Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
815 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.19% | — | Honeywell Softmaster | 16/9/2022 | 17/6/2026 | A local unprivileged attacker may escalate to administrator privileges in Honeywell SoftMaster version 4.51, due to insecure permission assignment. | |
| Modificada | Alta (7.5) | 0.68% | — | Siemens Cp-8021 Master Module FirmwareSiemens Cp-8000 Master Module With I/O -25/+70 FirmwareSiemens Cp-8000 Master Module With I/O -40/+70 FirmwareSiemens Cp-8022 Master Module With Gprs Firmware | 10/8/2022 | 17/6/2026 | A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions), CP-8021 MASTER MODULE (All versions), CP-8022 MASTER MODULE WITH GPRS (All versions). The component allows to activate a web server module which provides… | |
| Modificada | Crítica (9.8) | 6.9% | 💥 Exploit | Devbunch Master Elements | 25/4/2022 | 17/6/2026 | The Master Elements WordPress plugin through 8.0 does not validate and escape the meta_ids parameter of its remove_post_meta_condition AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL Injection | |
| Modificada | Alta (7.5) | 2.4% | — | Terra-master TOS | 25/4/2022 | 17/6/2026 | It is possible to obtain the first administrator's hash set up in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) on the system as well as other information such as MAC address, internal IP address etc. by performing a request to the /module/api.php?mobile/wapNasIPS endpoint. | |
| Modificada | Alta (8.1) | 8.4% | 💥 Exploit | Terra-master TOS | 25/4/2022 | 17/6/2026 | In Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the target's MAC address and the user's password hash. Guest users (disabled by default) can be abused using a null/empty hash and allow an unauthenticated attacker to login as guest. | |
| Modificada | Crítica (9.8) | 3.9% | — | Terra-master TOS | 25/4/2022 | 17/6/2026 | It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending specifically crafted input to /tos/index.php?app/app_start_stop. | |
| Modificada | Media (6.5) | 9.9% | 💥 Exploit | Terra-master TOS | 25/4/2022 | 17/6/2026 | It is possible to obtain the first administrator's hash set up on the system in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) as well as other information such as MAC address, internal IP address etc. by performing a request to the /module/api.php?mobile/webNasIPS endpoint. | |
| Modificada | Crítica (9.8) | 16% | 💥 Exploit | Terra-master TOS | 25/4/2022 | 17/6/2026 | It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending a specifically crafted input to /tos/index.php?app/del. | |
| Modificada | Alta (8.8) | 2.5% | — | Terra-master TOS | 25/4/2022 | 17/6/2026 | An authenticated attacker can execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by injecting a maliciously crafted input in the request through /tos/index.php?app/hand_app. | |
| Modificada | Media (6.1) | 0.80% | — | Jeweltheme Master Addons FOR Elementor | 14/3/2022 | 17/6/2026 | The Master Addons for Elementor WordPress plugin before 1.8.5 does not sanitise and escape the error_message parameter before outputting it back in the response of the jltma_restrict_content AJAX action, available to unauthenticated and authenticated users, leading to a Reflected Cross-Site Scripting | |
| Modificada | Crítica (9.8) | 85% | 💥 Exploit | Stylemixthemes Masterstudy LMS | 7/3/2022 | 17/6/2026 | The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin | |
| Modificada | Crítica (9.8) | 1.4% | — | Itunesrpc-remastered Project Itunesrpc-remastered | 4/2/2022 | 17/6/2026 | iTunesRPC-Remastered is a Discord Rich Presence for iTunes on Windows utility. In affected versions iTunesRPC-Remastered did not properly sanitize image file paths leading to OS level command injection. This issue has been patched in commit cdcd48b. Users are advised to upgrade. | |
| Modificada | Crítica (9.1) | 1.0% | — | Itunesrpc-remastered Project Itunesrpc-remastered | 4/2/2022 | 17/6/2026 | iTunesRPC-Remastered is a Discord Rich Presence for iTunes on Windows utility. In affected versions iTunesRPC-Remastered did not properly sanitize user input used to remove files leading to file deletion only limited by the process permissions. Users are advised to upgrade as soon as possible. | |
| Modificada | Media (6.1) | 0.99% | — | Itunesrpc-remastered Project Itunesrpc-remastered | 1/2/2022 | 17/6/2026 | iTunesRPC-Remastered is a discord rich presence application for use with iTunes & Apple Music. In code before commit 24f43aa user input is not properly sanitized and code injection is possible. Users are advised to upgrade as soon as is possible. There are no known workarounds for this issue. | |
| Modificada | Alta (8.8) | 0.68% | — | Webmaster-source Wp125 | 24/1/2022 | 17/6/2026 | The WP125 WordPress plugin before 1.5.5 does not have CSRF checks in various action, for example when deleting an ad, allowing attackers to make a logged in admin delete them via a CSRF attack | |
