Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
815 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.9) | 1.0% | — | Pepperl-fuchs Io-link Master 4-eip FirmwarePepperl-fuchs Io-link Master 8-eip FirmwarePepperl-fuchs Io-link Master 8-eip-l FirmwarePepperl-fuchs Io-link Master Dr-8-eip Firmware+8 | 22/1/2021 | 17/6/2026 | Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a NULL Pointer Dereference that leads to a DoS in discoveryd | |
| Modificada | Alta (8.8) | 31% | — | Pepperl-fuchs Io-link Master 4-eip FirmwarePepperl-fuchs Io-link Master 8-eip FirmwarePepperl-fuchs Io-link Master 8-eip-l FirmwarePepperl-fuchs Io-link Master Dr-8-eip Firmware+8 | 22/1/2021 | 17/6/2026 | Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection. | |
| Modificada | Media (5.4) | 0.72% | — | Pepperl-fuchs Io-link Master 4-eip FirmwarePepperl-fuchs Io-link Master 8-eip FirmwarePepperl-fuchs Io-link Master 8-eip-l FirmwarePepperl-fuchs Io-link Master Dr-8-eip Firmware+8 | 22/1/2021 | 17/6/2026 | Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated reflected POST Cross-Site Scripting | |
| Modificada | Alta (8.8) | 0.57% | — | Pepperl-fuchs Io-link Master 4-eip FirmwarePepperl-fuchs Io-link Master 8-eip FirmwarePepperl-fuchs Io-link Master 8-eip-l FirmwarePepperl-fuchs Io-link Master Dr-8-eip Firmware+8 | 22/1/2021 | 17/6/2026 | Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a Cross-Site Request Forgery (CSRF) in the web interface. | |
| Modificada | Alta (7.5) | 1.2% | — | SAP Netweaver Master Data Management | 12/1/2021 | 17/6/2026 | When security guidelines for SAP NetWeaver Master Data Management running on windows have not been thoroughly reviewed, it might be possible for an external operator to try and set custom paths in the MDS server configuration. When no adequate protection has been enforced on any level (e.g., MDS Server password not… | |
| Modificada | Media (5.3) | 1.1% | — | Code-industry Master PDF EditorFoxitsoftware Foxit ReaderFoxitsoftware PhantompdfGonitro Nitro PRO+9 | 7/1/2021 | 17/6/2026 | The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability exists in multiple products. When an attacker uses the Incremental Saving feature to add pages or annotations, Body Updates… | |
| Modificada | Crítica (9.9) | 76% | 💥 Exploit | Expresstech Quiz AND Survey Master | 1/1/2021 | 17/6/2026 | An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as wp-config.php file, which could effectively take a site offline and allow an attacker to reinstall with a WordPress instance under their control. This occurred via… | |
| Modificada | Crítica (9.8) | 5.1% | — | Expresstech Quiz AND Survey Master | 1/1/2021 | 17/6/2026 | An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthenticated attackers to upload arbitrary files and achieve remote code execution. If a quiz question could be answered by uploading a file, only the Content-Type header was checked during the upload,… | |
| Modificada | Alta (8.1) | 1.9% | — | Terra-master TOS | 24/12/2020 | 9/7/2026 | Incorrect Access Control vulnerability in TerraMaster TOS <= 4.2.06 allows remote authenticated attackers to bypass read-only restriction and obtain full access to any folder within the NAS | |
| Modificada | Media (5.9) | 0.79% | — | Terra-master TOS | 24/12/2020 | 17/6/2026 | TerraMaster TOS <= 4.2.06 was found to check for updates (of both system and applications) via an insecure channel (HTTP). Man-in-the-middle attackers are able to intercept these requests and serve a weaponized/infected version of applications or updates. | |
| Modificada | Crítica (9.8) | 97% | 💥 Exploit | Terra-master TOS | 24/12/2020 | 17/6/2026 | Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php in Event parameter. | |
