Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

119 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.1%—Cybelesoft Thinfinity Virtualui4/6/202017/6/2026
Cybele Thinfinity VirtualUI 2.5.17.2 allows ../ path traversal that can be used for data exfiltration. This enables files outside of the web directory to be retrieved if the exact location is known and the user has permissions.
ModificadaMedia (5.5)0.29%—Hisense Infinity F17 Firmware14/11/201917/6/2026
The Hisense F17 Android device with a build fingerprint of Hisense/F17_4G/HS6739MT:8.1.0/O11019/Hisense_F17_4G_00_S01:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system…
ModificadaMedia (5.5)0.29%—Hisense Infinity U965 Firmware14/11/201917/6/2026
The Hisense U965 Android device with a build fingerprint of Hisense/U965_4G_10/HS6739MT:8.1.0/O11019/Hisense_U965_4G_10_S01:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system…
ModificadaMedia (6.1)0.91%—Pinfinity Project Pinfinity10/9/201917/6/2026
The Pinfinity theme before 2.0 for WordPress has XSS via the s parameter.
ModificadaMedia (6.5)0.79%—Draeger Kappa FirmwareDraeger Infinity Explorer C700 FirmwareDraeger Delta XL FirmwareDraeger Infinity Delta Firmware28/1/201917/6/2026
Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. Log files are accessible over an unauthenticated network connection. By accessing the log files, an attacker is able to gain insights about internals of the patient monitor, the…
ModificadaMedia (6.5)0.77%—Draeger Kappa FirmwareDraeger Infinity Explorer C700 FirmwareDraeger Delta XL FirmwareDraeger Infinity Delta Firmware28/1/201917/6/2026
Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. A malformed network packet may cause the monitor to reboot. By repeatedly sending the malformed network packet, an attacker may be able to disrupt patient monitoring by causing the…
ModificadaAlta (7.8)0.39%—Draeger Kappa FirmwareDraeger Infinity Explorer C700 FirmwareDraeger Delta XL FirmwareDraeger Infinity Delta Firmware28/1/201917/6/2026
Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. Via a specific dialog it is possible to break out of the kiosk mode and reach the underlying operating system. By breaking out of the kiosk mode, an attacker is able to take…
ModificadaAlta (7.5)4.5%—Navarino Infinity24/7/201817/6/2026
Some Navarino Infinity functions, up to version 2.2, placed in the URL can bypass any authentication mechanism leading to an information leak.
ModificadaAlta (8.8)4.0%—Navarino Infinity24/7/201817/6/2026
Navarino Infinity is prone to session fixation attacks. The server accepts the session ID as a GET parameter which can lead to bypassing the two factor authentication in some installations. This could lead to phishing attacks that can bypass the two factor authentication that is present in some installations.
ModificadaCrítica (9.8)4.2%—Navarino Infinity24/7/201817/6/2026
Navarino Infinity web interface up to version 2.2 exposes an unauthenticated script that is prone to blind sql injection. If successfully exploited the user can get info from the underlying postgresql database that could lead into to total compromise of the product. The said script is available with no authentication.
ModificadaAlta (7.5)2.0%—Cybelesoft Thinfinity Remote Desktop Workstation6/10/201717/6/2026
Directory traversal vulnerability in Cybele Software Thinfinity Remote Desktop Workstation 3.0.0.3 32-bit and 64-bit allows remote attackers to download arbitrary files via a .. (dot dot) in an unspecified parameter.
ModificadaCrítica (9.8)1.7%—Libinfinity Project Libinfinity21/7/201717/6/2026
libinfinity before 0.6.6-1 does not validate expired SSL certificates, which allows remote attackers to have unspecified impact via unknown vectors.
ModificadaCrítica (9.8)3.5%—Pexip Infinity2/5/201717/6/2026
Pexip Infinity before 14.2 allows remote attackers to cause a denial of service (service restart) or execute arbitrary code via vectors related to Conferencing Nodes.
ModificadaAlta (7.1)1.4%—Pexip Infinity3/2/201517/6/2026
Pexip Infinity before 8 uses the same SSH host keys across different customers' installations, which allows man-in-the-middle attackers to spoof Management and Conferencing Nodes by leveraging these keys.
ModificadaAlta (7.5)2.2%—Vivaprograms Infinity Script16/11/200916/6/2026
cp/profile.php in VivaPrograms Infinity 2.0.5 and earlier does not require administrative authentication for the donewauthor action, which allows remote attackers to create administrative accounts via the name, password, and conf_password parameters.
ModificadaMedia (6.8)1.0%—Dimofinf Infinity Script16/9/200916/6/2026
SQL injection vulnerability in VivaPrograms Infinity Script 2.x.x, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username field.
ModificadaMedia (6.8)1.9%—Dimofinf Infinity Script16/9/200916/6/2026
Directory traversal vulnerability in VivaPrograms Infinity Script 2.x.x, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the options[style_dir] parameter to the default URI.
ModificadaAlta (7.5)1.1%—Infinity Technologies Infinitytechs Restaurants CM4/12/200616/6/2026
Multiple SQL injection vulnerabilities in Infinitytechs Restaurants CM allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in rating.asp, (2) the mealid parameter in meal_rest.asp, and (3) the resid parameter in res_details.asp.
ModificadaAlta (7.5)1.3%—Websoft Infinity WEB6/12/200416/6/2026
SQL injection vulnerability in Infinity WEB 1.0 allows remote attackers to bypass authentication and gain privileges via the login page.