Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
291 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.37% | — | Typps Calendarista-basic-editionAI | 21/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in typps Calendarista Basic Edition calendarista-basic-edition.This issue affects Calendarista Basic Edition: from n/a through <= 3.0.2. | |
| Modificada | Alta (8.8) | 0.26% | — | Sysbasics Customize MY Account | 15/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SysBasics Customize My Account for WooCommerce.This issue affects Customize My Account for WooCommerce: from n/a through 1.8.3. | |
| Modificada | Crítica (9.8) | 0.63% | — | Sysbasics Easy Checkout Field Editor | 26/2/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in SYSBASICS WooCommerce Easy Checkout Field Editor, Fees & Discounts.This issue affects WooCommerce Easy Checkout Field Editor, Fees & Discounts: from n/a through 3.5.12. | |
| Modificada | Alta (8.8) | 0.21% | — | Wpsimpletools Basic LOG Viewer | 12/2/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WpSimpleTools Basic Log Viewer.This issue affects Basic Log Viewer: from n/a through 1.0.4. | |
| Modificada | Alta (7.5) | 0.33% | — | Phoenixcontact Automationworx Software SuitePhoenixcontact AXC 1050 FirmwarePhoenixcontact AXC 1050 XC FirmwarePhoenixcontact AXC 3050 Firmware+14 | 14/12/2023 | 17/6/2026 | Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC. | |
| Modificada | Crítica (9.8) | 0.88% | — | Phoenixcontact Automationworx Software SuitePhoenixcontact AXC 1050 FirmwarePhoenixcontact AXC 1050 XC FirmwarePhoenixcontact AXC 3050 Firmware+14 | 14/12/2023 | 17/6/2026 | Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthenticated attacker to gain full access of the affected device. | |
| Modificada | Media (4.8) | 0.39% | — | Wpmapplugins Basic Interactive World MAP | 8/11/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP Map Plugins Basic Interactive World Map plugin <= 2.0 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Laposta Signup Basic | 6/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Laposta - Roel Bousardt Laposta Signup Basic plugin <= 1.4.1 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | WP Basic Elements Project WP Basic Elements | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Damir Calusic WP Basic Elements plugin <= 5.2.15 versions. | |
| Modificada | Media (5.4) | 0.36% | — | Wpjam Basic Project Wpjam Basic | 16/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Denis WPJAM Basic plugin <= 6.2.1 versions. | |
| Modificada | Alta (7.5) | 1.00% | — | Seiko-sol Skybridge Basic Mb-a130 FirmwareSeiko-sol Skybridge Mb-a200 FirmwareSeiko-sol Skyspider Mb-r210 Firmware | 10/5/2023 | 17/6/2026 | Use of weak credentials exists in Seiko Solutions SkyBridge and SkySpider series, which may allow a remote unauthenticated attacker to decrypt password for the WebUI of the product. Affected products and versions are as follows: SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier, SkyBridge BASIC MB-A130 firmware… | |
| Modificada | Media (6.5) | 0.46% | — | Seiko-sol Skybridge Basic Mb-a130 FirmwareSeiko-sol Skybridge Mb-a200 Firmware | 10/5/2023 | 17/6/2026 | Improper following of a certificate's chain of trust exists in SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier, and SkyBridge BASIC MB-A130 firmware Ver. 1.4.1 and earlier, which may allow a remote unauthenticated attacker to eavesdrop on or alter the communication sent to the WebUI of the product. | |
| Modificada | Alta (8.6) | 0.98% | — | Seiko-sol Skybridge Basic Mb-a130 FirmwareSeiko-sol Skybridge Mb-a200 Firmware | 10/5/2023 | 17/6/2026 | Missing authentication for critical function exists in Seiko Solutions SkyBridge series, which may allow a remote attacker to obtain or alter the setting information of the product or execute some critical functions without authentication, e.g., rebooting the product. Affected products and versions are as follows:… | |
