Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

2344 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.41%—Tungstenautomation Power PDF11/2/202517/6/2026
Tungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tungsten Automation Power PDF. User interaction is required to exploit this vulnerability in that the target must…
AnalizadaAlta (7.8)0.35%—Tungstenautomation Power PDF11/2/202517/6/2026
Tungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Tungsten Automation Power PDF. User interaction is required to exploit this vulnerability in that the target…
AnalizadaAlta (7.8)0.36%—Tungstenautomation Power PDF11/2/202517/6/2026
Tungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tungsten Automation Power PDF. User interaction is required to exploit this vulnerability in that the target must…
AnalizadaBaja (3.3)0.35%—Tungstenautomation Power PDF11/2/202517/6/2026
Tungsten Automation Power PDF JP2 File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Tungsten Automation Power PDF. User interaction is required to exploit this vulnerability in that the target must…
AnalizadaAlta (8.8)0.85%—Tungstenautomation Power PDF11/2/202517/6/2026
Tungsten Automation Power PDF JPF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tungsten Automation Power PDF. User interaction is required to exploit this vulnerability in that the target must…
AnalizadaAlta (8.8)0.23%—Devolutions Remote Desktop ManagerDevolutions Remote Desktop Manager Powershell10/2/202517/6/2026
Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack. Versions affected are : Remote Desktop Manager macOS 2024.3.9.0 and earlier Remote Desktop Manager Linux 2024.3.2.5 and…
AplazadaMedia (6.5)0.31%—Felipe Peixoto Powerful Auto ChatAI3/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Felipe Peixoto Powerful Auto Chat powers-triggers-of-woo-to-chat allows Stored XSS.This issue affects Powerful Auto Chat: from n/a through <= 1.9.8.
AnalizadaMedia (4.3)0.29%—Rapidload Power-up FOR Autoptimize1/2/202517/6/2026
The RapidLoad – Optimize Web Vitals Automatically plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_deactivate() function in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with Subscriber-level access and…
AnalizadaMedia (5.4)0.30%—Wppug Power UPS FOR Elementor25/1/202517/6/2026
The Power Ups for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'magic-button' shortcode in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…
AnalizadaCrítica (9.8)0.57%—Sungrowpower Winet-s Firmware24/1/202517/6/2026
SunGrow WiNet-SV200.001.00.P027 and earlier versions is vulnerable to heap-based buffer overflow due to bounds checks of the MQTT message content.
AnalizadaAlta (8.1)0.45%—Sungrowpower Winet-s Firmware24/1/202517/6/2026
In SunGrow WiNet-SV200.001.00.P027 and earlier versions, when decrypting MQTT messages, the code that parses specific TLV fields does not have sufficient bounds checks. This may result in a stack-based buffer overflow.
AnalizadaCrítica (9.8)0.57%—Sungrowpower Winet-s Firmware24/1/202517/6/2026
SunGrow WiNet-SV200.001.00.P027 and earlier versions is vulnerable to stack-based buffer overflow when parsing MQTT messages, due to missing MQTT topic bounds checks.
AnalizadaCrítica (9.8)0.57%—Sungrowpower Winet-s Firmware24/1/202517/6/2026
In SunGrow WiNet-SV200.001.00.P027 and earlier versions, when copying the timestamp read from an MQTT message, the underlying code does not check the bounds of the buffer that is used to store the message. This may lead to a stack-based buffer overflow.
AnalizadaMedia (5.4)0.24%—Sungrowpower Winet-s Firmware24/1/202517/6/2026
SunGrow WiNet-SV200.001.00.P027 and earlier versions contains hardcoded MQTT credentials that allow an attacker to send arbitrary commands to an arbitrary inverter. It is also possible to impersonate the broker, because TLS is not used to identify the real MQTT broker. This means that MQTT communications are…
AnalizadaMedia (6.5)0.25%—Sungrowpower Winet-s Firmware24/1/202517/6/2026
SunGrow WiNet-SV200.001.00.P027 and earlier versions contains a hardcoded password that can be used to decrypt all firmware updates.
AnalizadaAlta (7.2)0.65%—Aipower22/1/202517/6/2026
The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.96 via deserialization of untrusted input from the $form['post_content'] variable through the wpaicg_export_ai_forms() function. This allows authenticated attackers, with administrative…
AnalizadaAlta (7.2)0.65%—Aipower22/1/202517/6/2026
The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.96 via deserialization of untrusted input from the $form['post_content'] variable through the wpaicg_export_prompts function. This allows authenticated attackers, with administrative…
AnalizadaAlta (8.8)0.32%—Aipower22/1/202517/6/2026
The AI Power: Complete AI Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpaicg_save_image_media function in all versions up to, and including, 1.8.96. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload image…
AnalizadaMedia (5.4)0.24%—Aipower22/1/202517/6/2026
The AI Power: Complete AI Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.8.96 via the wpaicg_troubleshoot_add_vector(). This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations…
AplazadaAlta (7.5)0.62%—Cyberpower Powerpanel BusinessAI15/1/202517/6/2026
A denial-of-service vulnerability exists in CyberPower PowerPanel Business (PPB) 4.11.0. An unauthenticated remote attacker can restart the ppbd.exe process via the PowerPanel Business Service Watchdog service listening on TCP port 2003. The attacker can repeatedly restart ppbd.exe to render it unavailable.
AnalizadaAlta (7.8)0.75%—Microsoft Power Automate FOR Desktop14/1/202517/6/2026
Microsoft Power Automate Remote Code Execution Vulnerability
AnalizadaAlta (7.5)1.7%—Microsoft .netMicrosoft PowershellMicrosoft Visual Studio 202214/1/202517/6/2026
.NET Remote Code Execution Vulnerability
ModificadaAlta (7.5)4.7%—Samba RsyncRedhat DiscoveryRedhat Openshift Container PlatformRedhat Enterprise Linux+1614/1/202530/6/2026
A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory.
ModificadaAlta (7.5)2.3%—Samba RsyncAlmalinuxArchlinux Arch LinuxGentoo Linux+1414/1/202530/6/2026
A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the `--inc-recursive` option, a lack of proper symlink verification…
ModificadaAlta (7.5)8.8%💥 PoCSamba RsyncRedhat OpenshiftRedhat Openshift Container PlatformRedhat Enterprise Linux+1814/1/202521/9/2026
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.