Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

52 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.38%—Akbim Panon3/4/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Akbim Computer Panon allows Reflected XSS. This issue affects Panon: before 1.0.2.
ModificadaCrítica (9.8)0.70%—Akbim Panon3/4/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Akbim Computer Panon allows SQL Injection. This issue affects Panon: before 1.0.2.
ModificadaMedia (5.4)0.36%—Wepanow Print Away3/2/202317/6/2026
WEPA Print Away does not verify that a user has authorization to access documents before generating print orders and associated release codes. This could allow an attacker to generate print orders and release codes for documents they don´t own and print hem without authorization. In order to exploit this…
ModificadaMedia (5.4)0.37%—Wepanow Print Away3/2/202317/6/2026
WEPA Print Away is vulnerable to a stored XSS. It does not properly sanitize uploaded filenames, allowing an attacker to deceive a user into uploading a document with a malicious filename, which will be included in subsequent HTTP responses, allowing a stored XSS to occur. This attack is persistent across victim…
ModificadaMedia (5.4)0.47%—Ipanorama 360 Wordpress Virtual Tour Builder Project Ipanorama 360 Wordpress Virtual Tour Builder9/1/202317/6/2026
The iPanorama 360 WordPress Virtual Tour Builder plugin through 1.6.29 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaCrítica (9.8)2.2%—Kopano Groupware Core1/4/202217/6/2026
An issue in provider/libserver/ECKrbAuth.cpp of Kopano Core <= v11.0.2.51 contains an issue which allows attackers to authenticate even if the user account or password is expired. It also exists in the predecessor Zarafa Collaboration Platform (ZCP) in provider/libserver/ECPamAuth.cpp of Zarafa >= 6.30 (introduced…
ModificadaAlta (7.2)1.6%—Bosch Autodome IP 4000i FirmwareBosch Autodome IP 5000i FirmwareBosch Autodome IP Starlight 5000i FirmwareBosch Autodome IP Starlight 7000i Firmware+6430/3/202217/6/2026
A specially crafted TCP/IP packet may cause the camera recovery image web interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can only be booted with administrative rights or with physical access to the camera and allows the upload of a new firmware in…
ModificadaAlta (7.2)1.6%—Bosch Autodome IP 4000i FirmwareBosch Autodome IP 5000i FirmwareBosch Autodome IP Starlight 5000i FirmwareBosch Autodome IP Starlight 7000i Firmware+6430/3/202217/6/2026
A specially crafted TCP/IP packet may cause a camera recovery image telnet interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can only be booted with administrative rights or with physical access to the camera and allows the upload of a new firmware in…
ModificadaCrítica (9.1)2.1%—Libpano13 Project Libpano13Debian Linux10/3/202217/6/2026
Panorama Tools libpano13 v2.9.20 was discovered to contain an out-of-bounds read in the function panoParserFindOLine() in parser.c.
ModificadaCrítica (9.8)1.9%—Libpano13 Project Libpano13Fedoraproject FedoraDebian Linux5/4/202117/6/2026
Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2.9.20~rc2+dfsg-3 and earlier can lead to read and write arbitrary memory values.
ModificadaAlta (7.5)2.0%—Kopano Groupware CoreZarafa31/3/202117/6/2026
kopano-ical (formerly zarafa-ical) in Kopano Groupware Core through 8.7.16, 9.x through 9.1.0, 10.x through 10.0.7, and 11.x through 11.0.1 and Zarafa 6.30.x through 7.2.x allows memory exhaustion via long HTTP headers.
ModificadaMedia (6.1)4.1%—Krpano7/1/202117/6/2026
The default installation of Krpano Panorama Viewer version <=1.20.8 is vulnerable to Reflected XSS due to insecure remote js load in file viewer/krpano.html, parameter plugin[test].url.
ModificadaMedia (6.1)0.87%—Krpano7/1/202117/6/2026
The default installation of Krpano Panorama Viewer version <=1.20.8 is prone to Reflected XSS due to insecure XML load in file /viewer/krpano.html, parameter xml.
