Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1025 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.12% | — | Dell EMC Idrac Service Module | 21/8/2025 | 17/6/2026 | Dell iDRAC Service Module (iSM), versions prior to 6.0.3.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution. | |
| Aplazada | Alta (8.8) | 0.41% | — | Schneider-electric 5032 16pt Digital Configurable ModuleAI | 14/8/2025 | 17/6/2026 | A security issue exists within the 5032 16pt Digital Configurable module’s web server. Intercepted session credentials can be used within a 3-minute timeout window, allowing unauthorized users to perform privileged actions. | |
| Aplazada | Alta (8.8) | 0.41% | — | Phoenixcontact 5032 16pt Digital Configurable ModuleAI | 14/8/2025 | 17/6/2026 | A security issue exists within the 5032 16pt Digital Configurable module’s web server. The web server’s session number increments at an interval that correlates to the last two consecutive sign in session interval, making it predictable. | |
| Aplazada | Crítica (9.3) | 0.85% | — | Rockwellautomation Controllogix Ethernet ModulesAI | 14/8/2025 | 17/6/2026 | A security issue exists due to the web-based debugger agent enabled on Rockwell Automation ControlLogix® Ethernet Modules. If a specific IP address is used to connect to the WDB agent, it can allow remote attackers to perform memory dumps, modify memory, and control execution flow. | |
| Aplazada | Media (5.6) | 0.10% | — | Intel TDX Module FirmwareAI | 12/8/2025 | 17/6/2026 | Improper locking for some Intel(R) TDX Module firmware before version 1.5.13 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (5.7) | 0.13% | — | Intel TDX Module | 12/8/2025 | 31/8/2026 | Out-of-bounds read in some Intel(R) TDX module software before version TDX_1.5.07.00.774 may allow an authenticated user to potentially enable information disclosure via local access. | |
| Aplazada | Crítica (9.1) | 0.83% | — | Mitsubishi Electric Corporation Melsec Iq-f Series CPU ModulesAI | 29/5/2025 | 17/6/2026 | Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU modules allows a remote unauthenticated attacker to read information in the product, to cause a Denial-of-Service (DoS) condition in MELSOFT connection, or to stop the operation… | |
| Aplazada | Alta (7.1) | 0.28% | — | Saurabh Sharma WP Post Modules FOR ElementorAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SaurabhSharma WP Post Modules for Elementor wp-post-modules-el allows Reflected XSS.This issue affects WP Post Modules for Elementor: from n/a through <= 2.5.0. | |
| Aplazada | Alta (7.1) | 0.26% | — | Ms/tp Point Pickup ModuleAI | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in MS/TP Point Pickup Module (All versions). Affected devices improperly handle specific incoming BACnet MSTP messages. This could allow an attacker residing in the same BACnet network to send a specially crafted MSTP message that results in a denial of service condition of the… | |
| Aplazada | Alta (7.5) | 0.91% | — | Mitsubishielectric Cc-link IE TSN Remote IO ModuleAIMitsubishielectric Cc-link IE TSN Analog-digital Converter ModuleAIMitsubishielectric Cc-link IE TSN Digital-analog Converter ModuleAIMitsubishielectric Cc-link IE TSN Fpga ModuleAI+8 | 25/4/2025 | 27/8/2026 | Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module, CC-Link IE TSN Analog-Digital Converter module, CC-Link IE TSN Digital-Analog Converter module, CC-Link IE TSN FPGA module, CC-Link IE TSN Remote Station Communication LSI CP620 with… | |
| Modificada | Alta (7.7) | 0.81% | — | Openresty Lua-nginx-module | 22/4/2025 | 17/6/2026 | An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request. | |
| Aplazada | Crítica (9.1) | 0.85% | 💥 PoC | Ksix Zigbee Gateway ModuleAIKsix Door SensorAIKsix Motion SensorAI | 15/4/2025 | 17/6/2026 | A replay attack vulnerability was discovered in a Zigbee smart home kit manufactured by Ksix (Zigbee Gateway Module = v1.0.3, Door Sensor = v1.0.7, Motion Sensor = v1.0.12), where the Zigbee anti-replay mechanism - based on the frame counter field - is improperly implemented. As a result, an attacker within wireless… | |
