Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2829▼ 255 respecto a la semana anterior
Críticas / altas1324▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

1921 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)98%💥 ExploitZohocorp Manageengine Admanager Plus13/4/202317/6/2026
Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings.
ModificadaAlta (7.4)0.26%—Siemens Scalance X200-4p IRT FirmwareSiemens Scalance X201-3p IRT FirmwareSiemens Scalance X201-3p IRT PRO FirmwareSiemens Scalance X202-2irt Firmware+911/4/202317/6/2026
A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT PRO (All versions < V5.5.2), SCALANCE X202-2IRT (All versions < V5.5.2), SCALANCE X202-2IRT (All versions < V5.5.2), SCALANCE X202-2P IRT (All versions < V5.5.2),…
ModificadaAlta (7.5)0.95%—Siemens Simatic CP 1242-7 V2 FirmwareSiemens Simatic CP 1243-1 FirmwareSiemens Simatic CP 1243-1 Dnp3 FirmwareSiemens Simatic CP 1243-1 IEC Firmware+2011/4/202317/6/2026
A vulnerability has been identified in SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions < V3.4.29),…
ModificadaAlta (7.5)0.72%—Siemens Simatic CP 1242-7 V2 FirmwareSiemens Simatic CP 1243-1 FirmwareSiemens Simatic CP 1243-1 Dnp3 FirmwareSiemens Simatic CP 1243-1 IEC Firmware+2011/4/202317/6/2026
A vulnerability has been identified in SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions < V3.4.29),…
ModificadaAlta (7.5)0.95%—Siemens Simatic CP 1242-7 V2 FirmwareSiemens Simatic CP 1243-1 FirmwareSiemens Simatic CP 1243-1 Dnp3 FirmwareSiemens Simatic CP 1243-1 IEC Firmware+2011/4/202317/6/2026
A vulnerability has been identified in SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions < V3.4.29),…
ModificadaMedia (4.8)32%💥 PoCUpdraftplus All-in-one Security10/4/202317/6/2026
The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not escape the content of log files before outputting it to the plugin admin page, allowing an authorized user (admin+) to plant bogus log files containing malicious JavaScript code that will be executed in the context of any administrator visiting this…
ModificadaMedia (4.9)20%💥 PoCUpdraftplus All-in-one Security10/4/202317/6/2026
The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not limit what log files to display in it's settings pages, allowing an authorized user (admin+) to view the contents of arbitrary files and list directories anywhere on the server (to which the web server has access). The plugin only displays the last…
ModificadaAlta (7.5)78%—Zohocorp Manageengine Adselfservice Plus5/4/202317/6/2026
Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.
ModificadaCrítica (9.8)1.5%—Sato-global Cl4nx Plus Firmware31/3/202317/6/2026
An authentication bypass vulnerability in the web client interface for the CL4NX printer before firmware version 1.13.3-u724_r2 provides remote unauthenticated attackers with access to execute commands intended only for valid/authenticated users, such as file uploads and configuration changes.
ModificadaMedia (5.4)20%—Zohocorp Manageengine OpmanagerZohocorp Manageengine Opmanager PlusZohocorp Manageengine Opmanager MSP30/3/202317/6/2026
A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability.
ModificadaAlta (7.5)0.41%—Cpplusworld Kvms PRO28/3/202317/6/2026
CP Plus KVMS Pro versions 2.01.0.T.190521 and prior are vulnerable to sensitive credentials being leaked because they are insufficiently protected.
ModificadaAlta (8.8)0.73%—Xxyopen Novel-plus23/3/202317/6/2026
Se encontró una vulnerabilidad en novel-plus 3.6.2. Se ha clasificado como crítico. Esto afecta a una parte desconocida del archivo /common/sysFile/list. La manipulación del argumento sort conduce a la inyección sql. Es posible iniciar el ataque de forma remota. El exploit ha sido divulgado al público y puede ser…
ModificadaCrítica (9.1)3.1%—Zohocorp Manageengine Adselfservice Plus23/3/202317/6/2026
Zoho ManageEngine ADSelfService Plus through 6203 is vulnerable to a brute-force attack that leads to a password reset on IDM applications.
