Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

252 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.37%—Automation Systems Engineering 432es-ig3 Series AAIAutomation Systems Engineering Guardlink Ethernet IP InterfaceAI9/12/202517/6/2026
A security issue exists within 432ES-IG3 Series A, which affects GuardLink® EtherNet/IP Interface, resulting in denial-of-service. A manual power cycle is required to recover the device.
AplazadaAlta (8.5)0.13%—Asus System Control InterfaceAI25/11/202517/6/2026
A local privilege escalation vulnerability exists in the restore mechanism of ASUS System Control Interface. It can be triggered when an unprivileged actor copies files without proper validation into protected system paths, potentially leading to arbitrary files being executed as SYSTEM. For more information, please…
AplazadaBaja (1)0.12%—Xilinx Versal Adaptive SOCAIARM Trusted Firmware FOR Cortex AAIARM Power State Coordination InterfaceAI23/11/202517/6/2026
The Secure Flag passed to Versal™ Adaptive SoC’s Trusted Firmware for Cortex®-A processors (TF-A) for Arm’s Power State Coordination Interface (PSCI) commands were incorrectly set to secure instead of using the processor’s actual security state. This would allow the PSCI requests to appear they were from processors in…
AnalizadaBaja (1.9)0.25%—Fabian Email Logging Interface15/11/202517/6/2026
A vulnerability was found in code-projects Email Logging Interface 2.0. Affected is an unknown function of the file signup.cpp. The manipulation of the argument Username results in path traversal: '../filedir'. The attack is only possible with local access. The exploit has been made public and could be used.
AplazadaAlta (8.9)0.14%—Rockwellautomation Studio 5000 Simulation InterfaceAI11/11/202517/6/2026
A local code execution security issue exists within Studio 5000® Simulation Interface™ via the API. This vulnerability allows any Windows user on the system to extract files using path traversal sequences, resulting in execution of scripts with Administrator privileges on system reboot.
AplazadaAlta (8.9)0.17%—Rockwellautomation Studio 5000 Simulation InterfaceAI11/11/202517/6/2026
A local server-side request forgery (SSRF) security issue exists within Studio 5000® Simulation Interface™ via the API. This vulnerability allows any Windows user on the system to trigger outbound SMB requests, enabling the capture of NTLM hashes.
AnalizadaAlta (8.2)0.44%—Pi-hole WEB Interface27/10/202517/6/2026
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application. Pi-hole Admin Interface before 6.3 is vulnerable to Carriage Return Line Feed (CRLF) injection. When a request is made to a file ending with the .lp extension, the application…
AnalizadaMedia (5.1)0.59%—Pi-hole WEB Interface27/10/202517/6/2026
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application. Pi-hole Admin Interface versions 6.2.1 and earlier are vulnerable to reflected cross-site scripting (XSS) via a malformed URL path. The 404 error page includes the requested path in…
AnalizadaBaja (2)0.25%—Pi-hole WEB Interface27/10/202517/6/2026
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application. Pi-hole Admin Interface versions prior to 6.3 are vulnerable to cross-site scripting (XSS) via the Address field in the Subscribed Lists group management section. An authenticated…
AplazadaAlta (8.1)0.54%—Wpinterface BlogmarksAI28/8/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpinterface BlogMarks blogmarks allows PHP Local File Inclusion.This issue affects BlogMarks: from n/a through <= 1.0.8.
