Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
234 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.97% | — | Novastar Cx40AI | 31/3/2025 | 17/6/2026 | A vulnerability classified as critical has been found in Novastar CX40 up to 2.44.0. Affected is the function system/popen of the file /usr/nova/bin/netconfig of the component NetFilter Utility. The manipulation leads to command injection. The exploit has been disclosed to the public and may be used. The vendor was… | |
| Aplazada | Media (5.1) | 0.29% | — | Novastar Cx40AI | 31/3/2025 | 17/6/2026 | A vulnerability was found in Novastar CX40 up to 2.44.0. It has been rated as critical. This issue affects the function getopt of the file /usr/nova/bin/netconfig of the component NetFilter Utility. The manipulation of the argument cmd/netmask/pipeout/nettask leads to stack-based buffer overflow. The exploit has been… | |
| Aplazada | Media (6.9) | 0.36% | — | Innovacion Y Cualificacion Local Administration PluginAI | 17/3/2025 | 17/6/2026 | Broken access control vulnerability in the Innovación y Cualificación local administration plugin ajax.php. This vulnerability allows an attacker to obtain sensitive information about other users such as id, name, login and email. | |
| Aplazada | Media (6.9) | 0.36% | — | Icprogress Innovacion Y CualificacionAI | 17/3/2025 | 17/6/2026 | Broken access control vulnerability in the IcProgress Innovación y Cualificación plugin. This vulnerability allows an attacker to obtain sensitive information about other users such as public IP addresses, messages with other users and more. | |
| Aplazada | Crítica (9.3) | 0.34% | — | Icprogreso Innovacion Y CualificacionAI | 17/3/2025 | 17/6/2026 | SQL injection vulnerability in the IcProgreso Innovación y Cualificación plugin. This vulnerability allows an attacker to obtain, update and delete data from the database by injecting an SQL query on the parameters user, id, idGroup, start_date and end_date in the endpoint /report/icprogreso/generar_blocks.php. | |
| Aplazada | Crítica (9.3) | 0.34% | — | Innovacion Y Cualificacion Local Administration PluginAI | 17/3/2025 | 17/6/2026 | SQL injection vulnerability in the Innovación y Cualificación local administration plugin ajax.php. This vulnerability allows an attacker to obtain, update and delete data from the database by injecting an SQL query in ‘searchActionsToUpdate’, ‘searchSpecialitiesPending’, ‘searchSpecialitiesLinked’,… | |
| Analizada | Alta (8.8) | 0.43% | — | Inovalogic Customer Monitor | 13/3/2025 | 17/6/2026 | Incorrect access control in the scheduled tasks console of Inova Logic CUSTOMER MONITOR (CM) v3.1.757.1 allows attackers to escalate privileges via placing a crafted executable into a scheduled task. | |
| Aplazada | Media (6.1) | 0.18% | — | GE Vernova UR IEDAIGE Vernova Enervista UR SetupAI | 10/3/2025 | 17/6/2026 | Insufficient Verification of Data Authenticity vulnerability in GE Vernova UR IED family devices allows an authenticated user to install a modified firmware. The firmware signature verification is enforced only on the client-side dedicated software Enervista UR Setup, allowing the integration check to be bypassed. | |
| Aplazada | Alta (8.3) | 0.28% | — | GE Vernova Enervista UR SetupAI | 10/3/2025 | 17/6/2026 | Missing Authentication for Critical Function vulnerability in GE Vernova Enervista UR Setup application allows Authentication Bypass due to a missing SSH server authentication. Since the client connection is not authenticated, an attacker may perform a man-in-the-middle attack on the network. | |
| Aplazada | Alta (8) | 0.15% | — | GE Vernova Enervista UR SetupAI | 10/3/2025 | 17/6/2026 | Use of Hard-coded Credentials vulnerability in GE Vernova EnerVista UR Setup allows Privilege Escalation. The local user database is encrypted using an hardcoded password retrievable by an attacker analyzing the application code. | |
| Aplazada | Alta (8) | 0.19% | — | GE Vernova Enervista UR SetupAI | 10/3/2025 | 17/6/2026 | CWE-282 "Improper Ownership Management" in GE Vernova EnerVista UR Setup allows Authentication Bypass. The software's startup authentication can be disabled by altering a Windows registry setting that any user can modify. | |
