Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

68 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.27%—TrmtrackerAI25/3/202517/6/2026
The TRMTracker web application is vulnerable to LDAP injection attack potentially allowing an attacker to inject code into a query and execute remote commands that can read and update data on the website.
ModificadaMedia (4.3)0.18%—Mtrv Teachpress25/3/202517/6/2026
The teachPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.0.9. This is due to missing or incorrect nonce validation on the import.php page. This makes it possible for unauthenticated attackers to delete imports via a forged request granted they can trick a…
AnalizadaAlta (8.8)0.50%—Mtrv Teachpress4/3/202517/6/2026
The teachPress plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tpsearch' shortcode in all versions up to, and including, 9.0.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaMedia (6.1)0.40%—CamtraceAI1/11/202417/6/2026
Cross Site Scripting vulnerability in Camtrace v.9.16.2.1 allows a remote attacker to execute arbitrary code via the login.php.
AnalizadaMedia (4.9)0.19%—Tomtretbar Mikrotik27/9/202417/6/2026
Improper Certificate Validation in Checkmk Exchange plugin MikroTik allows attackers in MitM position to intercept traffic. This issue affects MikroTik: from 2.0.0 through 2.5.5, from 0.4a_mk through 2.0a.
AplazadaMedia (6.5)0.18%—Comtrend Wld71-t1AIComtrend Grg-4280usAI10/6/202417/6/2026
Cross-Site Request Forgery vulnerability in Comtrend router WLD71-T1_v2.0.201820, affecting the GRG-4280us version. This vulnerability allows an attacker to force an end user to execute unwanted actions in a web application to which he is authenticated.
AplazadaAlta (8)0.89%—Comtrend Wld71-t1AIGeminasystems Grg-4280usAI10/6/202417/6/2026
Command injection vulnerability in Comtrend router WLD71-T1_v2.0.201820, affecting the GRG-4280us version. This vulnerability could allow an authenticated user to execute commands inside the router by making a POST request to the URL “/boaform/admin/formUserTracert”.
ModificadaAlta (8.1)0.58%—Demomentsomtres Export Posts With Images15/1/202417/6/2026
The DeMomentSomTres WordPress Export Posts With Images WordPress plugin through 20220825 does not check authorization of requests to export the blog data, allowing any logged in user, such as subscribers to export the contents of the blog, including restricted and unpublished posts, as well as passwords of protected…
ModificadaAlta (8.8)0.18%—Mtrv Teachpress5/1/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Michael Winkler teachPress.This issue affects teachPress: from n/a through 9.0.4.
ModificadaAlta (8.8)0.27%—Mtrv Teachpress18/12/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Michael Winkler teachPress.This issue affects teachPress: from n/a through 9.0.5.
ModificadaCrítica (9.8)1.1%—Armorxgt Spamtrap15/12/202317/6/2026
ArmorX Global Technology Corporation ArmorX Spam has insufficient validation for user input within a special function. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify and delete database.
ModificadaMedia (6.1)0.41%—Mtrv Teachpress25/7/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Michael Winkler teachPress plugin <= 9.0.2 versions.
ModificadaMedia (6.1)0.41%—Mtrv Teachpress23/3/202317/6/2026
Reflected Cross-Site Scripting (XSS) vulnerability in Michael Winkler teachPress plugin <= 8.1.8 versions.
ModificadaMedia (5.3)0.61%—Schismtracker Schism Tracker17/2/202317/6/2026
An issue in Schism Tracker v20200412 fixed in v.20200412 allows attacker to obtain sensitive information via the fmt_mtm_load_song function in fmt/mtm.c.
ModificadaMedia (5.4)0.97%💥 PoCComtrend Ar-5387un Firmware23/10/202017/6/2026
A cross-site scripting (XSS) vulnerability on Comtrend AR-5387un devices with A731-410JAZ-C04_R02.A2pD035g.d23i firmware allows remote attackers to inject arbitrary web script or HTML via the Service Description parameter while creating a WAN service.
ModificadaAlta (8.8)77%💥 ExploitComtrend Vr-3033 Firmware5/3/202017/6/2026
Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabilities via the ping and traceroute diagnostic pages, as demonstrated by shell metacharacters in the pingIpAddress parameter to ping.cgi.
ModificadaAlta (7.8)1.3%—Schismtracker Schism TrackerOpensuse BackportsOpensuse Leap2/8/201917/6/2026
An issue was discovered in Schism Tracker through 20190722. There is a heap-based buffer overflow via a large number of song patterns in fmt_mtm_load_song in fmt/mtm.c, a different vulnerability than CVE-2019-14465.
ModificadaAlta (7.8)1.2%—Schismtracker Schism Tracker2/8/201917/6/2026
An issue was discovered in Schism Tracker through 20190722. There is an integer underflow via a large plen in fmt_okt_load_song in the Amiga Oktalyzer parser in fmt/okt.c.
ModificadaAlta (7.8)1.2%—Schismtracker Schism Tracker31/7/201917/6/2026
fmt_mtm_load_song in fmt/mtm.c in Schism Tracker 20190722 has a heap-based buffer overflow.
ModificadaCrítica (9.8)1.5%—Comtrend Cm-6200un FirmwareComtrend Cm-6300n Firmware23/12/201817/6/2026
Comtrend CM-6200un 123.447.007 and CM-6300n 123.553mp1.005 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
ModificadaMedia (5.9)0.96%—Belden Hirschmann Rs20-0900mmm2tdauBelden Hirschmann Rs20-0900nnm4tdauBelden Hirschmann Rs20-0900vvm2tdauBelden Hirschmann Rs20-1600l2l2sdau+1306/3/201817/6/2026
A Cleartext Transmission of Sensitive Information issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. A cleartext transmission of sensitive information vulnerability in the web interface has been identified, which may allow an attacker to…
ModificadaCrítica (9.8)2.8%—Belden Hirschmann Rs20-0900mmm2tdauBelden Hirschmann Rs20-0900nnm4tdauBelden Hirschmann Rs20-0900vvm2tdauBelden Hirschmann Rs20-1600l2l2sdau+1306/3/201817/6/2026
An Improper Restriction of Excessive Authentication Attempts issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An improper restriction of excessive authentication vulnerability in the web interface has been identified, which may allow an…
ModificadaMedia (6.5)1.3%—Belden Hirschmann Rs20-0900mmm2tdauBelden Hirschmann Rs20-0900nnm4tdauBelden Hirschmann Rs20-0900vvm2tdauBelden Hirschmann Rs20-1600l2l2sdau+1306/3/201817/6/2026
An Information Exposure Through Query Strings in GET Request issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An information exposure through query strings vulnerability in the web interface has been identified, which may allow an attacker…
ModificadaAlta (8.8)1.7%—Belden Hirschmann Rs20-0900mmm2tdauBelden Hirschmann Rs20-0900nnm4tdauBelden Hirschmann Rs20-0900vvm2tdauBelden Hirschmann Rs20-1600l2l2sdau+1306/3/201817/6/2026
A Session Fixation issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. A session fixation vulnerability in the web interface has been identified, which may allow an attacker to hijack web sessions.
ModificadaMedia (6.5)0.44%—Belden Hirschmann Rs20-0900mmm2tdauBelden Hirschmann Rs20-0900nnm4tdauBelden Hirschmann Rs20-0900vvm2tdauBelden Hirschmann Rs20-1600l2l2sdau+1306/3/201817/6/2026
An Inadequate Encryption Strength issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An inadequate encryption strength vulnerability in the web interface has been identified, which may allow an attacker to obtain sensitive information through…
Orbitaley — Vulnerabilidades