Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
107 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8) | 0.29% | — | Starcharge Artemis AC ChargerAI | 27/10/2025 | 17/6/2026 | StarCharge Artemis AC Charger 7-22 kW v1.0.4 was discovered to contain a stack overflow via the cgiMain function at download.cgi. | |
| Aplazada | Alta (8) | 0.17% | — | Startcharge Artemis AC Charger 7-22 KWAI | 27/10/2025 | 17/6/2026 | An issue in the Web Configuration module of Startcharge Artemis AC Charger 7-22 kW v1.0.4 allows authenticated network-adjacent attackers to upload crafted firmware, leading to arbitrary code execution. | |
| Aplazada | Crítica (9.4) | 87% | 💥 Exploit | Shenzhen Aitemi M300 Wi-fi RepeaterAI | 7/8/2025 | 17/6/2026 | An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) via the 'time' parameter of the '/protocol.csp?' endpoint. The input is processed by the internal date '-s' command without rebooting or disrupting HTTP service. Unlike other injection points,… | |
| Aplazada | Crítica (9.4) | 3.7% | — | Shenzhen Aitemi M300AI | 7/8/2025 | 17/6/2026 | A command injection vulnerability exists in the 'passwd' parameter of the PPPoE setup process on the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02). The input is passed directly to system-level commands without sanitation, enabling unauthenticated attackers to achieve root-level code execution. | |
| Aplazada | Crítica (9.4) | 1.4% | — | Shenzhen Aitemi M300AI | 7/8/2025 | 17/6/2026 | The PPPoE configuration interface of the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) is vulnerable to command injection via the 'user' parameter. Input is processed unsafely during network setup, allowing attackers to execute arbitrary system commands with root privileges. | |
| Aplazada | Crítica (9.4) | 1.4% | — | Shenzhen Aitemi M300AI | 7/8/2025 | 17/6/2026 | A command injection vulnerability affects the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) during WPA2 configuration. The 'key' parameter is interpreted directly by the system shell, enabling attackers to execute arbitrary commands as root. Exploitation requires no authentication and can be triggered… | |
| Aplazada | Crítica (9.4) | 1.3% | — | Shenzhen Aitemi M300AI | 7/8/2025 | 17/6/2026 | An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02). When configuring the device in WISP mode, the 'ssid' parameter is passed unsanitized to system-level scripts. This allows remote attackers within Wi-Fi range to inject arbitrary shell commands… | |
| Aplazada | Crítica (9.4) | 1.0% | — | Shenzhen Aitemi M300AI | 4/8/2025 | 17/6/2026 | An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02). When configuring the device in Extender mode via its captive portal, the extap2g SSID field is inserted unescaped into a reboot-time shell script. This allows remote attackers within Wi-Fi… | |
| Aplazada | Media (5.5) | 0.17% | — | Apache Activemq ArtemisAIActivemq Artemis OperatorAI | 26/5/2025 | 17/6/2026 | A flaw was found in ActiveMQ Artemis. The password generated by activemq-artemis-operator does not regenerate between separated CR dependencies. | |
| Analizada | Media (6.8) | 0.43% | — | Apache Artemis | 9/4/2025 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker properties are logged when the org.apache.activemq.artemis.core.config.impl.ConfigurationImpl logger has the debug level enabled. This issue affects Apache ActiveMQ Artemis: from 1.5.1 before 2.40.0.… | |
| Analizada | Baja (2.3) | 0.64% | — | Apache Artemis | 1/4/2025 | 17/6/2026 | A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or createNonDurableQueue permission on an address can augment the routing-type supported by that address even if said user doesn't have the createAddress permission for that particular address. When combined with the send… | |
| Analizada | Media (6.5) | 0.31% | — | Systemic-rm Risk Value | 18/3/2025 | 17/6/2026 | Systemic Risk Value <=2.8.0 is vulnerable to improper access control in /RiskValue/GroupingEntities/Controls/GetFile.aspx?ID=. Uploaded files are accessible via a predictable numerical ID parameter, allowing unauthorized users to increment or decrement the ID to access and download files they do not have permission to… | |
