Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
234 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.9) | 0.61% | — | GST Electronics Inohom Nova Panel N7AI | 12/8/2024 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in GST Electronics inohom Nova Panel N7 allows Authentication Bypass. This issue affects inohom Nova Panel N7: through 1.9.9.6. NOTE: The vendor was contacted and it was learned that the product is not supported. | |
| Modificada | Media (6.5) | 0.95% | — | Openstack Nova | 24/7/2024 | 17/6/2026 | In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the… | |
| Modificada | Media (6.5) | 0.83% | — | Openstack CinderOpenstack GlanceOpenstack Nova | 5/7/2024 | 17/6/2026 | An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that… | |
| Modificada | Media (6.3) | 0.26% | — | Technovama Quotes FOR Woocommerce | 12/6/2024 | 17/6/2026 | Missing Authorization vulnerability in TechnoVama Quotes for WooCommerce.This issue affects Quotes for WooCommerce: from n/a through 2.0.1. | |
| Aplazada | Media (6.3) | 0.46% | — | Innovaphone MypbxAI | 22/4/2024 | 9/7/2026 | Cross Site Scripting vulnerability in Innovaphone myPBX v.14r1, v.13r3, v.12r2 allows a remote attacker to execute arbitrary code via the query parameter to the /CMD0/xml_modes.xml endpoint | |
| Analizada | Media (5.3) | 0.47% | — | Innovaphone PBX | 27/2/2024 | 17/6/2026 | An issue was discovered in the Forgot password function in Innovaphone PBX before 14r1 devices. It provides information about whether a user exists on a system. | |
| Analizada | Media (6.5) | 0.31% | — | Innovaphone PBX | 27/2/2024 | 17/6/2026 | An issue was discovered on Innovaphone PBX before 14r1 devices. The password form, used to authenticate, allows a Brute Force Attack through which an attacker may be able to access the administration panel | |
| Modificada | Crítica (9.8) | 0.61% | — | Innovadeluxe Manufacturer OR Supplier Alphabetical Search | 9/2/2024 | 17/6/2026 | SQL injection vulnerability in InnovaDeluxe "Manufacturer or supplier alphabetical search" (idxrmanufacturer) module for PrestaShop versions 2.0.4 and before, allows remote attackers to escalate privileges and obtain sensitive information via the methods IdxrmanufacturerFunctions::getCornersLink,… | |
| Modificada | Alta (7.5) | 0.57% | — | Progress OpenedgeProgress Openedge Innovation | 18/1/2024 | 17/6/2026 | This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases prior to 12.8.0 . An attacker who can produce a malformed web request may cause the crash of a PASOE agent potentially disrupting the thread activities of many web… | |
| Modificada | Crítica (9.9) | 0.56% | — | Progress OpenedgeProgress Openedge Innovation | 18/1/2024 | 17/6/2026 | This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases prior to 12.8.0. An attacker can formulate a request for a WEB transport that allows unintended file uploads to a server directory path on the system running PASOE. If the… | |
| Modificada | Alta (7.8) | 0.24% | — | Innovadeluxe Quick Order | 28/12/2023 | 17/6/2026 | SQL Injection vulnerability in the Innovadeluxe Quick Order module for PrestaShop before v.1.4.0, allows local attackers to execute arbitrary code via the getProducts() function in the productlist.php file. | |
| Modificada | Media (5.9) | 94% | 💥 Exploit | Openbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+64 | 18/12/2023 | 17/6/2026 | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some… | |
| Modificada | Alta (7.5) | 0.82% | — | Idnovate Superuser | 31/10/2023 | 17/6/2026 | An issue in the component SuperUserSetuserModuleFrontController:init() of idnovate superuser before v2.4.2 allows attackers to bypass authentication via a crafted HTTP call. | |
| Modificada | Crítica (9.8) | 0.62% | — | Minovateknoloji Etrace | 24/5/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Minova Technology eTrace allows SQL Injection. This issue affects eTrace: before 23.05.20. | |
| Modificada | Alta (7.5) | 1.8% | — | Illumina Iscan FirmwareIllumina Iseq 100 FirmwareIllumina Miniseq FirmwareIllumina Miseq Firmware+7 | 28/4/2023 | 17/6/2026 | Instruments with Illumina Universal Copy Service v2.x are vulnerable due to binding to an unrestricted IP address. An unauthenticated malicious actor could use UCS to listen on all IP addresses, including those capable of accepting remote communications. | |
