Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

107 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8)0.29%—Starcharge Artemis AC ChargerAI27/10/202517/6/2026
StarCharge Artemis AC Charger 7-22 kW v1.0.4 was discovered to contain a stack overflow via the cgiMain function at download.cgi.
AplazadaAlta (8)0.17%—Startcharge Artemis AC Charger 7-22 KWAI27/10/202517/6/2026
An issue in the Web Configuration module of Startcharge Artemis AC Charger 7-22 kW v1.0.4 allows authenticated network-adjacent attackers to upload crafted firmware, leading to arbitrary code execution.
AplazadaCrítica (9.4)87%💥 ExploitShenzhen Aitemi M300 Wi-fi RepeaterAI7/8/202517/6/2026
An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) via the 'time' parameter of the '/protocol.csp?' endpoint. The input is processed by the internal date '-s' command without rebooting or disrupting HTTP service. Unlike other injection points,…
AplazadaCrítica (9.4)3.7%—Shenzhen Aitemi M300AI7/8/202517/6/2026
A command injection vulnerability exists in the 'passwd' parameter of the PPPoE setup process on the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02). The input is passed directly to system-level commands without sanitation, enabling unauthenticated attackers to achieve root-level code execution.
AplazadaCrítica (9.4)1.4%—Shenzhen Aitemi M300AI7/8/202517/6/2026
The PPPoE configuration interface of the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) is vulnerable to command injection via the 'user' parameter. Input is processed unsafely during network setup, allowing attackers to execute arbitrary system commands with root privileges.
AplazadaCrítica (9.4)1.4%—Shenzhen Aitemi M300AI7/8/202517/6/2026
A command injection vulnerability affects the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) during WPA2 configuration. The 'key' parameter is interpreted directly by the system shell, enabling attackers to execute arbitrary commands as root. Exploitation requires no authentication and can be triggered…
AplazadaCrítica (9.4)1.3%—Shenzhen Aitemi M300AI7/8/202517/6/2026
An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02). When configuring the device in WISP mode, the 'ssid' parameter is passed unsanitized to system-level scripts. This allows remote attackers within Wi-Fi range to inject arbitrary shell commands…
AplazadaCrítica (9.4)1.0%—Shenzhen Aitemi M300AI4/8/202517/6/2026
An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02). When configuring the device in Extender mode via its captive portal, the extap2g SSID field is inserted unescaped into a reboot-time shell script. This allows remote attackers within Wi-Fi…
AplazadaMedia (5.5)0.17%—Apache Activemq ArtemisAIActivemq Artemis OperatorAI26/5/202517/6/2026
A flaw was found in ActiveMQ Artemis. The password generated by activemq-artemis-operator does not regenerate between separated CR dependencies.
AnalizadaMedia (6.8)0.43%—Apache Artemis9/4/202517/6/2026
Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker properties are logged when the org.apache.activemq.artemis.core.config.impl.ConfigurationImpl logger has the debug level enabled. This issue affects Apache ActiveMQ Artemis: from 1.5.1 before 2.40.0.…
AnalizadaBaja (2.3)0.64%—Apache Artemis1/4/202517/6/2026
A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or createNonDurableQueue permission on an address can augment the routing-type supported by that address even if said user doesn't have the createAddress permission for that particular address. When combined with the send…
AnalizadaMedia (6.5)0.31%—Systemic-rm Risk Value18/3/202517/6/2026
Systemic Risk Value <=2.8.0 is vulnerable to improper access control in /RiskValue/GroupingEntities/Controls/GetFile.aspx?ID=. Uploaded files are accessible via a predictable numerical ID parameter, allowing unauthorized users to increment or decrement the ID to access and download files they do not have permission to…
AnalizadaAlta (7.5)0.38%—Systemic-rm Risk Value18/3/202517/6/2026
Systemic Risk Value <=2.8.0 is vulnerable to Local File Inclusion via /GetFile.aspx?ReportUrl=. An unauthenticated attacker can exploit this issue to read arbitrary system files by supplying a crafted file path, potentially exposing sensitive information.