AplazadaAlta (7.3)0.15%—Moxa Serial Interface ServiceAI25/8/202517/6/2026
An Unquoted Search Path vulnerability has been identified in the utility for Moxa’s industrial computers (Windows). Due to the unquoted path configuration in the SerialInterfaceService.exe utility, a local attacker with limited privileges could place a malicious executable in a higher-priority directory within the…
AplazadaAlta (7.6)0.45%—Sinotrack Device Management InterfaceAI12/6/202517/6/2026
A username and password are required to authenticate to the central SinoTrack device management interface. The username for all devices is an identifier printed on the receiver. The default password is well-known and common to all devices. Modification of the default password is not enforced during device setup. A…
AplazadaMedia (5.3)0.15%—Intel Integrated Connectivity I O Interface CnviAIIntel Core Ultra ProcessorsAI13/5/202517/6/2026
Improper locking in the Intel(R) Integrated Connectivity I/O interface (CNVi) for some Intel(R) Core™ Ultra Processors may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
AplazadaAlta (7.5)0.91%—Mitsubishielectric Cc-link IE TSN Remote IO ModuleAIMitsubishielectric Cc-link IE TSN Analog-digital Converter ModuleAIMitsubishielectric Cc-link IE TSN Digital-analog Converter ModuleAIMitsubishielectric Cc-link IE TSN Fpga ModuleAI+825/4/202527/8/2026
Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module, CC-Link IE TSN Analog-Digital Converter module, CC-Link IE TSN Digital-Analog Converter module, CC-Link IE TSN FPGA module, CC-Link IE TSN Remote Station Communication LSI CP620 with…
AplazadaMedia (6.9)0.66%—Amazon Serverless Application Model Command Line InterfaceAI31/3/202517/6/2026
After completing a build with AWS Serverless Application Model Command Line Interface (SAM CLI) which include symlinks, the content of those symlinks are copied to the cache of the local workspace as regular files or directories. As a result, a user who does not have access to those symlinks outside of the Docker…
AnalizadaMedia (6.5)0.47%—Openairinterface5g27/3/202517/6/2026
A segmentation fault in openairinterface5g v2.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted UE Context Modification response.
ModificadaCrítica (9.8)0.43%—Vestel Evc04 Configuration Interface18/3/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Vestel EVC04 Configuration Interface allows SQL Injection. This issue affects EVC04 Configuration Interface: before V3.187, V4.53.
AnalizadaAlta (8.4)0.43%—Microsoft Azure Command-line Interface11/3/202517/6/2026
Improper neutralization of special elements used in a command ('command injection') in Azure Command Line Integration (CLI) allows an unauthorized attacker to elevate privileges locally.
AplazadaMedia (4.3)0.69%—DZS Router WEB InterfaceAI4/3/202517/6/2026
Cross-Site Scripting (XSS) vulnerability exists in the WPA/WAPI Passphrase field of the Wireless Security settings (2.4GHz & 5GHz bands) in DZS Router Web Interface. An authenticated attacker can inject malicious JavaScript into the passphrase field, which is stored and later executed when an administrator views the…
AplazadaMedia (6.5)0.31%—Openairinterface Oai-cn5g-amfAI21/1/20255/7/2026
An uninitialized pointer dereference in the ngap_handle_pdu_session_resource_setup_response routine of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted PDU Session Resource Setup Response.
AplazadaAlta (7.5)0.91%—Openairinterface Oai-cn5g-amfAI21/1/20255/7/2026
A stack overflow in the sctp_server::sctp_receiver_thread component of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) by repeatedly establishing SCTP connections with the N2 interface.
AplazadaMedia (6.5)0.25%—Openairinterface OAI Cn5g AMFAI21/1/20255/7/2026
OpenAirInterface CN5G AMF (oai-cn5g-amf) <= 2.0.0 contains a null dereference in its handling of unsupported NGAP protocol messages which allows an attacker with network-adjacent access to the AMF to carry out denial of service. When a procedure code/presence field tuple is received that is unsupported, OAI indexes…
AplazadaAlta (7.5)0.43%—Openairinterface Cn5g AMFAI21/1/20255/7/2026
Improper file descriptor handling for closed connections in OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) by repeatedly establishing SCTP connections with the N2 interface.
AplazadaAlta (7.5)0.43%—Openairinterface OAI Cn5g AMFAI21/1/20255/7/2026
A NULL pointer dereference in the ngap_app::handle_receive routine of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP message.
AplazadaMedia (4.3)0.33%—Martin Gibson WP Custom Admin InterfaceAI2/1/202517/6/2026
Missing Authorization vulnerability in Martin Gibson WP Custom Admin Interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through 7.32.