Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

234 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.1)0.97%—Novastar Cx40AI31/3/202517/6/2026
A vulnerability classified as critical has been found in Novastar CX40 up to 2.44.0. Affected is the function system/popen of the file /usr/nova/bin/netconfig of the component NetFilter Utility. The manipulation leads to command injection. The exploit has been disclosed to the public and may be used. The vendor was…
AplazadaMedia (5.1)0.29%—Novastar Cx40AI31/3/202517/6/2026
A vulnerability was found in Novastar CX40 up to 2.44.0. It has been rated as critical. This issue affects the function getopt of the file /usr/nova/bin/netconfig of the component NetFilter Utility. The manipulation of the argument cmd/netmask/pipeout/nettask leads to stack-based buffer overflow. The exploit has been…
AplazadaMedia (6.9)0.36%—Innovacion Y Cualificacion Local Administration PluginAI17/3/202517/6/2026
Broken access control vulnerability in the Innovación y Cualificación local administration plugin ajax.php. This vulnerability allows an attacker to obtain sensitive information about other users such as id, name, login and email.
AplazadaMedia (6.9)0.36%—Icprogress Innovacion Y CualificacionAI17/3/202517/6/2026
Broken access control vulnerability in the IcProgress Innovación y Cualificación plugin. This vulnerability allows an attacker to obtain sensitive information about other users such as public IP addresses, messages with other users and more.
AplazadaCrítica (9.3)0.34%—Icprogreso Innovacion Y CualificacionAI17/3/202517/6/2026
SQL injection vulnerability in the IcProgreso Innovación y Cualificación plugin. This vulnerability allows an attacker to obtain, update and delete data from the database by injecting an SQL query on the parameters user, id, idGroup, start_date and end_date in the endpoint /report/icprogreso/generar_blocks.php.
AplazadaCrítica (9.3)0.34%—Innovacion Y Cualificacion Local Administration PluginAI17/3/202517/6/2026
SQL injection vulnerability in the Innovación y Cualificación local administration plugin ajax.php. This vulnerability allows an attacker to obtain, update and delete data from the database by injecting an SQL query in ‘searchActionsToUpdate’, ‘searchSpecialitiesPending’, ‘searchSpecialitiesLinked’,…
AnalizadaAlta (8.8)0.43%—Inovalogic Customer Monitor13/3/202517/6/2026
Incorrect access control in the scheduled tasks console of Inova Logic CUSTOMER MONITOR (CM) v3.1.757.1 allows attackers to escalate privileges via placing a crafted executable into a scheduled task.
AplazadaMedia (6.1)0.18%—GE Vernova UR IEDAIGE Vernova Enervista UR SetupAI10/3/202517/6/2026
Insufficient Verification of Data Authenticity vulnerability in GE Vernova UR IED family devices allows an authenticated user to install a modified firmware. The firmware signature verification is enforced only on the client-side dedicated software Enervista UR Setup, allowing the integration check to be bypassed.
AplazadaAlta (8.3)0.28%—GE Vernova Enervista UR SetupAI10/3/202517/6/2026
Missing Authentication for Critical Function vulnerability in GE Vernova Enervista UR Setup application allows Authentication Bypass due to a missing SSH server authentication. Since the client connection is not authenticated, an attacker may perform a man-in-the-middle attack on the network.
AplazadaAlta (8)0.15%—GE Vernova Enervista UR SetupAI10/3/202517/6/2026
Use of Hard-coded Credentials vulnerability in GE Vernova EnerVista UR Setup allows Privilege Escalation. The local user database is encrypted using an hardcoded password retrievable by an attacker analyzing the application code.
AplazadaAlta (8)0.19%—GE Vernova Enervista UR SetupAI10/3/202517/6/2026
CWE-282 "Improper Ownership Management" in GE Vernova EnerVista UR Setup allows Authentication Bypass. The software's startup authentication can be disabled by altering a Windows registry setting that any user can modify.
