Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

1900 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.1%—Hitachienergy Sys600 FirmwareHitachienergy Rtu500 FirmwareHitachienergy Reb500 FirmwareHitachienergy Pwc600 Firmware+921/2/202317/6/2026
A vulnerability exists in the IEC 61850 communication stack that affects multiple Hitachi Energy products. An attacker could exploit the vulnerability by using a specially crafted message sequence, to force the IEC 61850 MMS-server communication stack, to stop accepting new MMS-client connections. Already…
ModificadaMedia (6.1)2.6%—Zohocorp Manageengine Assetexplorer1/2/202317/6/2026
Cross Site Scripting (XSS) vulnerability in Zoho Asset Explorer 6.9 via the credential name when creating a new Assets Workstation.
AnalizadaCrítica (9.8)100%⚠ Explotación activaZohocorp Manageengine Access Manager PlusZohocorp Manageengine Ad360Zohocorp Manageengine Adaudit PlusZohocorp Manageengine Admanager Plus+1818/1/202331/7/2026
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections,…
ModificadaAlta (8.6)0.86%—Microchip Bm78 FirmwareMicrochip Bm83 FirmwareMicrochip Rn4870 FirmwareMicrochip Rn4871 Firmware+519/12/202217/6/2026
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) mishandles reject messages.
ModificadaMedia (6.5)0.49%—Microchip Bm78 FirmwareMicrochip Bm83 FirmwareMicrochip Rn4870 FirmwareMicrochip Rn4871 Firmware+519/12/202217/6/2026
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PairCon_rmSend with incorrect values.
ModificadaMedia (5.4)0.68%—Microchip Bm78 FirmwareMicrochip Bm83 FirmwareMicrochip Rn4870 FirmwareMicrochip Rn4871 Firmware+819/12/202217/6/2026
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PauseEncReqPlainText before pairing is complete.
ModificadaMedia (5.4)0.64%—Microchip Bm78 FirmwareMicrochip Bm83 FirmwareMicrochip Rn4870 FirmwareMicrochip Rn4871 Firmware+519/12/202217/6/2026
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) allows attackers to bypass passkey entry in legacy pairing.
ModificadaAlta (7.5)0.77%—Microchip Bm78 FirmwareMicrochip Bm83 FirmwareMicrochip Rn4870 FirmwareMicrochip Rn4871 Firmware+1019/12/202217/6/2026
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) is unresponsive with ConReqTimeoutZero.
ModificadaAlta (7.5)0.89%—Kodcloud Kodexplorer6/12/202217/6/2026
Kodexplorer is a chinese language web based file manager and browser based code editor. Versions prior to 4.50 did not prevent unauthenticated users from requesting arbitrary files from the host OS file system. As a result any files available to the host process may be accessed by arbitrary users. This issue has been…
ModificadaMedia (6.5)3.2%—Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter PlusZohocorp Manageengine Assetexplorer23/11/202217/6/2026
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to a validation bypass that allows users to access sensitive data via the report module.
ModificadaMedia (4.9)3.7%—Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter PlusZohocorp Manageengine Assetexplorer23/11/202217/6/2026
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to an XML External Entity attack that leads to Information Disclosure.
ModificadaMedia (5.3)0.56%—Jenkins S3 Explorer19/10/202217/6/2026
Jenkins S3 Explorer Plugin 1.0.8 and earlier does not mask the AWS_SECRET_ACCESS_KEY form field, increasing the potential for attackers to observe and capture it.
ModificadaCrítica (9.8)1.7%—10-strike Network Inventory Explorer23/9/202217/6/2026
10-Strike Network Inventory Explorer v9.3 was discovered to contain a buffer overflow via the Add Computers function.
ModificadaAlta (7.5)6.2%—Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter PlusZohocorp Manageengine Assetexplorer12/7/202217/6/2026
Zoho ManageEngine ServiceDesk Plus before 13008, ServiceDesk Plus MSP before 10606, and SupportCenter Plus before 11022 are affected by an unauthenticated local file disclosure vulnerability via ticket-creation email. (This also affects Asset Explorer before 6977 with authentication.)
ModificadaCrítica (9.8)2.0%—Pypi Explore24/6/202217/6/2026
The KGExplore package in PyPI v0.1.1 to v0.1.2 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
ModificadaAlta (7.8)0.29%—Naver Cloud Explorer13/6/202217/6/2026
Naver Cloud Explorer Beta allows the attacker to execute arbitrary code as System privilege via malicious DLL injection.
ModificadaAlta (8.1)2.0%—Caphyon Advanced Installer3CX Call Flow Designer3CX CRM Template GeneratorBoomtv Streamer Portal+666/6/20229/7/2026
Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected…
ModificadaCrítica (9.8)4.1%—Exploreit Explore CMS9/5/202217/6/2026
Explore CMS v1.0 was discovered to contain a SQL injection vulnerability via a /page.php?id= request.
ModificadaAlta (7.8)0.46%—Systemexplorer System Explorer4/4/202217/6/2026
An Unquoted Service Path vulnerability exists in System Explorer 7.0.0 via via a specially crafted file in the SystemExplorerHelpService service executable path.
ModificadaMedia (4.3)1.6%—Microsoft Azure Data Explorer9/2/202217/6/2026
Azure Data Explorer Spoofing Vulnerability
ModificadaAlta (7.8)0.81%—Opendesign Drawings Explorer21/12/202117/6/2026
An out-of-bounds read vulnerability exists when reading a BMP file using Open Design Alliance (ODA) Drawings Explorer before 2022.12. The specific issue exists after loading BMP files. Unchecked input data from a crafted BMP file leads to an out-of-bounds read. An attacker can leverage this vulnerability to execute…
ModificadaAlta (7.8)0.84%—Opendesign Drawings Explorer5/12/202117/6/2026
An out-of-bounds write vulnerability exists when reading a TIF file using Open Design Alliance (ODA) Drawings Explorer before 2022.11. The specific issue exists after loading TIF files. Crafted data in a TIF file can trigger a write operation past the end of an allocated buffer. An attacker can leverage this…
ModificadaMedia (4.6)0.42%—File Explorer Project File Explorer22/10/202117/6/2026
An issue in the authentication mechanism in Nong Ge File Explorer v1.4 unauthenticated allows to access sensitive data.
ModificadaMedia (6.5)0.56%—Netexplorer MY Smtp Contact10/8/202117/6/2026
A cross-site request forgery (CSRF) vulnerability in the My SMTP Contact v1.1.1 plugin for GetSimple CMS allows remote attackers to change the SMTP settings of the contact forms for the webpages of the CMS after an authenticated admin visits a malicious third-party site.
ModificadaCrítica (9.8)7.4%—Zohocorp Manageengine Assetexplorer19/7/202117/6/2026
Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allow an attacker to send a NEWSCAN request to a listening agent on the network as well as receive the…