| Aplazada | Media (6) | 0.17% | — | Arctera Enterprise Vault Collection ModuleAIVeritas Ediscovery PlatformAI | 15/4/2025 | 17/6/2026 | Arctera eDiscovery Platform before 10.3.2, when Enterprise Vault Collection Module is used, places a cleartext password on a command line in EVSearcher. | |
| Aplazada | Media (4.3) | 0.30% | — | Acmemediakits Acme-divi-modulesAI | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in acmemediakits ACME Divi Modules acme-divi-modules allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ACME Divi Modules: from n/a through <= 1.3.5. | |
| Aplazada | Media (5.8) | 0.33% | — | Stellarwp Give - Divi Donation ModulesAI | 23/2/2025 | 17/6/2026 | Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in StellarWP Give – Divi Donation Modules give-donation-modules-for-divi allows Retrieve Embedded Sensitive Data.This issue affects Give – Divi Donation Modules: from n/a through <= 2.0.0. | |
| Aplazada | Alta (7.1) | 0.26% | — | Brandexponents Oshine ModulesAI | 16/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandexponents Oshine Modules oshine-modules allows Reflected XSS.This issue affects Oshine Modules: from n/a through < 3.3.8. | |
| Aplazada | Alta (7.5) | 0.55% | — | Module-from-stringAI | 5/2/2025 | 17/6/2026 | A prototype pollution in the lib.requireFromString function of module-from-string v3.3.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload. | |
| Aplazada | Baja (1.3) | 0.43% | — | Maxd Lightning ModuleAIOpencartAI | 3/2/2025 | 17/6/2026 | A vulnerability was determined in MaxD Lightning Module 4.43/4.44 on OpenCart. This issue affects some unknown processing. Executing a manipulation of the argument li_op/md can lead to deserialization. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is assessed… | |
| Aplazada | Media (5.4) | 0.26% | — | Brandexponents Oshine ModulesAI | 31/1/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in brandexponents Oshine Modules oshine-modules.This issue affects Oshine Modules: from n/a through < 3.3.8. | |
| Aplazada | Media (6.3) | 0.38% | — | Shiprocket ModuleAIOpencartAI | 20/1/2025 | 17/6/2026 | A vulnerability was found in Shiprocket Module 3 on OpenCart. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php?route=extension/module/rest_api&action=getOrders of the component REST API Module. The manipulation of the argument contentHash leads to incorrect… | |
| Aplazada | Media (6.9) | 0.39% | — | Shiprocket ModuleAIOpencartAI | 20/1/2025 | 17/6/2026 | A vulnerability was found in Shiprocket Module 3/4 on OpenCart. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /index.php?route=extension/shiprocket/module/restapi of the component REST API Module. The manipulation of the argument x-username leads to sql… | |
| Aplazada | Crítica (10) | 0.39% | — | Roblox Bible ModuleAI | 17/1/2025 | 17/6/2026 | Bible Module is a tool designed for ROBLOX developers to integrate Bible functionality into their games. The `FetchVerse` and `FetchPassage` functions in the Bible Module are susceptible to injection attacks due to the absence of input validation. This vulnerability could allow an attacker to manipulate the API… | |
| Analizada | Crítica (9.8) | 0.46% | — | Opigno Module | 9/1/2025 | 17/6/2026 | Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno module allows PHP Local File Inclusion.This issue affects Opigno module: from 0.0.0 before 3.1.2. | |
| Analizada | Media (5.3) | 0.32% | — | Huawei IPS Module FirmwareHuawei Ngfw Module FirmwareHuawei Nip6300 FirmwareHuawei Nip6600 Firmware+5 | 28/12/2024 | 17/6/2026 | There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt… | |
| Analizada | Media (5.3) | 0.25% | — | Huawei IPS Module FirmwareHuawei Ngfw Module FirmwareHuawei Nip6300 FirmwareHuawei Nip6600 Firmware+5 | 28/12/2024 | 17/6/2026 | There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt… |