AplazadaMedia (6.1)0.23%—GE Vernova UR IEDAI10/3/202517/6/2026
A CWE-15 "External Control of System or Configuration Setting" in GE Vernova UR IED family devices from version 7.0 up to 8.60 allows an attacker to provide input that establishes a TCP connection through a port forwarding. The lack of the IP address and port validation may allow the attacker to bypass firewall rules…
AplazadaCrítica (9.8)0.42%—Novachron Zeitsysteme Smart Time PlusAI24/2/202517/6/2026
NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability via the getCookieNames method in the smarttimeplus/MySQLConnection endpoint.
AplazadaMedia (5.4)0.24%—Novachron Zeitsysteme Gmbh & CO. KG Smart Time PlusAI24/2/202517/6/2026
NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability via the addProject method in the smarttimeplus/MySQLConnection endpoint.
AplazadaMedia (6.5)0.24%—Novachron Zeitsysteme Smart Time PlusAI24/2/202517/6/2026
Incorrect access control in the component /iclock/Settings?restartNCS=1 of NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 allows attackers to arbitrarily restart the NCServiceManger via a crafted GET request.
AplazadaCrítica (9.3)0.37%—Ihor KIT Shipping FOR Nova PoshtaAI27/1/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ihor Kit Shipping for Nova Poshta nova-poshta-ttn allows SQL Injection.This issue affects Shipping for Nova Poshta: from n/a through <= 1.19.6.
AplazadaAlta (7.1)0.20%—Nova706 OrangeboxAI16/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in nova706 OrangeBox orangebox allows Cross Site Request Forgery.This issue affects OrangeBox: from n/a through <= 3.0.0.
AnalizadaAlta (7.8)0.13%—Huawei Mate 20 PRO FirmwareHuawei Mate 20 PRO (ud) FirmwareHuawei Nova 5I Firmware27/12/202417/6/2026
There is an improper privilege management vulnerability in Huawei smart phone product. A local, authenticated attacker could craft a specific input to exploit this vulnerability. Successful exploitation may lead to local privilege escalation. (Vulnerability ID: HWPSIRT-2020-05272) This vulnerability has been assigned…
AplazadaMedia (6.9)0.75%—Fujifilm Business Innovation Apeos C3070AIFujifilm Business Innovation Apeos C5570AIFujifilm Business Innovation Apeos C6580AI19/12/202417/6/2026
A vulnerability has been found in Fujifilm Business Innovation Apeos C3070, Apeos C5570 and Apeos C6580 up to 24.8.28 and classified as critical. This vulnerability affects unknown code of the file /home/index.html#hashHome of the component Web Interface. The manipulation leads to improper authorization. The attack…
AplazadaMedia (5.3)0.63%—Michal Novak Secure Admin IPAI13/12/202417/6/2026
Authentication Bypass by Spoofing vulnerability in Michal Novák Secure Admin IP allows Functionality Bypass.This issue affects Secure Admin IP: from n/a through 2.0.
AplazadaCrítica (9.8)0.96%—Inovance Am401 Cpu1608tptnAI4/12/202417/6/2026
An issue in INOVANCE AM401_CPU1608TPTN allows a remote attacker to execute arbitrary code via the ExecuteUserProgramUpgrade function
AplazadaMedia (6.5)0.27%—Inovance Hcplc Am401-cpu1608tptnAIInovance Hcplc Am402-cpu1608tptnAIInovance Hcplc Am403-cpu1608tnAI13/11/202417/6/2026
A buffer overflow in the RecvSocketData function of Inovance HCPLC_AM401-CPU1608TPTN 21.38.0.0, HCPLC_AM402-CPU1608TPTN 41.38.0.0, and HCPLC_AM403-CPU1608TN 81.38.0.0 allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted Modbus message.
ModificadaAlta (8.8)0.49%—Rudrainnovative Training - Courses4/11/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in rudrainn Training – Courses training allows Upload a Web Shell to a Web Server.This issue affects Training – Courses: from n/a through <= 2.0.1.
AplazadaMedia (6.9)0.37%—Nova-cms Nova CMSAI10/10/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TE Informatics Nova CMS allows SQL Injection. This issue affects Nova CMS: before 5.0.
AnalizadaMedia (5.4)0.37%—Pixelgrade Nova Blocks10/9/202417/6/2026
The Nova Blocks by Pixelgrade plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' attribute of the 'wp:separator' Gutenberg block in all versions up to, and including, 2.1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
Orbitaley — Vulnerabilidades