.14%—Intel ARC Iris XE Graphics SoftwareAI13/5/202517/6/2026
Improper access control for some Intel(R) Arc™ &amp; Iris(R) Xe graphics software before version 31.0.101.4032 may allow an authenticated user to potentially enable denial of service via local access.
AplazadaMedia (6.5)0.28%—Zackdesign Nextgen Cooliris GalleryAI7/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zackdesign NextGen Cooliris Gallery nextgen-cooliris-gallery allows Stored XSS.This issue affects NextGen Cooliris Gallery: from n/a through <= 0.7.
AplazadaAlta (7.1)0.15%—Irish Cathal OUT OF Stock BadgeAI2/12/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Irish_Cathal Out Of Stock Badge out-of-stock-badge allows Cross Site Request Forgery.This issue affects Out Of Stock Badge: from n/a through <= 2.0.
AplazadaAlta (7.1)0.18%—Irish Cathal Continue Shopping From CartAI2/12/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Irish_Cathal Continue Shopping From Cart continue-shopping-from-cart-page allows Stored XSS.This issue affects Continue Shopping From Cart: from n/a through <= 1.3.
ModificadaCrítica (9.8)0.47%—Madirisalmanaashish Adding Drop Down Roles IN Registration17/10/202417/6/2026
Incorrect Privilege Assignment vulnerability in madiriaashish Adding drop down roles in registration user-drop-down-roles-in-registration allows Privilege Escalation.This issue affects Adding drop down roles in registration: from n/a through <= 1.1.
AnalizadaMedia (5.1)0.13%—Intel ARC A GraphicsIntel Iris XE Graphics14/8/202417/6/2026
Improper access control in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.4824 may allow an authenticated user to potentially enable denial of service via local access.
AplazadaCrítica (9.8)0.77%—Kirisun Fujian KelixunAI9/7/202417/6/2026
Fujian Kelixun <=7.6.6.4391 is vulnerable to SQL Injection in send_event.php.
AplazadaMedia (6.3)0.30%—Apiris KafeoAI28/5/202417/6/2026
An issue was discovered in Apiris Kafeo 6.4.4. It permits a bypass, of the protection in place, to access to the data stored in the embedded database file.
AplazadaAlta (7.3)0.18%—Apiris KafeoAI28/5/202417/6/2026
An issue was discovered in Apiris Kafeo 6.4.4. It permits DLL hijacking, allowing a user to trigger the execution of arbitrary code every time the product is executed.
AplazadaAlta (8.8)1.0%—Iris-evtx-moduleAIIris-webAI23/5/202417/6/2026
IrisEVTXModule is an interface module for Evtx2Splunk and Iris in order to ingest Microsoft EVTX log files. The `iris-evtx-module` is a pipeline plugin of `iris-web` that processes EVTX files through IRIS web application. During the upload of an EVTX through this pipeline, the filename is not safely handled and may…
AplazadaAlta (7.8)0.34%—Intel ARC GraphicsAIIntel Iris XE GraphicsAI16/5/202417/6/2026
Improper neutralization in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.5081 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent network access.