Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

196 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)8.5%💥 ExploitNortekcontrol Emerge E3 Firmware25/8/202217/6/2026
Nortek Linear eMerge E3-Series 0.32-07p devices are vulnerable to /card_scan.php?CardFormatNo= XSS with session fixation (via PHPSESSID) when they are chained together. This would allow an attacker to take over an admin account or a user account.
ModificadaCrítica (9.8)65%💥 ExploitNortekcontrol Emerge E3 Firmware25/8/202217/6/2026
Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists because of an incomplete fix for CVE-2019-7256.
ModificadaAlta (8.2)7.0%💥 ExploitNortekcontrol Emerge E3 Firmware25/8/202217/6/2026
Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors. (This occurs in situations where the CVE-2019-7271 default credentials have been changed.)
ModificadaCrítica (9.8)1.8%—Typescript Deep Merge Project Typescript Deep Merge9/8/202217/6/2026
The package ts-deepmerge before 2.0.2 are vulnerable to Prototype Pollution due to missing sanitization of the merge function.
ModificadaCrítica (9.8)0.80%—Merge Project Merge25/7/202217/6/2026
All versions of package @ianwalter/merge are vulnerable to Prototype Pollution via the main (merge) function. Maintainer suggests using @generates/merger instead.
ModificadaMedia (6.5)0.73%—Jenkins Jigomerge30/6/202217/6/2026
Jenkins Jigomerge Plugin 0.9 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
ModificadaMedia (6.5)0.49%—Fastify Github Action Merge Dependabot31/5/202217/6/2026
github-action-merge-dependabot is an action that automatically approves and merges dependabot pull requests (PRs). Prior to version 3.2.0, github-action-merge-dependabot does not check if a commit created by dependabot is verified with the proper GPG key. There is just a check if the actor is set to `dependabot[bot]`…
ModificadaCrítica (9.8)1.7%—Deepmerge-ts Project Deepmerge-ts1/4/202217/6/2026
deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. deepmerge-ts is vulnerable to Prototype Pollution via file deepmerge.ts, function defaultMergeRecords(). This issue has been patched in version 4.0.2. There are no known workarounds for this issue.
ModificadaCrítica (9.8)1.3%—Putil-merge Project Putil-merge4/2/202217/6/2026
This affects the package putil-merge before 3.8.0. The merge() function does not check the values passed into the argument. An attacker can supply a malicious value by adjusting the value to include the constructor property. Note: This vulnerability derives from an incomplete fix in…
ModificadaCrítica (9.8)1.2%—Merge-deep2 Project Merge-deep210/12/202117/6/2026
All versions of package merge-deep2 are vulnerable to Prototype Pollution via the mergeDeep() function.
AnalizadaCrítica (10)100%⚠ Explotación activa💥 ExploitSiemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+13910/12/202111/8/2026
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can…
ModificadaCrítica (9.8)1.4%—Merge Project Merge10/9/202117/6/2026
merge is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
ModificadaCrítica (9.8)1.1%—Merge-change Project Merge-change11/8/202117/6/2026
All versions of package merge-change are vulnerable to Prototype Pollution via the utils.set function.
ModificadaCrítica (9.8)1.1%—Deepmergefn Project Deepmergefn28/7/202117/6/2026
All versions of package deepmergefn are vulnerable to Prototype Pollution via deepMerge function.
ModificadaCrítica (9.8)3.0%—Putil-merge Project Putil-merge14/7/202117/6/2026
Prototype pollution vulnerability in 'putil-merge' versions1.0.0 through 3.6.6 allows attacker to cause a denial of service and may lead to remote code execution.
ModificadaCrítica (9.8)1.9%—Merge-deep Project Merge-deepNetapp E-series Performance Analyzer2/6/202117/6/2026
The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These properties are then inherited by every object in the program, thus facilitating prototype-pollution attacks against applications using this library.
ModificadaCrítica (9.8)3.5%—Patchmerge Project Patchmerge16/3/202117/6/2026
Prototype pollution vulnerability in 'patchmerge' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.
ModificadaCrítica (9.8)1.4%—Merge Project Merge18/2/202117/6/2026
All versions of package merge are vulnerable to Prototype Pollution via _recursiveMerge .
ModificadaMedia (6.5)0.91%—Cisco Emergency ResponderCisco Prime License ManagerCisco Unified Communications ManagerCisco Unified Communications Manager IM & Presence Service+113/1/202117/6/2026
A vulnerability in the audit logging component of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, Cisco Unity Connection, Cisco Emergency Responder, and Cisco Prime License Manager could allow an…
ModificadaMedia (6.1)1.6%—Papermerge2/12/202017/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Papermerge before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the rename, tag, upload, or create folder function. The payload can be in a folder, a tag, or a document's filename. If email consumption is configured in Papermerge, a…
ModificadaAlta (7.5)3.6%—Controlled-merge Project Controlled-merge15/11/202017/6/2026
Prototype pollution vulnerability in 'controlled-merge' versions 1.0.0 through 1.2.0 allows attacker to cause a denial of service and may lead to remote code execution.
ModificadaAlta (7.5)1.3%—Json8-merge-patch Project Json8-merge-patch9/11/202017/6/2026
Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties of the global object constructor.
ModificadaMedia (4.8)0.62%—Cisco Emergency Responder23/9/202017/6/2026
A vulnerability in the web framework of Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of some parameters that are passed to the web server…
ModificadaMedia (5.4)0.67%—IBM Intelligent Operations CenterIBM Intelligent Operations Center FOR Emergency ManagementIBM Water Operations FOR Waternamics28/7/202017/6/2026
IBM Intelligent Operations Center for Emergency Management, Intelligent Operations Center (IOC), and IBM Water Operations for Waternamics are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading…
ModificadaMedia (5.4)0.56%—IBM Intelligent Operations CenterIBM Intelligent Operations Center FOR Emergency ManagementIBM Water Operations FOR Waternamics28/7/202017/6/2026
IBM Intelligent Operations Center for Emergency Management, Intelligent Operations Center (IOC), and IBM Water Operations for Waternamics are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading…
Orbitaley — Vulnerabilidades