Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
142 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.3) | 0.14% | — | Ecovacs Deebot X1S PRO FirmwareEcovacs Deebot X1 PRO Omni FirmwareEcovacs Deebot X1 Omni FirmwareEcovacs Deebot X1 Turbo Firmware+9 | 5/9/2025 | 17/6/2026 | ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic AES encryption key, which can be easily derived. | |
| Analizada | Alta (7.5) | 0.29% | — | Ecovacs Deebot X1S PRO FirmwareEcovacs Deebot X1 PRO Omni FirmwareEcovacs Deebot X1 Omni FirmwareEcovacs Deebot X1 Turbo Firmware+9 | 5/9/2025 | 17/6/2026 | ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be sent to base station via insecure connection between robot and base station. | |
| Analizada | Baja (2.3) | 0.22% | — | Ecovacs Deebot X1S PRO FirmwareEcovacs Deebot X1 PRO Omni FirmwareEcovacs Deebot X1 Omni FirmwareEcovacs Deebot X1 Turbo Firmware+9 | 5/9/2025 | 17/6/2026 | ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easily derived. | |
| Aplazada | Crítica (10) | 1.5% | 💥 Exploit | Turbo FTP ServerAI | 5/8/2025 | 16/6/2026 | Turbo FTP Server versions 1.30.823 and 1.30.826 contain a buffer overflow vulnerability in the handling of the PORT command. By sending a specially crafted payload, an unauthenticated remote attacker can overwrite memory structures and execute arbitrary code with SYSTEM privileges. | |
| Analizada | Media (6.9) | 0.68% | — | Harry0703 Moneyprinterturbo | 20/7/2025 | 17/6/2026 | A vulnerability was found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this issue is the function verify_token of the file app/controllers/base.py of the component API Endpoint. The manipulation leads to missing authentication. The attack may be launched remotely. | |
| Analizada | Media (5.3) | 0.46% | — | Harry0703 Moneyprinterturbo | 20/7/2025 | 17/6/2026 | A vulnerability has been found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this vulnerability is the function download_video/delete_video of the file app/controllers/v1/video.py. The manipulation leads to path traversal. The attack can be launched remotely. | |
| Analizada | Media (5.3) | 0.40% | — | Harry0703 Moneyprinterturbo | 20/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in harry0703 MoneyPrinterTurbo up to 1.2.6. Affected is the function upload_bgm_file of the file app/controllers/v1/video.py of the component File Extension Handler. The manipulation of the argument File leads to unrestricted upload. It is possible to launch… | |
| Aplazada | Media (6.5) | 0.40% | — | Turbo Addons ElementorAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Turbo Addons Turbo Addons Elementor turbo-addons-elementor allows DOM-Based XSS.This issue affects Turbo Addons Elementor: from n/a through <= 1.7.7. | |
| Analizada | Crítica (9.5) | 0.35% | — | Ecovacs Deebot X2 Omni FirmwareEcovacs Deebot X2 Combo FirmwareEcovacs Deebot X2S FirmwareEcovacs Deebot X5 PRO Firmware+16 | 23/1/2025 | 17/6/2026 | ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modifying firmware updates. | |
| Aplazada | Alta (7.1) | 0.33% | — | TurbosmtpAI | 15/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in turboSMTP turboSMTP turbosmtp allows Reflected XSS.This issue affects turboSMTP: from n/a through <= 4.6. | |
| Aplazada | Media (6.1) | 0.36% | — | TurbosmtpAI | 10/12/2024 | 17/6/2026 | The turboSMTP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in all versions up to, and including, 4.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if… | |
| Aplazada | Media (5.3) | 0.43% | — | Rakuten Turbo 5GAI | 20/11/2024 | 17/6/2026 | Exposure of sensitive system information to an unauthorized control sphere issue exists in Rakuten Turbo 5G firmware version V1.3.18 and earlier. If this vulnerability is exploited, a remote unauthenticated attacker may obtain information of the other devices connected through the Wi-Fi. | |
