Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

165 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.24%—Cozyvision SMS Alert Order Notifications13/3/202417/6/2026
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.9. This is due to missing or incorrect nonce validation on the processBulkAction function. This makes it possible for unauthenticated attackers to delete pages and…
ModificadaAlta (7.8)0.25%—Quescom Nextbx Qwalerter15/9/202317/6/2026
A vulnerability was found in NextBX QWAlerter 4.50. It has been rated as critical. Affected by this issue is some unknown functionality of the file QWAlerter.exe. The manipulation leads to unquoted search path. It is possible to launch the attack on the local host. The identifier of this vulnerability is VDB-239804.…
ModificadaMedia (5.4)0.63%—Prometheus AlertmanagerDebian Linux25/8/202317/6/2026
Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager. This issue has been fixed in Alertmanager version…
ModificadaMedia (4.8)0.47%—Pottie SEO Alert16/8/202317/6/2026
The SEO ALert WordPress plugin through 1.59 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
ModificadaAlta (8.8)0.26%—Sitealert18/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in SiteAlert plugin <= 1.9.7 versions.
ModificadaCrítica (9.8)0.61%—Honeywell Alerton Bcm-web Firmware28/6/202317/6/2026
** UNSUPPORTED WHEN ASSIGNED ** [An attacker can capture an authenticating hash and utilize it to create new sessions. The hash is also a poorly salted MD5 hash, which could result in a successful brute force password attack. Impacted product is BCM-WEB version 3.3.X. Recommended fix: Upgrade to a supported product…
ModificadaMedia (6.1)0.38%—Wpoperation Salert - Fake Sales Notification Woocommerce12/6/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPoperation SALERT – Fake Sales Notification WooCommerce plugin <= 1.2.1 versions.
ModificadaCrítica (9.8)2.7%—Pi.alert Project Pi.alert11/1/202317/6/2026
The jokob-sk/Pi.Alert fork (before 22.12.20) of Pi.Alert allows Remote Code Execution via nmap_scan.php (scan parameter) OS Command Injection.
ModificadaMedia (5.4)0.36%—Digitalalertsystems Dasdec II FirmwareDigitalalertsystems One-net SE FirmwareDigitalalertsystems Dasdec I FirmwareDigitalalertsystems One-net Firmware+11/12/202217/6/2026
A cross-site scripting (XSS) vulnerability exists in all current versions of Digital Alert Systems DASDEC software via the Host Header in undisclosed pages after login.
ModificadaMedia (5.4)0.47%—Digitalalertsystems Dasdec II FirmwareDigitalalertsystems One-net SE FirmwareDigitalalertsystems Dasdec I FirmwareDigitalalertsystems One-net Firmware+130/11/202217/6/2026
Digital Alert Systems’ DASDEC software prior to version 4.1 contains a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web script or HTML via the SSH username, username field of the login page, or via the HTTP host header. The injected content is stored in logs and rendered…
ModificadaMedia (6.5)1.3%—Honeywell Alerton Compass15/7/202217/6/2026
Honeywell Alerton Compass Software 1.6.5 allows unauthenticated configuration changes from remote users. This enables configuration data to be stored on the controller and then implemented. A user with malicious intent can send a crafted packet to change the controller configuration without the knowledge of other…
ModificadaAlta (8)1.5%—Honeywell Alerton Ascent Control Module Firmware15/7/202217/6/2026
Honeywell Alerton Ascent Control Module (ACM) through 2022-05-04 allows unauthenticated programming writes from remote users. This enables code to be store on the controller and then run without verification. A user with malicious intent can send a crafted packet to change and/or stop the program without the knowledge…
ModificadaMedia (6.8)1.3%—Honeywell Alerton Ascent Control Module Firmware15/7/202217/6/2026
Honeywell Alerton Ascent Control Module (ACM) through 2022-05-04 allows unauthenticated configuration changes from remote users. This enables configuration data to be stored on the controller and then implemented. A user with malicious intent can send a crafted packet to change the controller configuration without the…
ModificadaMedia (6.5)0.40%—Philips E-alert Firmware1/4/202217/6/2026
The software does not perform any authentication for critical system functionality.
ModificadaMedia (4.3)0.43%—Madewithfuel Customize Wordpress Emails AND Alerts28/2/202217/6/2026
The Customize WordPress Emails and Alerts WordPress plugin before 1.8.7 does not have authorisation and CSRF check in its bnfw_search_users AJAX action, allowing any authenticated users to call it and query for user e-mail prefixes (finding the first letter, then the second one, then the third one etc.).
AnalizadaCrítica (9)100%⚠ Explotación activa💥 ExploitApache Log4jCvat Computer Vision Annotation ToolIntel Audio Development KITIntel Datacenter Manager+5114/12/202117/6/2026
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example,…
ModificadaAlta (8.8)1.5%—Talariax Sendquick Alert Plus Server Admin14/11/202117/6/2026
A SQL Injection vulnerability in /appliance/shiftmgn.php in TalariaX sendQuick Alert Plus Server Admin 4.3 before 8HF11 allows attackers to obtain sensitive information via a Roster Time to Roster Management.
ModificadaMedia (6.7)0.26%—Sophos Hitmanpro.alert8/10/202117/6/2026
A local attacker could execute arbitrary code with administrator privileges in HitmanPro.Alert before version Build 901.
ModificadaMedia (6.1)0.83%—Cozyvision SMS Alert Order Notifications6/9/202117/6/2026
The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerability in the plugin's setting page.
ModificadaMedia (6.1)0.94%—Followistic Smart Email Alerts16/8/202117/6/2026
The Smart Email Alerts WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the api_key in the ~/views/settings.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.10.
ModificadaCrítica (9.8)66%💥 ExploitAlerta Project Alerta6/11/202017/6/2026
In Alerta before version 8.1.0, users may be able to bypass LDAP authentication if they provide an empty password when Alerta server is configure to use LDAP as the authorization provider. Only deployments where LDAP servers are configured to allow unauthenticated authentication mechanism for anonymous authorization…
ModificadaAlta (7.8)0.36%—Sophos Hitmanpro.alert2/3/202017/6/2026
Sophos HitmanPro.Alert before build 861 allows local elevation of privilege.
ModificadaMedia (5.3)0.98%—Ready Wireless Emergency Alerts2/11/201917/6/2026
The Wireless Emergency Alerts (WEA) protocol allows remote attackers to spoof a Presidential Alert because cryptographic authentication is not used, as demonstrated by MessageIdentifier 4370 in LTE System Information Block 12 (aka SIB12). NOTE: testing inside an RF-isolated shield box suggested that all LTE phones are…
ModificadaAlta (7.8)2.1%—Pivotal Cloud Foundry Command Line InterfacePivotal Cloud Foundry Command Line Interface ReleasePivotal Cloud Foundry DeploymentPivotal Cloud Foundry Deployment Concourse Tasks+515/8/201917/6/2026
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.
ModificadaAlta (8.8)3.0%—Avtech Room Alert 3E Firmware7/7/201917/6/2026
On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privileges from an unauthenticated user to administrator by performing a cmd.cgi?action=ResetDefaults&src=RA reset and using the default credentials to get in.
Orbitaley — Vulnerabilidades