Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

234 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.9)0.61%—GST Electronics Inohom Nova Panel N7AI12/8/202417/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in GST Electronics inohom Nova Panel N7 allows Authentication Bypass. This issue affects inohom Nova Panel N7: through 1.9.9.6. NOTE: The vendor was contacted and it was learned that the product is not supported.
ModificadaMedia (6.5)0.95%—Openstack Nova24/7/202417/6/2026
In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the…
ModificadaMedia (6.5)0.83%—Openstack CinderOpenstack GlanceOpenstack Nova5/7/202417/6/2026
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that…
ModificadaMedia (6.3)0.26%—Technovama Quotes FOR Woocommerce12/6/202417/6/2026
Missing Authorization vulnerability in TechnoVama Quotes for WooCommerce.This issue affects Quotes for WooCommerce: from n/a through 2.0.1.
AplazadaMedia (6.3)0.46%—Innovaphone MypbxAI22/4/20249/7/2026
Cross Site Scripting vulnerability in Innovaphone myPBX v.14r1, v.13r3, v.12r2 allows a remote attacker to execute arbitrary code via the query parameter to the /CMD0/xml_modes.xml endpoint
AnalizadaMedia (5.3)0.47%—Innovaphone PBX27/2/202417/6/2026
An issue was discovered in the Forgot password function in Innovaphone PBX before 14r1 devices. It provides information about whether a user exists on a system.
AnalizadaMedia (6.5)0.31%—Innovaphone PBX27/2/202417/6/2026
An issue was discovered on Innovaphone PBX before 14r1 devices. The password form, used to authenticate, allows a Brute Force Attack through which an attacker may be able to access the administration panel
ModificadaCrítica (9.8)0.61%—Innovadeluxe Manufacturer OR Supplier Alphabetical Search9/2/202417/6/2026
SQL injection vulnerability in InnovaDeluxe "Manufacturer or supplier alphabetical search" (idxrmanufacturer) module for PrestaShop versions 2.0.4 and before, allows remote attackers to escalate privileges and obtain sensitive information via the methods IdxrmanufacturerFunctions::getCornersLink,…
ModificadaAlta (7.5)0.57%—Progress OpenedgeProgress Openedge Innovation18/1/202417/6/2026
This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases prior to 12.8.0 . An attacker who can produce a malformed web request may cause the crash of a PASOE agent potentially disrupting the thread activities of many web…
ModificadaCrítica (9.9)0.56%—Progress OpenedgeProgress Openedge Innovation18/1/202417/6/2026
This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases prior to 12.8.0. An attacker can formulate a request for a WEB transport that allows unintended file uploads to a server directory path on the system running PASOE. If the…
ModificadaAlta (7.8)0.24%—Innovadeluxe Quick Order28/12/202317/6/2026
SQL Injection vulnerability in the Innovadeluxe Quick Order module for PrestaShop before v.1.4.0, allows local attackers to execute arbitrary code via the getProducts() function in the productlist.php file.
ModificadaMedia (5.9)94%💥 ExploitOpenbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+6418/12/202317/6/2026
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some…
ModificadaAlta (7.5)0.82%—Idnovate Superuser31/10/202317/6/2026
An issue in the component SuperUserSetuserModuleFrontController:init() of idnovate superuser before v2.4.2 allows attackers to bypass authentication via a crafted HTTP call.
ModificadaCrítica (9.8)0.62%—Minovateknoloji Etrace24/5/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Minova Technology eTrace allows SQL Injection. This issue affects eTrace: before 23.05.20.
ModificadaAlta (7.5)1.8%—Illumina Iscan FirmwareIllumina Iseq 100 FirmwareIllumina Miniseq FirmwareIllumina Miseq Firmware+728/4/202317/6/2026
Instruments with Illumina Universal Copy Service v2.x are vulnerable due to binding to an unrestricted IP address. An unauthenticated malicious actor could use UCS to listen on all IP addresses, including those capable of accepting remote communications.
