Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
–

1970 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.4)0.71%—10-strike Network Inventory Explorer15/1/202617/6/2026
10-Strike Network Inventory Explorer Pro 9.31 contains a buffer overflow vulnerability in the text file import functionality that allows remote code execution. Attackers can craft a malicious text file with carefully constructed payload to trigger a reverse shell and execute arbitrary code on the target system.
AnalizadaAlta (8.5)0.24%—10-strike Network Inventory Explorer15/1/202617/6/2026
10-Strike Network Inventory Explorer Pro 9.31 contains an unquoted service path vulnerability in the srvInventoryWebServer service running with LocalSystem privileges. Attackers can exploit the unquoted path by placing malicious executables in potential path segments to achieve privilege escalation and execute code…
AnalizadaAlta (7)0.58%—Explorerplusplus Explorer++13/1/202617/6/2026
Explorer32++ 1.3.5.531 contains a buffer overflow vulnerability in Structured Exception Handler (SEH) records that allows attackers to execute arbitrary code. Attackers can exploit the vulnerability by providing a long file name argument over 396 characters to corrupt the SEH chain and potentially execute malicious…
AnalizadaCrítica (9.3)5.8%—Extplorer13/1/20266/10/2026
eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without a password by manipulating the login request. Attackers can exploit this flaw to upload malicious PHP files and execute remote commands on the vulnerable file management system.
AnalizadaMedia (5.3)0.32%—Kodcloud Kodexplorer11/12/202517/6/2026
KodExplorer 4.52 contains an open redirect vulnerability in the user login page that allows attackers to manipulate the 'link' parameter. Attackers can craft malicious URLs in the link parameter to redirect users to arbitrary external websites after authentication.
AnalizadaMedia (5.5)0.38%—Ml-explore MLX21/11/202517/6/2026
MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a segmentation fault in mlx::core::load_gguf() when loading malicious GGUF files. Untrusted pointer from external gguflib library is dereferenced without validation, causing application crash. This issue has been patched…
AnalizadaMedia (5.5)0.53%—Ml-explore MLX21/11/202517/6/2026
MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a heap buffer overflow in mlx::core::load() when parsing malicious NumPy .npy files. Attacker-controlled file causes 13-byte out-of-bounds read, leading to crash or information disclosure. This issue has been patched in…
ModificadaMedia (5.1)0.25%—Extplorer12/11/202517/6/2026
A security flaw has been discovered in soerennb eXtplorer up to 2.1.15. The affected element is an unknown function of the component Filename Handler. The manipulation results in cross site scripting. The attack may be launched remotely. The patch is identified as 002def70b985f7012586df2c44368845bf405ab3. Applying a…
AplazadaAlta (8.7)0.43%—BookloreAI22/10/202517/6/2026
BookLore is a self-hosted web app for organizing and managing personal book collections. In versions 1.8.1 and prior, an authentication bypass vulnerability in the BookMediaController allows any unauthenticated user to access and download book covers, thumbnails, and complete PDF/CBX page content without…
AplazadaAlta (8.2)0.16%—Apollo SandboxAISpeed Software ExplorerAI26/9/202517/6/2026
Apollo Studio Embeddable Explorer & Embeddable Sandbox are website embeddable software solutions from Apollo GraphQL. Prior to Apollo Sandbox version 2.7.2 and Apollo Explorer version 3.7.3, a cross-site request forgery (CSRF) vulnerability was identified. The vulnerability arises from missing origin validation in the…
AplazadaMedia (6.9)0.13%—Cognex In-sight ExplorerAICognex In-sight Camera FirmwareAI18/9/202517/6/2026
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 in order to allow management operations on the device such as firmware upgrades and device reboot requiring an authentication. A wrong management of login failures of the service allows a denial-of-service attack, leaving…
AplazadaAlta (8.6)0.15%—Cognex In-sight ExplorerAICognex In-sight Camera FirmwareAI18/9/202517/6/2026
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a proprietary protocol on TCP port 1069 to perform management operations such as modifying system properties. The user management functionality handles sensitive data such as registered usernames and passwords over an unencrypted channel, allowing an…
AplazadaAlta (8.6)0.20%—Cognex In-sight ExplorerAICognex In-sight Camera FirmwareAI18/9/202517/6/2026
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a proprietary protocol on TCP port 1069 to perform management operations such as modifying system properties. The user management functionality handles sensitive data such as registered usernames and passwords over an unencrypted channel, allowing an…
AplazadaAlta (7.2)0.31%—Cognex In-sight ExplorerAICognex In-sight Camera FirmwareAI18/9/202517/6/2026
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgrades and device reboots, which require authentication. A user with protected privileges can successfully invoke the SetSerialPort functionality to modify relevant device…
AplazadaAlta (8.6)0.39%—Cognex In-sight ExplorerAICognex In-sight CameraAI18/9/202517/6/2026
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a service implementing a proprietary protocol on TCP port 1069 to allow the client-side software, such as the In-Sight Explorer tool, to perform management operations such as changing network settings or modifying users' access to the device.