| Analizada | Alta (7.5) | 0.38% | — | Systemic-rm Risk Value | 18/3/2025 | 17/6/2026 | Systemic Risk Value <=2.8.0 is vulnerable to Local File Inclusion via /GetFile.aspx?ReportUrl=. An unauthenticated attacker can exploit this issue to read arbitrary system files by supplying a crafted file path, potentially exposing sensitive information. | |
| Aplazada | Alta (7.8) | 0.70% | — | SysteminformationAI | 20/12/2024 | 17/6/2026 | systeminformation is a System and OS information library for node.js. In affected versions SSIDs are not sanitized when before they are passed as a parameter to cmd.exe in the `getWindowsIEEE8021x` function. This means that malicious content in the SSID can be executed as OS commands. This vulnerability may enable an… | |
| Modificada | Alta (8.8) | 17% | 💥 PoC | Apache Artemis | 14/10/2024 | 17/6/2026 | Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia endpoint. Before version 2.29.0, this also included the Log4J2 MBean. This MBean is not meant for exposure to non-administrative users. This could eventually allow an… | |
| Aplazada | Media (5.3) | 0.40% | — | Lara-zeus Dynamic DashboardAILara-zeus Filament DashboardAIApache ArtemisAI | 7/10/2024 | 17/6/2026 | Lara-zeus Dynamic Dashboard simple way to manage widgets for your website landing page, and filament dashboard and Lara-zeus artemis is a collection of themes for the lara-zeus ecosystem. If values passed to a paragraph widget are not valid and contain a specific set of characters, applications are vulnerable to XSS… | |
| Aplazada | Media (5.8) | 0.25% | — | Optemiz Xplainer - Woocommerce Product FAQAI | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Optemiz XPlainer - WooCommerce Product FAQ allows Reflected XSS.This issue affects XPlainer - WooCommerce Product FAQ: from n/a through 1.6.3. | |
| Modificada | Alta (8.2) | 0.36% | — | Ls1intum Artemis Java Test Sandbox | 19/1/2024 | 14/7/2026 | Artemis Java Test Sandbox versions less than 1.7.6 are vulnerable to a sandbox escape when an attacker crafts a special subclass of InvocationTargetException. An attacker can abuse this issue to execute arbitrary Java when a victim executes the supposedly sandboxed code. | |
| Modificada | Alta (8.2) | 0.35% | — | Ls1intum Artemis Java Test Sandbox | 19/1/2024 | 14/7/2026 | Artemis Java Test Sandbox versions before 1.8.0 are vulnerable to a sandbox escape when an attacker includes class files in a package that Ares trusts. An attacker can abuse this issue to execute arbitrary Java when a victim executes the supposedly sandboxed code. | |
| Modificada | Alta (8.2) | 0.34% | — | Ls1intum Artemis Java Test Sandbox | 19/1/2024 | 14/7/2026 | Artemis Java Test Sandbox versions before 1.11.2 are vulnerable to a sandbox escape when an attacker loads untrusted libraries using System.load or System.loadLibrary. An attacker can abuse this issue to execute arbitrary Java when a victim executes the supposedly sandboxed code. | |
| Modificada | Crítica (9.8) | 2.2% | — | Systeminformation | 21/9/2023 | 17/6/2026 | systeminformation is a System Information Library for Node.JS. Versions 5.0.0 through 5.21.6 have a SSID Command Injection Vulnerability. The problem was fixed with a parameter check in version 5.21.7. As a workaround, check or sanitize parameter strings that are passed to `wifiConnections()`, `wifiNetworks()` (string… | |
| Modificada | Crítica (9.8) | 0.88% | — | Yontemizleme Vehicle Tracking System | 10/7/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yontem Informatics Vehicle Tracking System allows SQL Injection. This issue affects Vehicle Tracking System: before 8. | |
| Modificada | Media (5.4) | 3.1% | 💥 Exploit | Broadcom Symantec Siteminder Webagent | 30/5/2023 | 17/6/2026 | A user can supply malicious HTML and JavaScript code that will be executed in the client browser | |
| Modificada | Media (5.3) | 3.1% | — | Redhat AMQ BrokerApache Artemis | 24/8/2022 | 17/6/2026 | A flaw was found in AMQ Broker. This issue can cause a partial interruption to the availability of AMQ Broker via an Out of memory (OOM) condition. This flaw allows an attacker to partially disrupt availability to the broker through a sustained attack of maliciously crafted messages. The highest threat from this… | |
| Modificada | Media (6.1) | 1.7% | — | Apache ArtemisNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation | 23/8/2022 | 17/6/2026 | In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue. |