| Modificada | Crítica (9.8) | 16% | — | Terra-master TOS | 24/12/2020 | 17/6/2026 | Multiple directory traversal vulnerabilities in TerraMaster TOS <= 4.2.06 allow remote authenticated attackers to read, edit or delete any file within the filesystem via the (1) filename parameter to /tos/index.php?editor/fileGet, Event parameter to /include/ajax/logtable.php, or opt parameter to… | |
| Modificada | Alta (7.3) | 4.1% | — | Terra-master TOS | 24/12/2020 | 17/6/2026 | Email Injection in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to abuse the forget password functionality and achieve account takeover. | |
| Modificada | Media (5.3) | 18% | 💥 Exploit | Terra-master TOS | 24/12/2020 | 17/6/2026 | User Enumeration vulnerability in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to identify valid users within the system via the username parameter to wizard/initialise.php. | |
| Modificada | Media (5.4) | 0.87% | — | Terra-master TOS | 24/12/2020 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in TerraMaster TOS <= 4.2.06 allows remote authenticated users to inject arbitrary web script or HTML via the mod parameter to /module/index.php. | |
| Modificada | Crítica (9.8) | 78% | 💥 Exploit | Terra-master Terramaster Operating System | 23/12/2020 | 17/6/2026 | An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in include/makecvs.php during CSV creation. | |
| Modificada | Alta (7.8) | 0.69% | — | Kepware Linkmaster | 18/12/2020 | 17/6/2026 | A privilege escalation vulnerability exists in Kepware LinkMaster 3.0.94.0. In its default configuration, an attacker can globally overwrite service configuration to execute arbitrary code with NT SYSTEM privileges. | |
| Modificada | Crítica (9.8) | 2.2% | — | Airleader Master Control | 16/11/2020 | 17/6/2026 | Airleader Master <= 6.21 devices have default credentials that can be used to access the exposed Tomcat Manager for deployment of a new .war file, with resultant remote code execution. | |
| Modificada | Alta (7.5) | 1.1% | — | Airleader Master Control | 16/11/2020 | 17/6/2026 | Airleader Master and Easy <= 6.21 devices have default credentials that can be used for a denial of service. | |
| Modificada | Alta (7.8) | 1.3% | 💥 PoC | AMD Ryzen Master | 13/10/2020 | 17/6/2026 | A vulnerability in a dynamically loaded AMD driver in AMD Ryzen Master V15 may allow any authenticated user to escalate privileges to NT authority system. | |
| Modificada | Media (6.5) | 11% | 💥 PoC | Vmware Spring FrameworkOracle Commerce Guided SearchOracle Communications BRMOracle Communications Design Studio+34 | 19/9/2020 | 17/6/2026 | In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter. | |
| Modificada | Alta (7.8) | 0.40% | — | 163 Netease Mail Master | 3/9/2020 | 17/6/2026 | Guangzhou NetEase Mail Master 4.14.1.1004 on Windows has a DLL hijacking vulnerability. Attackers can use this vulnerability to execute malicious code. | |
| Modificada | Media (6.1) | 0.49% | — | Designmasterevents Conference Management CMS | 27/8/2020 | 17/6/2026 | DesignMasterEvents Conference management 1.0.0 has cross site scripting via the 'certificate.php' | |
| Modificada | Crítica (9.8) | 2.2% | — | Designmasterevents Conference Management | 27/8/2020 | 17/6/2026 | DesignMasterEvents Conference management 1.0.0 allows SQL Injection via the username field on the administrator login page. | |
| Modificada | Media (6.5) | 1.0% | — | Expresstech Quiz AND Survey Master | 16/8/2020 | 17/6/2026 | php/qmn_options_questions_tab.php in the quiz-master-next plugin before 4.7.9 for WordPress allows CSRF, with resultant stored XSS, via the question_name parameter because js/admin_question.js mishandles parsing inside of a SCRIPT element. |