Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
104 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.0% | — | Soundminer | 27/9/2023 | 17/6/2026 | Soundminer – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | |
| Modificada | Alta (7.5) | 0.76% | — | Canaan Avalon Asic Miner Firmware | 1/9/2022 | 17/6/2026 | An access control issue in Canaan Avalon ASIC Miner 2020.3.30 and below allows unauthenticated attackers to arbitrarily change user passwords via a crafted POST request. | |
| Modificada | Crítica (9.8) | 1.2% | — | Jinglemining Jasminer X4 Server Firmware | 1/9/2022 | 17/6/2026 | The Eclipse TCF debug interface in JasMiner-X4-Server-20220621-090907 and below is open on port 1534. This issue allows unauthenticated attackers to gain root privileges on the affected device and access sensitive data or execute arbitrary commands. | |
| Modificada | Alta (7.5) | 0.64% | — | Goldshell Miner Firmware | 20/7/2022 | 17/6/2026 | The debug interface of Goldshell ASIC Miners v2.2.1 and below was discovered to be exposed publicly on the web interface, allowing attackers to access passwords and other sensitive information in plaintext. | |
| Modificada | Alta (7.5) | 1.6% | — | Goldshell Miner Firmware | 20/7/2022 | 17/6/2026 | Goldshell ASIC Miners v2.2.1 and below was discovered to contain a path traversal vulnerability which allows unauthenticated attackers to retrieve arbitrary files from the device. | |
| Modificada | Crítica (9.8) | 1.2% | — | Goldshell Miner Firmware | 20/7/2022 | 17/6/2026 | Goldshell ASIC Miners v2.1.x was discovered to contain hardcoded credentials which allow attackers to remotely connect via the SSH protocol (port 22). | |
| Modificada | Alta (7.8) | 0.40% | — | Adminer Login Project Adminer Login | 20/6/2022 | 17/6/2026 | A vulnerability has been found in Adminer Login 1.4.4 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improper access controls. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. | |
| Modificada | Crítica (9.8) | 4.5% | 💥 PoC | Antminer Monitor Project Antminer Monitor | 17/6/2022 | 17/6/2026 | A vulnerability in Antminer Monitor 0.50.0 exists because of backdoor or misconfiguration inside a settings file in flask server. Settings file has a predefined secret string, which would be randomly generated, however it is static. | |
| Modificada | Crítica (9.8) | 2.7% | — | Feminer WMS Project Feminer WMS | 16/5/2022 | 17/6/2026 | A remote command execution (RCE) vulnerability was found in FeMiner wms V1.0 in /wms/src/system/datarec.php. The $_POST[r_name] is directly passed into the $mysqlstr and is executed by exec. | |
| Modificada | Alta (7.5) | 14% | 💥 PoC | AdminerDebian Linux | 5/4/2022 | 17/6/2026 | Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an attacker to achieve Arbitrary File Read on the remote server by requesting the Adminer to connect to a remote MySQL database. | |
| Modificada | Crítica (9.8) | 1.8% | — | Science-miner Pdf2xml | 10/11/2021 | 17/6/2026 | pdf2xml v2.0 was discovered to contain a stack buffer overflow in the component getObjectStream. | |
| Modificada | Alta (7.5) | 1.4% | — | Science-miner Pdf2xml | 10/11/2021 | 17/6/2026 | pdf2xml v2.0 was discovered to contain a memory leak in the function TextPage::testLinkedText. | |
| Modificada | Crítica (9.8) | 2.1% | — | Science-miner Pdf2xml | 10/11/2021 | 17/6/2026 | pdf2xml v2.0 was discovered to contain a heap-buffer overflow in the function TextPage::addAttributsNode. | |
| Modificada | Crítica (9.8) | 2.1% | — | Science-miner Pdf2xml | 10/11/2021 | 17/6/2026 | pdf2xml v2.0 was discovered to contain a heap-buffer overflow in the function TextPage::dump. | |
| Modificada | Alta (7.5) | 1.4% | — | Science-miner Pdf2xml | 10/11/2021 | 17/6/2026 | A NULL pointer dereference in the function TextPage::restoreState of pdf2xml v2.0 allows attackers to cause a denial of service (DoS). | |
| Modificada | Media (5.4) | 0.85% | — | Ari-soft ARI Adminer | 15/9/2021 | 17/6/2026 | Cross Site Scripting (XSS) in Ari Adminer v1 allows remote attackers to execute arbitrary code via the 'Title' parameter of the 'Add New Connections' component when the 'save()' function is called. | |
| Modificada | Media (6.1) | 9.6% | 💥 Exploit | Adminer | 19/5/2021 | 17/6/2026 | Adminer is open-source database management software. A cross-site scripting vulnerability in Adminer versions 4.6.1 to 4.8.0 affects users of MySQL, MariaDB, PgSQL and SQLite. XSS is in most cases prevented by strict CSP in all modern browsers. The only exception is when Adminer is using a `pdo_` extension to… | |
| Analizada | Alta (7.2) | 98% | ⚠ Explotación activa💥 Exploit | AdminerDebian Linux | 11/2/2021 | 17/6/2026 | Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all drivers (e.g. `adminer.php`) are affected. This is fixed in version 4.7.9. | |
| Modificada | Media (6.1) | 2.0% | — | Adminer | 9/2/2021 | 17/6/2026 | Adminer through 4.7.8 allows XSS via the history parameter to the default URI. | |
| Modificada | Crítica (9.8) | 2.9% | — | Docker Adminer | 17/12/2020 | 17/6/2026 | The official adminer docker images before 4.7.0-fastcgi contain a blank password for a root user. System using the adminer docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Alta (7.5) | 3.7% | 💥 PoC | Netwrix Account Lockout Examiner | 20/10/2020 | 17/6/2026 | Netwrix Account Lockout Examiner before 5.1 allows remote attackers to capture the Net-NTLMv1/v2 authentication challenge hash of the Domain Administrator (that is configured within the product in its installation state) by generating a single Kerberos Pre-Authentication Failed (ID 4771) event on a Domain Controller. | |
| Modificada | Crítica (9.8) | 1.1% | — | Minerstat Msos | 12/12/2019 | 17/6/2026 | minerstat msOS before 2019-10-23 does not have a unique SSH key for each instance of the product. | |
| Modificada | Baja (3.1) | 1.0% | — | Nicehash Miner | 6/11/2019 | 17/6/2026 | A Username Enumeration via Error Message issue was discovered in NiceHash Miner before 2.0.3.0 because an "EMAIL DOES NOT EXIST" error message occurs whenever a submitted email address is incorrect, but there is a different error message for invalid credentials with a correct email address. | |
| Modificada | Baja (3.7) | 1.0% | — | Nicehash Miner | 6/11/2019 | 17/6/2026 | An issue was discovered in NiceHash Miner before 2.0.3.0. Missing Authorization allows an adversary to can gain access to a miner's information about such as his recent payments, unclaimed Balance, Old Balance (at the time of December 2017 breach) , Projected payout, Mining stats like profitability, Efficiency, Number… | |
| Modificada | Alta (7.5) | 1.7% | — | Nicehash Miner | 6/11/2019 | 17/6/2026 | An issue was discovered in NiceHash Miner before 2.0.3.0. A missing rate limit while adding a wallet via Email address allows remote attackers to submit a large number of email addresses to identify valid ones. By exploiting this vulnerability with CVE-2019-6122 (Username Enumeration) an adversary can enumerate a… |