Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
815 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.84% | — | Fresenius-kabi Agilia Connect FirmwareFresenius-kabi Agilia Partner Maintenance SoftwareFresenius-kabi Vigilant CenteriumFresenius-kabi Vigilant Insight+2 | 21/1/2022 | 17/6/2026 | Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 has the option for automated indexing (directory listing) activated. When accessing a directory, a web server delivers its entire content in HTML form. If an index file does not exist and directory listing is enabled, all content of the… | |
| Modificada | Media (6.1) | 0.72% | — | Broadcom Netmaster File Transfer ManagementBroadcom Netmaster Network Management FOR Tcp/ip | 18/1/2022 | 17/6/2026 | NetMaster 12.2 Network Management for TCP/IP and NetMaster File Transfer Management contain a XSS (Cross-Site Scripting) vulnerability in ReportCenter UI due to insufficient input validation that could potentially allow an attacker to execute code on the affected machine. | |
| Modificada | Media (5.4) | 0.97% | — | Expresstech Quiz AND Survey Master | 17/1/2022 | 17/6/2026 | Stored cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote authenticated attacker to inject an arbitrary script via an website that uses Quiz And Survey Master. | |
| Modificada | Media (6.1) | 1.3% | — | Expresstech Quiz AND Survey Master | 17/1/2022 | 17/6/2026 | Reflected cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Alta (8.8) | 0.65% | — | Expresstech Quiz AND Survey Master | 17/1/2022 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to hijack the authentication of administrators and conduct arbitrary operations via a specially crafted web page. | |
| Modificada | Alta (7.5) | 2.3% | — | Siemens Cp-8000 Master Module With I/O -25/+70 FirmwareSiemens Cp-8000 Master Module With I/O -40/+70 FirmwareSiemens Cp-8021 Master Module FirmwareSiemens Cp-8022 Master Module With Gprs Firmware | 11/1/2022 | 17/6/2026 | A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions < V16.20), CP-8021 MASTER MODULE (All versions < V16.20), CP-8022 MASTER MODULE WITH GPRS (All versions < V16.20). The web server of the affected system allows… | |
| Modificada | Alta (8.8) | 0.91% | — | Siemens Cp-8000 Master Module With I/O -25/+70 FirmwareSiemens Cp-8000 Master Module With I/O -40/+70 FirmwareSiemens Cp-8021 Master Module FirmwareSiemens Cp-8022 Master Module With Gprs Firmware | 11/1/2022 | 17/6/2026 | A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions < V16.20), CP-8021 MASTER MODULE (All versions < V16.20), CP-8022 MASTER MODULE WITH GPRS (All versions < V16.20). An undocumented debug port uses hard-coded… | |
| Modificada | Media (5.9) | 100% | 💥 PoC | Apache Log4jNetapp Cloud ManagerDebian LinuxSonicwall Email Security+112 | 18/12/2021 | 25/8/2026 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j… | |
| Modificada | Media (5.4) | 0.33% | — | Huawei Imaster Nce-fabric Firmware | 23/11/2021 | 17/6/2026 | There is a XSS injection vulnerability in iMaster NCE-Fabric V100R019C10. A module of the client does not verify the input sufficiently. Attackers can exploit this vulnerability by modifying input after logging onto the client. This may compromise the normal service of the client. | |
| Modificada | Media (4.8) | 0.62% | — | Expresstech Quiz AND Survey Master | 11/10/2021 | 17/6/2026 | The Quiz And Survey Master WordPress plugin before 7.3.2 does not escape the Quiz Url Slug setting before outputting it in some pages, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Alta (8.8) | 1.3% | — | Offshorewebmaster Availability Calendar | 20/9/2021 | 17/6/2026 | The Availability Calendar WordPress plugin before 1.2.1 does not escape the category attribute from its shortcode before using it in a SQL statement, leading to a SQL Injection issue, which can be exploited by any user able to add shortcode to posts/pages, such as contributor+ | |
| Modificada | Media (4.8) | 0.62% | — | Offshorewebmaster Availability Calendar | 20/9/2021 | 17/6/2026 | The Availability Calendar WordPress plugin before 1.2.2 does not sanitise or escape its Category Names before outputting them in page/post where the associated shortcode is embed, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed | |
