Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3090▲ 501 respecto a la semana anterior
Críticas / altas1463▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

21.656 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.26%—Event OrganiserAI1/7/20261/7/2026
The Event Organiser plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.12.9. This is due to the 'eo_events' shortcode accepting attacker-controlled 'no_events' content and rendering it in event list templates without output escaping. This makes it possible for…
AplazadaMedia (5.3)0.29%—Invoiceninja Invoice NinjaAI30/6/202614/7/2026
Invoice Ninja through 5.13.26 contains an open redirect vulnerability in the client portal login that allows unauthenticated attackers to redirect authenticated victims to attacker-controlled external URLs by injecting a malicious value into the intended query parameter. Attackers can craft a client login link with an…
AplazadaAlta (7.1)0.41%—Nightingale N9EAI30/6/202614/7/2026
Nightingale (n9e) before 9.0.0-beta.2 exposes full datasource configurations, including plaintext database passwords, HTTP bearer tokens, HTTP basic-auth passwords, and mTLS client keys, to any authenticated low-privilege (Standard role) user through POST /api/n9e/datasource/list. The route is registered without an…
AplazadaMedia (6.1)0.25%—Eksagate Electronic Engineering AND Computer Industry Trade Sysguard 6001AI30/6/202630/6/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. SYSGUARD 6001 allows Stored XSS. This issue affects SYSGUARD 6001: from 2.0.2 before 6.1.4.0. NOTE: The vendor was contacted and it was learned that the…
AplazadaCrítica (9.8)0.47%—Eksagate Electronic Engineering AND Computer Industry Trade Sysguard 6001AI30/6/202630/6/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. SYSGUARD 6001 allows Blind SQL Injection. This issue affects SYSGUARD 6001: from 2.0.2 before 6.1.16.0. NOTE: The vendor was contacted and it was…
AplazadaMedia (5.1)0.34%—Ricoh WEB Image MonitorAI30/6/202631/8/2026
Multiple laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor contain a reflected cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who accesses a crafted URL.
AplazadaCrítica (9.3)0.54%—Delta Electronics Dvp12seAI30/6/202630/6/2026
Delta Electronics DVP12SE PLC exposes a Modbus TCP service over a specified port without authentication or access control, permitting unauthenticated interaction with security-sensitive PLC functions.
AplazadaCrítica (9.3)0.43%—Delta Electronics Dvp12seAI30/6/202630/6/2026
Delta Electronics DVP12SE PLCs are susceptible to a resource allocation vulnerability without limits or throttling (CWE-770) within their Modbus TCP service.
AplazadaAlta (7.5)0.49%—Javascript Minifier XSAI29/6/202630/6/2026
JavaScript::Minifier::XS versions before 0.16 for Perl crash with a NULL pointer dereference when the first meaningful token of the input is a slash. The regexp versus division disambiguator in JsTokenizeString (XS.xs) inspects the previous token's last byte to choose between a regexp literal and a division operator.…
AplazadaMedia (6.5)0.29%—CSS Minifier XSAI29/6/202630/6/2026
CSS::Minifier::XS versions before 0.14 for Perl have a memory leak when the entire document is minified away. The minify function has a memory leak when processing a document containing only characters to be removed, such as comments and whitespace.
AplazadaAlta (7.7)2.3%—Luci-app-tailscale-communityAI29/6/202614/7/2026
luci-app-tailscale-community contains a command injection vulnerability in the tailscale.do_login RPC method that allows authenticated users to execute arbitrary commands as root. The vulnerability exists because user-controlled loginserver and loginserver_authkey parameters are improperly quoted within a…
AplazadaAlta (7.7)0.48%—NitterAI29/6/202614/7/2026
Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and uses a hardcoded default HMAC key, allowing unauthenticated attackers to compute valid HMACs for arbitrary URLs. Attackers can retrieve HTTP responses from any host reachable by the server, including cloud metadata…
AnalizadaMedia (6.5)0.44%—Devolutions Powershell Universal29/6/20262/7/2026
Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent read access to obtain reusable, potentially higher-privileged authentication tokens via App Tokens serialized in plaintext in job API responses.
AplazadaMedia (6.5)0.33%—Artisanworkshop Japanized FOR WoocommerceAI29/6/202629/6/2026
Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions.
AplazadaAlta (7.5)0.26%—Home-assistant IOS Companion APPAI29/6/202630/6/2026
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2025.5.0, The iOS companion app ignores the SSID allowlist for internal networks. The app uses SSID to detect when to use the internal URL, but whenever the app cannot find any other URL to be used, it fallbacks…
AplazadaMedia (4.3)0.26%—Harmonicdesign HD QuizAI27/6/202629/6/2026
The HD Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.2.0 to 2.2.1. This is due to missing or incorrect nonce validation on the hdq_validate_nonce function. This makes it possible for unauthenticated attackers to delete or modify quizzes and questions, create new quizzes, and…
AnalizadaAlta (8.4)0.44%—Daktronics Dmp-5000 FirmwareDaktronics Dmp-8000 FirmwareDaktronics Vfc-dmp-5000 Firmware26/6/20266/7/2026
The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filtering or content inspection is enforced which allows executable binaries and scripts to be accepted and…
AnalizadaCrítica (9.3)0.57%—Daktronics Dmp-5000 FirmwareDaktronics Dmp-8000 FirmwareDaktronics Vfc-dmp-5000 Firmware26/6/20266/7/2026
The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed during initial configuration or operation. Using these accounts provides full system access.
AnalizadaCrítica (9.3)0.68%—Daktronics Dmp-5000 FirmwareDaktronics Dmp-8000 FirmwareDaktronics Vfc-dmp-5000 Firmware26/6/20266/7/2026
Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape the intended directory and enumerate arbitrary file system paths.
AplazadaAlta (7.5)0.55%—Technitium DNS ServerAI26/6/20265/7/2026
An issue in Technitium DNS Server v.14.3 and before allows a remote attacker to cause a denial of service via the DnsServerApp.exe, DnsServerApp.dll, TechnitiumLibrary.Net/Dns/DnsClient.cs components
AnalizadaMedia (5)0.28%—Canonical LXD26/6/20266/7/2026
In Canonical LXD versions 4.12 through 6.9, a Server-Side Request Forgery (SSRF) vulnerability in the image import functionality allows authenticated users with the can_create_images entitlement to interact with internal network infrastructure via the /images endpoint. When importing an image from a URL source, the…
AnalizadaAlta (7.2)0.63%—Canonical LXD26/6/20262/7/2026
A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restriction policies during snapshot restoration.. An authenticated project operator in a restricted multi-tenant environment can bypass policy restrictions by…
AnalizadaMedia (6.5)0.55%—Canonical LXD26/6/20262/7/2026
Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted custom-volume backup tarball that omits the expires_at snapshot field.
AnalizadaCrítica (9.6)0.29%—Canonical LXD26/6/20262/7/2026
Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when security.devlxd.management.volumes is enabled.
AplazadaMedia (5.4)0.29%—Omnisend Email Marketing FOR WoocommerceAI26/6/202626/6/2026
Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions.