Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
1019 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4) | 0.45% | — | Safenet Luna Hardware Security ModuleAIPaloaltonetworks Pan-osAI | 10/9/2026 | 11/9/2026 | A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI and the device must be configured with a Luna Hardware… | |
| Aplazada | Alta (8.8) | 2.9% | — | Newfold WP Module DataAINewfold WP Plugin Crazy DomainsAINewfold WP Plugin WEBAINewfold WP Plugin HostgatorAI+1 | 9/9/2026 | 9/9/2026 | Several Newfold plugins are vulnerable to Authentication Bypass. The vulnerability exists because the plugins bundle the wp-module-data module. In the module, the `authenticate()` method — registered on the `rest_authentication_errors` filter and therefore evaluated for every unauthenticated REST API request —… | |
| Aplazada | Alta (7.5) | 0.30% | — | Paytr Virtual POS Iframe APIAIPaytr Whmcs ModuleAI | 8/9/2026 | 1/10/2026 | Observable timing discrepancy vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API WHMCS Module allows Black Box Reverse Engineering. This issue affects PayTR Virtual Pos iFrame API WHMCS Module: from v9.0.0 before v9.0.3. | |
| Pendiente de análisis | Alta (7) | 0.13% | — | Redundancy Module Configuration ToolAI | 1/9/2026 | 1/9/2026 | A security issue exists within the Redundancy Module Configuration Tool. The RMConfigTool.exe binary searches directories in the system path for a required DLL, and one or more of these directories may be writable by standard (non-administrator) users due to incorrect default permissions. If a local attacker places a… | |
| Pendiente de análisis | Alta (7) | 0.13% | — | Redundancy Module RM3 Config ToolAI | 1/9/2026 | 1/9/2026 | A security issue exists within the Redundancy Module Configuration Tool. The RM3ConfigTool.exe binary searches directories in the system path for a required DLL, and one or more of these directories may be writable by standard (non-administrator) users due to incorrect default permissions. If a local attacker places a… | |
| Aplazada | Media (5.3) | 0.38% | — | Nasa CFSAINasa SBN TCP ModuleAI | 30/8/2026 | 1/9/2026 | A vulnerability was identified in NASA cFS up to 7.0.1. Impacted is the function OS_read of the file modules/protocol/tcp/fsw/src/sbn_tcp_if.c of the component SBN TCP Module. Such manipulation of the argument MsgSz leads to buffer overflow. The attack must be carried out from within the local network. The vendor was… | |
| Analizada | Alta (7) | 0.15% | — | Intel TDX Module | 11/8/2026 | 31/8/2026 | Improper authentication in the Intel(R) TDX module for some Intel(R) platforms within Ring 0: Trust Domain may allow an information disclosure and escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may… | |
| Analizada | Media (6.8) | 0.10% | — | Intel TDX Module | 11/8/2026 | 31/8/2026 | Uncaught exception for some Intel(R) TDX modules within Ring 0: Trust Domain may allow a denial of service. System software adversary with a privileged user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are present… | |
| Analizada | Media (6.8) | 0.10% | — | Intel TDX Module | 11/8/2026 | 31/8/2026 | Insecure storage of sensitive information in the Intel(R) TDX module for some Intel(R) platform within Ring 0: Trust Domain may allow information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local… | |
| Aplazada | Media (6.9) | 0.12% | — | CSL 1010 M2M 3G Wifi ModuleAI | 30/7/2026 | 31/7/2026 | CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak encryption vulnerability that allows unauthenticated attackers to recover all stored secrets in plaintext by reversing a single-byte XOR cipher that uses a static key to obfuscate the configuration backup file. Attackers can trivially decrypt the… | |
| Aplazada | Alta (7.1) | 0.19% | — | Mitsubishielectric Melsec MX Controller Mx-rAIMitsubishielectric Melsec MX Controller Mx-fAIMitsubishielectric Cc-link IE TSN Interface BoardAIMitsubishielectric Motion ModuleAI+25 | 30/7/2026 | 18/9/2026 | Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, MELSEC iQ-L Series Motion Module, Motion Control Board,… | |
| Aplazada | Alta (8.1) | 0.19% | — | Regularlabs Modules AnywhereAI | 23/7/2026 | 24/7/2026 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - The editor popup could expose restricted module data to authenticated users without the required module permissions or valid request tokens. | |