| Modificada | Alta (8.8) | 0.82% | — | Mastersoft Zook AgentMastersoft Zook Viewer | 7/9/2021 | 17/6/2026 | A buffer overflow issue was discovered in ZOOK solution(remote administration tool) through processing 'ConnectMe' command while parsing a crafted OUTERIP value because of missing boundary check. This vulnerability allows the attacker to execute remote arbitrary command. | |
| Modificada | Media (6.1) | 3.4% | 💥 Exploit | Expresstech Quiz AND Survey Master | 18/8/2021 | 17/6/2026 | Cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.1.14 allows a remote attacker to inject arbitrary script via unspecified vectors. | |
| Modificada | Media (6.5) | 0.46% | — | IBM Infosphere Master Data Management Server | 16/7/2021 | 17/6/2026 | IBM InfoSphere Master Data Management Server 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 186324. | |
| Modificada | Alta (8.8) | 1.6% | — | Mastersoft Zook | 29/6/2021 | 17/6/2026 | An improper input validation vulnerability of ZOOK software (remote administration tool) could allow a remote attacker to create arbitrary file. The ZOOK viewer has the "Tight file CMD" function to create file. An attacker could create and execute arbitrary file in the ZOOK agent program using "Tight file CMD" without… | |
| Modificada | Media (6.1) | 0.83% | — | Expresstech Quiz AND Survey Master | 20/6/2021 | 17/6/2026 | The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin WordPress plugin before 7.1.18 did not sanitise or escape its result_id parameter when displaying an existing quiz result page, leading to a reflected Cross-Site Scripting issue. This could allow for privilege escalation by inducing a logged in admin to… | |
| Modificada | Alta (8.3) | 0.42% | — | SAP Netweaver Master Data Management | 13/4/2021 | 17/6/2026 | SAP NetWeaver Master Data Management, versions - 710, 710.750, allows a malicious unauthorized user with access to the MDM Server subnet to find the password using a brute force method. If successful, the attacker could obtain access to highly sensitive data and MDM administrative privileges leading to information… | |
| Modificada | Alta (8.8) | 1.9% | — | Expresstech Quiz AND Survey Master | 12/4/2021 | 17/6/2026 | The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin before 7.1.12 did not sanitise the result_id GET parameter on pages with the [qsm_result] shortcode without id attribute, concatenating it in a SQL statement and leading to an SQL injection. The lowest role allowed to use this… | |
| Modificada | Alta (7.3) | 0.85% | — | Terra-master F2-210 Firmware | 3/4/2021 | 17/6/2026 | TerraMaster F2-210 devices through 2021-04-03 use UPnP to make the admin web server accessible over the Internet on TCP port 8181, which is arguably inconsistent with the "It is only available on the local network" documentation. NOTE: manually editing /etc/upnp.json provides a partial but undocumented workaround. | |
| Modificada | Crítica (9.8) | 1.3% | — | Masterlab | 25/2/2021 | 17/6/2026 | A server-side request forgery (SSRF) vulnerability in Upgrade.php of gopeak masterlab 2.1.5, via the 'source' parameter. | |
| Modificada | Alta (7.5) | 1.9% | — | SAP Netweaver Master Data Management Server | 9/2/2021 | 17/6/2026 | Under specific circumstances SAP Master Data Management, versions - 710, 710.750, allows an unauthorized attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs. Due to this Directory Traversal… | |
| Modificada | Alta (7.8) | 0.23% | — | Huawei Imaster Mae-mHuawei ManageoneHuawei Network Functions Virtualization FusionsphereHuawei Smc2.0 Firmware | 6/2/2021 | 17/6/2026 | There is a local privilege escalation vulnerability in some Huawei products. A local, authenticated attacker could craft specific commands to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege. Affected product versions include: ManageOne versions… | |
| Modificada | Crítica (9.8) | 29% | 💥 Exploit | Terra-master TOS | 30/1/2021 | 17/6/2026 | TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation vulnerability in include/exportUser.php, in which an attacker can trigger a call to the exec method with (for example) OS commands in the opt parameter. | |
| Modificada | Alta (7.8) | 1.3% | — | Emerson Rosemount Transmitter Interface SoftwarePepperl-fuchs PactwareWago Dtminspector 3Wago Fdtcontainer Application+3 | 22/1/2021 | 17/6/2026 | M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage. |