Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
–

252 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.37%—Northernbeacheswebsites WP Custom Admin InterfaceAI9/12/202417/6/2026
Missing Authorization vulnerability in Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through <= 7.31.
AplazadaCrítica (9.1)0.49%—Halyra Collect AND Deliver Interface FOR WoocommerceAI16/11/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Halyra CDI collect-and-deliver-interface-for-woocommerce.This issue affects CDI: from n/a through <= 5.5.3.
AplazadaMedia (6.5)0.35%—Openairinterface Cn5g AMFAI15/11/202417/6/2026
An uninitialized pointer dereference in OpenAirInterface CN5G AMF up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted InitialContextSetupResponse message sent to the AMF.
AplazadaAlta (7.5)0.50%—Openairinterface MagmaAIOpenairinterface OAI EPC FederationAI15/11/202417/6/2026
Reachable assertions in the NGAP_FIND_PROTOCOLIE_BY_ID function of OpenAirInterface Magma v1.8.0 and OAI EPC Federation v1.2.0 allow attackers to cause a Denial of Service (DoS) via a crafted NGAP packet.
AplazadaMedia (5.3)1.5%—Openairinterface Cn5g AMFAI15/11/202417/6/2026
Stack-based memcpy buffer overflow in the ngap_handle_pdu_session_resource_setup_response routine in OpenAirInterface CN5G AMF <= 2.0.0 allows a remote attacker with access to the N2 interface to carry out denial of service against the AMF and potentially execute code by sending a PDU Session Resource Setup Response…
AplazadaMedia (6.5)0.43%—Openairinterface Cn5g AMFAI15/11/202417/6/2026
An uninitialized pointer dereference in the NasPdu::NasPdu component of OpenAirInterface CN5G AMF up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted InitialUEMessage message sent to the AMF.
ModificadaCrítica (9.8)0.87%—Rittal IOT Interface FirmwareRittal CMC III Processing Units Firmware15/10/202417/6/2026
The devices are vulnerable to session hijacking due to insufficient entropy in its session ID generation algorithm. The session IDs are predictable, with only 32,768 possible values per user, which allows attackers to pre-generate valid session IDs, leading to unauthorized access to user sessions. This is not only due…
AplazadaCrítica (9.8)0.64%—Rittal IOT InterfaceAIRittal CMC III Processing UnitAI15/10/202417/6/2026
The firmware upgrade function in the admin web interface of the Rittal IoT Interface & CMC III Processing Unit devices checks if the patch files are signed before executing the containing run.sh script. The signing process is kind of an HMAC with a long string as key which is hard-coded in the firmware and is freely…
AnalizadaCrítica (9.1)1.6%—Microsoft Azure Command-line InterfaceMicrosoft Azure Service Connector8/10/202417/6/2026
Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability
AplazadaAlta (7.5)0.93%—Sopas ET InterfaceAI12/9/202424/7/2026
A vulnerability allows a remote unauthenticated attacker to modify the prod uct’s IP address over the Sopas ET interface. This can lead to a Denial of Service attack.
ModificadaCrítica (10)1.0%—Openhab WEB Interface12/8/20245/8/2026
openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. In versions 3.4.0.M4 through 4.2.0,, the proxy endpoint of openHAB's CometVisu add-on can be accessed without authentication. This proxy-feature can be exploited as Server-Side Request Forgery (SSRF)…
AplazadaMedia (5.3)0.37%—Admin Trim InterfaceAI27/7/202417/6/2026
The Admin Trim Interface plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.5.1. This is due to the plugin utilizing bootstrap and leaving test files with display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web…
ModificadaMedia (5.4)0.26%—Themehorse Interface21/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Theme Horse Interface allows Stored XSS.This issue affects Interface: from n/a through 3.1.0.
AplazadaMedia (4.8)0.14%—Motorola Interface Test ToolAI3/5/202417/6/2026
An improper export vulnerability was reported in the Motorola Interface Test Tool application that could allow a malicious local application to execute OS commands.
AnalizadaMedia (4.3)0.13%—Google Firebase Command Line Interface2/5/202417/6/2026
This vulnerability was a potential CSRF attack. When running the Firebase emulator suite, there is an export endpoint that is used normally to export data from running emulators. If a user was running the emulator and navigated to a malicious website with the exploit on a browser that allowed calls to localhost (ie…
AplazadaMedia (6.5)0.35%—Interfacelab Media CloudAIAmazon S3AIImgixAIGoogle Cloud StorageAI+127/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Interfacelab Media Cloud for Amazon S3, Imgix, Google Cloud Storage, DigitalOcean Spaces and more allows Stored XSS.This issue affects Media Cloud for Amazon S3, Imgix, Google Cloud Storage, DigitalOcean Spaces and…
ModificadaMedia (5.5)0.29%—Appwrite Command Line Interface9/1/202417/6/2026
In Appwrite CLI before 3.0.0, when using the login command, the credentials of the Appwrite user are stored in a ~/.appwrite/prefs.json file with 0644 as UNIX permissions. Any user of the local system can access those credentials.
ModificadaCrítica (9.1)0.61%—SAP Application Interface Framework9/1/202417/6/2026
In SAP Application Interface Framework File Adapter - version 702, a high privilege user can use a function module to traverse through various layers and execute OS commands directly. By this, such user can control the behaviour of the application. This leads to considerable impact on confidentiality, integrity and…
ModificadaAlta (7.5)0.32%—Hitachienergy Rtu500 Scripting Interface19/12/202317/6/2026
A vulnerability exists in the component RTU500 Scripting interface. When a client connects to a server using TLS, the server presents a certificate. This certificate links a public key to the identity of the service and is signed by a Certification Authority (CA), allowing the client to validate that the remote…
ModificadaAlta (7.3)0.48%—SAP Graphical User Interface12/12/202317/6/2026
SAP GUI for Windows and SAP GUI for Java - versions SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, allow an unauthenticated attacker to access information which would otherwise be restricted and confidential. In addition, this vulnerability allows the unauthenticated attacker to create Layout…
AnalizadaAlta (8.6)21%—Microsoft Azure Command-line Interface14/11/202317/6/2026
Azure CLI REST Command Information Disclosure Vulnerability
ModificadaCrítica (9.8)0.81%—Johnsoncontrols Quantum HD Unity Compressor FirmwareJohnsoncontrols Quantum HD Unity Acuair FirmwareJohnsoncontrols Quantum HD Unity Condenser/vessel FirmwareJohnsoncontrols Quantum HD Unity Evaporator Firmware+210/11/202317/6/2026
An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.
ModificadaCrítica (9.8)0.70%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connection
ModificadaAlta (7.5)0.57%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable due to exposure of sensitive password information in the URL as a URL search parameter
ModificadaCrítica (9.8)0.70%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP strict-transport-security policy