Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
–

525 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.52%—Bluewavelabs CheckmateAI10/5/202517/6/2026
In BlueWave Checkmate through 2.0.2 before b387eba, a profile edit request can include a role parameter.
AplazadaAlta (8.1)0.50%—Bluewavelabs CheckmateAI4/5/202517/6/2026
In BlueWave Checkmate through 2.0.2 before d4a6072, an invite request can be modified to specify a privileged role.
AnalizadaCrítica (9.8)1.00%—Tcpwave DDI22/4/202517/6/2026
TCPWave DDI 11.34P1C2 allows Remote Code Execution via Unrestricted File Upload (combined with Path Traversal).
AplazadaAlta (8.1)0.14%—Filewave Windows ClientAI21/4/202517/6/2026
The FileWave Windows client before 16.0.0, in some non-default configurations, allows an unprivileged local user to escalate privileges to SYSTEM.
AplazadaAlta (7.1)0.15%—Review Wave Google Places ReviewsAI17/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in MessageMetric Review Wave – Google Places Reviews review-wave-google-places-reviews allows Stored XSS.This issue affects Review Wave – Google Places Reviews: from n/a through <= 1.4.7.
AnalizadaAlta (7.9)0.48%—Trustwave Modsecurity25/2/202517/6/2026
Libmodsecurity is one component of the ModSecurity v3 project. The library codebase serves as an interface to ModSecurity Connectors taking in web traffic and applying traditional ModSecurity processing. A bug that exists only in Libmodsecurity3 version 3.0.13 means that, in 3.0.13, Libmodsecurity3 can't decode…
AnalizadaAlta (7.5)0.98%—Yawave25/2/202517/6/2026
The Yawave plugin for WordPress is vulnerable to SQL Injection via the 'lbid' parameter in all versions up to, and including, 2.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append…
AplazadaAlta (7.1)0.28%—Inwavethemes InfundingAI22/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in inwavethemes InFunding infunding allows Reflected XSS.This issue affects InFunding: from n/a through <= 1.0.
AplazadaMedia (6.4)0.35%—Easy Waveform PlayerAI18/12/202417/6/2026
The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easywaveformplayer' shortcode in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AplazadaAlta (7.2)0.79%—Airwave CLIAI10/12/202417/6/2026
An authenticated Remote Code Execution (RCE) vulnerability exists in the AirWave CLI. Successful exploitation of this vulnerability could allow a remote authenticated threat actor to run arbitrary commands as a privileged user on the underlying host.
AnalizadaMedia (4.6)0.22%—Silabs Z-wave Software Development KIT10/12/202417/6/2026
Silicon Labs Z-Wave Series 500 v6.84.0 was discovered to contain insecure permissions.
AnalizadaAlta (8.8)0.30%—Silabs Z-wave Software Development KIT10/12/202417/6/2026
An issue in Silicon Labs Z-Wave Series 500 v6.84.0 allows attackers to execute arbitrary code.
AnalizadaMedia (6.2)0.22%—Silabs Z-wave Software Development KIT10/12/202417/6/2026
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to arbitrarily change the device type in the controller's memory, leading to a Denial of Service (DoS).
AnalizadaMedia (6.5)0.36%—Silabs Z-wave Software Development KIT10/12/202417/6/2026
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to change the wakeup interval of end devices in controller memory, disrupting the device's communications with the controller.
AnalizadaMedia (6.5)0.40%—Silabs Z-wave Software Development KIT10/12/202417/6/2026
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause disrupt communications between the controller and the device itself via repeatedly sending crafted packets to the controller.
AnalizadaMedia (6.5)0.40%—Silabs Z-wave Software Development KIT10/12/202417/6/2026
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause a Denial of Service (DoS) via repeatedly sending crafted packets to the controller.
AnalizadaAlta (8.8)0.46%—Silabs Z-wave Software Development KIT10/12/202417/6/2026
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to create a fake node via supplying crafted packets.
AnalizadaCrítica (9.3)0.53%—63moons Aero63moons Wave 2.04/11/202417/6/2026
This vulnerability exists in Aero due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by intercepting and manipulating the responses exchanged during the second factor authentication process. Successful exploitation of…
AnalizadaAlta (7.1)0.35%—63moons Aero63moons Wave 2.04/11/202417/6/2026
This vulnerability exists in the Wave 2.0 due to improper exception handling for invalid inputs at certain API endpoint. An authenticated remote attacker could exploit this vulnerability by providing invalid inputs for “userId” parameter in the API request leading to generation of error message containing sensitive…
ModificadaAlta (7.1)0.34%—63moons Aero63moons Wave 2.04/11/202417/6/2026
This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating API input parameters to gain unauthorized access and perform malicious activities on other user accounts.
AnalizadaCrítica (9.3)0.57%—63moons Aero63moons Wave 2.04/11/202417/6/2026
This vulnerability exists in the Wave 2.0 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack against legitimate user OTP, MPIN or password, which could lead to gain unauthorized access…
AnalizadaAlta (7.1)0.47%—63moons Aero63moons Wave 2.04/11/202417/6/2026
This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoint which could lead to the OTP bombing/flooding on the targeted system.
ModificadaAlta (7.1)0.21%—63moons Aero63moons Wave 2.04/11/202417/6/2026
This vulnerability exists in the Wave 2.0 due to insufficient encryption of sensitive data received at the API response. An authenticated remote attacker could exploit this vulnerability by manipulating API input parameters through API request URL/payload leading to unauthorized access to sensitive information…
AnalizadaCrítica (9.8)0.66%—Wavelog14/10/202417/6/2026
Wavelog 1.8.5 allows Oqrs_model.php get_worked_modes station_id SQL injectioin.
ModificadaCrítica (9.8)0.55%—Wavelog14/10/202417/6/2026
Wavelog 1.8.5 allows Activated_gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.