Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
96 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.93% | — | Interspire Email Marketer | 11/10/2022 | 17/6/2026 | Interspire Email Marketer through 6.5.0 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can cause a .php file to be accessible under a /admin/temp/surveys/ URI. NOTE: this issue exists because of an incomplete fix for CVE-2018-19550. | |
| Modificada | Alta (7.8) | 0.38% | — | Acer Altos T110 F3 FirmwareAcer Ap130 F2 FirmwareAcer Aspire 1600x FirmwareAcer Aspire 1602m Firmware+30 | 23/9/2022 | 9/7/2026 | There is a stack buffer overflow vulnerability, which could lead to arbitrary code execution in UEFI DXE driver on some Acer products. An attack could exploit this vulnerability to escalate privilege from ring 3 to ring 0, and hijack control flow during UEFI DXE execution. This affects Altos T110 F3 firmware version… | |
| Modificada | Alta (8.8) | 1.6% | — | Aspiresoftware Open Aviation Strategic Engineering System | 16/9/2022 | 17/6/2026 | OASES (aka Open Aviation Strategic Engineering System) 8.8.0.2 allows attackers to execute arbitrary code via the Open Print Folder menu. | |
| Modificada | Alta (7.5) | 0.71% | — | DJI Mavic 3 FirmwareDJI RC PRO FirmwareDJI AIR 2S FirmwareDJI AIR 2 Firmware+7 | 29/4/2022 | 17/6/2026 | DJI drone devices sold in 2017 through 2022 broadcast unencrypted information about the drone operator's physical location via the AeroScope protocol. | |
| Modificada | Alta (7.5) | 4.9% | 💥 Exploit | Bluespire Aurelia-path | 27/9/2021 | 17/6/2026 | aurelia-path is part of the Aurelia platform and contains utilities for path manipulation. There is a prototype pollution vulnerability in aurelia-path before version 1.1.7. The vulnerability exposes Aurelia application that uses `aurelia-path` package to parse a string. The majority of this will be Aurelia… | |
| Modificada | Media (6.1) | 1.4% | — | Bluespire Aurelia Framework | 13/5/2021 | 17/6/2026 | The HTMLSanitizer class in html-sanitizer.ts in all released versions of the Aurelia framework 1.x repository is vulnerable to XSS. The sanitizer only attempts to filter SCRIPT elements, which makes it feasible for remote attackers to conduct XSS attacks via (for example) JavaScript code in an attribute of various… | |
| Modificada | Baja (3.1) | 0.92% | — | Necplatforms Univerge Aspire WX FirmwareNecplatforms Univerge Aspire UX FirmwareNecplatforms Univerge Sv9100 FirmwareNecplatforms Sl2100 Firmware | 26/3/2021 | 17/6/2026 | UNIVERGE Aspire series PBX (UNIVERGE Aspire WX from 1.00 to 3.51, UNIVERGE Aspire UX from 1.00 to 9.70, UNIVERGE SV9100 from 1.00 to 10.70, and SL2100 from 1.00 to 3.00) allows a remote authenticated attacker to cause system down and a denial of service (DoS) condition by sending a specially crafted command. | |
| Modificada | Crítica (9.8) | 3.4% | — | Inspireui Mstore API | 18/3/2021 | 17/6/2026 | A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign In With Apple allowing unauthenticated users to recover an authentication cookie with only an email address. | |
| Modificada | Media (6.8) | 0.72% | — | Cncf Spire | 5/3/2021 | 17/6/2026 | In SPIRE before versions 0.8.5, 0.9.4, 0.10.2, 0.11.3 and 0.12.1, the "aws_iid" Node Attestor improperly normalizes the path provided through the agent ID templating feature, which may allow the issuance of an arbitrary SPIFFE ID within the same trust domain, if the attacker controls the value of an EC2 tag prior to… | |
| Modificada | Alta (8.1) | 0.56% | — | Cncf Spire | 5/3/2021 | 17/6/2026 | In SPIRE 0.8.1 through 0.8.4 and before versions 0.9.4, 0.10.2, 0.11.3 and 0.12.1, specially crafted requests to the FetchX509SVID RPC of SPIRE Server’s Legacy Node API can result in the possible issuance of an X.509 certificate with a URI SAN for a SPIFFE ID that the agent is not authorized to distribute. Proper… | |
