Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
47 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.26% | — | Wptrio Conditional Shipping FOR Woocommerce | 2/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Lauri Karisola / WP Trio Conditional Shipping for WooCommerce plugin <= 2.3.1 versions. | |
| Modificada | Alta (8.8) | 2.7% | — | Poly Trio 8800 Firmware | 28/12/2021 | 17/6/2026 | A remote code execution issue in the ping command on Poly Trio 8800 5.7.1.4145 devices allows remote authenticated users to execute commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.1% | — | NI Compactrio Firmware | 11/12/2020 | 17/6/2026 | Incorrect permissions are set by default for an API entry-point of a specific service, allowing a non-authenticated user to trigger a function that could reboot the CompactRIO (Driver versions prior to 20.5) remotely. | |
| Modificada | Alta (7.8) | 0.51% | — | Patriotmemory Viper RGB Firmware | 6/3/2020 | 17/6/2026 | Patriot Viper RGB Driver 1.1 and prior exposes IOCTL and allows insufficient access control. The IOCTL Codes 0x80102050 and 0x80102054 allows a local user with low privileges to read/write 1/2/4 bytes from or to an IO port. This could be leveraged in a number of ways to ultimately run code with elevated privileges. | |
| Modificada | Alta (7.8) | 0.51% | — | Patriotmemory Viper RGB Driver | 21/2/2020 | 17/6/2026 | A buffer overflow was found in Patriot Viper RGB through 1.1 when processing IoControlCode 0x80102040. Local attackers (including low integrity processes) can exploit this to gain NT AUTHORITY\SYSTEM privileges. | |
| Modificada | Media (5.9) | 0.60% | — | Fujitsu Gp7000f FirmwareFujitsu Primepower FirmwareFujitsu GPS FirmwareFujitsu Sparc Enterprise M3000 Firmware+36 | 7/2/2020 | 17/6/2026 | The Fujitsu TLS library allows a man-in-the-middle attack. This affects Interstage Application Development Cycle Manager V10 and other versions, Interstage Application Server V12 and other versions, Interstage Business Application Manager V2 and other versions, Interstage Information Integrator V11 and other versions,… | |
| Modificada | Alta (7.1) | 0.41% | 💥 PoC | Patriotmemory Viper RGB Firmware | 9/11/2019 | 17/6/2026 | The MsIo64.sys and MsIo32.sys drivers in Patriot Viper RGB before 1.1 allow local users (including low integrity processes) to read and write to arbitrary memory locations, and consequently gain NT AUTHORITY\SYSTEM privileges, by mapping \Device\PhysicalMemory into the calling process via ZwOpenSection and… | |
| Modificada | Media (6.1) | 0.65% | — | Polycom Trio 8500 Firmware | 15/11/2018 | 17/6/2026 | The Web administration console on Polycom Trio devices with software before 5.5.4 has XSS. | |
| Modificada | Media (6.5) | 0.54% | — | Polycom Trio 8500 Firmware | 15/11/2018 | 17/6/2026 | The Bluetooth subsystem on Polycom Trio devices with software before 5.5.4 has Incorrect Access Control. An attacker can connect without authentication and subsequently record audio from the device microphone. | |
| Modificada | Media (6.8) | 1.2% | — | Trioniclabs Sentinel | 25/10/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in wordpress_sentinel.php in the Sentinel plugin 1.0.0 for WordPress allows remote attackers to hijack the authentication of an administrator for requests that trigger snapshots. | |
| Modificada | Media (4.3) | 2.5% | — | Trioniclabs Sentinel | 25/10/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in wordpress_sentinel.php in the Sentinel plugin 1.0.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | |
| Modificada | Alta (7.5) | 2.7% | — | Trioniclabs Sentinel | 25/10/2012 | 16/6/2026 | SQL injection vulnerability in the Sentinel plugin 1.0.0 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Activecampaign Triolive | 13/11/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in department_offline_context.php in ActiveCampaign TrioLive before 1.58.7 allows remote attackers to inject arbitrary web script or HTML via the department_id parameter to index.php. | |
| Modificada | Alta (7.5) | 1.3% | — | Activecampaign Triolive | 13/11/2008 | 16/6/2026 | SQL injection vulnerability in department_offline_context.php in ActiveCampaign TrioLive before 1.58.7 allows remote attackers to execute arbitrary SQL commands via the department_id parameter to index.php. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Willo Trio | 31/7/2008 | 16/6/2026 | SQL injection vulnerability in browse.php in TriO 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (6.8) | 29% | 💥 Exploit | Trionic Cite CMS | 8/10/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Trionic Cite CMS 1.2 rev9 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the bField[bf_data] parameter to (1) interface/editors/-custom.php or (2) interface/editors/custom.php. | |
| Modificada | Media (5) | 1.5% | — | Activecampaign Supporttrio | 29/3/2006 | 16/6/2026 | ActiveCampaign SupportTrio 2.5 allows remote attackers to obtain the full path of the server via invalid (1) article or (2) print parameters in a kb action to index.php, or (3) an invalid category parameter to modules/KB/pdf.php, which leaks the path in an error message. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Activecampaign Supporttrio | 29/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ActiveCampaign SupportTrio 2.50.2 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the KnowledgeBase search module. | |
| Modificada | Alta (7.5) | 1.5% | — | Activecampaign 1-2-allActivecampaign GeneralActivecampaign IsalientActivecampaign Knowledgebuilder+2 | 3/3/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in one or more ActiveCampaign products, possibly SupportTrio, allows remote attackers to include and execute arbitrary files via the page parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Activecampaign Supporttrio | 31/12/2005 | 16/6/2026 | SQL injection vulnerability in index.php in ActiveCampaign SupportTrio 1.4 allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the provenance of this information is unknown because the source URL is not available; the details are obtained solely from third party information. | |
| Modificada | Media (5) | 1.6% | — | Activecampaign SupporttrioAI | 26/11/2005 | 16/6/2026 | index.php in ActiveCampaign SupportTrio 1.4 and earlier allows remote attackers to read or include arbitrary files via the page parameter, possibly due to a directory traversal vulnerability. | |
| Modificada | Alta (7.5) | 3.2% | — | Triornis Zoneminder | 14/6/2004 | 16/6/2026 | Buffer overflow in the zms script in ZoneMinder before 1.19.2 may allow a remote attacker to execute arbitrary code via a long query string. |