Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

815 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.9)1.0%—Pepperl-fuchs Io-link Master 4-eip FirmwarePepperl-fuchs Io-link Master 8-eip FirmwarePepperl-fuchs Io-link Master 8-eip-l FirmwarePepperl-fuchs Io-link Master Dr-8-eip Firmware+822/1/202117/6/2026
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a NULL Pointer Dereference that leads to a DoS in discoveryd
ModificadaAlta (8.8)31%—Pepperl-fuchs Io-link Master 4-eip FirmwarePepperl-fuchs Io-link Master 8-eip FirmwarePepperl-fuchs Io-link Master 8-eip-l FirmwarePepperl-fuchs Io-link Master Dr-8-eip Firmware+822/1/202117/6/2026
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection.
ModificadaMedia (5.4)0.72%—Pepperl-fuchs Io-link Master 4-eip FirmwarePepperl-fuchs Io-link Master 8-eip FirmwarePepperl-fuchs Io-link Master 8-eip-l FirmwarePepperl-fuchs Io-link Master Dr-8-eip Firmware+822/1/202117/6/2026
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated reflected POST Cross-Site Scripting
ModificadaAlta (8.8)0.57%—Pepperl-fuchs Io-link Master 4-eip FirmwarePepperl-fuchs Io-link Master 8-eip FirmwarePepperl-fuchs Io-link Master 8-eip-l FirmwarePepperl-fuchs Io-link Master Dr-8-eip Firmware+822/1/202117/6/2026
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a Cross-Site Request Forgery (CSRF) in the web interface.
ModificadaAlta (7.5)1.2%—SAP Netweaver Master Data Management12/1/202117/6/2026
When security guidelines for SAP NetWeaver Master Data Management running on windows have not been thoroughly reviewed, it might be possible for an external operator to try and set custom paths in the MDS server configuration. When no adequate protection has been enforced on any level (e.g., MDS Server password not…
ModificadaMedia (5.3)1.1%—Code-industry Master PDF EditorFoxitsoftware Foxit ReaderFoxitsoftware PhantompdfGonitro Nitro PRO+97/1/202117/6/2026
The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability exists in multiple products. When an attacker uses the Incremental Saving feature to add pages or annotations, Body Updates…
ModificadaCrítica (9.9)76%💥 ExploitExpresstech Quiz AND Survey Master1/1/202117/6/2026
An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as wp-config.php file, which could effectively take a site offline and allow an attacker to reinstall with a WordPress instance under their control. This occurred via…
ModificadaCrítica (9.8)5.1%—Expresstech Quiz AND Survey Master1/1/202117/6/2026
An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthenticated attackers to upload arbitrary files and achieve remote code execution. If a quiz question could be answered by uploading a file, only the Content-Type header was checked during the upload,…
ModificadaAlta (8.1)1.9%—Terra-master TOS24/12/20209/7/2026
Incorrect Access Control vulnerability in TerraMaster TOS <= 4.2.06 allows remote authenticated attackers to bypass read-only restriction and obtain full access to any folder within the NAS
ModificadaMedia (5.9)0.79%—Terra-master TOS24/12/202017/6/2026
TerraMaster TOS <= 4.2.06 was found to check for updates (of both system and applications) via an insecure channel (HTTP). Man-in-the-middle attackers are able to intercept these requests and serve a weaponized/infected version of applications or updates.
ModificadaCrítica (9.8)97%💥 ExploitTerra-master TOS24/12/202017/6/2026
Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php in Event parameter.
ModificadaCrítica (9.8)16%—Terra-master TOS24/12/202017/6/2026
Multiple directory traversal vulnerabilities in TerraMaster TOS <= 4.2.06 allow remote authenticated attackers to read, edit or delete any file within the filesystem via the (1) filename parameter to /tos/index.php?editor/fileGet, Event parameter to /include/ajax/logtable.php, or opt parameter to…
ModificadaAlta (7.3)4.1%—Terra-master TOS24/12/202017/6/2026
Email Injection in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to abuse the forget password functionality and achieve account takeover.
ModificadaMedia (5.3)18%💥 ExploitTerra-master TOS24/12/202017/6/2026
User Enumeration vulnerability in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to identify valid users within the system via the username parameter to wizard/initialise.php.
ModificadaMedia (5.4)0.87%—Terra-master TOS24/12/202017/6/2026
Cross-site scripting (XSS) vulnerability in TerraMaster TOS <= 4.2.06 allows remote authenticated users to inject arbitrary web script or HTML via the mod parameter to /module/index.php.
ModificadaCrítica (9.8)78%💥 ExploitTerra-master Terramaster Operating System23/12/202017/6/2026
An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in include/makecvs.php during CSV creation.
ModificadaAlta (7.8)0.69%—Kepware Linkmaster18/12/202017/6/2026
A privilege escalation vulnerability exists in Kepware LinkMaster 3.0.94.0. In its default configuration, an attacker can globally overwrite service configuration to execute arbitrary code with NT SYSTEM privileges.
ModificadaCrítica (9.8)2.2%—Airleader Master Control16/11/202017/6/2026
Airleader Master <= 6.21 devices have default credentials that can be used to access the exposed Tomcat Manager for deployment of a new .war file, with resultant remote code execution.
ModificadaAlta (7.5)1.1%—Airleader Master Control16/11/202017/6/2026
Airleader Master and Easy <= 6.21 devices have default credentials that can be used for a denial of service.
ModificadaAlta (7.8)1.3%💥 PoCAMD Ryzen Master13/10/202017/6/2026
A vulnerability in a dynamically loaded AMD driver in AMD Ryzen Master V15 may allow any authenticated user to escalate privileges to NT authority system.
ModificadaMedia (6.5)11%💥 PoCVmware Spring FrameworkOracle Commerce Guided SearchOracle Communications BRMOracle Communications Design Studio+3419/9/202017/6/2026
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
ModificadaAlta (7.8)0.40%—163 Netease Mail Master3/9/202017/6/2026
Guangzhou NetEase Mail Master 4.14.1.1004 on Windows has a DLL hijacking vulnerability. Attackers can use this vulnerability to execute malicious code.
ModificadaMedia (6.1)0.49%—Designmasterevents Conference Management CMS27/8/202017/6/2026
DesignMasterEvents Conference management 1.0.0 has cross site scripting via the 'certificate.php'
ModificadaCrítica (9.8)2.2%—Designmasterevents Conference Management27/8/202017/6/2026
DesignMasterEvents Conference management 1.0.0 allows SQL Injection via the username field on the administrator login page.
ModificadaMedia (6.5)1.0%—Expresstech Quiz AND Survey Master16/8/202017/6/2026
php/qmn_options_questions_tab.php in the quiz-master-next plugin before 4.7.9 for WordPress allows CSRF, with resultant stored XSS, via the question_name parameter because js/admin_question.js mishandles parsing inside of a SCRIPT element.
Orbitaley — Vulnerabilidades