Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2712▼ 359 respecto a la semana anterior
Críticas / altas1261▼ 231 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
–

3306 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (10)0.74%—Itel Idgateway Firmware18/11/202517/6/2026
The Itel DAB Gateway (IDGat build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT token obtained from one device to authenticate and gain administrative access to any other device running the same firmware, even if the passwords and…
AnalizadaCrítica (9.8)0.24%—Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+518/11/202517/6/2026
A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST APIs and SOAP services in multiple WSO2 products. Due to improper validation of client certificate–based authentication in certain default configurations, the affected components may permit…
AnalizadaAlta (8.8)0.23%—Wso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server+518/11/202517/6/2026
A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method for state-changing operations within admin services, specifically in the event processor of the Carbon console. Although the SameSite=Lax cookie attribute is used as a mitigation, it is ineffective…
AplazadaMedia (5.3)0.27%—Cryptocurrency Payment GatewayAI18/11/202517/6/2026
The Cryptocurrency Payment Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'handle_optin_optout' function in all versions up to, and including, 2.0.25. This makes it possible for unauthenticated attackers to opt in and out of…
AplazadaCrítica (9.2)0.63%—General Industrial Controls Lynx+ GatewayAI15/11/202517/6/2026
General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could allow an attacker to remotely reset the device.
AplazadaAlta (8.7)0.31%—General Industrial Controls Lynx Plus GatewayAI14/11/20257/10/2026
General Industrial Controls Lynx+ Gateway es vulnerable a una vulnerabilidad de transmisión en texto claro que podría permitir a un atacante observar el tráfico de red para obtener información sensible, incluyendo credenciales en texto claro.
AplazadaAlta (8.7)0.37%—General Industrial Controls Lynx+ GatewayAI14/11/20257/10/2026
El Gateway Lynx+ de General Industrial Controls carece de autenticación crítica en el servidor web integrado, lo que podría permitir a un atacante enviar solicitudes GET para obtener información sensible del dispositivo.
AplazadaAlta (8.8)0.28%—General Industrial Controls Lynx Plus GatewayAI14/11/20257/10/2026
El Gateway Lynx+ de General Industrial Controls es vulnerable a una vulnerabilidad de requisito de contraseña débil, lo que puede permitir a un atacante ejecutar un ataque de fuerza bruta, resultando en acceso no autorizado e inicio de sesión.
AplazadaAlta (8.7)2.1%💥 ExploitOzeki SMS GatewayAI12/11/202517/6/2026
Ozeki SMS Gateway versions up to and including 10.3.208 contain a path traversal vulnerability. Successful exploitation allows an unauthenticated attacker to use URL-encoded traversal sequences to read arbitrary files from the underlying filesystem with the privileges of the gateway service, leading to disclosure of…
AplazadaAlta (7.8)0.43%—Nvidia Megatron-lmAI11/11/202517/6/2026
NVIDIA Megatron-LM for all platforms contains a vulnerability in a script, where malicious data created by an attacker may cause a code injection issue. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, data tampering.
