Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.78% | — | Astrbot | 7/11/2025 | 17/6/2026 | AstrBot Project v3.5.22 contains a directory traversal vulnerability. The handler function install_plugin_upload of the interface '/plugin/install-upload' parses the filename from the request body provided by the user, and directly uses the filename to assign to file_path without checking the validity of the filename.… | |
| Analizada | Alta (7.5) | 0.74% | — | Astrbot | 2/6/2025 | 17/6/2026 | AstrBot is a large language model chatbot and development framework. A path traversal vulnerability present in versions 3.4.4 through 3.5.12 may lead to information disclosure, such as API keys for LLM providers, account passwords, and other sensitive data. The vulnerability has been addressed in Pull Request #1676… | |
| Analizada | Media (6.1) | 0.26% | — | Sfarbota Download Html Tinymce Button | 15/5/2025 | 17/6/2026 | The Download HTML TinyMCE Button WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Modificada | Alta (7.7) | 0.22% | — | Ecovacs Deebot 900 FirmwareEcovacs Deebot N8 FirmwareEcovacs Deebot T8 FirmwareEcovacs Deebot N9 Firmware+10 | 23/1/2025 | 17/6/2026 | ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can create and encrypt malicious firmware that will be successfully decrypted and installed by the robot. | |
| Analizada | Baja (1.8) | 0.21% | — | Ecovacs Deebot N8 FirmwareEcovacs Deebot 900 FirmwareEcovacs Deebot T8 FirmwareEcovacs Deebot N9 Firmware+10 | 23/1/2025 | 17/6/2026 | ECOVACS robot lawnmowers and vacuums insecurely store audio files used to indicate that the camera is on. An attacker with access to the /data filesystem can delete or modify warning files such that users may not be aware that the camera is on. | |
| Analizada | Media (4.8) | 0.15% | — | Ecovacs Deebot 900 FirmwareEcovacs Deebot N8 FirmwareEcovacs Deebot T8 FirmwareEcovacs Deebot N9 Firmware+10 | 23/1/2025 | 17/6/2026 | ECOVACS robot lawnmowers store the anti-theft PIN in cleartext on the device filesystem. An attacker can steal a lawnmower, read the PIN, and reset the anti-theft mechanism. | |
| Analizada | Media (5.3) | 0.33% | — | Ecovacs Deebot N10 FirmwareEcovacs Deebot T10 FirmwareEcovacs Deebot X1 FirmwareEcovacs Deebot T20 Firmware+10 | 23/1/2025 | 17/6/2026 | ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthenticated attacker within BLE range can control any robot using the same key. | |
| Analizada | Alta (7) | 0.40% | — | Ecovacs Deebot 900 FirmwareEcovacs Deebot N8 FirmwareEcovacs Deebot T8 FirmwareEcovacs Deebot N9 Firmware+10 | 23/1/2025 | 17/6/2026 | ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial number. An attacker with shell access can login as root. | |
| Modificada | Alta (7.5) | 0.80% | — | Torbot Project TorbotValidators Project Validators | 18/10/2023 | 17/6/2026 | Torbot is an open source tor network intelligence tool. In affected versions the `torbot.modules.validators.validate_link function` uses the python-validators URL validation regex. This particular regular expression has an exponential complexity which allows an attacker to cause an application crash using a… | |
| Modificada | Crítica (9.8) | 0.66% | — | Flairbot Project Flairbot | 7/1/2023 | 17/6/2026 | A vulnerability was found in tiredtyrant flairbot. It has been declared as critical. This vulnerability affects unknown code of the file flair.py. The manipulation leads to sql injection. The patch is identified as 5e112b68c6faad1d4699d02c1ebbb7daf48ef8fb. It is recommended to apply a patch to fix this issue.… | |
| Modificada | Crítica (9.8) | 3.4% | — | Ruby-rbot Rbot | 6/11/2019 | 16/6/2026 | Rbot Reaction plugin allows command execution | |
| Modificada | Alta (7.5) | 1.2% | — | Makerbot Replicator 5TH Generation Firmware | 24/6/2019 | 17/6/2026 | The MakerBot Replicator 5G printer runs an Apache HTTP Server with directory indexing enabled. Apache logs, system logs, design files (i.e., a history of print files), and more are exposed to unauthenticated attackers through this HTTP server. | |
| Modificada | Alta (7.5) | 1.5% | — | Turbotraffictrader PHP | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in tttadmin/settings.php in Turbo Traffic Trader PHP 1.0 allows remote attackers to execute arbitrary SQL commands via the ttt_admin parameter. | |
| Modificada | Media (4.3) | 2.8% | 💥 Exploit | Turbotraffictrader C | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Turbo Traffic Trader C (TTT-C) 1.0 allow remote attackers to inject arbitrary HTML or web script, as demonstrated via (1) the link parameter to ttt-out, (2) the X-Forwarded-For header in a GET request to ttt-in, (3) the Referer header in a GET request to ttt-in,… | |
| Modificada | Media (4.3) | 1.4% | — | Turbotraffictrader PHP | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ttt-webmaster.php in Turbo Traffic Trader PHP 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) msg[0] or (2) siteurl parameters. |