Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▼ 12 respecto a la semana anterior
Críticas / altas1272▼ 242 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
11.346 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 1.1% | — | Pfsense | 9/9/2025 | 14/7/2026 | In pfSense CE /usr/local/www/haproxy/haproxy_stats.php, the value of the showsticktablecontent parameter is displayed after being read from HTTP GET requests. This can enable reflected cross-site scripting when the victim is authenticated. | |
| Aplazada | Baja (1.9) | 0.14% | — | Zhenshi Mibro FITAI | 9/9/2025 | 17/6/2026 | A flaw has been found in ZhenShi Mibro Fit App 1.6.3.17499 on Android. This impacts an unknown function of the file AndroidManifest.xml of the component com.xiaoxun.xunoversea.mibrofit. This manipulation causes improper export of android application components. The attack requires local access. The exploit has been… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Siemens Simatic Virtualization AS A ServiceAI | 9/9/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC Virtualization as a Service (SIVaaS) (All versions). The affected application exposes a network share without any authentication. This could allow an attacker to access or alter sensitive data without proper authorization. | |
| Analizada | Baja (2.3) | 0.18% | — | Siemens Ruggedcom Rst2428p Firmware | 9/9/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device exposes certain non-critical information from the device. This could allow an unauthenticated attacker to access sensitive data, potentially leading to a breach of confidentiality. | |
| Analizada | Baja (2.3) | 0.18% | — | Siemens Ruggedcom Rst2428p Firmware | 9/9/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device may be susceptible to resource exhaustion when subjected to high volumes of query requests. This could allow an attacker to cause a temporary denial of service, with the system recovering once the activity… | |
| Modificada | Alta (8.7) | 0.52% | — | Siemens Simatic PCS NEOSiemens User Management Component | 9/9/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions < V6.0 SP1 Update 1), User Management Component (UMC) (All versions < V2.15.1.3). Affected products contain a out-of-bounds read vulnerability in the integrated UMC… | |
| Modificada | Alta (8.7) | 0.52% | — | Siemens Simatic PCS NEOSiemens User Management Component | 9/9/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions < V6.0 SP1 Update 1), User Management Component (UMC) (All versions < V2.15.1.3). Affected products contain a out-of-bounds read vulnerability in the integrated UMC… | |
| Modificada | Alta (8.7) | 0.48% | — | Siemens Simatic PCS NEOSiemens User Management Component | 9/9/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions < V6.0 SP1 Update 1), User Management Component (UMC) (All versions < V2.15.1.3). Affected products contain a out-of-bounds read vulnerability in the integrated UMC… | |
| Modificada | Crítica (9.3) | 0.70% | — | Siemens Simatic PCS NEOSiemens User Management Component | 9/9/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions < V6.0 SP1 Update 1), User Management Component (UMC) (All versions < V2.15.1.3). Affected products contain a stack-based buffer overflow vulnerability in the integrated… | |
| Modificada | Media (6.9) | 0.21% | — | Siemens Sinamics G220 FirmwareSiemens Sinamics S200 FirmwareSiemens Sinamics S210 Firmware | 9/9/2025 | 17/6/2026 | A vulnerability has been identified in SINAMICS G220 V6.4 (All versions < V6.4 HF2), SINAMICS S200 V6.4 (All versions < V6.4 HF7), SINAMICS S210 V6.4 (All versions < V6.4 HF2). The affected devices allow a factory reset to be executed without the required privileges due to improper privilege management as well as… | |
| Aplazada | Baja (3.4) | 0.14% | — | SAP Netweaver AS JavaAIAdobe Document ServiceAIOpensslAI | 9/9/2025 | 17/6/2026 | SAP NetWeaver AS Java application uses Adobe Document Service, installed with a vulnerable version of OpenSSL.Successful exploitation of known vulnerabilities in the outdated OpenSSL library would allow user with high system privileges to access and modify system information.This vulnerability has a low impact on… | |
| Analizada | Crítica (9.8) | 2.9% | ⚠ Explotación activa💥 PoC | Linux KernelDebian LinuxSiemens Simatic CN 4100 Firmware | 5/9/2025 | 7/10/2026 | In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA record If the next record has different type than what has already been processed we… | |