AplazadaMedia (5.9)25%💥 ExploitCitrix Netscaler ADCAICitrix Netscaler GatewayAI11/11/202517/6/2026
Cross-Site Scripting (XSS) in NetScaler ADC and NetScaler Gateway when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
AplazadaCrítica (9.2)0.62%—Ruijie Gateway EGAIRuijie NBRAI7/11/202517/6/2026
Various Ruijie Gateway EG and NBR models firmware versions 11.1(6)B9P1 < 11.9(4)B12P1 contain a code execution vulnerability in the EWEB management system that can be abused via front-end functionality. Attackers can exploit front-end code when features such as guest authentication, local server authentication, or…
AnalizadaMedia (5.4)0.18%—IBM Sterling B2B IntegratorIBM Sterling File Gateway7/11/202517/6/2026
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7_1, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web…
AplazadaMedia (5.3)0.16%—KgatewayAI7/11/202517/6/2026
kgateway es un Gateway de API e IA nativo de la nube. Las versiones 2.0.4 e inferiores y de la 2.1.0-agw-cel-rbac a la 2.1.0-rc.2 carecen de autenticación, lo que permite a cualquier cliente con acceso de red sin restricciones al puerto xDS recuperar datos de configuración potencialmente sensibles, incluyendo datos de…
AplazadaAlta (8.8)17%—Netgate PfsenseAISuricataAI6/11/20257/10/2026
Vulnerabilidad de salto de ruta y ejecución remota de código de Netgate pfSense CE Suricata. Esta vulnerabilidad permite a atacantes remotos crear archivos arbitrarios en instalaciones afectadas de Netgate pfSense. Se requiere autenticación para explotar esta vulnerabilidad. La falla específica reside en el paquete…
AplazadaCrítica (9.3)0.36%—Hiecor Hcv4-payment-gatewayAI6/11/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hiecor HieCOR Payment Gateway Plugin hcv4-payment-gateway allows SQL Injection.This issue affects HieCOR Payment Gateway Plugin: from n/a through <= 1.5.11.
AnalizadaMedia (6.1)0.19%—Wso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server+55/11/202517/6/2026
A reflected cross-site scripting (XSS) vulnerability exists in the management console of multiple WSO2 products due to improper output encoding. By tampering with specific parameters, a malicious actor can inject arbitrary JavaScript into the response, leading to reflected XSS. Successful exploitation could result in…
AnalizadaAlta (7.2)0.47%—Wso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Micro Integrator+25/11/202517/6/2026
An arbitrary code execution vulnerability exists in multiple WSO2 products due to insufficient restrictions in the GraalJS and NashornJS Script Mediator engines. Authenticated users with elevated privileges can execute arbitrary code within the integration runtime environment. By default, access to these scripting…
AnalizadaAlta (7.2)0.60%—Wso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server+55/11/202517/6/2026
An arbitrary file upload vulnerability exists in multiple WSO2 products due to insufficient validation of uploaded content and destination in SOAP admin services. A malicious actor with administrative privileges can upload a specially crafted file to a user-controlled location within the deployment. Successful…
AnalizadaCrítica (9.1)0.46%—Wso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server+45/11/202517/6/2026
An XML External Entity (XXE) vulnerability exists in multiple WSO2 products due to improper configuration of the XML parser. The application parses user-supplied XML without applying sufficient restrictions, allowing resolution of external entities. A successful attack could enable a remote, unauthenticated attacker…
AnalizadaCrítica (9.8)1.9%💥 PoCDynatrace Activegate Ping Extension5/11/202517/6/2026
OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address.
AnalizadaAlta (7.2)0.91%—Wso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server+45/11/202517/6/2026
An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper input validation in the CarbonAppUploader admin service endpoint. An authenticated attacker with appropriate privileges can upload a malicious file to a user-controlled location on the server, potentially leading to remote code…
AplazadaMedia (4.3)0.13%—WPM Navigation Links FOR Sections AND HeadingsAI4/11/202517/6/2026
The Posts Navigation Links for Sections and Headings – Free by WP Masters plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the 'wpm_navigation_links_settings' page. This makes it possible for…
AplazadaAlta (7.5)0.30%—Crypto Payment Gateway With PayeerAI4/11/202517/6/2026
The Crypto Payment Gateway with Payeer for WooCommerce plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 1.0.3. This is due to the plugin not properly verifying a payments status through server-side validation though the /wc-api/bp-payeer-gateway-callback endpoint. This makes…
AnalizadaMedia (4.3)0.30%—Dell Secure Connect Gateway30/10/202517/6/2026
Dell Secure Connect Gateway (SCG) 5.0 Application and Appliance version(s) 5.26.00.00 - 5.30.00.00, contain a Relative Path Traversal vulnerability in the SCG exposed for an internal collection download REST API (if this REST API is enabled by Admin user from UI). A low privileged attacker with remote access could…