Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
603 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.8) | 0.29% | — | Eusing Free IP Switcher | 30/3/2026 | 17/6/2026 | Free IP Switcher 3.1 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Computer Name field. Attackers can paste a malicious payload into the Computer Name input field and click Activate to trigger a denial of service condition… | |
| Analizada | Media (5.7) | 0.46% | — | Qnap Qunetswitch | 20/3/2026 | 17/6/2026 | A command injection vulnerability has been reported to affect QuNetSwitch. If a local attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.5.0906 and later | |
| Analizada | Media (6.3) | 0.95% | — | Qnap Qunetswitch | 20/3/2026 | 17/6/2026 | A command injection vulnerability has been reported to affect QuNetSwitch. If a remote attacker gains a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.5.0906 and later | |
| Analizada | Media (6.8) | 0.32% | — | Qnap Qunetswitch | 20/3/2026 | 17/6/2026 | A use of hard-coded credentials vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to gain unauthorized access. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.5.0906 and later | |
| Analizada | Alta (8.1) | 1.1% | — | Qnap Qunetswitch | 20/3/2026 | 17/6/2026 | A command injection vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.4.0415 and later | |
| Analizada | Alta (7.1) | 0.24% | — | Samsung Smart Switch | 16/3/2026 | 17/6/2026 | Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Smart Switch privilege. | |
| Analizada | Media (6.9) | 0.18% | — | Samsung Smart Switch | 16/3/2026 | 17/6/2026 | Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of service. | |
| Analizada | Alta (7.1) | 0.31% | — | Samsung Smart Switch | 16/3/2026 | 17/6/2026 | Authentication bypass by replay in Smart Switch prior to version 3.7.69.15 allows remote attackers to trigger privileged functions. | |
| Analizada | Alta (7.1) | 0.55% | — | Samsung Smart Switch | 16/3/2026 | 17/6/2026 | Improper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication. | |
| Analizada | Media (5.3) | 0.26% | — | Samsung Smart Switch | 16/3/2026 | 17/6/2026 | Improper verification of cryptographic signature in Smart Switch prior to version 3.7.69.15 allows remote attackers to potentially bypass authentication. | |
| Analizada | Alta (7.1) | 0.17% | — | Samsung Smart Switch | 16/3/2026 | 17/6/2026 | Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.69.15 allows remote attackers to configure a downgraded scheme for authentication. | |
| Analizada | Media (5.3) | 0.28% | — | Samsung Smart Switch | 16/3/2026 | 17/6/2026 | Exposure of sensitive functionality to an unauthorized actor in Smart Switch prior to version 3.7.69.15 allows remote attackers to set a specific configuration. | |
| Aplazada | Media (5.3) | 0.26% | — | Woobewoo WBW Currency Switcher FOR WoocommerceAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in WBW Plugins WBW Currency Switcher for WooCommerce woo-currency allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WBW Currency Switcher for WooCommerce: from n/a through <= 2.2.5. | |
| Analizada | Media (6.7) | 0.15% | — | Fortinet Fortiswitchaxfixed | 10/3/2026 | 17/6/2026 | An improper access control vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an authenticated admin to execute system commands via a specifically crafted SSH config file. | |
| Analizada | Alta (8.8) | 0.29% | — | Fortinet Fortiswitchaxfixed | 10/3/2026 | 17/6/2026 | A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an unauthenticated attacker within the same adjacent network to execute unauthorized code or commands on the device via sending a crafted LLDP packet. | |
| Aplazada | Alta (7.7) | 0.31% | — | Cisco Nexus 9000 Series Fabric SwitchesAI | 25/2/2026 | 17/6/2026 | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper processing when parsing SNMP… | |
| Aplazada | Alta (7.4) | 0.17% | — | Cisco Nexus 9000 Series Fabric SwitchesAI | 25/2/2026 | 17/6/2026 | A vulnerability in Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation when processing specific Ethernet frames. An attacker could exploit this… | |
| Aplazada | Media (5.5) | 0.36% | — | User Language SwitchAI | 14/2/2026 | 17/6/2026 | The User Language Switch plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.10 due to missing URL validation on the 'download_language()' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web… | |
| Aplazada | Media (4.4) | 0.25% | — | User Language SwitchAI | 14/2/2026 | 17/6/2026 | The User Language Switch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tab_color_picker_language_switch' parameter in all versions up to, and including, 1.6.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.1) | 0.71% | — | Ruijienetworks Switch Eweb S29 RgosAI | 29/1/2026 | 17/6/2026 | The Ruijie Networks Switch eWeb S29_RGOS version 11.4 contains a directory traversal vulnerability that allows unauthenticated attackers to access sensitive configuration files by manipulating file path parameters. Attackers can exploit the /download.do endpoint with '../' sequences to retrieve system configuration… | |
| Aplazada | Media (6.7) | 0.29% | — | Managed Switch Port Mapping ToolAI | 23/1/2026 | 17/6/2026 | Managed Switch Port Mapping Tool 2.85.2 contains a denial of service vulnerability that allows attackers to crash the application by creating an oversized buffer. Attackers can generate a 10,000-character buffer and paste it into the IP Address and SNMP Community Name fields to trigger the application crash. | |
| Analizada | Crítica (9.8) | 3.9% | ⚠ Explotación activa | Fortinet FortiosFortinet FortiswitchmanagerFortinet FortisaseSiemens Ruggedcom Ape1808 Firmware | 13/1/2026 | 10/9/2026 | A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized… | |
| Aplazada | Media (4.3) | 0.13% | — | Tikweb Fast User SwitchingAI | 24/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tikweb Management Fast User Switching fast-user-switching allows Cross Site Request Forgery.This issue affects Fast User Switching: from n/a through <= 1.4.10. | |
| Analizada | Crítica (9.8) | 68% | ⚠ Explotación activa | Fortinet FortiproxyFortinet FortiswitchmanagerFortinet FortiosSiemens Ruggedcom Ape1808 Firmware | 9/12/2025 | 17/6/2026 | A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through… | |
| Analizada | Alta (7.1) | 9.8% | — | Phoenixcontact FL NAT 2008 FirmwarePhoenixcontact FL NAT 2208 FirmwarePhoenixcontact FL NAT 2304-2gc-2sfp FirmwarePhoenixcontact FL Switch 2005 Firmware+65 | 9/12/2025 | 30/9/2026 | An XSS vulnerability in pxc_portSfp.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as… |