ModificadaCrítica (9.8)0.92%—Illumina Iscan FirmwareIllumina Iseq 100 FirmwareIllumina Miniseq FirmwareIllumina Miseq Firmware+728/4/202317/6/2026
Instruments with Illumina Universal Copy Service v1.x and v2.x contain an unnecessary privileges vulnerability. An unauthenticated malicious actor could upload and execute code remotely at the operating system level, which could allow an attacker to change settings, configurations, software, or access sensitive data…
ModificadaCrítica (9.8)3.0%💥 ExploitIdnovate Popup Module (ON Entering, Exit Popup, ADD Product) AND Newsletter12/4/202317/6/2026
Prestashop advancedpopupcreator v1.1.21 to v1.1.24 was discovered to contain a SQL injection vulnerability via the component AdvancedPopup::getPopups().
ModificadaAlta (7.5)0.39%—Sauter-controls Nova 220 Eyk220f001 FirmwareSauter-controls Nova 230 Eyk230f001 FirmwareSauter-controls Nova 106 Eyk300f001 FirmwareSauter-controls Modunet300 Ey-am300f001 Firmware+22/3/202317/6/2026
SAUTER Controls Nova 200–220 Series with firmware version 3.3-006 and prior and BACnetstac version 4.2.1 and prior have only FTP and Telnet available for device management. Any sensitive information communicated through these protocols, such as credentials, is sent in cleartext. An attacker could obtain sensitive…
ModificadaCrítica (10)1.2%—Baicells Neutrino 430 FirmwareBaicells Nova430l FirmwareBaicells Nova430e FirmwareBaicells Nova436q Firmware11/2/202317/6/2026
Baicells Nova 436Q, Nova 430E, Nova 430I, and Neutrino 430 LTE TDD eNodeB devices with firmware through QRTB 2.12.7 are vulnerable to remote shell code exploitation via HTTP command injections. Commands are executed using pre-login execution and executed with root permissions. The following methods below have been…
ModificadaMedia (5.7)1.0%—Openstack CinderOpenstack GlanceOpenstack NovaDebian Linux26/1/202317/6/2026
An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0. By supplying a specially created VMDK flat image that references a specific backing file path, an authenticated user…
ModificadaAlta (8.8)0.71%—Sauter-controls Nova 220 Eyk220f001 FirmwareSauter-controls Nova 230 Eyk230f001 FirmwareSauter-controls Nova 106 Eyk300f001 FirmwareSauter-controls Modunet300 Ey-am300f001 Firmware+120/1/202317/6/2026
SAUTER Controls Nova 200–220 Series with firmware version 3.3-006 and prior and BACnetstac version 4.2.1 and prior allows the execution of commands without credentials. As Telnet and file transfer protocol (FTP) are the only protocols available for device management, an unauthorized user could access the system and…
ModificadaMedia (6.1)0.52%—Ingnovarq Project Ingnovarq1/1/202317/6/2026
A vulnerability, which was classified as problematic, has been found in admont28 Ingnovarq. Affected by this issue is some unknown functionality of the file app/controller/insertarSliderAjax.php. The manipulation of the argument imagetitle leads to cross site scripting. The attack may be launched remotely. The name of…
ModificadaAlta (7.2)1.3%—Innovaphone Firmware30/9/202217/6/2026
AP Manager in Innovaphone before 13r2 Service Release 17 allows command injection via a modified service ID during app upload.
ModificadaBaja (3.3)0.31%—Openstack Nova3/8/202217/6/2026
An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and 25.x before 25.0.2. By creating a neutron port with the direct vnic_type, creating an instance bound to that port, and then changing the vnic_type of the bound port to macvtap, an authenticated user may cause the compute service to fail…
ModificadaAlta (8.8)1.6%—Novastar Novaicare12/7/202217/6/2026
An issue has been discovered in Novastar-VNNOX-iCare Novaicare 7.16.0 that gives attacker privilege escalation and allows attackers to view corporate information and SMTP server details, delete users, view roles, and other unspecified impacts. NOTE: As of April 2026, the vendor has officially decommissioned the…
Orbitaley — Vulnerabilidades