Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
2287 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 3.0% | — | Zohocorp Manageengine Adaudit Plus | 20/5/2024 | 17/6/2026 | Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while getting file server details. | |
| Analizada | Alta (8.8) | 3.0% | — | Zohocorp Manageengine Adaudit Plus | 20/5/2024 | 17/6/2026 | Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while exporting a full summary report. | |
| Analizada | Alta (8.8) | 3.0% | — | Zohocorp Manageengine Adaudit Plus | 20/5/2024 | 17/6/2026 | Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the dashboard graph feature. | |
| Analizada | Alta (8.8) | 3.0% | — | Zohocorp Manageengine Adaudit Plus | 20/5/2024 | 17/6/2026 | Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while adding file shares. | |
| Analizada | Alta (8.8) | 3.0% | — | Zohocorp Manageengine Adaudit Plus | 20/5/2024 | 17/6/2026 | Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the aggregate reports search option. | |
| Analizada | Alta (8.8) | 2.3% | — | Zohocorp Manageengine Adaudit Plus | 20/5/2024 | 17/6/2026 | Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while getting aggregate report data. | |
| Analizada | Alta (7.8) | 0.20% | — | Intel Ethernet Controller I225-it FirmwareIntel Ethernet Controller I225-lm FirmwareIntel Ethernet Controller I225-v FirmwareIntel Ethernet Adapter Complete Driver | 16/5/2024 | 17/6/2026 | Improper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (4.3) | 0.25% | — | Shortpixel Adaptive ImagesAI | 14/5/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ShortPixel ShortPixel Adaptive Images shortpixel-adaptive-images.This issue affects ShortPixel Adaptive Images: from n/a through <= 3.8.3. | |
| Aplazada | Media (4.4) | 0.36% | — | Shortpixel Adaptive ImagesAI | 14/5/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in ShortPixel ShortPixel Adaptive Images shortpixel-adaptive-images.This issue affects ShortPixel Adaptive Images: from n/a through <= 3.8.3. | |
| Aplazada | Media (6.5) | 0.41% | — | Adam Dehaven Perfect PullquotesAI | 14/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adam DeHaven Perfect Pullquotes allows Stored XSS.This issue affects Perfect Pullquotes: from n/a through 1.7.5. | |
| Analizada | Media (6.8) | 0.43% | — | IBM Qradar Security Information AND Event Manager | 14/5/2024 | 17/6/2026 | IBM QRadar SIEM 7.5 could allow a privileged user to configure user management that would disclose unintended sensitive information across tenants. IBM X-Force ID: 284575. | |
| Analizada | Alta (8.8) | 2.3% | — | Trianglemicroworks Scada Data Gateway | 7/5/2024 | 17/6/2026 | Triangle MicroWorks SCADA Data Gateway Restore Workspace Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Triangle MicroWorks SCADA Data Gateway. Although authentication is required to exploit this vulnerability,… | |
| Aplazada | Media (5.3) | 0.60% | — | Faraday Gm8181AIFaraday Gm828xAI | 7/5/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Faraday GM8181 and GM828x up to 20240429. Affected by this issue is some unknown functionality of the file /command_port.ini. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to… | |
| Aplazada | Media (5.3) | 0.59% | — | Faraday Gm8181AIFaraday Gm828xAI | 7/5/2024 | 17/6/2026 | A vulnerability classified as problematic was found in Faraday GM8181 and GM828x up to 20240429. Affected by this vulnerability is an unknown functionality of the component Request Handler. The manipulation leads to information disclosure. The attack can be launched remotely. The exploit has been disclosed to the… | |
| Aplazada | Alta (7.3) | 1.4% | — | Faraday Gm8181AIFaraday Gm828xAI | 7/5/2024 | 17/6/2026 | A vulnerability classified as critical has been found in Faraday GM8181 and GM828x up to 20240429. Affected is an unknown function of the component NTP Service. The manipulation of the argument ntp_srv leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Alta (7.2) | 1.9% | — | Trianglemicroworks Scada Data Gateway | 3/5/2024 | 17/6/2026 | Triangle MicroWorks SCADA Data Gateway DbasSectorFileToExecuteOnReset Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is required to exploit this… | |
| Analizada | Media (5.3) | 0.58% | — | Trianglemicroworks Scada Data Gateway | 3/5/2024 | 17/6/2026 | Triangle MicroWorks SCADA Data Gateway certificate Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not required to exploit this vulnerability. The specific flaw… | |
| Analizada | Media (5.3) | 1.0% | — | Trianglemicroworks Scada Data Gateway | 3/5/2024 | 17/6/2026 | Triangle MicroWorks SCADA Data Gateway get_config Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not required to exploit this vulnerability.… | |
| Analizada | Alta (7.5) | 0.76% | — | Trianglemicroworks Scada Data Gateway | 3/5/2024 | 17/6/2026 | Triangle MicroWorks SCADA Data Gateway Use of Hard-coded Cryptograhic Key Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not required to exploit this vulnerability.… | |
| Analizada | Alta (7.2) | 2.0% | — | Trianglemicroworks Scada Data Gateway | 3/5/2024 | 17/6/2026 | Triangle MicroWorks SCADA Data Gateway GTWWebMonitorService Unquoted Search Path Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute code on affected installations of Triangle MicroWorks SCADA Data Gateway. Although authentication is required to exploit this vulnerability, the… | |
| Analizada | Alta (7.2) | 1.2% | — | Trianglemicroworks Scada Data Gateway | 3/5/2024 | 17/6/2026 | Triangle MicroWorks SCADA Data Gateway Trusted Certification Unrestricted Upload of File Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Triangle MicroWorks SCADA Data Gateway. Although authentication is required to exploit this… | |
| Analizada | Media (6.5) | 1.5% | — | Trianglemicroworks Scada Data Gateway | 3/5/2024 | 17/6/2026 | Triangle MicroWorks SCADA Data Gateway Workspace Unrestricted Upload Vulnerability. This vulnerability allows remote attackers to upload arbitrary files on affected installations of Triangle MicroWorks SCADA Data Gateway. Although authentication is required to exploit this vulnerability, the existing authentication… | |
| Analizada | Media (4.4) | 1.3% | — | Trianglemicroworks Scada Data Gateway | 3/5/2024 | 17/6/2026 | Triangle MicroWorks SCADA Data Gateway Event Log Improper Output Neutralization For Logs Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to write arbitrary files on affected installations of Triangle MicroWorks SCADA Data Gateway. Although authentication is required to exploit this… | |
| Analizada | Alta (7.2) | 3.4% | — | Trianglemicroworks Scada Data Gateway | 3/5/2024 | 17/6/2026 | Triangle MicroWorks SCADA Data Gateway Event Log Directory Traversal Arbitrary File Creation Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Triangle MicroWorks SCADA Data Gateway. Although authentication is required to exploit this vulnerability, the… | |
| Analizada | Alta (7.8) | 0.96% | — | Trianglemicroworks Scada Data Gateway | 3/5/2024 | 17/6/2026 | Triangle MicroWorks SCADA Data Gateway Directory Traversal Arbitrary File Creation Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Triangle MicroWorks SCADA Data Gateway. User interaction is required to exploit this vulnerability in that the target must… |