Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
140 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.65% | — | Socomec Diris M-70 Firmware | 1/12/2025 | 25/9/2026 | A buffer overflow vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted set of network packets can lead to denial of service. An attacker can send a sequence of unauthenticated packets to trigger this vulnerability. | |
| Analizada | Alta (7.5) | 0.54% | — | Socomec Diris M-70 Firmware | 1/12/2025 | 25/9/2026 | A denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to denial of service. An attacker can send an unauthenticated packet to trigger this vulnerability. | |
| Analizada | Media (6.5) | 0.34% | — | Socomec Diris M-70 Firmware | 1/12/2025 | 25/9/2026 | A denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to denial of service and weaken credentials resulting in default documented credentials being applied to the device. An attacker can send an… | |
| Analizada | Alta (8.8) | 0.24% | — | Socomec Diris M-70 Firmware | 1/12/2025 | 26/9/2026 | A cross-site request forgery (csrf) vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted HTTP request can lead to unauthorized access. An attacker can stage a malicious webpage to trigger this vulnerability. | |
| Analizada | Media (6.5) | 0.34% | — | Socomec Diris M-70 Firmware | 1/12/2025 | 26/9/2026 | A denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to denial of service and weaken credentials resulting in default documented credentials being applied to the device. An attacker can send an unauthenticated packet… | |
| Analizada | Alta (7.5) | 1.1% | — | Socomec Diris M-70 Firmware | 1/12/2025 | 26/9/2026 | A cleartext transmission vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can sniff network traffic to trigger this vulnerability. | |
| Analizada | Alta (7.5) | 0.54% | — | Socomec Diris M-70 Firmware | 1/12/2025 | 26/9/2026 | A denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to denial of service. An attacker can send an unauthenticated packet to trigger this vulnerability. | |
| Aplazada | Alta (8.8) | 0.12% | — | Altiris Core Agent UpdaterAI | 11/9/2025 | 30/9/2026 | The Altiris Core Agent Updater package (AeXNSC.exe) is prone to an elevation of privileges vulnerability through DLL hijacking. | |
| Aplazada | Alta (8.1) | 0.65% | — | Cocobsaic CalirisAIPHPAI | 20/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CocoBasic Caliris caliris-wp allows PHP Local File Inclusion.This issue affects Caliris: from n/a through <= 1.5. | |
| Analizada | Media (5.3) | 0.47% | — | Kirisun Fujian Kelixun | 23/5/2025 | 17/6/2026 | A vulnerability was found in Fujian Kelixun 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /app/xml_cdr/xml_cdr_details.php. The manipulation of the argument uuid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and… | |
| Aplazada | Media (6.9) | 2.1% | — | Kirisun Fujian KelixunAI | 23/5/2025 | 17/6/2026 | A vulnerability was found in Fujian Kelixun 1.0. It has been classified as critical. This affects an unknown part of the file /app/fax/fax_view.php of the component Filename Handler. The manipulation of the argument fax_file leads to os command injection. It is possible to initiate the attack remotely. The exploit has… | |
| Aplazada | Media (5.4) | 0.15% | — | Intel Graphics SoftwareAIIntel ARC GraphicsAIIntel Iris XE GraphicsAI | 13/5/2025 | 17/6/2026 | Uncontrolled search path for some Intel(R) Graphics software for Intel(R) Arc™ graphics and Intel(R) Iris(R) Xe graphics before version 32.0.101.6325/32.0.101.6252 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.4) | 0.15% | — | Intel ARC Iris XE Graphics SoftwareAI | 13/5/2025 | 17/6/2026 | Uncontrolled search path for some Intel(R) Arc™ & Iris(R) Xe graphics software before version 32.0.101.6083/32.0.101.5736 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.2) | 0.14% | — | Intel ARC AND Iris XE Graphics SoftwareAI | 13/5/2025 | 17/6/2026 | Improper access control for some Intel(R) Arc™ & Iris(R) Xe graphics software before version 32.0.101.6077 may allow an authenticated user to potentially enable denial of service via local access. | |
| Aplazada | Media (5.1) | 0.14% | — | Intel ARC Iris XE Graphics SoftwareAI | 13/5/2025 | 17/6/2026 | Improper access control for some Intel(R) Arc™ & Iris(R) Xe graphics software before version 31.0.101.4032 may allow an authenticated user to potentially enable denial of service via local access. | |
| Aplazada | Media (6.5) | 0.28% | — | Zackdesign Nextgen Cooliris GalleryAI | 7/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zackdesign NextGen Cooliris Gallery nextgen-cooliris-gallery allows Stored XSS.This issue affects NextGen Cooliris Gallery: from n/a through <= 0.7. | |
| Aplazada | Alta (7.1) | 0.15% | — | Irish Cathal OUT OF Stock BadgeAI | 2/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Irish_Cathal Out Of Stock Badge out-of-stock-badge allows Cross Site Request Forgery.This issue affects Out Of Stock Badge: from n/a through <= 2.0. | |
| Aplazada | Alta (7.1) | 0.18% | — | Irish Cathal Continue Shopping From CartAI | 2/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Irish_Cathal Continue Shopping From Cart continue-shopping-from-cart-page allows Stored XSS.This issue affects Continue Shopping From Cart: from n/a through <= 1.3. | |
| Modificada | Crítica (9.8) | 0.47% | — | Madirisalmanaashish Adding Drop Down Roles IN Registration | 17/10/2024 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in madiriaashish Adding drop down roles in registration user-drop-down-roles-in-registration allows Privilege Escalation.This issue affects Adding drop down roles in registration: from n/a through <= 1.1. | |
| Analizada | Media (5.1) | 0.13% | — | Intel ARC A GraphicsIntel Iris XE Graphics | 14/8/2024 | 17/6/2026 | Improper access control in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.4824 may allow an authenticated user to potentially enable denial of service via local access. | |
| Aplazada | Crítica (9.8) | 0.77% | — | Kirisun Fujian KelixunAI | 9/7/2024 | 17/6/2026 | Fujian Kelixun <=7.6.6.4391 is vulnerable to SQL Injection in send_event.php. | |
| Aplazada | Media (6.3) | 0.30% | — | Apiris KafeoAI | 28/5/2024 | 17/6/2026 | An issue was discovered in Apiris Kafeo 6.4.4. It permits a bypass, of the protection in place, to access to the data stored in the embedded database file. | |
| Aplazada | Alta (7.3) | 0.18% | — | Apiris KafeoAI | 28/5/2024 | 17/6/2026 | An issue was discovered in Apiris Kafeo 6.4.4. It permits DLL hijacking, allowing a user to trigger the execution of arbitrary code every time the product is executed. | |
| Aplazada | Alta (8.8) | 1.0% | — | Iris-evtx-moduleAIIris-webAI | 23/5/2024 | 17/6/2026 | IrisEVTXModule is an interface module for Evtx2Splunk and Iris in order to ingest Microsoft EVTX log files. The `iris-evtx-module` is a pipeline plugin of `iris-web` that processes EVTX files through IRIS web application. During the upload of an EVTX through this pipeline, the filename is not safely handled and may… | |
| Aplazada | Alta (7.8) | 0.34% | — | Intel ARC GraphicsAIIntel Iris XE GraphicsAI | 16/5/2024 | 17/6/2026 | Improper neutralization in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.5081 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent network access. |