Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

815 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.84%—Fresenius-kabi Agilia Connect FirmwareFresenius-kabi Agilia Partner Maintenance SoftwareFresenius-kabi Vigilant CenteriumFresenius-kabi Vigilant Insight+221/1/202217/6/2026
Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 has the option for automated indexing (directory listing) activated. When accessing a directory, a web server delivers its entire content in HTML form. If an index file does not exist and directory listing is enabled, all content of the…
ModificadaMedia (6.1)0.72%—Broadcom Netmaster File Transfer ManagementBroadcom Netmaster Network Management FOR Tcp/ip18/1/202217/6/2026
NetMaster 12.2 Network Management for TCP/IP and NetMaster File Transfer Management contain a XSS (Cross-Site Scripting) vulnerability in ReportCenter UI due to insufficient input validation that could potentially allow an attacker to execute code on the affected machine.
ModificadaMedia (5.4)0.97%—Expresstech Quiz AND Survey Master17/1/202217/6/2026
Stored cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote authenticated attacker to inject an arbitrary script via an website that uses Quiz And Survey Master.
ModificadaMedia (6.1)1.3%—Expresstech Quiz AND Survey Master17/1/202217/6/2026
Reflected cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to inject an arbitrary script via unspecified vectors.
ModificadaAlta (8.8)0.65%—Expresstech Quiz AND Survey Master17/1/202217/6/2026
Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to hijack the authentication of administrators and conduct arbitrary operations via a specially crafted web page.
ModificadaAlta (7.5)2.3%—Siemens Cp-8000 Master Module With I/O -25/+70 FirmwareSiemens Cp-8000 Master Module With I/O -40/+70 FirmwareSiemens Cp-8021 Master Module FirmwareSiemens Cp-8022 Master Module With Gprs Firmware11/1/202217/6/2026
A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions < V16.20), CP-8021 MASTER MODULE (All versions < V16.20), CP-8022 MASTER MODULE WITH GPRS (All versions < V16.20). The web server of the affected system allows…
ModificadaAlta (8.8)0.91%—Siemens Cp-8000 Master Module With I/O -25/+70 FirmwareSiemens Cp-8000 Master Module With I/O -40/+70 FirmwareSiemens Cp-8021 Master Module FirmwareSiemens Cp-8022 Master Module With Gprs Firmware11/1/202217/6/2026
A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions < V16.20), CP-8021 MASTER MODULE (All versions < V16.20), CP-8022 MASTER MODULE WITH GPRS (All versions < V16.20). An undocumented debug port uses hard-coded…
ModificadaMedia (5.9)100%💥 PoCApache Log4jNetapp Cloud ManagerDebian LinuxSonicwall Email Security+11218/12/202125/8/2026
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j…
ModificadaMedia (5.4)0.33%—Huawei Imaster Nce-fabric Firmware23/11/202117/6/2026
There is a XSS injection vulnerability in iMaster NCE-Fabric V100R019C10. A module of the client does not verify the input sufficiently. Attackers can exploit this vulnerability by modifying input after logging onto the client. This may compromise the normal service of the client.
ModificadaMedia (4.8)0.62%—Expresstech Quiz AND Survey Master11/10/202117/6/2026
The Quiz And Survey Master WordPress plugin before 7.3.2 does not escape the Quiz Url Slug setting before outputting it in some pages, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaAlta (8.8)1.3%—Offshorewebmaster Availability Calendar20/9/202117/6/2026
The Availability Calendar WordPress plugin before 1.2.1 does not escape the category attribute from its shortcode before using it in a SQL statement, leading to a SQL Injection issue, which can be exploited by any user able to add shortcode to posts/pages, such as contributor+
ModificadaMedia (4.8)0.62%—Offshorewebmaster Availability Calendar20/9/202117/6/2026
The Availability Calendar WordPress plugin before 1.2.2 does not sanitise or escape its Category Names before outputting them in page/post where the associated shortcode is embed, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
ModificadaAlta (8.8)0.82%—Mastersoft Zook AgentMastersoft Zook Viewer7/9/202117/6/2026
A buffer overflow issue was discovered in ZOOK solution(remote administration tool) through processing 'ConnectMe' command while parsing a crafted OUTERIP value because of missing boundary check. This vulnerability allows the attacker to execute remote arbitrary command.
