Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2344 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.27% | — | Legrand SMS PowerviewAI | 31/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Legrand SMS PowerView 1.x. Affected is an unknown function. The manipulation of the argument redirect leads to file inclusion. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was… | |
| Aplazada | Media (5.1) | 0.24% | — | Legrand SMS PowerviewAI | 31/3/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Legrand SMS PowerView 1.x. This issue affects some unknown processing. The manipulation of the argument redirect leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The… | |
| Aplazada | Media (5.1) | 0.27% | — | Legrand SMS PowerviewAI | 31/3/2025 | 17/6/2026 | A vulnerability classified as problematic was found in Legrand SMS PowerView 1.x. This vulnerability affects unknown code. The manipulation of the argument redirect leads to open redirect. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early… | |
| Analizada | Media (4.4) | 0.13% | — | IBM Powervm Hypervisor | 28/3/2025 | 17/6/2026 | IBM PowerVM Hypervisor FW1050.00 through FW1050.30 and FW1060.00 through FW1060.20 could allow a local user, under certain Linux processor combability mode configurations, to cause undetected data loss or errors when performing gzip compression using HW acceleration. | |
| Aplazada | Media (6.5) | 0.22% | — | Codetrendy Power MAGAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codetrendy Power Mag power-mag allows DOM-Based XSS.This issue affects Power Mag: from n/a through <= 1.1.5. | |
| Aplazada | Media (4.3) | 0.19% | — | Powerfulwp Gift Message FOR WoocommerceAI | 27/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in powerfulwp Gift Message for WooCommerce gift-message-for-woocommerce allows Cross Site Request Forgery.This issue affects Gift Message for WooCommerce: from n/a through <= 1.7.8. | |
| Aplazada | Media (5.3) | 0.28% | — | Alfasado PowercmsAI | 27/3/2025 | 17/6/2026 | The affected versions of PowerCMS allow HTTP header injection. This vulnerability can be leveraged to direct the affected product to send email with a tampered URL, such as password reset mail. | |
| Analizada | Crítica (9.8) | 0.64% | — | Dell Chassis Management Controller FOR Poweredge FX2 FirmwareDell Chassis Management Controller FOR Poweredge Vrtx Firmware | 21/3/2025 | 17/6/2026 | Dell Chassis Management Controller Firmware for Dell PowerEdge FX2, version(s) prior to 2.40.200.202101130302, and Dell Chassis Management Controller Firmware for Dell PowerEdge VRTX version(s) prior to 3.41.200.202209300499, contain(s) a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with… | |
| Aplazada | Media (5.9) | 0.54% | — | Powerpack Print Invoice Delivery NotesAI | 8/3/2025 | 17/6/2026 | The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.4.1 via the 'wcdn/invoice' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the… | |
| Analizada | Alta (7.8) | 0.16% | — | Mongodb MongoshRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder FOR Arm64 EUSRedhat Codeready Linux Builder FOR IBM Z Systems EUS+9 | 27/2/2025 | 17/6/2026 | mongosh may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privilege, when a crafted file is stored in C:\node_modules\. This issue affects mongosh prior to 2.3.0 | |
| Analizada | Alta (7.8) | 0.15% | — | Mongodb CompassRedhat Enterprise Linux FOR ARM 64Redhat Enterprise Linux FOR IBM Z SystemsRedhat Enterprise Linux Server FOR Power Little Endian Update Services FOR SAP Solutions+1 | 27/2/2025 | 17/6/2026 | MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a crafted file is stored in C:\node_modules\. This issue affects MongoDB Compass prior to 1.42.1 | |
| Analizada | Alta (7.5) | 0.22% | — | Sungrowpower Winet-s Firmware | 26/2/2025 | 17/6/2026 | SunGrow WiNet-S V200.001.00.P025 and earlier versions is missing integrity checks for firmware upgrades. Sending a specific MQTT message allows an update to an inverter or a WiNet connectivity dongle with a bogus firmware file that is located on attacker-controlled server. | |
| Analizada | Crítica (9.1) | 0.51% | — | Sungrowpower Isolarcloud | 26/2/2025 | 17/6/2026 | SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the userService API model. | |
| Analizada | Alta (7.4) | 0.23% | — | Sungrowpower Isolarcloud | 26/2/2025 | 17/6/2026 | SunGrow iSolarCloud Android app V2.1.6.20241104 and prior suffers from Missing SSL Certificate Validation. The app explicitly ignores certificate errors and is vulnerable to MiTM attacks. Attackers can impersonate the iSolarCloud server and communicate with the Android app. | |
| Analizada | Crítica (9.1) | 0.49% | — | Sungrowpower Isolarcloud | 26/2/2025 | 17/6/2026 | SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the orgService API model. | |
| Analizada | Crítica (9.8) | 0.51% | — | Sungrowpower Isolarcloud | 26/2/2025 | 17/6/2026 | SunGrow iSolarCloud Android application V2.1.6.20241017 and prior contains hardcoded credentials. The application (regardless of the user account) and the cloud uses the same MQTT credentials for exchanging the device telemetry. | |
| Analizada | Crítica (9.1) | 0.44% | — | Sungrowpower Isolarcloud | 26/2/2025 | 17/6/2026 | SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the devService API model. | |
| Analizada | Crítica (9.1) | 0.49% | — | Sungrowpower Isolarcloud | 26/2/2025 | 17/6/2026 | SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the commonService API model. | |
| Analizada | Crítica (9.1) | 0.49% | — | Sungrowpower Isolarcloud | 26/2/2025 | 17/6/2026 | SunGrow iSolarCloud before the October 31, 2024 remediation, is vulnerable to insecure direct object references (IDOR) via the powerStationService API model. | |
| Analizada | Media (6.5) | 0.34% | — | Sungrowpower Isolarcloud | 26/2/2025 | 17/6/2026 | SunGrow iSolarCloud Android app V2.1.6.20241017 and prior uses an insecure AES key to encrypt client data (insufficient entropy). This may allow attackers to decrypt intercepted communications between the mobile app and iSolarCloud. | |
| Analizada | Crítica (9.8) | 1.6% | ⚠ Explotación activa | Microsoft Power Pages | 19/2/2025 | 17/6/2026 | An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. This vulnerability has already been mitigated in the service and all affected customers have been notified. This update addressed the… | |
| Analizada | Media (6.5) | 0.51% | — | IBM Power Hardware Management Console | 14/2/2025 | 17/6/2026 | IBM Power Hardware Management Console V10.3.1050.0 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. | |
| Analizada | Alta (8.7) | 0.46% | — | Outbackpower Mojave Inverter Oghi8048a Firmware | 13/2/2025 | 17/6/2026 | The Mojave Inverter uses the GET method for sensitive information. | |
| Analizada | Alta (8.7) | 0.46% | — | Outbackpower Mojave Inverter Oghi8048a Firmware | 13/2/2025 | 17/6/2026 | An attacker may modify the URL to discover sensitive information about the target network. | |
| Analizada | Alta (8.7) | 0.55% | — | Outbackpower Mojave Inverter Oghi8048a Firmware | 13/2/2025 | 17/6/2026 | An attacker may inject commands via specially-crafted post requests. |