Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2826▼ 248 respecto a la semana anterior
Críticas / altas1321▼ 176 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
3327 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.31% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker with elevated privileges to falsify tamper events by accessing internal components. | |
| Modificada | Media (4.1) | 0.19% | — | Entrust Nshield Connect XC High FirmwareEntrust Nshield Connect XC MID FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Hsmi Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker (with elevated privileges) to read and modify the Appliance SSD contents (because they are unencrypted). | |
| Modificada | Baja (3.9) | 0.18% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker with root access to modify the Recovery Partition (because of a lack of integrity protection). | |
| Modificada | Media (6.8) | 0.33% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to escalate privileges by booting from a USB device with a valid root filesystem. This occurs because of insecure default settings in the Legacy GRUB… | |
| Modificada | Media (6.8) | 0.33% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), might allow a physically proximate attacker to gain access to the EOL legacy bootloader. | |
| Modificada | Alta (7.2) | 0.31% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to escalate privileges by editing the Legacy GRUB bootloader configuration to start a root shell upon boot of the host OS. This is called F06. | |
| Modificada | Baja (3.2) | 0.24% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to modify or erase tamper events via the Chassis management board. | |
| Modificada | Crítica (9.8) | 0.67% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a user with OS root access to alter firmware on the Chassis Management Board (without Authentication). This is called F04. | |
| Modificada | Media (6.8) | 0.32% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allows a physically proximate attacker to persistently modify firmware and influence the (insecurely configured) appliance boot process. To exploit this, the… | |
| Modificada | Crítica (9.8) | 0.90% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allows a physically proximate attacker to obtain debug access and escalate privileges by bypassing the tamper label and opening the chassis without leaving… | |
| Aplazada | Alta (7.5) | 0.33% | — | E4jconnect VikrentcarAI | 2/12/2025 | 17/6/2026 | The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'month' parameter in all versions up to, and including, 1.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Aplazada | Media (4.3) | 0.20% | — | Gsheetconnector FOR Ninja FormsAI | 22/11/2025 | 17/6/2026 | The GSheetConnector For Ninja Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'njform-google-sheet-config ' page in all versions up to, and including, 2.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Aplazada | Media (5.3) | 0.29% | — | Bigbuy Dropshipping ConnectorAI | 21/11/2025 | 8/10/2026 | El plugin BigBuy Dropshipping Connector para WooCommerce para WordPress es vulnerable a la suplantación de dirección IP en todas las versiones hasta la 2.0.5, inclusive, debido a una validación insuficiente de la dirección IP y al uso de encabezados HTTP proporcionados por el usuario como método principal para la… | |
| Aplazada | Alta (8.6) | 0.30% | — | Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+28 | 19/11/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,… | |
| Aplazada | Alta (8.6) | 0.30% | — | Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+28 | 19/11/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,… | |
| Analizada | Media (6.5) | 0.21% | — | Hcltech Connections | 18/11/2025 | 17/6/2026 | HCL Connections is vulnerable to a sensitive information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper rendering of application data. | |
| Analizada | Alta (7.8) | 0.40% | 💥 PoC | Ispyconnect Agent DVR | 18/11/2025 | 17/6/2026 | Local Agent DVR versions thru 6.6.1.0 are vulnerable to directory traversal that allows an unauthenticated local attacker to gain access to sensitive information, cause a server-side forgery request (SSRF), or execute OS commands. | |
| Analizada | Alta (7.5) | 0.45% | — | Metz-connect Ewio2-m FirmwareMetz-connect Ewio2-m-bm FirmwareMetz-connect Ewio2-bm Firmware | 18/11/2025 | 17/6/2026 | Due to webserver misconfiguration an unauthenticated remote attacker is able to read the source of php modules. | |
| Analizada | Alta (8.8) | 0.72% | — | Metz-connect Ewio2-m FirmwareMetz-connect Ewio2-m-bm FirmwareMetz-connect Ewio2-bm Firmware | 18/11/2025 | 17/6/2026 | A low privileged remote attacker can upload a new or overwrite an existing python script by using a path traversal of the target filename in php resulting in a remote code execution. | |
| Analizada | Alta (8.8) | 0.59% | — | Metz-connect Ewio2-m FirmwareMetz-connect Ewio2-m-bm FirmwareMetz-connect Ewio2-bm Firmware | 18/11/2025 | 17/6/2026 | A low privileged remote attacker can upload any file to an arbitrary location due to missing file check resulting in remote code execution. | |
| Analizada | Crítica (9.8) | 0.52% | — | Metz-connect Ewio2-m FirmwareMetz-connect Ewio2-m-bm FirmwareMetz-connect Ewio2-bm Firmware | 18/11/2025 | 17/6/2026 | An unauthenticated remote attacker can execute arbitrary php files and gain full access of the affected devices. | |
| Analizada | Crítica (9.8) | 0.63% | — | Metz-connect Ewio2-m FirmwareMetz-connect Ewio2-m-bm FirmwareMetz-connect Ewio2-bm Firmware | 18/11/2025 | 17/6/2026 | The commissioning wizard on the affected devices does not validate if the device is already initialized. An unauthenticated remote attacker can construct POST requests to set root credentials. | |
| Aplazada | Alta (7.1) | 0.18% | 💥 PoC | Redpine Signals Rs9116 Wiseconnect SDKAI | 17/11/2025 | 7/10/2026 | En un dispositivo Bluetooth, el uso del SDK RS9116-WiseConnect experimenta una denegación de servicio si recibe paquetes L2CAP malformados; solo un reinicio forzado devolverá el dispositivo a su funcionamiento normal. | |
| Aplazada | Media (5.2) | 0.12% | — | Zscaler Client ConnectorAI | 12/11/2025 | 17/6/2026 | A health check port on Zscaler Client Connector on Windows, versions 4.6 < 4.6.0.216 and 4.7 < 4.7.0.47, which under specific circumstances was not released after use, allowed traffic to potentially bypass ZCC forwarding controls. | |
| Analizada | Media (6.8) | 0.28% | — | SAP Business Connector | 11/11/2025 | 17/6/2026 | Due to a Path Traversal vulnerability in SAP Business Connector, an attacker authenticated as an administrator with adjacent access could read, write, overwrite, and delete arbitrary files on the host system. Successful exploitation could enable the attacker to execute arbitrary operating system commands on the… |