Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
2344 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.30% | — | Tungstenautomation Power PDF | 22/11/2024 | 17/6/2026 | Tungsten Automation Power PDF XPS File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tungsten Automation Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Analizada | Alta (7.8) | 0.49% | — | Tungstenautomation Power PDF | 22/11/2024 | 17/6/2026 | Kofax Power PDF JP2 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open… | |
| Analizada | Media (5.5) | 0.46% | — | Tungstenautomation Power PDF | 22/11/2024 | 17/6/2026 | Kofax Power PDF JP2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page… | |
| Analizada | Alta (7.8) | 0.49% | — | Tungstenautomation Power PDF | 22/11/2024 | 17/6/2026 | Kofax Power PDF JP2 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a… | |
| Analizada | Alta (7.8) | 0.49% | — | Tungstenautomation Power PDF | 22/11/2024 | 17/6/2026 | Kofax Power PDF JP2 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a… | |
| Analizada | Media (5.9) | 0.35% | — | IBM Powervm Hypervisor | 22/11/2024 | 17/6/2026 | IBM PowerVM Platform KeyStore (IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1030.00 through FW1030.60, FW1050.00 through FW1050.20, and FW1060.00 through FW1060.10 functionality can be compromised if an attacker gains service access to the HMC. An attacker that gains service access to the HMC can locate and… | |
| Aplazada | Media (6.1) | 0.43% | — | Cisco Adaptive Security ApplianceAICisco Firepower Threat DefenseAI | 18/11/2024 | 17/6/2026 | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to… | |
| Aplazada | Media (6.9) | 0.55% | — | Altenergy Power Control SoftwareAI | 18/11/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Altenergy Power Control Software up to 20241108. This issue affects some unknown processing of the file /index.php/display/database/. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been… | |
| Aplazada | Media (5.3) | 3.7% | 💥 Exploit | Altenergy Power Control SoftwareAI | 18/11/2024 | 17/6/2026 | A vulnerability classified as critical was found in Altenergy Power Control Software up to 20241108. This vulnerability affects the function get_status_zigbee of the file /index.php/display/status_zigbee. The manipulation of the argument date leads to sql injection. The attack can be initiated remotely. The exploit… | |
| Analizada | Alta (8.7) | 0.82% | — | Schneider-electric Powerlogic Pm5341 FirmwareSchneider-electric Powerlogic Pm5340 FirmwareSchneider-electric Powerlogic Pm5320 Firmware | 13/11/2024 | 17/6/2026 | CWE-400: An Uncontrolled Resource Consumption vulnerability exists that could cause the device to become unresponsive resulting in communication loss when a large amount of IGMP packets is present in the network. | |
| Analizada | Alta (8.5) | 0.14% | — | Siemens Spectrum Power 7 | 12/11/2024 | 17/6/2026 | A vulnerability has been identified in Spectrum Power 7 (All versions < V24Q3). The affected product contains several root-owned SUID binaries that could allow an authenticated local attacker to escalate privileges. | |
| Analizada | Crítica (9.8) | 0.42% | — | Powerjob | 11/11/2024 | 17/6/2026 | Powerjob >= 3.20 is vulnerable to SQL injection via the version parameter. | |
| Aplazada | Crítica (9.8) | 1.0% | — | Powertac-serverAI | 11/11/2024 | 17/6/2026 | An XML External Entity (XXE) vulnerability in the component DocumentBuilderFactory of powertac-server v1.9.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities. | |
| Aplazada | Crítica (9.8) | 0.77% | — | Lens VisualAIMicrosoft Power BIAI | 5/11/2024 | 17/6/2026 | An issue in Lens Visual integration with Power BI v.4.0.0.3 allows a remote attacker to execute arbitrary code via the Natural language processing component | |
| Aplazada | Crítica (9.8) | 15% | — | Aipower Complete AI PackAI | 31/10/2024 | 17/6/2026 | The AI Power: Complete AI Pack plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handle_image_upload' function in all versions up to, and including, 1.8.89. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's… | |
| Modificada | Media (6.1) | 0.31% | — | Samglover Client Power Tools | 29/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sam Glover Client Power Tools Portal client-power-tools allows Reflected XSS.This issue affects Client Power Tools Portal: from n/a through <= 1.9.0. | |
| Analizada | Crítica (9.8) | 0.45% | — | IBM Power System E1080 (9080-hex) FirmwareIBM Power System L922 (9008-22l) FirmwareIBM Power System S922 (9009-22a) FirmwareIBM Power System S922 (9009-22g) Firmware+24 | 29/10/2024 | 17/6/2026 | IBM Flexible Service Processor (FSP) FW860.00 through FW860.B3, FW950.00 through FW950.C0, FW1030.00 through FW1030.61, FW1050.00 through FW1050.21, and FW1060.00 through FW1060.10 has static credentials which may allow network users to gain service privileges to the FSP. | |
| Aplazada | Alta (8.8) | 0.44% | — | Ironman Powershell UniversalAI | 27/10/2024 | 17/6/2026 | Ironman PowerShell Universal 5.x before 5.0.12 allows an authenticated attacker to elevate their privileges and view job information. | |
| Analizada | Media (6.1) | 0.32% | — | Cisco Firepower Management CenterCisco Secure Firewall Management Center | 23/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of… | |
| Analizada | Media (6.1) | 0.32% | — | Cisco Firepower Management CenterCisco Secure Firewall Management Center | 23/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of… | |
| Analizada | Media (6.1) | 0.32% | — | Cisco Firepower Management CenterCisco Secure Firewall Management Center | 23/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of… | |
| Analizada | Media (5.4) | 0.30% | — | Cisco Firepower Management CenterCisco Secure Firewall Management Center | 23/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of… | |
| Analizada | Media (5.3) | 0.41% | — | Cisco Firepower Management CenterCisco Secure Firewall Management CenterCisco Secure Firewall Threat Defense | 23/10/2024 | 11/8/2026 | A vulnerability in the password change feature of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote attacker to determine valid user names on an affected device. This vulnerability is due to improper authentication of password update responses. An attacker could exploit this… | |
| Analizada | Media (5.4) | 0.31% | — | Cisco Firepower Management CenterCisco Secure Firewall Management Center | 23/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco FMC Software could allow an authenticated, remote attacker to store malicious content for use in XSS attacks. This vulnerability is due to improper input sanitization in the web-based management interface of Cisco FMC Software. An attacker could exploit… | |
| Analizada | Media (6.1) | 0.39% | — | Cisco Firepower Management CenterCisco Secure Firewall Management Center | 23/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of… |