| Aplazada | Alta (8.8) | 1.0% | — | Rakuten Turbo 5GAI | 20/11/2024 | 17/6/2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Rakuten Turbo 5G firmware version V1.3.18 and earlier. If this vulnerability is exploited, a remote authenticated attacker may execute an arbitrary OS command. | |
| Aplazada | Media (5.3) | 0.42% | — | Rakuten Turbo 5GAI | 20/11/2024 | 17/6/2026 | Missing authentication for critical function vulnerability exists in Rakuten Turbo 5G firmware version V1.3.18 and earlier. If this vulnerability is exploited, a remote unauthenticated attacker may update or downgrade the firmware on the device. | |
| Modificada | Crítica (9.8) | 41% | 💥 Exploit | Rhubcom Turbomeeting | 25/7/2024 | 17/6/2026 | A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to extract hashed passwords from the database, and authenticate to the application, via crafted SQL input. | |
| Modificada | Alta (7.2) | 3.2% | 💥 Exploit | Rhubcom Turbomeeting | 25/7/2024 | 17/6/2026 | A command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allows authenticated attackers with administrator privileges to execute arbitrary commands on the underlying server as root. | |
| Modificada | Crítica (9.8) | 0.54% | — | Rhubcom Turbomeeting | 25/7/2024 | 17/6/2026 | The password-reset mechanism in the Forgot Password functionality in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to force the application into resetting the administrator's password to a random insecure 8-digit value. | |
| Aplazada | Media (6.4) | 0.35% | — | Mihdan Yandex Turbo FeedAI | 14/5/2024 | 17/6/2026 | The Mihdan: Yandex Turbo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.6.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.1) | 0.17% | — | Itel Vision 3 TurboAITranssion Autotest FactoryAI | 22/4/2024 | 17/6/2026 | Certain software builds for the Itel Vision 3 Turbo Android device contain a vulnerable pre-installed app with a package name of com.transsion.autotest.factory (versionCode='7', versionName='1.8.0(220310_1027)') that allows local third-party apps to execute arbitrary shell commands in its context (system user) due to… | |
| Analizada | Alta (8.1) | 0.80% | — | Turboboost Commands Project Turboboost Commands | 14/3/2024 | 17/6/2026 | turbo_boost-commands is a set of commands to help you build robust reactive applications with Rails & Hotwire. TurboBoost Commands has existing protections in place to guarantee that only public methods on Command classes can be invoked; however, the existing checks aren't as robust as they should be. It's possible… | |
| Analizada | Media (6.1) | 0.37% | — | Opentext Exceed Turbox | 13/3/2024 | 17/6/2026 | HTML injection in OpenText™ Exceed Turbo X affecting version 12.5.1. The vulnerability could result in Cross site scripting. | |
| Analizada | Crítica (9.8) | 0.27% | — | Opentext Exceed Turbox | 13/3/2024 | 17/6/2026 | Use of Hard-coded Cryptographic Key vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.1 and 12.5.2. The vulnerability could compromise the cryptographic keys. | |
| Analizada | Alta (7.5) | 0.50% | — | Opentext Exceed Turbox | 13/3/2024 | 17/6/2026 | Improper authentication vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.0 and 12.5.1. The vulnerability could allow disclosure of restricted information in unauthenticated RPC. | |
| Modificada | Alta (7.1) | 0.82% | — | Libjpeg-turboFedoraproject Fedora | 22/8/2023 | 17/6/2026 | libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompress_smooth_data in jdcoefct.c. | |
| Modificada | Media (6.5) | 0.69% | — | Turbowarp Desktop | 17/8/2023 | 17/6/2026 | TurboWarp is a desktop application that compiles scratch projects to JavaScript. TurboWarp Desktop versions prior to version 1.8.0 allowed a malicious project or custom extension to read arbitrary files from disk and upload them to a remote server. The only required user interaction is opening the sb3 file or loading… |