Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
252 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.37% | — | Automation Systems Engineering 432es-ig3 Series AAIAutomation Systems Engineering Guardlink Ethernet IP InterfaceAI | 9/12/2025 | 17/6/2026 | A security issue exists within 432ES-IG3 Series A, which affects GuardLink® EtherNet/IP Interface, resulting in denial-of-service. A manual power cycle is required to recover the device. | |
| Aplazada | Alta (8.5) | 0.13% | — | Asus System Control InterfaceAI | 25/11/2025 | 17/6/2026 | A local privilege escalation vulnerability exists in the restore mechanism of ASUS System Control Interface. It can be triggered when an unprivileged actor copies files without proper validation into protected system paths, potentially leading to arbitrary files being executed as SYSTEM. For more information, please… | |
| Aplazada | Baja (1) | 0.12% | — | Xilinx Versal Adaptive SOCAIARM Trusted Firmware FOR Cortex AAIARM Power State Coordination InterfaceAI | 23/11/2025 | 17/6/2026 | The Secure Flag passed to Versal™ Adaptive SoC’s Trusted Firmware for Cortex®-A processors (TF-A) for Arm’s Power State Coordination Interface (PSCI) commands were incorrectly set to secure instead of using the processor’s actual security state. This would allow the PSCI requests to appear they were from processors in… | |
| Analizada | Baja (1.9) | 0.25% | — | Fabian Email Logging Interface | 15/11/2025 | 17/6/2026 | A vulnerability was found in code-projects Email Logging Interface 2.0. Affected is an unknown function of the file signup.cpp. The manipulation of the argument Username results in path traversal: '../filedir'. The attack is only possible with local access. The exploit has been made public and could be used. | |
| Aplazada | Alta (8.9) | 0.14% | — | Rockwellautomation Studio 5000 Simulation InterfaceAI | 11/11/2025 | 17/6/2026 | A local code execution security issue exists within Studio 5000® Simulation Interface™ via the API. This vulnerability allows any Windows user on the system to extract files using path traversal sequences, resulting in execution of scripts with Administrator privileges on system reboot. | |
| Aplazada | Alta (8.9) | 0.17% | — | Rockwellautomation Studio 5000 Simulation InterfaceAI | 11/11/2025 | 17/6/2026 | A local server-side request forgery (SSRF) security issue exists within Studio 5000® Simulation Interface™ via the API. This vulnerability allows any Windows user on the system to trigger outbound SMB requests, enabling the capture of NTLM hashes. | |
| Analizada | Alta (8.2) | 0.44% | — | Pi-hole WEB Interface | 27/10/2025 | 17/6/2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application. Pi-hole Admin Interface before 6.3 is vulnerable to Carriage Return Line Feed (CRLF) injection. When a request is made to a file ending with the .lp extension, the application… | |
| Analizada | Media (5.1) | 0.59% | — | Pi-hole WEB Interface | 27/10/2025 | 17/6/2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application. Pi-hole Admin Interface versions 6.2.1 and earlier are vulnerable to reflected cross-site scripting (XSS) via a malformed URL path. The 404 error page includes the requested path in… | |
| Analizada | Baja (2) | 0.25% | — | Pi-hole WEB Interface | 27/10/2025 | 17/6/2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application. Pi-hole Admin Interface versions prior to 6.3 are vulnerable to cross-site scripting (XSS) via the Address field in the Subscribed Lists group management section. An authenticated… | |
| Aplazada | Alta (8.1) | 0.54% | — | Wpinterface BlogmarksAI | 28/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpinterface BlogMarks blogmarks allows PHP Local File Inclusion.This issue affects BlogMarks: from n/a through <= 1.0.8. | |
| Aplazada | Alta (7.3) | 0.15% | — | Moxa Serial Interface ServiceAI | 25/8/2025 | 17/6/2026 | An Unquoted Search Path vulnerability has been identified in the utility for Moxa’s industrial computers (Windows). Due to the unquoted path configuration in the SerialInterfaceService.exe utility, a local attacker with limited privileges could place a malicious executable in a higher-priority directory within the… | |
| Aplazada | Alta (7.6) | 0.45% | — | Sinotrack Device Management InterfaceAI | 12/6/2025 | 17/6/2026 | A username and password are required to authenticate to the central SinoTrack device management interface. The username for all devices is an identifier printed on the receiver. The default password is well-known and common to all devices. Modification of the default password is not enforced during device setup. A… | |
