Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1414▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
603 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.50% | — | Freeswitch | 9/6/2026 | 23/7/2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, mod_verto's JSON-RPC handler bound the connection to the client-supplied sessid on the first frame, before the… | |
| Analizada | Alta (7.5) | 0.58% | — | Freeswitch | 9/6/2026 | 23/7/2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, mod_verto's WebSocket frame loop intercepts a #-prefixed speed-test protocol (#SPU / #SPB / #SPE) before any… | |
| Analizada | Crítica (9.8) | 0.60% | — | Freeswitch | 9/6/2026 | 23/7/2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, the mod_verto HTTP request handler allocates a fixed 2 MiB buffer for a POST application/x-www-form-urlencoded… | |
| Analizada | Crítica (9.1) | 0.48% | — | Freeswitch | 9/6/2026 | 23/7/2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, esl_recv_event() parses Content-Length with atol() and passes the result straight to malloc(len + 1) with no… | |
| Analizada | Alta (7.5) | 0.49% | — | Freeswitch | 9/6/2026 | 23/7/2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.0, a STUN packet whose declared attribute length is shorter than the structure the parser casts to causes the… | |
| Analizada | Media (5.3) | 0.37% | — | Freeswitch | 9/6/2026 | 23/7/2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.0, FreeSWITCH includes a vulnerable function, PREFIX(prologTok)(), in… | |
| Analizada | Alta (7.5) | 0.49% | — | Freeswitch | 9/6/2026 | 20/7/2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.0, FreeSWITCH's bundled XML parser expands nested <!ENTITY> declarations without a depth or count bound, so a… | |
| Pendiente de análisis | Media (6.5) | 0.41% | — | OpenvswitchAI | 4/6/2026 | 22/7/2026 | A missing upper-bound check in the udpif_set_threads() function of Open vSwitch v3.6.90 allows an attacker with OVSDB write access to request an excessive number of handler or revalidation threads. This can cause a denial of service (DoS) via resource exhaustion. | |
| Aplazada | Media (4.3) | 0.37% | — | FOX Currency Switcher ProfessionalAI | 28/5/2026 | 17/6/2026 | The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 1.4.6. This is due to the `get_value()` function in `classes/fixed/fixed_user_role.php` trusting the attacker-controlled… | |
| Aplazada | Alta (7.1) | 0.25% | — | Realmag777 Wpcs Currency-switcherAI | 27/5/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 WPCS currency-switcher allows DOM-Based XSS.This issue affects WPCS: from n/a through <= 1.3.1. | |
| Pendiente de análisis | Media (6.8) | 0.47% | — | Cisco Nexus 3000 Series SwitchesAICisco Nexus 9000 Series SwitchesAI | 20/5/2026 | 23/7/2026 | A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to trigger BGP peer flaps, resulting in a denial of service (DoS) condition. This… | |
| Aplazada | Alta (8.8) | 0.52% | — | Account SwitcherAI | 20/5/2026 | 24/7/2026 | The Account Switcher plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.2. This is due to the `rememberLogin` REST API endpoint using a loose comparison (`!=` instead of `!==`) for secret validation at `app/RestAPI.php:111`, combined with no validation that the secret… | |
| Aplazada | Alta (8.1) | 0.50% | — | FOX Currency Switcher ProfessionalAI | 15/5/2026 | 17/6/2026 | The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'admin_head' function in all versions up to, and including, 1.4.5. This makes it possible for authenticated attackers, with Contributor-level access and above,… | |
| Aplazada | Baja (3.2) | 0.11% | — | Sangoma SwitchvoxAI | 12/5/2026 | 17/6/2026 | Sangoma Switchvox before 8.4 places cleartext SIP authentication credentials in a backup file. | |
| Pendiente de análisis | Alta (7.2) | 1.1% | — | Hikvision SwitchAI | 9/5/2026 | 24/7/2026 | Some Hikvision switch products (discontinued since December 2023) are vulnerable to authenticated remote command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary… | |
| Pendiente de análisis | Alta (7.7) | 0.39% | — | Cisco 350 Series Managed SwitchesAICisco 350x Series Stackable Managed SwitchesAI | 6/5/2026 | 17/6/2026 | This vulnerability is due to improper error handling when parsing response data for a specific SNMP request. An attacker could exploit this vulnerability by sending a specific SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a… | |
| Pendiente de análisis | Media (5.9) | 0.64% | — | Openvswitch Open VswitchAI | 5/5/2026 | 1/9/2026 | A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service… | |
| Pendiente de análisis | Media (6.5) | 0.66% | — | Openvswitch OVNAI | 24/4/2026 | 17/6/2026 | When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a… | |
| Aplazada | Media (6.4) | 0.41% | — | Switch CTA BOXAI | 22/4/2026 | 17/6/2026 | The Switch CTA Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wppw_cta_box' shortcode in all versions up to, and including, 1.1. This is due to insufficient input sanitization and output escaping on user-supplied post meta values including 'cta_box_button_link', 'cta_box_button_id',… | |
| Modificada | Media (6.5) | 0.50% | — | Fortinet FortiosFortinet FortipamFortinet FortiproxyFortinet Fortiswitchmanager | 14/4/2026 | 17/6/2026 | An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.7.0, FortiPAM 1.6 all versions, FortiPAM 1.5 all… | |
| Aplazada | Baja (2.1) | 0.20% | — | Farion1231 Cc-switchAI | 13/4/2026 | 17/6/2026 | A security flaw has been discovered in farion1231 cc-switch up to 3.12.3. Affected by this issue is some unknown functionality of the file src-tauri/src/proxy/server.rs of the component ProxyServer. The manipulation results in permissive cross-domain policy with untrusted domains. The attack can be executed remotely.… | |
| Aplazada | Media (5.3) | 0.31% | — | Realmag777 FOX Woocommerce Currency SwitcherAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in RealMag777 FOX woocommerce-currency-switcher allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FOX: from n/a through <= 1.4.5. | |
| Aplazada | Alta (7.6) | 0.38% | — | Realmag777 FOX Woocommerce Currency SwitcherAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 FOX woocommerce-currency-switcher allows Blind SQL Injection.This issue affects FOX: from n/a through <= 1.4.5. | |
| Pendiente de análisis | Media (4.6) | 0.24% | — | Aziot Node Smart Switch 16ampAI | 6/4/2026 | 5/7/2026 | An information disclosure vulnerability exists in AZIOT 1 Node Smart Switch (16amp)- WiFi/Bluetooth Enabled Software Version: 1.1.9 due to improper access control on the UART debug interface. An attacker with physical access can connect to the UART interface and obtain sensitive information from the serial console… | |
| Analizada | Crítica (9.2) | 0.51% | — | Belden Hios Switch | 2/4/2026 | 24/7/2026 | HiOS Switch Platform versions 09.1.00 through 09.4.04 and 10.0.00 through 10.3.00 contain a denial-of-service vulnerability in the web interface that allows remote attackers to reboot the affected device by sending a malicious HTTP GET request to a specific endpoint. Attackers can trigger an uncontrolled reboot… |