| Modificada | Crítica (9.8) | 0.92% | — | Illumina Iscan FirmwareIllumina Iseq 100 FirmwareIllumina Miniseq FirmwareIllumina Miseq Firmware+7 | 28/4/2023 | 17/6/2026 | Instruments with Illumina Universal Copy Service v1.x and v2.x contain an unnecessary privileges vulnerability. An unauthenticated malicious actor could upload and execute code remotely at the operating system level, which could allow an attacker to change settings, configurations, software, or access sensitive data… | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Idnovate Popup Module (ON Entering, Exit Popup, ADD Product) AND Newsletter | 12/4/2023 | 17/6/2026 | Prestashop advancedpopupcreator v1.1.21 to v1.1.24 was discovered to contain a SQL injection vulnerability via the component AdvancedPopup::getPopups(). | |
| Modificada | Alta (7.5) | 0.39% | — | Sauter-controls Nova 220 Eyk220f001 FirmwareSauter-controls Nova 230 Eyk230f001 FirmwareSauter-controls Nova 106 Eyk300f001 FirmwareSauter-controls Modunet300 Ey-am300f001 Firmware+2 | 2/3/2023 | 17/6/2026 | SAUTER Controls Nova 200–220 Series with firmware version 3.3-006 and prior and BACnetstac version 4.2.1 and prior have only FTP and Telnet available for device management. Any sensitive information communicated through these protocols, such as credentials, is sent in cleartext. An attacker could obtain sensitive… | |
| Modificada | Crítica (10) | 1.2% | — | Baicells Neutrino 430 FirmwareBaicells Nova430l FirmwareBaicells Nova430e FirmwareBaicells Nova436q Firmware | 11/2/2023 | 17/6/2026 | Baicells Nova 436Q, Nova 430E, Nova 430I, and Neutrino 430 LTE TDD eNodeB devices with firmware through QRTB 2.12.7 are vulnerable to remote shell code exploitation via HTTP command injections. Commands are executed using pre-login execution and executed with root permissions. The following methods below have been… | |
| Modificada | Media (5.7) | 1.0% | — | Openstack CinderOpenstack GlanceOpenstack NovaDebian Linux | 26/1/2023 | 17/6/2026 | An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0. By supplying a specially created VMDK flat image that references a specific backing file path, an authenticated user… | |
| Modificada | Alta (8.8) | 0.71% | — | Sauter-controls Nova 220 Eyk220f001 FirmwareSauter-controls Nova 230 Eyk230f001 FirmwareSauter-controls Nova 106 Eyk300f001 FirmwareSauter-controls Modunet300 Ey-am300f001 Firmware+1 | 20/1/2023 | 17/6/2026 | SAUTER Controls Nova 200–220 Series with firmware version 3.3-006 and prior and BACnetstac version 4.2.1 and prior allows the execution of commands without credentials. As Telnet and file transfer protocol (FTP) are the only protocols available for device management, an unauthorized user could access the system and… | |
| Modificada | Media (6.1) | 0.52% | — | Ingnovarq Project Ingnovarq | 1/1/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in admont28 Ingnovarq. Affected by this issue is some unknown functionality of the file app/controller/insertarSliderAjax.php. The manipulation of the argument imagetitle leads to cross site scripting. The attack may be launched remotely. The name of… | |
| Modificada | Alta (7.2) | 1.3% | — | Innovaphone Firmware | 30/9/2022 | 17/6/2026 | AP Manager in Innovaphone before 13r2 Service Release 17 allows command injection via a modified service ID during app upload. | |
| Modificada | Baja (3.3) | 0.31% | — | Openstack Nova | 3/8/2022 | 17/6/2026 | An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and 25.x before 25.0.2. By creating a neutron port with the direct vnic_type, creating an instance bound to that port, and then changing the vnic_type of the bound port to macvtap, an authenticated user may cause the compute service to fail… | |
| Modificada | Alta (8.8) | 1.6% | — | Novastar Novaicare | 12/7/2022 | 17/6/2026 | An issue has been discovered in Novastar-VNNOX-iCare Novaicare 7.16.0 that gives attacker privilege escalation and allows attackers to view corporate information and SMTP server details, delete users, view roles, and other unspecified impacts. NOTE: As of April 2026, the vendor has officially decommissioned the… |