Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

184 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.2%—Propumpservice Osprey Pump Controller Firmware28/3/202317/6/2026
Osprey Pump Controller version 1.01 contains an unauthenticated command injection vulnerability that could allow system access with www-data permissions.
ModificadaCrítica (9.8)0.77%—Propumpservice Osprey Pump Controller Firmware28/3/202317/6/2026
Osprey Pump Controller version 1.01 has a hidden administrative account that has the hardcoded password that allows full access to the web management interface configuration. The user is not visible in Usernames and Passwords menu list of the application and the password cannot be changed through any normal operation…
ModificadaMedia (6.1)0.83%—Propumpservice Osprey Pump Controller Firmware28/3/202317/6/2026
Osprey Pump Controller version 1.01 inputs passed to a GET parameter are not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML/JS code in a user's browser session in context of an affected site.
ModificadaCrítica (9.8)0.89%—Propumpservice Osprey Pump Controller Firmware28/3/202317/6/2026
Osprey Pump Controller version 1.01 could allow an unauthenticated user to create an account and bypass authentication, thereby gaining unauthorized access to the system. A threat actor could exploit this vulnerability to create a user account without providing valid credentials. A threat actor who successfully…
ModificadaAlta (7.5)1.5%—Propumpservice Osprey Pump Controller Firmware28/3/202317/6/2026
Osprey Pump Controller version 1.01 is vulnerable to an unauthenticated file disclosure. Using a GET parameter, attackers can disclose arbitrary files on the affected device and disclose sensitive and system information.
ModificadaCrítica (9.8)1.6%—Propumpservice Osprey Pump Controller Firmware28/3/202317/6/2026
Osprey Pump Controller version 1.01 is vulnerable to an unauthenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands through a HTTP POST parameter called by index.php script.
ModificadaCrítica (9.8)18%—Propumpservice Osprey Pump Controller Firmware28/3/202317/6/2026
Osprey Pump Controller version 1.01 is vulnerable an unauthenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands through a HTTP GET parameter called by DataLogView.php, EventsView.php and AlarmsView.php scripts.
ModificadaAlta (7.5)0.65%—Propumpservice Osprey Pump Controller Firmware28/3/202317/6/2026
Osprey Pump Controller version 1.01 is vulnerable to a weak session token generation algorithm that can be predicted and can aid in authentication and authorization bypass. This may allow an attacker to hijack a session by predicting the session id and gain unauthorized access to the product.
ModificadaCrítica (9.9)0.85%—Fit2cloud JumpserverFit2cloud Koko16/3/202317/6/2026
Jumpserver is a popular open source bastion host, and Koko is a Jumpserver component that is the Go version of coco, refactoring coco's SSH/SFTP service and Web Terminal service. Prior to version 2.28.8, using illegal tokens to connect to a Kubernetes cluster through Koko can result in the execution of dangerous…
ModificadaCrítica (9.8)12%—GE Digital Industrial Gateway ServerPTC Kepware ServerPTC Kepware ServerexPTC Thingworx .net-sdk+523/2/202317/6/2026
The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.
ModificadaCrítica (9.8)2.9%—GE Digital Industrial Gateway ServerPTC Kepware ServerPTC Kepware ServerexPTC Thingworx .net-sdk+523/2/202317/6/2026
The affected products are vulnerable to an integer overflow or wraparound, which could allow an attacker to crash the server and remotely execute arbitrary code.