| Aplazada | Media (5.3) | 0.15% | — | Intel Integrated Connectivity I O Interface CnviAIIntel Core Ultra ProcessorsAI | 13/5/2025 | 17/6/2026 | Improper locking in the Intel(R) Integrated Connectivity I/O interface (CNVi) for some Intel(R) Core™ Ultra Processors may allow an unauthenticated user to potentially enable escalation of privilege via physical access. | |
| Aplazada | Alta (7.5) | 0.91% | — | Mitsubishielectric Cc-link IE TSN Remote IO ModuleAIMitsubishielectric Cc-link IE TSN Analog-digital Converter ModuleAIMitsubishielectric Cc-link IE TSN Digital-analog Converter ModuleAIMitsubishielectric Cc-link IE TSN Fpga ModuleAI+8 | 25/4/2025 | 27/8/2026 | Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module, CC-Link IE TSN Analog-Digital Converter module, CC-Link IE TSN Digital-Analog Converter module, CC-Link IE TSN FPGA module, CC-Link IE TSN Remote Station Communication LSI CP620 with… | |
| Aplazada | Media (6.9) | 0.66% | — | Amazon Serverless Application Model Command Line InterfaceAI | 31/3/2025 | 17/6/2026 | After completing a build with AWS Serverless Application Model Command Line Interface (SAM CLI) which include symlinks, the content of those symlinks are copied to the cache of the local workspace as regular files or directories. As a result, a user who does not have access to those symlinks outside of the Docker… | |
| Analizada | Media (6.5) | 0.47% | — | Openairinterface5g | 27/3/2025 | 17/6/2026 | A segmentation fault in openairinterface5g v2.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted UE Context Modification response. | |
| Modificada | Crítica (9.8) | 0.43% | — | Vestel Evc04 Configuration Interface | 18/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Vestel EVC04 Configuration Interface allows SQL Injection. This issue affects EVC04 Configuration Interface: before V3.187, V4.53. | |
| Analizada | Alta (8.4) | 0.43% | — | Microsoft Azure Command-line Interface | 11/3/2025 | 17/6/2026 | Improper neutralization of special elements used in a command ('command injection') in Azure Command Line Integration (CLI) allows an unauthorized attacker to elevate privileges locally. | |
| Aplazada | Media (4.3) | 0.69% | — | DZS Router WEB InterfaceAI | 4/3/2025 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability exists in the WPA/WAPI Passphrase field of the Wireless Security settings (2.4GHz & 5GHz bands) in DZS Router Web Interface. An authenticated attacker can inject malicious JavaScript into the passphrase field, which is stored and later executed when an administrator views the… | |
| Aplazada | Media (6.5) | 0.31% | — | Openairinterface Oai-cn5g-amfAI | 21/1/2025 | 5/7/2026 | An uninitialized pointer dereference in the ngap_handle_pdu_session_resource_setup_response routine of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted PDU Session Resource Setup Response. | |
| Aplazada | Alta (7.5) | 0.91% | — | Openairinterface Oai-cn5g-amfAI | 21/1/2025 | 5/7/2026 | A stack overflow in the sctp_server::sctp_receiver_thread component of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) by repeatedly establishing SCTP connections with the N2 interface. | |
| Aplazada | Media (6.5) | 0.25% | — | Openairinterface OAI Cn5g AMFAI | 21/1/2025 | 5/7/2026 | OpenAirInterface CN5G AMF (oai-cn5g-amf) <= 2.0.0 contains a null dereference in its handling of unsupported NGAP protocol messages which allows an attacker with network-adjacent access to the AMF to carry out denial of service. When a procedure code/presence field tuple is received that is unsupported, OAI indexes… | |
| Aplazada | Alta (7.5) | 0.43% | — | Openairinterface Cn5g AMFAI | 21/1/2025 | 5/7/2026 | Improper file descriptor handling for closed connections in OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) by repeatedly establishing SCTP connections with the N2 interface. | |
| Aplazada | Alta (7.5) | 0.43% | — | Openairinterface OAI Cn5g AMFAI | 21/1/2025 | 5/7/2026 | A NULL pointer dereference in the ngap_app::handle_receive routine of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP message. | |
| Aplazada | Media (4.3) | 0.33% | — | Martin Gibson WP Custom Admin InterfaceAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Martin Gibson WP Custom Admin Interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through 7.32. |