Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

104 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.0%—Soundminer27/9/202317/6/2026
Soundminer – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
ModificadaAlta (7.5)0.76%—Canaan Avalon Asic Miner Firmware1/9/202217/6/2026
An access control issue in Canaan Avalon ASIC Miner 2020.3.30 and below allows unauthenticated attackers to arbitrarily change user passwords via a crafted POST request.
ModificadaCrítica (9.8)1.2%—Jinglemining Jasminer X4 Server Firmware1/9/202217/6/2026
The Eclipse TCF debug interface in JasMiner-X4-Server-20220621-090907 and below is open on port 1534. This issue allows unauthenticated attackers to gain root privileges on the affected device and access sensitive data or execute arbitrary commands.
ModificadaAlta (7.5)0.64%—Goldshell Miner Firmware20/7/202217/6/2026
The debug interface of Goldshell ASIC Miners v2.2.1 and below was discovered to be exposed publicly on the web interface, allowing attackers to access passwords and other sensitive information in plaintext.
ModificadaAlta (7.5)1.6%—Goldshell Miner Firmware20/7/202217/6/2026
Goldshell ASIC Miners v2.2.1 and below was discovered to contain a path traversal vulnerability which allows unauthenticated attackers to retrieve arbitrary files from the device.
ModificadaCrítica (9.8)1.2%—Goldshell Miner Firmware20/7/202217/6/2026
Goldshell ASIC Miners v2.1.x was discovered to contain hardcoded credentials which allow attackers to remotely connect via the SSH protocol (port 22).
ModificadaAlta (7.8)0.40%—Adminer Login Project Adminer Login20/6/202217/6/2026
A vulnerability has been found in Adminer Login 1.4.4 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improper access controls. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
ModificadaCrítica (9.8)4.5%💥 PoCAntminer Monitor Project Antminer Monitor17/6/202217/6/2026
A vulnerability in Antminer Monitor 0.50.0 exists because of backdoor or misconfiguration inside a settings file in flask server. Settings file has a predefined secret string, which would be randomly generated, however it is static.
ModificadaCrítica (9.8)2.7%—Feminer WMS Project Feminer WMS16/5/202217/6/2026
A remote command execution (RCE) vulnerability was found in FeMiner wms V1.0 in /wms/src/system/datarec.php. The $_POST[r_name] is directly passed into the $mysqlstr and is executed by exec.
ModificadaAlta (7.5)14%💥 PoCAdminerDebian Linux5/4/202217/6/2026
Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an attacker to achieve Arbitrary File Read on the remote server by requesting the Adminer to connect to a remote MySQL database.
ModificadaCrítica (9.8)1.8%—Science-miner Pdf2xml10/11/202117/6/2026
pdf2xml v2.0 was discovered to contain a stack buffer overflow in the component getObjectStream.
ModificadaAlta (7.5)1.4%—Science-miner Pdf2xml10/11/202117/6/2026
pdf2xml v2.0 was discovered to contain a memory leak in the function TextPage::testLinkedText.
ModificadaCrítica (9.8)2.1%—Science-miner Pdf2xml10/11/202117/6/2026
pdf2xml v2.0 was discovered to contain a heap-buffer overflow in the function TextPage::addAttributsNode.
ModificadaCrítica (9.8)2.1%—Science-miner Pdf2xml10/11/202117/6/2026
pdf2xml v2.0 was discovered to contain a heap-buffer overflow in the function TextPage::dump.
ModificadaAlta (7.5)1.4%—Science-miner Pdf2xml10/11/202117/6/2026
A NULL pointer dereference in the function TextPage::restoreState of pdf2xml v2.0 allows attackers to cause a denial of service (DoS).
ModificadaMedia (5.4)0.85%—Ari-soft ARI Adminer15/9/202117/6/2026
Cross Site Scripting (XSS) in Ari Adminer v1 allows remote attackers to execute arbitrary code via the 'Title' parameter of the 'Add New Connections' component when the 'save()' function is called.
ModificadaMedia (6.1)9.6%💥 ExploitAdminer19/5/202117/6/2026
Adminer is open-source database management software. A cross-site scripting vulnerability in Adminer versions 4.6.1 to 4.8.0 affects users of MySQL, MariaDB, PgSQL and SQLite. XSS is in most cases prevented by strict CSP in all modern browsers. The only exception is when Adminer is using a `pdo_` extension to…
AnalizadaAlta (7.2)98%⚠ Explotación activa💥 ExploitAdminerDebian Linux11/2/202117/6/2026
Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all drivers (e.g. `adminer.php`) are affected. This is fixed in version 4.7.9.
ModificadaMedia (6.1)2.0%—Adminer9/2/202117/6/2026
Adminer through 4.7.8 allows XSS via the history parameter to the default URI.
ModificadaCrítica (9.8)2.9%—Docker Adminer17/12/202017/6/2026
The official adminer docker images before 4.7.0-fastcgi contain a blank password for a root user. System using the adminer docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
ModificadaAlta (7.5)3.7%💥 PoCNetwrix Account Lockout Examiner20/10/202017/6/2026
Netwrix Account Lockout Examiner before 5.1 allows remote attackers to capture the Net-NTLMv1/v2 authentication challenge hash of the Domain Administrator (that is configured within the product in its installation state) by generating a single Kerberos Pre-Authentication Failed (ID 4771) event on a Domain Controller.
ModificadaCrítica (9.8)1.1%—Minerstat Msos12/12/201917/6/2026
minerstat msOS before 2019-10-23 does not have a unique SSH key for each instance of the product.
ModificadaBaja (3.1)1.0%—Nicehash Miner6/11/201917/6/2026
A Username Enumeration via Error Message issue was discovered in NiceHash Miner before 2.0.3.0 because an "EMAIL DOES NOT EXIST" error message occurs whenever a submitted email address is incorrect, but there is a different error message for invalid credentials with a correct email address.
ModificadaBaja (3.7)1.0%—Nicehash Miner6/11/201917/6/2026
An issue was discovered in NiceHash Miner before 2.0.3.0. Missing Authorization allows an adversary to can gain access to a miner's information about such as his recent payments, unclaimed Balance, Old Balance (at the time of December 2017 breach) , Projected payout, Mining stats like profitability, Efficiency, Number…
ModificadaAlta (7.5)1.7%—Nicehash Miner6/11/201917/6/2026
An issue was discovered in NiceHash Miner before 2.0.3.0. A missing rate limit while adding a wallet via Email address allows remote attackers to submit a large number of email addresses to identify valid ones. By exploiting this vulnerability with CVE-2019-6122 (Username Enumeration) an adversary can enumerate a…
Orbitaley — Vulnerabilidades