Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

822 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.8)0.33%—Svenstaro Miniserve23/1/202617/6/2026
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared…
AplazadaCrítica (9.8)1.8%—Katana Network Development Starter KITAI23/1/202617/6/2026
Katana Network Development Starter Kit executeCommand Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Katana Network Development Starter Kit. Authentication is not required to exploit this vulnerability. The…
AnalizadaAlta (7.8)0.37%—Anritsu Vectorstar23/1/202617/6/2026
Anritsu VectorStar CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Anritsu VectorStar. User interaction is required to exploit this vulnerability in that the target must visit a…
AnalizadaAlta (7.8)0.37%—Anritsu Vectorstar23/1/202617/6/2026
Anritsu VectorStar CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Anritsu VectorStar. User interaction is required to exploit this vulnerability in that the target must visit a…
AplazadaCrítica (9)0.37%—Vollstart Event Tickets With Ticket ScannerAI22/1/202617/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Code Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through <= 2.8.5.
AnalizadaMedia (6.9)0.46%—Hamastar Meetinghub Paperless Meetings22/1/202617/6/2026
MeetingHub developed by HAMASTAR Technology has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access specific API functions and obtain meeting-related information.
AnalizadaCrítica (9.3)0.76%—Hamastar Meetinghub Paperless Meetings22/1/202617/6/2026
MeetingHub developed by HAMASTAR Technology has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
AnalizadaAlta (8.7)0.67%—Hamastar Meetinghub Paperless Meetings22/1/202617/6/2026
MeetingHub developed by HAMASTAR Technology has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.
AplazadaAlta (8.5)0.32%—Rockstargames Rockstar Games LauncherAI21/1/202617/6/2026
Rockstar Games Launcher 1.0.37.349 contains a privilege escalation vulnerability that allows authenticated users to modify the service executable with weak permissions. Attackers can replace the RockstarService.exe with a malicious binary to create a new administrator user and gain elevated system access.
AnalizadaMedia (5.4)0.22%—Thestarware Worklogpro21/1/202617/6/2026
The WorklogPRO - Timesheets for Jira plugin in Jira Data Center before version 4.23.6-jira10 and before version 4.23.5-jira9 allows users and attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability. The vulnerability is exploited via a specially crafted payload placed in an…
AnalizadaAlta (8.7)0.64%—Rockwellautomation Armorstart LT Firmware20/1/202617/6/2026
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP and CIP grammar tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.
AnalizadaAlta (8.7)0.48%—Rockwellautomation Armorstart LT Firmware20/1/202617/6/2026
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive grammar tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.
AnalizadaAlta (8.7)0.39%—Rockwellautomation Armorstart LT Firmware20/1/202617/6/2026
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. This vulnerability is triggered during fuzzing of multiple CIP classes, which causes the CIP port to become unresponsive.
AnalizadaAlta (8.7)0.60%—Rockwellautomation Armorstart LT Firmware20/1/202617/6/2026
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limits Storms tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.
AnalizadaAlta (8.7)0.60%—Rockwellautomation Armorstart LT Firmware20/1/202617/6/2026
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive limited storm tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.
AnalizadaAlta (8.7)0.60%—Rockwellautomation Armorstart LT Firmware20/1/202617/6/2026
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive step limit storm tests, the device reboots
AnalizadaAlta (8.7)0.48%—Rockwellautomation Armorstart LT Firmware20/1/202617/6/2026
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. Fuzzing performed using Defensics causes the device to become unresponsive, requiring a reboot.
AnalizadaAlta (8.7)0.60%—Rockwellautomation Armorstart LT Firmware20/1/202617/6/2026
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limit Storm tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.
AnalizadaAlta (8.7)0.48%—Rockwellautomation Armorstart LT Firmware20/1/202617/6/2026
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. After running a Burp Suite active scan, the device loses ICMP connectivity, causing the web application to become inaccessible.
ModificadaCrítica (9.8)40%💥 ExploitAdvantech IOT Edge Linux DockerAdvantech IOT Edge WindowsAdvantech Iotsuite Growth Linux DockerAdvantech Iotsuite Saas Composer+112/1/202617/6/2026
Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability. Users and administrators of affected product…
AplazadaMedia (6.1)0.36%—Starred ReviewAI7/1/202617/6/2026
The Starred Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the PHP_SELF variable in all versions up to, and including, 1.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
AplazadaAlta (8.6)0.27%—Rustaurius Five Star Restaurant ReservationsAI5/1/202630/9/2026
Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Five Star Restaurant Reservations: from n/a through <= 2.7.4.
AplazadaMedia (5.4)0.20%—Vollstart Serial Codes Generator AND ValidatorAI31/12/202517/6/2026
Missing Authorization vulnerability in Vollstart Serial Codes Generator and Validator with WooCommerce Support serial-codes-generator-and-validator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Serial Codes Generator and Validator with WooCommerce Support: from n/a through…
ModificadaMedia (5.4)0.22%—Qodeinteractive Fivestar30/12/20255/10/2026
Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes FiveStar fivestar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FiveStar: from n/a through <= 1.7.
AplazadaMedia (5.4)0.12%—Rustaurius Five Star Restaurant ReservationsAI24/12/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Cross Site Request Forgery.This issue affects Five Star Restaurant Reservations: from n/a through <= 2.7.8.
Orbitaley — Vulnerabilidades