| Aplazada | Media (6.1) | 0.23% | — | GE Vernova UR IEDAI | 10/3/2025 | 17/6/2026 | A CWE-15 "External Control of System or Configuration Setting" in GE Vernova UR IED family devices from version 7.0 up to 8.60 allows an attacker to provide input that establishes a TCP connection through a port forwarding. The lack of the IP address and port validation may allow the attacker to bypass firewall rules… | |
| Aplazada | Crítica (9.8) | 0.42% | — | Novachron Zeitsysteme Smart Time PlusAI | 24/2/2025 | 17/6/2026 | NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability via the getCookieNames method in the smarttimeplus/MySQLConnection endpoint. | |
| Aplazada | Media (5.4) | 0.24% | — | Novachron Zeitsysteme Gmbh & CO. KG Smart Time PlusAI | 24/2/2025 | 17/6/2026 | NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability via the addProject method in the smarttimeplus/MySQLConnection endpoint. | |
| Aplazada | Media (6.5) | 0.24% | — | Novachron Zeitsysteme Smart Time PlusAI | 24/2/2025 | 17/6/2026 | Incorrect access control in the component /iclock/Settings?restartNCS=1 of NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 allows attackers to arbitrarily restart the NCServiceManger via a crafted GET request. | |
| Aplazada | Crítica (9.3) | 0.37% | — | Ihor KIT Shipping FOR Nova PoshtaAI | 27/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ihor Kit Shipping for Nova Poshta nova-poshta-ttn allows SQL Injection.This issue affects Shipping for Nova Poshta: from n/a through <= 1.19.6. | |
| Aplazada | Alta (7.1) | 0.20% | — | Nova706 OrangeboxAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in nova706 OrangeBox orangebox allows Cross Site Request Forgery.This issue affects OrangeBox: from n/a through <= 3.0.0. | |
| Analizada | Alta (7.8) | 0.13% | — | Huawei Mate 20 PRO FirmwareHuawei Mate 20 PRO (ud) FirmwareHuawei Nova 5I Firmware | 27/12/2024 | 17/6/2026 | There is an improper privilege management vulnerability in Huawei smart phone product. A local, authenticated attacker could craft a specific input to exploit this vulnerability. Successful exploitation may lead to local privilege escalation. (Vulnerability ID: HWPSIRT-2020-05272) This vulnerability has been assigned… | |
| Aplazada | Media (6.9) | 0.75% | — | Fujifilm Business Innovation Apeos C3070AIFujifilm Business Innovation Apeos C5570AIFujifilm Business Innovation Apeos C6580AI | 19/12/2024 | 17/6/2026 | A vulnerability has been found in Fujifilm Business Innovation Apeos C3070, Apeos C5570 and Apeos C6580 up to 24.8.28 and classified as critical. This vulnerability affects unknown code of the file /home/index.html#hashHome of the component Web Interface. The manipulation leads to improper authorization. The attack… | |
| Aplazada | Media (5.3) | 0.63% | — | Michal Novak Secure Admin IPAI | 13/12/2024 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in Michal Novák Secure Admin IP allows Functionality Bypass.This issue affects Secure Admin IP: from n/a through 2.0. | |
| Aplazada | Crítica (9.8) | 0.96% | — | Inovance Am401 Cpu1608tptnAI | 4/12/2024 | 17/6/2026 | An issue in INOVANCE AM401_CPU1608TPTN allows a remote attacker to execute arbitrary code via the ExecuteUserProgramUpgrade function | |
| Aplazada | Media (6.5) | 0.27% | — | Inovance Hcplc Am401-cpu1608tptnAIInovance Hcplc Am402-cpu1608tptnAIInovance Hcplc Am403-cpu1608tnAI | 13/11/2024 | 17/6/2026 | A buffer overflow in the RecvSocketData function of Inovance HCPLC_AM401-CPU1608TPTN 21.38.0.0, HCPLC_AM402-CPU1608TPTN 41.38.0.0, and HCPLC_AM403-CPU1608TN 81.38.0.0 allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted Modbus message. | |
| Modificada | Alta (8.8) | 0.49% | — | Rudrainnovative Training - Courses | 4/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in rudrainn Training – Courses training allows Upload a Web Shell to a Web Server.This issue affects Training – Courses: from n/a through <= 2.0.1. | |
| Aplazada | Media (6.9) | 0.37% | — | Nova-cms Nova CMSAI | 10/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TE Informatics Nova CMS allows SQL Injection. This issue affects Nova CMS: before 5.0. | |
| Analizada | Media (5.4) | 0.37% | — | Pixelgrade Nova Blocks | 10/9/2024 | 17/6/2026 | The Nova Blocks by Pixelgrade plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' attribute of the 'wp:separator' Gutenberg block in all versions up to, and including, 2.1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… |