AplazadaAlta (7.8)0.70%—SysteminformationAI20/12/202417/6/2026
systeminformation is a System and OS information library for node.js. In affected versions SSIDs are not sanitized when before they are passed as a parameter to cmd.exe in the `getWindowsIEEE8021x` function. This means that malicious content in the SSID can be executed as OS commands. This vulnerability may enable an…
ModificadaAlta (8.8)17%💥 PoCApache Artemis14/10/202417/6/2026
Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia endpoint. Before version 2.29.0, this also included the Log4J2 MBean. This MBean is not meant for exposure to non-administrative users. This could eventually allow an…
AplazadaMedia (5.3)0.40%—Lara-zeus Dynamic DashboardAILara-zeus Filament DashboardAIApache ArtemisAI7/10/202417/6/2026
Lara-zeus Dynamic Dashboard simple way to manage widgets for your website landing page, and filament dashboard and Lara-zeus artemis is a collection of themes for the lara-zeus ecosystem. If values passed to a paragraph widget are not valid and contain a specific set of characters, applications are vulnerable to XSS…
AplazadaMedia (5.8)0.25%—Optemiz Xplainer - Woocommerce Product FAQAI21/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Optemiz XPlainer - WooCommerce Product FAQ allows Reflected XSS.This issue affects XPlainer - WooCommerce Product FAQ: from n/a through 1.6.3.
ModificadaAlta (8.2)0.36%—Ls1intum Artemis Java Test Sandbox19/1/202414/7/2026
Artemis Java Test Sandbox versions less than 1.7.6 are vulnerable to a sandbox escape when an attacker crafts a special subclass of InvocationTargetException. An attacker can abuse this issue to execute arbitrary Java when a victim executes the supposedly sandboxed code.
ModificadaAlta (8.2)0.35%—Ls1intum Artemis Java Test Sandbox19/1/202414/7/2026
Artemis Java Test Sandbox versions before 1.8.0 are vulnerable to a sandbox escape when an attacker includes class files in a package that Ares trusts. An attacker can abuse this issue to execute arbitrary Java when a victim executes the supposedly sandboxed code.
ModificadaAlta (8.2)0.34%—Ls1intum Artemis Java Test Sandbox19/1/202414/7/2026
Artemis Java Test Sandbox versions before 1.11.2 are vulnerable to a sandbox escape when an attacker loads untrusted libraries using System.load or System.loadLibrary. An attacker can abuse this issue to execute arbitrary Java when a victim executes the supposedly sandboxed code.
ModificadaCrítica (9.8)2.2%—Systeminformation21/9/202317/6/2026
systeminformation is a System Information Library for Node.JS. Versions 5.0.0 through 5.21.6 have a SSID Command Injection Vulnerability. The problem was fixed with a parameter check in version 5.21.7. As a workaround, check or sanitize parameter strings that are passed to `wifiConnections()`, `wifiNetworks()` (string…
ModificadaCrítica (9.8)0.88%—Yontemizleme Vehicle Tracking System10/7/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yontem Informatics Vehicle Tracking System allows SQL Injection. This issue affects Vehicle Tracking System: before 8.
ModificadaMedia (5.4)3.1%💥 ExploitBroadcom Symantec Siteminder Webagent30/5/202317/6/2026
A user can supply malicious HTML and JavaScript code that will be executed in the client browser
ModificadaMedia (5.3)3.1%—Redhat AMQ BrokerApache Artemis24/8/202217/6/2026
A flaw was found in AMQ Broker. This issue can cause a partial interruption to the availability of AMQ Broker via an Out of memory (OOM) condition. This flaw allows an attacker to partially disrupt availability to the broker through a sustained attack of maliciously crafted messages. The highest threat from this…
ModificadaMedia (6.1)1.7%—Apache ArtemisNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation23/8/202217/6/2026
In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue.
Orbitaley — Vulnerabilidades