Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
603 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 9.8% | — | Phoenixcontact FL NAT 2008 FirmwarePhoenixcontact FL NAT 2208 FirmwarePhoenixcontact FL NAT 2304-2gc-2sfp FirmwarePhoenixcontact FL Switch 2005 Firmware+65 | 9/12/2025 | 30/9/2026 | An XSS vulnerability in pxc_portCntr.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as… | |
| Analizada | Alta (7.1) | 9.8% | — | Phoenixcontact FL Switch 2008f FirmwarePhoenixcontact FL Switch 2016 FirmwarePhoenixcontact FL Switch 2105 FirmwarePhoenixcontact FL Switch 2108 Firmware+65 | 9/12/2025 | 30/9/2026 | An XSS vulnerability in pxc_PortCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as… | |
| Analizada | Alta (7.1) | 0.65% | — | Phoenixcontact FL Switch 2008f FirmwarePhoenixcontact FL Switch 2016 FirmwarePhoenixcontact FL Switch 2105 FirmwarePhoenixcontact FL Switch 2108 Firmware+65 | 9/12/2025 | 30/9/2026 | An XSS vulnerability in port_util.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as… | |
| Analizada | Alta (7.1) | 9.8% | — | Phoenixcontact FL NAT 2008 FirmwarePhoenixcontact FL NAT 2208 FirmwarePhoenixcontact FL NAT 2304-2gc-2sfp FirmwarePhoenixcontact FL Switch 2005 Firmware+65 | 9/12/2025 | 30/9/2026 | An XSS vulnerability in pxc_Dot1xCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as… | |
| Analizada | Alta (7.1) | 9.8% | — | Phoenixcontact FL NAT 2008 FirmwarePhoenixcontact FL NAT 2208 FirmwarePhoenixcontact FL NAT 2304-2gc-2sfp FirmwarePhoenixcontact FL Switch 2005 Firmware+65 | 9/12/2025 | 30/9/2026 | An XSS vulnerability in pxc_vlanIntfCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such… | |
| Analizada | Alta (7.1) | 9.8% | — | Phoenixcontact FL Switch 2406-2sfx PN FirmwarePhoenixcontact FL Switch 2408 FirmwarePhoenixcontact FL Switch 2408 PN FirmwarePhoenixcontact FL Switch 2412-2tc-2sfx Firmware+65 | 9/12/2025 | 30/9/2026 | An XSS vulnerability in pxc_portSecCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such… | |
| Analizada | Alta (7.1) | 0.65% | — | Phoenixcontact FL NAT 2008 FirmwarePhoenixcontact FL NAT 2208 FirmwarePhoenixcontact FL NAT 2304-2gc-2sfp FirmwarePhoenixcontact FL Switch 2005 Firmware+65 | 9/12/2025 | 30/9/2026 | An XSS vulnerability in pxc_portCntr2.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as… | |
| Analizada | Media (6.8) | 0.24% | — | Phoenixcontact FL Switch 2708 PN FirmwarePhoenixcontact FL Switch 2708 FirmwarePhoenixcontact FL Switch 2608 PN FirmwarePhoenixcontact FL Switch 2608 Firmware+65 | 9/12/2025 | 30/9/2026 | An attacker can use an undocumented UART port on the PCB as a side-channel to get root access e.g. with the credentials obtained from CVE-2025-41692. | |
| Analizada | Media (4.6) | 0.21% | — | Phoenixcontact FL Switch 2708 PN FirmwarePhoenixcontact FL Switch 2708 FirmwarePhoenixcontact FL Switch 2608 PN FirmwarePhoenixcontact FL Switch 2608 Firmware+65 | 9/12/2025 | 30/9/2026 | An attacker can use an undocumented UART port on the PCB as a side-channel with the user hardcoded credentials obtained from CVE-2025-41692 to gain read access to parts of the filesystem of the device. | |
| Analizada | Alta (7.1) | 0.66% | — | Phoenixcontact FL NAT 2008 FirmwarePhoenixcontact FL NAT 2208 FirmwarePhoenixcontact FL NAT 2304-2gc-2sfp FirmwarePhoenixcontact FL Switch 2005 Firmware+65 | 9/12/2025 | 30/9/2026 | An XSS vulnerability in dyn_conn.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as… | |
| Analizada | Media (6.5) | 0.48% | — | Phoenixcontact FL Switch 2708 PN FirmwarePhoenixcontact FL Switch 2708 FirmwarePhoenixcontact FL Switch 2608 PN FirmwarePhoenixcontact FL Switch 2608 Firmware+65 | 9/12/2025 | 30/9/2026 | A low privileged remote attacker can run the webshell with an empty command containing whitespace. The server will then block until it receives more data, resulting in a DoS condition of the websserver. | |
| Analizada | Media (4.3) | 0.52% | — | Phoenixcontact FL Switch 2708 PN FirmwarePhoenixcontact FL Switch 2708 FirmwarePhoenixcontact FL Switch 2608 PN FirmwarePhoenixcontact FL Switch 2608 Firmware+65 | 9/12/2025 | 30/9/2026 | A low privileged remote attacker can use the ssh feature to execute commands directly after login. The process stays open and uses resources which leads to a reduced performance of the management functions. Switching functionality is not affected. | |