ModificadaCrítica (9.8)0.89%—Xxyopen Novel-plus23/3/202317/6/2026
Se encontró una vulnerabilidad en novel-plus 3.6.2 y se clasificó como crítica. Este problema afecta a algunas funciones desconocidas del archivo DictController.java. La manipulación del argumento orderby conduce a la inyección sql. El ataque puede ser lanzado de forma remota. El exploit ha sido divulgado al público y…
ModificadaAlta (7.2)0.87%—Xxyopen Novel-plus23/3/202317/6/2026
Se ha encontrado una vulnerabilidad en novel-plus 3.6.2 y se ha clasificado como crítica. Esta vulnerabilidad afecta a una funcionalidad desconocida del archivo common/log/list. La manipulación del argumento sort conduce a la inyección sql. El ataque se puede lanzar de forma remota. El exploit ha sido divulgado al…
ModificadaCrítica (9.8)1.0%—Xxyopen Novel-plus23/3/202317/6/2026
Una vulnerabilidad, que se clasificó como crítica, se encontró en novel-plus 3.6.2. Afectando la función MenuService del archivo sys/menu/list. La manipulación del argumento sort conduce a la inyección sql. Es posible lanzar el ataque de forma remota. El exploit ha sido divulgado al público y puede ser utilizado.…
ModificadaCrítica (9.8)9.8%💥 ExploitNetgate Pfsense PlusPfsense22/3/202317/6/2026
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web requests.
ModificadaMedia (4.8)0.37%—Plustime Service Area Postcode Checker20/3/202317/6/2026
Auth. (admin+) vulnerability in Second2none Service Area Postcode Checker plugin <= 2.0.8 versions.
ModificadaMedia (5.5)0.32%—Maxpcsecure Anti Virus Plus18/3/202317/6/2026
A vulnerability was found in Max Secure Anti Virus Plus 19.0.2.1. It has been rated as problematic. This issue affects the function 0x220019 in the library MaxProctetor64.sys of the component IoControlCode Handler. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The…
ModificadaMedia (5.5)0.32%—Maxpcsecure Anti Virus Plus18/3/202317/6/2026
A vulnerability was found in Max Secure Anti Virus Plus 19.0.2.1. It has been declared as problematic. This vulnerability affects the function 0x220019 in the library MaxProc64.sys of the component IoControlCode Handler. The manipulation of the argument SystemBuffer leads to denial of service. Attacking locally is a…
ModificadaMedia (5.5)0.30%—Maxpcsecure Anti Virus Plus18/3/202317/6/2026
A vulnerability was found in Max Secure Anti Virus Plus 19.0.2.1. It has been classified as critical. This affects the function 0x220020 in the library MaxCryptMon.sys of the component IoControlCode Handler. The manipulation leads to improper access controls. Local access is required to approach this attack. The…
ModificadaMedia (5.5)0.30%—Maxpcsecure Anti Virus Plus18/3/202317/6/2026
A vulnerability was found in Max Secure Anti Virus Plus 19.0.2.1 and classified as critical. Affected by this issue is the function 0x220020 in the library SDActMon.sys of the component IoControlCode Handler. The manipulation leads to improper access controls. An attack has to be approached locally. The exploit has…
ModificadaMedia (4.6)0.29%—Dell Inspiron 14 Plus 7420 FirmwareDell Inspiron 14 Plus 7620 FirmwareDell Inspiron 3511 FirmwareDell Inspiron 3520 Firmware+718/3/202317/6/2026
Dell BIOS contains an Improper Authorization vulnerability. An unauthenticated physical attacker may potentially exploit this vulnerability, leading to denial of service.
ModificadaMedia (6.5)0.80%—Posimyth THE Plus Addons FOR Elementor7/3/202317/6/2026
The Plus Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in versions up to, and including 4.1.9 (pro) and 2.0.6 (free). The plugin has a feature to add an "Info Box" to an Elementor created page. This Info Box can include an SVG image for the box. Unfortunately, the plugin used…
ModificadaAlta (8.8)0.89%—Posimyth THE Plus Addons FOR Elementor7/3/202317/6/2026
The Plus Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 4.1.9 (pro) and 2.0.6 (free). The plugin adds a registration form to the Elementor page builders functionality. As part of the registration form, users can choose which role to set as the default…
Orbitaley — Vulnerabilidades