Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
68 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.27% | — | TrmtrackerAI | 25/3/2025 | 17/6/2026 | The TRMTracker web application is vulnerable to LDAP injection attack potentially allowing an attacker to inject code into a query and execute remote commands that can read and update data on the website. | |
| Modificada | Media (4.3) | 0.18% | — | Mtrv Teachpress | 25/3/2025 | 17/6/2026 | The teachPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.0.9. This is due to missing or incorrect nonce validation on the import.php page. This makes it possible for unauthenticated attackers to delete imports via a forged request granted they can trick a… | |
| Analizada | Alta (8.8) | 0.50% | — | Mtrv Teachpress | 4/3/2025 | 17/6/2026 | The teachPress plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tpsearch' shortcode in all versions up to, and including, 9.0.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (6.1) | 0.40% | — | CamtraceAI | 1/11/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Camtrace v.9.16.2.1 allows a remote attacker to execute arbitrary code via the login.php. | |
| Analizada | Media (4.9) | 0.19% | — | Tomtretbar Mikrotik | 27/9/2024 | 17/6/2026 | Improper Certificate Validation in Checkmk Exchange plugin MikroTik allows attackers in MitM position to intercept traffic. This issue affects MikroTik: from 2.0.0 through 2.5.5, from 0.4a_mk through 2.0a. | |
| Aplazada | Media (6.5) | 0.18% | — | Comtrend Wld71-t1AIComtrend Grg-4280usAI | 10/6/2024 | 17/6/2026 | Cross-Site Request Forgery vulnerability in Comtrend router WLD71-T1_v2.0.201820, affecting the GRG-4280us version. This vulnerability allows an attacker to force an end user to execute unwanted actions in a web application to which he is authenticated. | |
| Aplazada | Alta (8) | 0.89% | — | Comtrend Wld71-t1AIGeminasystems Grg-4280usAI | 10/6/2024 | 17/6/2026 | Command injection vulnerability in Comtrend router WLD71-T1_v2.0.201820, affecting the GRG-4280us version. This vulnerability could allow an authenticated user to execute commands inside the router by making a POST request to the URL “/boaform/admin/formUserTracert”. | |
| Modificada | Alta (8.1) | 0.58% | — | Demomentsomtres Export Posts With Images | 15/1/2024 | 17/6/2026 | The DeMomentSomTres WordPress Export Posts With Images WordPress plugin through 20220825 does not check authorization of requests to export the blog data, allowing any logged in user, such as subscribers to export the contents of the blog, including restricted and unpublished posts, as well as passwords of protected… | |
| Modificada | Alta (8.8) | 0.18% | — | Mtrv Teachpress | 5/1/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Michael Winkler teachPress.This issue affects teachPress: from n/a through 9.0.4. | |
| Modificada | Alta (8.8) | 0.27% | — | Mtrv Teachpress | 18/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Michael Winkler teachPress.This issue affects teachPress: from n/a through 9.0.5. | |
| Modificada | Crítica (9.8) | 1.1% | — | Armorxgt Spamtrap | 15/12/2023 | 17/6/2026 | ArmorX Global Technology Corporation ArmorX Spam has insufficient validation for user input within a special function. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify and delete database. | |
| Modificada | Media (6.1) | 0.41% | — | Mtrv Teachpress | 25/7/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Michael Winkler teachPress plugin <= 9.0.2 versions. | |
| Modificada | Media (6.1) | 0.41% | — | Mtrv Teachpress | 23/3/2023 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) vulnerability in Michael Winkler teachPress plugin <= 8.1.8 versions. | |
| Modificada | Media (5.3) | 0.61% | — | Schismtracker Schism Tracker | 17/2/2023 | 17/6/2026 | An issue in Schism Tracker v20200412 fixed in v.20200412 allows attacker to obtain sensitive information via the fmt_mtm_load_song function in fmt/mtm.c. | |