| Modificada | Media (6.7) | 1.6% | — | Spirent AvalancheSpirent Testcenter | 13/8/2020 | 17/6/2026 | An issue was discovered on Spirent TestCenter and Avalanche appliance admin interface firmware. An attacker, who already has access to an SSH restricted shell, can achieve root access via shell metacharacters. The attacker can then, for example, read sensitive files such as appliance admin configuration source code.… | |
| Modificada | Media (5.3) | 1.3% | — | GE Aestiva 7100 FirmwareGE Aestiva 7900 FirmwareGE Aespire 7100 FirmwareGE Aespire 7900 Firmware | 10/7/2019 | 17/6/2026 | In GE Aestiva and Aespire versions 7100 and 7900, a vulnerability exists where serial devices are connected via an added unsecured terminal server to a TCP/IP network configuration, which could allow an attacker to remotely modify device configuration and silence alarms. | |
| Modificada | Media (6.5) | 0.85% | — | Interspire Email Marketer | 28/11/2018 | 17/6/2026 | admin/functions/remote.php in Interspire Email Marketer through 6.1.6 has Server Side Request Forgery (SSRF) via a what=importurl&url= request with an http or https URL. This also allows reading local files with a file: URL. | |
| Modificada | Alta (8.8) | 0.98% | — | Interspire Email Marketer | 26/11/2018 | 17/6/2026 | Interspire Email Marketer through 6.1.6 has SQL Injection via an updateblock sortorder request to Dynamiccontenttags.php | |
| Modificada | Alta (8.8) | 0.98% | — | Interspire Email Marketer | 26/11/2018 | 17/6/2026 | Interspire Email Marketer through 6.1.6 has SQL Injection via a deleteblock blockid[] request to Dynamiccontenttags.php. | |
| Modificada | Alta (8.8) | 0.98% | — | Interspire Email Marketer | 26/11/2018 | 17/6/2026 | Interspire Email Marketer through 6.1.6 has SQL Injection via a checkduplicatetags tagname request to Dynamiccontenttags.php. | |
| Modificada | Alta (8.8) | 6.0% | 💥 Exploit | Interspire Email Marketer | 26/11/2018 | 17/6/2026 | Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can cause a .php file to be accessible under a admin/temp/surveys/ URI. | |
| Modificada | Alta (8.8) | 0.98% | — | Interspire Email Marketer | 26/11/2018 | 17/6/2026 | Interspire Email Marketer through 6.1.6 has SQL Injection via a tagids Delete action to Dynamiccontenttags.php. | |
| Modificada | Crítica (9.8) | 37% | 💥 Exploit | Interspire Email Marketer | 18/10/2017 | 17/6/2026 | The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior to 6.1.6 allows remote attackers to bypass authentication and obtain administrative access by using the IEM_CookieLogin cookie with a specially crafted value. | |
| Modificada | Alta (7.5) | 1.9% | — | Inspire Ircd InspircdDebian Linux | 13/4/2017 | 16/6/2026 | InspIRCd before 2.0.7 allows remote attackers to cause a denial of service (infinite loop). | |
| Modificada | Media (5.4) | 0.27% | — | Magzter Inspire Weddings | 19/10/2014 | 17/6/2026 | The Inspire Weddings (aka com.magzter.inspireweddings) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 1.1% | — | Infor EclientInfor Enspire Distribution Management Solution | 1/11/2011 | 16/6/2026 | SQL injection vulnerability in eClient 7.3.2.3 in Enspire Distribution Management Solution 7.3.2.7 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Interspire Activekb | 22/7/2010 | 16/6/2026 | Directory traversal vulnerability in loadpanel.php in Interspire ActiveKB allows remote attackers to read arbitrary files and possibly have unspecified other impact via directory traversal sequences in the Panel parameter. | |
| Modificada | Media (5) | 2.7% | 💥 Exploit | Interspire Knowledge Manager | 3/12/2009 | 16/6/2026 | Directory traversal vulnerability in dialog/file_manager.php in Interspire Knowledge Manager 5 allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (5) | 2.3% | 💥 Exploit | Thenetguys Aspired2protect | 2/3/2009 | 16/6/2026 | The Net Guys ASPired2Protect stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request to ASPired2Protect.mdb. |