| Aplazada | Crítica (9.1) | 0.43% | — | Regularlabs Articles AnywhereAIRegularlabs Modules AnywhereAI | 22/7/2026 | 27/7/2026 | Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere extensions - Content tags could use ignore flags or property overrides to render restricted or unpublished articles or modules. A content author could thereby expose content to visitors who lacked the… | |
| Aplazada | Media (5.3) | 0.28% | — | Kirby-modulesAI | 21/7/2026 | 23/7/2026 | kirby-modules through 5.5.7, fixed in commit 315417e, contains an information disclosure vulnerability that allows any authenticated Kirby Panel user to retrieve the full plaintext commercial license key by sending a GET request to the modules/activate dialog endpoint. The plugin's activate dialog handler in… | |
| Pendiente de análisis | Alta (8.2) | 0.22% | — | Allen Bradley Compactlogix 5380AIAllen Bradley Controllogix 5580AIAllen Bradley EN4 Communication ModuleAI | 14/7/2026 | 14/7/2026 | A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Security certificate revocation handling. The security issue stems from the controller failing to properly reject certificates signed by an intermediate certificate that has been revoked via a… | |
| Aplazada | Alta (8.3) | 0.40% | — | Misp-modulesAI | 13/7/2026 | 14/7/2026 | A Server-Side Request Forgery (SSRF) protection bypass existed in the html_to_markdown expansion module of misp-modules. The module attempts to prevent requests to loopback, private, link-local, and other restricted IP address ranges. However, IP addresses were compared against the blocked ranges without first… | |
| Aplazada | Crítica (9.8) | 0.78% | — | Perl Module LoadAI | 7/7/2026 | 7/7/2026 | Module::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be loaded. Module names starting with "::" could be passed to the load function to specify arbitrary module paths. Attackers able to influence module names passed to load could use that bug to execute arbitrary code. | |
| Pendiente de análisis | Media (5.1) | 0.16% | — | Raspberrypi Raspberry PI 5AIRaspberrypi Compute Module 5AI | 7/7/2026 | 7/7/2026 | EEPROM firmware on Raspberry Pi 5 and Compute Module 5 devices produced non-random KASLR and RNG seed values. This resulted in consistent kernel addresses across boots and devices, potentially making it easier to exploit other vulnerabilities. Additionally, the low-quality RNG seed may affect the quality of random… | |
| Aplazada | Alta (8.6) | 0.62% | — | Simplesamlphp-module-casserverAI | 10/6/2026 | 23/7/2026 | SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. Prior to version 7.0.3, simplesamlphp-module-casserver builds file paths for the file-based CAS ticket store by directly concatenating the configured ticket directory with an attacker-controlled ticket identifier.… | |
| Aplazada | Baja (1) | 0.20% | — | Indian Motorcycle Scout Bobber Infotainment Digital Round DisplayAIIndian Motorcycle Wireless Control ModuleAI | 29/5/2026 | 21/7/2026 | Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the PIN entry screen. The Infotainment uses presence of Wireless Control Module (WCM) traffic during its boot window as a proxy for whether an… | |
| Analizada | Alta (7.7) | 0.35% | — | Oracle Financials Common Modules | 28/5/2026 | 21/7/2026 | Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials Common Modules.… | |
| Modificada | Alta (8.5) | 0.30% | — | Oracle Financials Common Modules | 28/5/2026 | 21/7/2026 | Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials Common Modules.… | |
| Aplazada | Crítica (9.8) | 0.52% | — | WosdefaulthttpmoduleAI | 27/5/2026 | 17/6/2026 | A stack-based buffer overflow condition exists in WOSDefaultHttpModule.dll when processing a long URL path starting with /woshome | |
| Aplazada | Alta (7.5) | 0.50% | — | WosdefaulthttpmoduleAI | 27/5/2026 | 17/6/2026 | A path traversal vulnerability exists in WOSDefaultHttpModule.dll when processing a URL path starting with /woshome | |
| Aplazada | Alta (7.5) | 0.46% | — | WOS Http Status ModuleAI | 27/5/2026 | 17/6/2026 | When processing a request with a URL path starting with /status or /sysinfo, WOSHttpStatusModule.dll is to be loaded to handle such URL patterns. The WOSBin_LoadHttpModule function in the dll would be called to set up a "module" object for that module. However, WOSHttpStatusModule.dll is not present in the… |