ModificadaAlta (7.4)0.97%—Panorama Project Nhiservisignadapter31/12/202017/6/2026
The digest generation function of NHIServiSignAdapter has not been verified for source file path, which leads to the SMB request being redirected to a malicious host, resulting in the leakage of user's credential.
ModificadaAlta (7.4)0.97%—Panorama Project Nhiservisignadapter31/12/202017/6/2026
Multiple functions of NHIServiSignAdapter failed to verify the users’ file path, which leads to the SMB request being redirected to a malicious host, resulting in the leakage of user's credential.
ModificadaCrítica (9.8)2.0%—Panorama Nhiservisignadapter31/12/202017/6/2026
The digest generation function of NHIServiSignAdapter has not been verified for parameter’s length, which leads to a stack overflow loophole. Remote attackers can use the leak to execute code without privilege.
ModificadaCrítica (9.8)2.0%—Panorama Nhiservisignadapter31/12/202017/6/2026
NHIServiSignAdapter fails to verify the length of digital credential files’ path which leads to a heap overflow loophole. Remote attackers can use the leak to execute code without privilege.
ModificadaAlta (7.5)0.51%—Panorama Nhiservisignadapter31/12/202017/6/2026
The encryption function of NHIServiSignAdapter fail to verify the file path input by users. Remote attacker can access arbitrary files through the flaw without privilege.
ModificadaAlta (7.8)0.50%—Opensuse LeapOpensuse Tumbleweed Kopano-spamd29/6/202017/6/2026
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of kopano-spamd of openSUSE Leap 15.1, openSUSE Tumbleweed allowed local attackers with the privileges of the kopano user to escalate to root. This issue affects: openSUSE Leap 15.1 kopano-spamd versions prior to 10.0.5-lp151.4.1. openSUSE…
ModificadaCrítica (9.8)2.2%—Kopano Groupware Core19/12/201917/6/2026
HrAddFBBlock in libfreebusy/freebusyutil.cpp in Kopano Groupware Core before 8.7.7 allows out-of-bounds access, as demonstrated by mishandling of an array copy during parsing of ICal data.
ModificadaCrítica (9.8)2.3%—Cylan Clever DOG Smart Camera Panorama Dog-2w FirmwareCylan Clever DOG Smart Camera Plus Dog-2w-v4 Firmware20/6/201917/6/2026
On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the network can login remotely to the camera and gain root access. The device ships with a hardcoded 12345678 password for the root account, accessible from a TELNET login prompt.
ModificadaMedia (5.5)0.35%—Cylan Clever DOG Smart Camera Panorama Dog-2w FirmwareCylan Clever DOG Smart Camera Plus Dog-2w-v4 Firmware20/6/201917/6/2026
On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the local network has unauthenticated access to the internal SD card via the HTTP service on port 8000. The HTTP web server on the camera allows anyone to view or download the video archive recorded and saved on the external memory…
ModificadaCrítica (9.8)5.2%—Polycom Group SeriesPolycom HDXPolycom Pano13/5/201917/6/2026
An issue was discovered in Polycom Group Series 6.1.6.1 and earlier, HDX 3.1.12 and earlier, and Pano 1.1.1 and earlier. A remote code execution vulnerability exists in the content sharing functionality because of a Buffer Overflow via crafted packets.
ModificadaMedia (6.1)0.75%—Kopano Webapp26/7/201717/6/2026
Cross-site scripting (XSS) vulnerability in js/ViewerPanel.js in the file previewer plugin in Kopano WebApp versions 3.3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via a specially crafted previewable file.
ModificadaBaja (3.5)0.94%—Panopoly Magic Project Panopoly Magic26/2/201517/6/2026
Cross-site scripting (XSS) vulnerability in the live preview in the Panopoly Magic module before 7.x-1.17 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a pane title.
Orbitaley — Vulnerabilidades