| Aplazada | Alta (7.6) | 0.37% | 💥 PoC | Wpexperts License Manager FOR WoocommerceAI | 5/9/2025 | 5/10/2026 | Vulnerabilidad de Neutralización Incorrecta de Elementos Especiales utilizados en un Comando SQL ('Inyección SQL') en Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce permite Inyección SQL Ciega. Este problema afecta a License Manager for WooCommerce: desde n/a hasta menor o igual a 3.0.12. | |
| Aplazada | Alta (8.6) | 0.37% | — | Crestron Touchscreens X70AICrestron Tsw-x70AICrestron Tsw-x60AICrestron Tst-1080AI+9 | 3/9/2025 | 17/6/2026 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in CRESTRON TOUCHSCREENS x70 allows Argument Injection.This issue affects TOUCHSCREENS x70: from 3.001.0031.001 through 3.001.0034.001. A specially crafted SCP command sent via SSH login string can lead a valid… | |
| Aplazada | Alta (8.5) | 0.17% | — | Opensuse TumbleweedAITraefikAI | 2/9/2025 | 17/6/2026 | A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of openSUSE Tumbleweed traefik2 allows the traefik user to escalate to root. This issue affects Tumbleweed: from ? before 2.11.29. | |
| Analizada | Media (6.5) | 0.60% | — | Opensecurity Mobile Security Framework | 2/9/2025 | 17/6/2026 | MobSF is a mobile application security testing tool used. In version 4.4.0, an authenticated user who uploaded a specially prepared one.a, can write arbitrary files to any directory writable by the user of the MobSF process. This issue has been patched in version 4.4.1. | |
| Analizada | Baja (1.3) | 0.78% | — | Opensecurity Mobile Security Framework | 2/9/2025 | 17/6/2026 | MobSF is a mobile application security testing tool used. In version 4.4.0, the GET /download/ route uses string path verification via os.path.commonprefix, which allows an authenticated user to download files outside the DWD_DIR download directory from "neighboring" directories whose absolute paths begin with the… | |
| Analizada | Alta (7.5) | 0.52% | — | Consensys Gnark | 29/8/2025 | 17/6/2026 | gnark is a zero-knowledge proof system framework. In version 0.12.0, there is a potential denial of service vulnerability when computing scalar multiplication is using the fake-GLV algorithm. This is because the algorithm didn't converge quickly enough for some of the inputs. This issue has been patched in version… | |
| Analizada | Alta (7.1) | 0.24% | — | Qnap License Center | 29/8/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following… | |
| Analizada | Media (5.1) | 0.25% | — | Opensolution Quick.cms | 28/8/2025 | 17/6/2026 | QuickCMS is vulnerable to Reflected XSS via sLangEdit parameter in admin's panel functionality. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. The vendor was notified early about this vulnerability, but didn't respond with… | |
| Analizada | Media (5.3) | 0.19% | — | Opensolution Quick.cms | 28/8/2025 | 17/6/2026 | QuickCMS is vulnerable to Stored XSS via aDirFilesDescriptions parameter in files editor functionality. Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. By default admin user is not able to add JavaScript into the… | |
| Analizada | Media (5.3) | 0.19% | — | Opensolution Quick.cms | 28/8/2025 | 17/6/2026 | QuickCMS is vulnerable to Stored XSS via sDescriptionMeta parameter in page editor SEO functionality. Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. By default admin user is not able to add JavaScript into the website.… | |
| Analizada | Media (6.9) | 0.14% | — | Opensolution Quick.cms | 28/8/2025 | 17/6/2026 | QuickCMS sends password and login via GET Request. This allows a local attacker with access to the victim's browser history to obtain the necessary credentials to log in as the user. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version… | |
| Analizada | Media (6.9) | 0.15% | — | Opensolution Quick.cms | 28/8/2025 | 17/6/2026 | QuickCMS is vulnerable to Cross-Site Request Forgery in page deletion functionality. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request deleting an article. The vendor was notified early about this vulnerability, but didn't respond with the details of… | |
| Analizada | Media (5.1) | 0.25% | — | Opensolution Quick.cms | 28/8/2025 | 17/6/2026 | QuickCMS is vulnerable to Reflected XSS via sSort parameter in admin's panel functionality. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. The vendor was notified early about this vulnerability, but didn't respond with the… |