| Modificada | Alta (8.8) | 0.64% | — | Fresenius-kabi Agilia Connect FirmwareFresenius-kabi Agilia Partner Maintenance SoftwareFresenius-kabi Vigilant CenteriumFresenius-kabi Vigilant Insight+2 | 21/1/2022 | 17/6/2026 | Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 contains service credentials likely to be common across all instances. An attacker in possession of the password may gain privileges on all installations of this software. | |
| Modificada | Crítica (9.8) | 0.98% | — | Fresenius-kabi Agilia Partner Maintenance SoftwareFresenius-kabi Vigilant CenteriumFresenius-kabi Vigilant InsightFresenius-kabi Vigilant Mastermed+2 | 21/1/2022 | 17/6/2026 | Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 allows user input to be validated on the client side without authentication by the server. The server should not rely on the correctness of the data because users might not support or block JavaScript or intentionally bypass the client-side… | |
| Modificada | Alta (7.5) | 0.30% | — | Fresenius-kabi Agilia Partner Maintenance SoftwareFresenius-kabi Vigilant CenteriumFresenius-kabi Vigilant InsightFresenius-kabi Vigilant Mastermed+2 | 21/1/2022 | 17/6/2026 | Fresenius Kabi Agilia Link + version 3.0 does not enforce transport layer encryption. Therefore, transmitted data may be sent in cleartext. Transport layer encryption is offered on Port TCP/443, but the affected service does not perform an automated redirect from the unencrypted service on Port TCP/80 to the encrypted… | |
| Modificada | Media (6.1) | 0.61% | — | Fresenius-kabi Agilia Connect FirmwareFresenius-kabi Agilia Partner Maintenance SoftwareFresenius-kabi Vigilant CenteriumFresenius-kabi Vigilant Insight+2 | 21/1/2022 | 17/6/2026 | Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 is vulnerable to reflected cross-site scripting attacks. An attacker could inject JavaScript in a GET parameter of HTTP requests and perform unauthorized actions such as stealing internal information and performing actions in context of an… | |
| Modificada | Alta (7.2) | 0.31% | — | Fresenius-kabi Agilia Partner Maintenance SoftwareFresenius-kabi Vigilant CenteriumFresenius-kabi Vigilant InsightFresenius-kabi Vigilant Mastermed+2 | 21/1/2022 | 17/6/2026 | Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 issues authentication tokens to authenticated users that are signed with a symmetric encryption key. An attacker in possession of the key can issue valid JWTs and impersonate arbitrary users. | |
| Modificada | Crítica (9.1) | 0.49% | — | Fresenius-kabi Agilia Connect FirmwareFresenius-kabi Agilia Partner Maintenance SoftwareFresenius-kabi Vigilant CenteriumFresenius-kabi Vigilant Insight+2 | 21/1/2022 | 17/6/2026 | The SSL/TLS configuration of Fresenius Kabi Agilia Link + version 3.0 has serious deficiencies that may allow an attacker to compromise SSL/TLS sessions in different ways. An attacker may be able to eavesdrop on transferred data, manipulate data allegedly secured by SSL/TLS, and impersonate an entity to gain access to… | |
| Modificada | Alta (7.5) | 1.1% | — | Fresenius-kabi Agilia Partner Maintenance SoftwareFresenius-kabi Vigilant CenteriumFresenius-kabi Vigilant InsightFresenius-kabi Vigilant Mastermed+2 | 21/1/2022 | 17/6/2026 | Requests may be used to interrupt the normal operation of the device. When exploited, Fresenius Kabi Agilia Link+ version 3.0 must be rebooted via a hard reset triggered by pressing a button on the rack system. | |
| Modificada | Crítica (9.8) | 0.95% | — | Fresenius-kabi Agilia Partner Maintenance SoftwareFresenius-kabi Vigilant CenteriumFresenius-kabi Vigilant InsightFresenius-kabi Vigilant Mastermed+2 | 21/1/2022 | 17/6/2026 | Sensitive endpoints in Fresenius Kabi Agilia Link+ v3.0 and prior can be accessed without any authentication information such as the session cookie. An attacker can send requests to sensitive endpoints as an unauthenticated user to perform critical actions or modify critical configuration parameters. | |
| Modificada | Media (5.5) | 0.22% | — | Fresenius-kabi Agilia ConnectFresenius-kabi Agilia Partner Maintenance SoftwareFresenius-kabi Vigilant CenteriumFresenius-kabi Vigilant Insight+2 | 21/1/2022 | 17/6/2026 | An attacker with physical access to the host can extract the secrets from the registry and create valid JWT tokens for the Fresenius Kabi Vigilant MasterMed version 2.0.1.3 application and impersonate arbitrary users. An attacker could manipulate RabbitMQ queues and messages by impersonating users. | |
| Modificada | Crítica (9.8) | 0.91% | — | Fresenius-kabi Agilia Connect FirmwareFresenius-kabi Agilia Partner Maintenance SoftwareFresenius-kabi Vigilant CenteriumFresenius-kabi Vigilant Insight+2 | 21/1/2022 | 17/6/2026 | The web application on Agilia Link+ version 3.0 implements authentication and session management mechanisms exclusively on the client-side and does not protect authentication attributes sufficiently. |