| Modificada | Media (5.4) | 0.97% | 💥 PoC | Comtrend Ar-5387un Firmware | 23/10/2020 | 17/6/2026 | A cross-site scripting (XSS) vulnerability on Comtrend AR-5387un devices with A731-410JAZ-C04_R02.A2pD035g.d23i firmware allows remote attackers to inject arbitrary web script or HTML via the Service Description parameter while creating a WAN service. | |
| Modificada | Alta (8.8) | 77% | 💥 Exploit | Comtrend Vr-3033 Firmware | 5/3/2020 | 17/6/2026 | Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabilities via the ping and traceroute diagnostic pages, as demonstrated by shell metacharacters in the pingIpAddress parameter to ping.cgi. | |
| Modificada | Alta (7.8) | 1.3% | — | Schismtracker Schism TrackerOpensuse BackportsOpensuse Leap | 2/8/2019 | 17/6/2026 | An issue was discovered in Schism Tracker through 20190722. There is a heap-based buffer overflow via a large number of song patterns in fmt_mtm_load_song in fmt/mtm.c, a different vulnerability than CVE-2019-14465. | |
| Modificada | Alta (7.8) | 1.2% | — | Schismtracker Schism Tracker | 2/8/2019 | 17/6/2026 | An issue was discovered in Schism Tracker through 20190722. There is an integer underflow via a large plen in fmt_okt_load_song in the Amiga Oktalyzer parser in fmt/okt.c. | |
| Modificada | Alta (7.8) | 1.2% | — | Schismtracker Schism Tracker | 31/7/2019 | 17/6/2026 | fmt_mtm_load_song in fmt/mtm.c in Schism Tracker 20190722 has a heap-based buffer overflow. | |
| Modificada | Crítica (9.8) | 1.5% | — | Comtrend Cm-6200un FirmwareComtrend Cm-6300n Firmware | 23/12/2018 | 17/6/2026 | Comtrend CM-6200un 123.447.007 and CM-6300n 123.553mp1.005 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests. | |
| Modificada | Media (5.9) | 0.96% | — | Belden Hirschmann Rs20-0900mmm2tdauBelden Hirschmann Rs20-0900nnm4tdauBelden Hirschmann Rs20-0900vvm2tdauBelden Hirschmann Rs20-1600l2l2sdau+130 | 6/3/2018 | 17/6/2026 | A Cleartext Transmission of Sensitive Information issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. A cleartext transmission of sensitive information vulnerability in the web interface has been identified, which may allow an attacker to… | |
| Modificada | Crítica (9.8) | 2.8% | — | Belden Hirschmann Rs20-0900mmm2tdauBelden Hirschmann Rs20-0900nnm4tdauBelden Hirschmann Rs20-0900vvm2tdauBelden Hirschmann Rs20-1600l2l2sdau+130 | 6/3/2018 | 17/6/2026 | An Improper Restriction of Excessive Authentication Attempts issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An improper restriction of excessive authentication vulnerability in the web interface has been identified, which may allow an… | |
| Modificada | Media (6.5) | 1.3% | — | Belden Hirschmann Rs20-0900mmm2tdauBelden Hirschmann Rs20-0900nnm4tdauBelden Hirschmann Rs20-0900vvm2tdauBelden Hirschmann Rs20-1600l2l2sdau+130 | 6/3/2018 | 17/6/2026 | An Information Exposure Through Query Strings in GET Request issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An information exposure through query strings vulnerability in the web interface has been identified, which may allow an attacker… | |
| Modificada | Alta (8.8) | 1.7% | — | Belden Hirschmann Rs20-0900mmm2tdauBelden Hirschmann Rs20-0900nnm4tdauBelden Hirschmann Rs20-0900vvm2tdauBelden Hirschmann Rs20-1600l2l2sdau+130 | 6/3/2018 | 17/6/2026 | A Session Fixation issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. A session fixation vulnerability in the web interface has been identified, which may allow an attacker to hijack web sessions. | |
| Modificada | Media (6.5) | 0.44% | — | Belden Hirschmann Rs20-0900mmm2tdauBelden Hirschmann Rs20-0900nnm4tdauBelden Hirschmann Rs20-0900vvm2tdauBelden Hirschmann Rs20-1600l2l2sdau+130 | 6/3/2018 | 17/6/2026 | An Inadequate Encryption Strength issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An inadequate encryption strength vulnerability in the web interface has been identified, which may allow an attacker to obtain sensitive information through… |