ModificadaMedia (6.1)3.4%💥 ExploitExpresstech Quiz AND Survey Master18/8/202117/6/2026
Cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.1.14 allows a remote attacker to inject arbitrary script via unspecified vectors.
ModificadaMedia (6.5)0.46%—IBM Infosphere Master Data Management Server16/7/202117/6/2026
IBM InfoSphere Master Data Management Server 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 186324.
ModificadaAlta (8.8)1.6%—Mastersoft Zook29/6/202117/6/2026
An improper input validation vulnerability of ZOOK software (remote administration tool) could allow a remote attacker to create arbitrary file. The ZOOK viewer has the "Tight file CMD" function to create file. An attacker could create and execute arbitrary file in the ZOOK agent program using "Tight file CMD" without…
ModificadaMedia (6.1)0.83%—Expresstech Quiz AND Survey Master20/6/202117/6/2026
The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin WordPress plugin before 7.1.18 did not sanitise or escape its result_id parameter when displaying an existing quiz result page, leading to a reflected Cross-Site Scripting issue. This could allow for privilege escalation by inducing a logged in admin to…
ModificadaAlta (8.3)0.42%—SAP Netweaver Master Data Management13/4/202117/6/2026
SAP NetWeaver Master Data Management, versions - 710, 710.750, allows a malicious unauthorized user with access to the MDM Server subnet to find the password using a brute force method. If successful, the attacker could obtain access to highly sensitive data and MDM administrative privileges leading to information…
ModificadaAlta (8.8)1.9%—Expresstech Quiz AND Survey Master12/4/202117/6/2026
The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin before 7.1.12 did not sanitise the result_id GET parameter on pages with the [qsm_result] shortcode without id attribute, concatenating it in a SQL statement and leading to an SQL injection. The lowest role allowed to use this…
ModificadaAlta (7.3)0.85%—Terra-master F2-210 Firmware3/4/202117/6/2026
TerraMaster F2-210 devices through 2021-04-03 use UPnP to make the admin web server accessible over the Internet on TCP port 8181, which is arguably inconsistent with the "It is only available on the local network" documentation. NOTE: manually editing /etc/upnp.json provides a partial but undocumented workaround.
ModificadaCrítica (9.8)1.3%—Masterlab25/2/202117/6/2026
A server-side request forgery (SSRF) vulnerability in Upgrade.php of gopeak masterlab 2.1.5, via the 'source' parameter.
ModificadaAlta (7.5)1.9%—SAP Netweaver Master Data Management Server9/2/202117/6/2026
Under specific circumstances SAP Master Data Management, versions - 710, 710.750, allows an unauthorized attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs. Due to this Directory Traversal…
ModificadaAlta (7.8)0.23%—Huawei Imaster Mae-mHuawei ManageoneHuawei Network Functions Virtualization FusionsphereHuawei Smc2.0 Firmware6/2/202117/6/2026
There is a local privilege escalation vulnerability in some Huawei products. A local, authenticated attacker could craft specific commands to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege. Affected product versions include: ManageOne versions…
ModificadaCrítica (9.8)29%💥 ExploitTerra-master TOS30/1/202117/6/2026
TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation vulnerability in include/exportUser.php, in which an attacker can trigger a call to the exec method with (for example) OS commands in the opt parameter.
ModificadaAlta (7.8)1.3%—Emerson Rosemount Transmitter Interface SoftwarePepperl-fuchs PactwareWago Dtminspector 3Wago Fdtcontainer Application+322/1/202117/6/2026
M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.