Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

2287 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.9)0.71%—Riskengine Radar18/10/202417/6/2026
A vulnerability has been found in wfh45678 Radar up to 1.0.8 and classified as critical. This vulnerability affects unknown code of the file /services/v1/common/upload. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public…
AplazadaAlta (7)0.65%—Laquis ScadaAI17/10/202417/6/2026
In LAquis SCADA version 4.7.1.511, a cross-site scripting vulnerability could allow an attacker to inject arbitrary code into a web page. This could allow an attacker to steal cookies, redirect users, or perform unauthorized actions.
AplazadaMedia (4.3)0.26%—Read More BY AdamAI12/10/202417/6/2026
The Read more By Adam plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the deleteRm() function in all versions up to, and including, 1.1.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete read more buttons.
AnalizadaMedia (5.3)0.33%—ADA4/10/202417/6/2026
Ada.cx's Sentry configuration allowed for blind server-side request forgeries (SSRF) through the use of a data scraping endpoint.
AplazadaAlta (7)0.22%—Advantech Adam-5630AI27/9/202417/6/2026
Advantech ADAM-5630 has built-in commands that can be executed without authenticating the user. These commands allow for restarting the operating system, rebooting the hardware, and stopping the execution. The commands can be sent to a simple HTTP request and are executed by the device automatically, without…
AnalizadaAlta (8.5)0.41%—Advantech Adam-5630 Firmware27/9/202417/6/2026
Cookies of authenticated Advantech ADAM-5630 users remain as active valid cookies when a session is closed. Forging requests with a legitimate cookie, even if the session was terminated, allows an unauthorized attacker to act with the same level of privileges of the legitimate user.
AnalizadaAlta (8.7)0.31%—Advantech Adam 5550-firmware27/9/202417/6/2026
Advantech ADAM 5550's web application includes a "logs" page where all the HTTP requests received are displayed to the user. The device doesn't correctly neutralize malicious code when parsing HTTP requests to generate page output.
AnalizadaMedia (6.8)0.37%—Advantech Adam-5550 Firmware27/9/202417/6/2026
Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding.
AnalizadaMedia (6.9)0.22%—Advantech Adam-5630 Firmware27/9/202417/6/2026
Advantech ADAM-5630 shares user credentials plain text between the device and the user source device during the login process.
AnalizadaAlta (8.5)0.22%—Advantech Adam-5630 Firmware27/9/202417/6/2026
Advantech ADAM-5630 contains a cross-site request forgery (CSRF) vulnerability. It allows an attacker to partly circumvent the same origin policy, which is designed to prevent different websites from interfering with each other.
AplazadaAlta (7.5)0.43%—Adacore ADA WEB ServicesAI25/9/202417/6/2026
An issue was discovered in AdaCore ada_web_services 20.0 allows an attacker to escalate privileges and steal sessions via the Random_String() function in the src/core/aws-utils.adb module.
ModificadaAlta (7.5)0.35%—Rapidscada Rapid Scada22/9/202417/6/2026
CheckUser in ScadaServerEngine/MainLogic.cs in Rapid SCADA through 5.8.4 allows an empty password.
AnalizadaMedia (6.1)0.31%—Mohammadarif Opor Ayam15/9/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Mohammad Arif Opor Ayam allows Reflected XSS.This issue affects Opor Ayam: from n/a through 1.8.
AnalizadaMedia (5.4)0.32%—Theme-fusion Avada13/9/202417/6/2026
The Avada | Website Builder For WordPress & eCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fusion_button shortcode in all versions up to, and including, 3.11.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…
AplazadaAlta (8.7)13%💥 PoCSpidercontrol Scada WEB ServerAI10/9/202417/6/2026
SpiderControl SCADA Web Server has a vulnerability that could allow an attacker to upload specially crafted malicious files without authentication.
AnalizadaMedia (6.9)0.53%—Kitsada8621 Digital Library Management System29/8/202417/6/2026
A vulnerability was found in kitsada8621 Digital Library Management System 1.0. It has been classified as problematic. Affected is the function JwtRefreshAuth of the file middleware/jwt_refresh_token_middleware.go. The manipulation of the argument Authorization leads to improper output neutralization for logs. It is…
AnalizadaMedia (4.3)0.34%—Hitachienergy Microscada X Sys60027/8/202417/6/2026
An HTTP parameter may contain a URL value and could cause the web application to redirect the request to the specified URL. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.
AnalizadaCrítica (9.8)0.58%—Hitachienergy Microscada X Sys60027/8/202417/6/2026
The product exposes a service that is intended for local only to all network interfaces without any authentication.
AnalizadaAlta (8.8)0.50%—Hitachienergy Microscada PRO Sys600Hitachienergy Microscada X Sys60027/8/202417/6/2026
A vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated attacker to inject code towards persistent data. Note that to successfully exploit this vulnerability an attacker must have a valid credential.
AnalizadaAlta (8.2)0.22%—Hitachienergy Microscada X Sys60027/8/202417/6/2026
An attacker with local access to machine where MicroSCADA X SYS600 is installed, could enable the session logging supporting the product and try to exploit a session hijacking of an already established session. By default, the session logging level is not enabled and only users with administrator rights can enable it.
AnalizadaAlta (8.8)0.61%—Hitachienergy Microscada PRO Sys600Hitachienergy Microscada X Sys60027/8/202417/6/2026
The MicroSCADA Pro/X SYS600 product allows an authenticated user input to control or influence paths or file names that are used in filesystem operations. If exploited the vulnerability allows the attacker to access or modify system files or other files that are critical to the application.
AnalizadaAlta (8.8)5.2%—Zohocorp Manageengine Adaudit Plus23/8/202417/6/2026
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in extranet lockouts report option.
AnalizadaAlta (8.8)4.5%—Zohocorp Manageengine Adaudit Plus23/8/202417/6/2026
Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in reports module.
AnalizadaAlta (8.8)4.0%—Zohocorp Manageengine Adaudit Plus23/8/202417/6/2026
Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in aggregate reports option.
AnalizadaAlta (8.8)4.5%—Zohocorp Manageengine Adaudit Plus23/8/202417/6/2026
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in account lockout report.