| Analizada | Media (6.8) | 0.30% | — | Phoenixcontact FL Switch 2708 PN FirmwarePhoenixcontact FL Switch 2708 FirmwarePhoenixcontact FL Switch 2608 PN FirmwarePhoenixcontact FL Switch 2608 Firmware+65 | 9/12/2025 | 30/9/2026 | A high privileged remote attacker with admin privileges for the webUI can brute-force the "root" and "user" passwords of the underlying OS due to a weak password generation algorithm. | |
| Aplazada | Alta (7.7) | 0.14% | — | Mitsubishielectric Milco.s Setting ApplicationAIMitsubishielectric Milco.s Easy Setting ApplicationAIMitsubishielectric Milco.s Easy Switch ApplicationAI | 18/11/2025 | 17/6/2026 | Uncontrolled Search Path Element Vulnerability in Setting and Operation Application for Lighting Control System MILCO.S Setting Application all versions, MILCO.S Setting Application (IR) all versions, MILCO.S Easy Setting Application (IR) all versions, and MILCO.S Easy Switch Application (IR) all versions allows a… | |
| Aplazada | Media (5.4) | 0.29% | — | Post Type SwitcherAI | 18/11/2025 | 17/6/2026 | The Post Type Switcher plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.0.0 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access and above, to modify the post type of arbitrary posts… | |
| Analizada | Media (6.5) | 0.23% | — | Samsung Smart Switch | 5/11/2025 | 17/6/2026 | Use of insufficiently random value of secretKey in Smart Switch prior to version 3.7.68.6 allows adjacent attackers to access backup data from applications. | |
| Aplazada | Ninguna (0) | 0.18% | — | Moxa Ethernet SwitchesAI | 23/10/2025 | 17/6/2026 | An acceptance of extraneous untrusted data with trusted data vulnerability has been identified in Moxa’s Ethernet switches, which allows attackers with administrative privileges to manipulate HTTP Host headers by injecting a specially crafted Host header into HTTP requests sent to an affected device’s web service.… | |
| Aplazada | Media (4.8) | 0.33% | — | Moxa Ethernet SwitchesAI | 23/10/2025 | 17/6/2026 | Cross-site Scripting has been identified in Moxa’s Ethernet switches, which allows an authenticated administrative attacker to inject malicious scripts to an affected device’s web service that could impact authenticated users interacting with the device’s web interface. This vulnerability is classified as stored… | |
| Modificada | Crítica (9.8) | 0.58% | — | Fortinet FortipamFortinet Fortiswitchmanager | 14/10/2025 | 17/6/2026 | A weak authentication vulnerability in Fortinet FortiPAM 1.5.0, FortiPAM 1.4.0 through 1.4.2, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiSwitchManager 7.2.0 through 7.2.4 allows attacker to execute unauthorized code or commands via specially crafted… | |
| Analizada | Alta (7.2) | 0.56% | — | Fortinet FortiosFortinet FortipamFortinet FortiproxyFortinet Fortisra+1 | 14/10/2025 | 17/6/2026 | A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0 through 1.4.2, 1.3.0 through 1.3.1, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy 7.6.0 through 7.6.1, 7.4.0 through 7.4.7, FortiOS 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.2… | |
| Analizada | Media (5.3) | 0.47% | — | Fortinet FortiosFortinet FortipamFortinet FortiproxyFortinet Fortiswitchmanager | 14/10/2025 | 17/6/2026 | An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7.4.0 through 7.4.3 and before 7.2.7, FortiProxy version 7.4.0 through 7.4.3 and before 7.2.9, FortiPAM before 1.2.0 and FortiSwitchManager version 7.2.0 through 7.2.3 and version 7.0.0 through 7.0.3 fgfm daemon may… | |
| Analizada | Alta (7.8) | 0.10% | — | Samsung Smart Switch | 10/10/2025 | 17/6/2026 | Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.67.2 allows local attackers to replace the restoring application. User interaction is required for triggering this vulnerability. | |
| Analizada | Media (5.5) | 0.10% | — | Samsung Smart Switch | 10/10/2025 | 17/6/2026 | Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access sensitive data. User interaction is required for triggering this vulnerability. | |
| Analizada | Media (6.5) | 0.27% | — | Samsung Smart Switch | 10/10/2025 | 30/9/2026 | Improper authentication in Smart Switch prior to version 3.7.66.6 allows adjacent attackers to access transferring data. | |
| Analizada | Media (5.5) | 0.10% | — | Samsung Smart Switch | 10/10/2025 | 30/9/2026 | Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access backup data from applications. User interaction is required for triggering this vulnerability. |