ModificadaAlta (7.5)0.88%—Httpserver Project Httpserver27/12/202217/6/2026
A vulnerability was found in RamseyK httpserver. It has been rated as critical. This issue affects the function ResourceHost::getResource of the file src/ResourceHost.cpp of the component URI Handler. The manipulation of the argument uri leads to path traversal: '../filedir'. The attack may be initiated remotely. The…
ModificadaCrítica (9.8)0.57%—Greenend Sftpserver18/12/202217/6/2026
A vulnerability was found in ewxrjk sftpserver. It has been declared as problematic. Affected by this vulnerability is the function sftp_parse_path of the file parse.c. The manipulation leads to uninitialized pointer. The real existence of this vulnerability is still doubted at the moment. The name of the patch is…
ModificadaMedia (5.3)0.82%—Phpservermonitor PHP Server Monitor15/11/202217/6/2026
A vulnerability, which was classified as problematic, was found in phpservermon. Affected is the function setUserLoggedIn of the file src/psm/Service/User.php. The manipulation leads to use of predictable algorithm in random number generator. The exploit has been disclosed to the public and may be used. The name of…
ModificadaMedia (5.3)0.86%—Phpservermonitor PHP Server Monitor15/11/202217/6/2026
A vulnerability, which was classified as problematic, was found in phpservermon. This affects the function generatePasswordResetToken of the file src/psm/Service/User.php. The manipulation leads to use of predictable algorithm in random number generator. The exploit has been disclosed to the public and may be used.…
ModificadaAlta (8.8)1.2%—Wampserver30/8/202217/6/2026
Incorrect access control in the install directory (C:\Wamp64) of Wamp v3.2.6 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in the directory.
ModificadaCrítica (9.8)1.5%—Fieldcommgroup HipserverFieldcommgroup Hart-ip Developer KIT Firmware19/5/202217/6/2026
A malicious attacker could exploit the interface of the Fieldcomm Group HART-IP (release 1.0.0.0) by constructing messages with sufficiently large payloads to overflow the internal buffer and crash the device, or obtain control of the device.
ModificadaMedia (6.1)2.3%💥 ExploitOpservices Opmon8/4/202217/6/2026
A Cross Site Scripting (XSS) vulnerability exists in OpServices OpMon through 9.11 via the search parameter in the request URL.
ModificadaMedia (5.4)0.87%—Phpservermonitor PHP Server Monitor12/12/202117/6/2026
phpservermon is vulnerable to Improper Neutralization of CRLF Sequences
ModificadaAlta (7.5)72%💥 ExploitWpserveur WPS Hide Login6/12/202117/6/2026
The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to /wp-admin/options.php as an unauthenticated user.
ModificadaCrítica (9.8)2.8%—Jumpserver23/7/202117/6/2026
An issue in Jumpserver before 2.6.2, before 2.5.4, before 2.4.5 allows attackers to create a connection token through an API which does not have access control and use it to access sensitive assets.
ModificadaMedia (4.9)0.94%—Matrix-appservice-bridge16/6/202117/6/2026
Matrix-appservice-bridge is the bridging service for the Matrix communication program's application services. In versions 2.6.0 and earlier, if a bridge has room upgrade handling turned on in the configuration (the `roomUpgradeOpts` key when instantiating a new `Bridge` instance.), any `m.room.tombstone` event it…
ModificadaMedia (5.3)1.5%—Osgeo MapserverFedoraproject Fedora6/5/202117/6/2026
MapServer before 7.0.8, 7.1.x and 7.2.x before 7.2.3, 7.3.x and 7.4.x before 7.4.5, and 7.5.x and 7.6.x before 7.6.3 does not properly enforce the MS_MAP_NO_PATH and MS_MAP_PATTERN restrictions that are intended to control the locations from which a mapfile may be loaded (with MapServer CGI).
ModificadaMedia (5.3)1.8%—Wpserveur WPS Hide Login1/3/202117/6/2026
WPS Hide Login 1.6.1 allows remote attackers to bypass a protection mechanism via post_password.
ModificadaMedia (6.1)5.8%💥 ExploitWftpserver Wing FTP Server26/1/202117/6/2026
An XSS issue was discovered in Wing FTP 6.4.4. An arbitrary IFRAME element can be included in the help pages via a crafted link, leading to the execution of (sandboxed) arbitrary HTML and JavaScript in the user's browser.
Orbitaley — Vulnerabilidades