AplazadaAlta (7.2)0.31%—Cognex In-sight ExplorerAICognex In-sight Camera FirmwareAI18/9/202517/6/2026
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgrades and device reboots, which require authentication. A user with protected privileges can successfully invoke the SetSystemConfig functionality to modify relevant device…
AplazadaAlta (8.1)0.26%—Zohocorp Asset ExplorerAIZohocorp Servicedesk PlusAIZohocorp Servicedesk Plus MSPAIZohocorp Supportcenter PlusAI20/8/202517/6/2026
There is an improper privilege management vulnerability identified in ManageEngine's Asset Explorer, ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus products by Zohocorp. This vulnerability impacts Asset Explorer versions before 7710, ServiceDesk Plus versions before 15110, ServiceDesk Plus MSP versions…
AplazadaMedia (4.3)0.24%—Runzero ExplorerAIBrotherAI12/8/202517/6/2026
By using the "uscan" protocol provided by the eSCL specification, an attacker can discover the serial number of multi-function printers that implement the Brother-provided firmware. This serial number can, in turn, can be leveraged by the flaw described by CVE-2024-51978 to calculate the default administrator…
AplazadaCrítica (9.3)1.7%—Pydio CellsAIAjaxplorerAI8/8/202516/6/2026
An unauthenticated remote command execution vulnerability exists in AjaXplorer (now known as Pydio Cells) versions prior to 2.6. The flaw resides in the checkInstall.php script within the access.ssh plugin, which fails to properly sanitize user-supplied input to the destServer GET parameter. By injecting shell…
ModificadaBaja (2.1)0.40%—Digitro NGC Explorer11/5/202531/7/2026
A weakness has been identified in Dígitro NGC Explorer up to 3.48.21. This affects an unknown function. Executing a manipulation can lead to session expiration. The attack can be launched remotely. Upgrading to version 3.48.22 mitigates this issue. It is recommended to upgrade the affected component. The action taken…
ModificadaBaja (2.9)0.59%—Digitro NGC Explorer11/5/202531/7/2026
A security flaw has been discovered in Dígitro NGC Explorer up to 3.48.21. The impacted element is an unknown function of the component Password Transmission Handler. Performing a manipulation results in client-side enforcement of server-side security. The attack can be initiated remotely. The complexity of an attack…
ModificadaBaja (2.1)0.29%—Digitro NGC Explorer11/5/202531/7/2026
A vulnerability was identified in Dígitro NGC Explorer up to 3.48.21. The affected element is an unknown function of the component Configuration Page. Such manipulation leads to missing password field masking. It is possible to launch the attack remotely. Upgrading to version 3.48.22 is sufficient to fix this issue.…
AplazadaAlta (7.2)0.53%—Florent Maillefaud WP MaintenanceAI7/5/202517/6/2026
Deserialization of Untrusted Data vulnerability in Florent Maillefaud WP Maintenance wp-maintenance allows Object Injection.This issue affects WP Maintenance: from n/a through <= 6.1.9.7.
AnalizadaCrítica (9.8)0.65%—Seclore18/4/202517/6/2026
An issue in the login page of Seclore v3.27.5.0 allows attackers to bypass authentication via a brute force attack.
AplazadaMedia (5.1)0.65%—Ready File ExplorerAI16/4/202517/6/2026
A cross-site scripting (XSS) vulnerability in Ready_'s File Explorer upload functionality allows injection of arbitrary JavaScript code in filename. Injected content is stored on server and is executed every time a user interacts with the uploaded file.