| Modificada | Media (6.1) | 0.52% | — | Backdropcms Basic Cart | 11/1/2023 | 16/6/2026 | A vulnerability was found in backdrop-contrib Basic Cart on Drupal. It has been classified as problematic. Affected is the function basic_cart_checkout_form_submit of the file basic_cart.cart.inc. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version… | |
| Modificada | Media (4.8) | 0.54% | — | Wpkube Simple Basic Contact Form | 26/12/2022 | 17/6/2026 | The Simple Basic Contact Form WordPress plugin before 20221201 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Alta (7.5) | 0.84% | — | Siemens Simatic HMI Comfort Panels FirmwareSiemens Simatic HMI Ktp400 Basic FirmwareSiemens Simatic HMI Ktp700 Basic FirmwareSiemens Simatic HMI Ktp900 Basic Firmware+6 | 11/10/2022 | 17/6/2026 | A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V17 Update 4), SIMATIC HMI KTP Mobile Panels (All versions < V17 Update 4), SIMATIC HMI KTP1200 Basic (All versions < V17 Update 5), SIMATIC HMI KTP400 Basic (All versions < V17 Update 5), SIMATIC HMI KTP700 Basic… | |
| Modificada | Crítica (9.8) | 1.6% | — | Phoenixcontact AXC 1050 FirmwarePhoenixcontact AXC 1050 XC FirmwarePhoenixcontact AXC 3050 FirmwarePhoenixcontact FC 350 PCI ETH Firmware+13 | 21/6/2022 | 17/6/2026 | An unauthenticated, remote attacker could upload malicious logic to devices based on ProConOS/ProConOS eCLR in order to gain full control over the device. | |
| Modificada | Crítica (9.8) | 1.7% | — | Powertekpdus Basic PDU FirmwarePowertekpdus PM PDU FirmwarePowertekpdus Piml PDU FirmwarePowertekpdus Smart PIM Firmware+3 | 13/6/2022 | 17/6/2026 | Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 have an insecure permissions setting on the user.token field that is accessible to everyone through the /cgi/get_param.cgi HTTP API. This leads to disclosing active session ids of currently logged-in administrators. The session id… | |
| Modificada | Alta (7.5) | 14% | 💥 Exploit | Powertekpdus Basic PDU FirmwarePowertekpdus PM PDU FirmwarePowertekpdus Piml PDU FirmwarePowertekpdus Smart PIM Firmware+3 | 13/6/2022 | 17/6/2026 | Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web interface. To exploit the vulnerability, an attacker must send an HTTP packet to the data retrieval interface (/cgi/get_param.cgi) with the tmpToken cookie set to an empty string… | |
| Modificada | Alta (8.1) | 0.80% | — | Circutor Compact Dc-s Basic Firmware | 24/5/2022 | 17/6/2026 | A buffer overflow vulnerability has been detected in the firewall function of the device management web portal. The device runs a CGI binary (index.cgi) to offer a management web application. Once authenticated with valid credentials in this web portal, a potential attacker could submit any "Address" value and it… | |
| Modificada | Alta (7.8) | 0.78% | — | Chitubox BasicAnycubic Chitubox | 14/4/2022 | 17/6/2026 | A heap-based buffer overflow vulnerability exists in the readDatHeadVec functionality of AnyCubic Chitubox AnyCubic Plugin 1.0.0. A specially-crafted GF file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 36% | — | Siemens Simatic Energy Manager BasicSiemens Simatic Energy Manager PRO | 12/4/2022 | 17/6/2026 | A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). The affected system allows remote users to send maliciously crafted objects. Due to insecure deserialization of user-supplied content by the affected software,… | |
| Modificada | Alta (7.3) | 0.33% | — | Siemens Simatic Energy Manager BasicSiemens Simatic Energy Manager PRO | 12/4/2022 | 17/6/2026 | A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). A DLL Hijacking vulnerability could allow a local attacker to execute code with elevated privileges by placing a malicious DLL in one of the directories on the… | |
| Modificada | Alta (7.8) | 0.25% | — | Siemens Simatic Energy Manager BasicSiemens Simatic Energy Manager PRO | 12/4/2022 | 17/6/2026 | A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). Affected applications improperly assign permissions to critical directories and files used by the application processes. This could allow a local unprivileged… | |
| Modificada | Media (6.5) | 1.4% | — | Opcfoundation Ua-nodesetSiemens Simatic NET PCSiemens Sitop ManagerSiemens Telecontrol Server Basic | 21/3/2022 | 17/6/2026 | The OPC autogenerated ANSI C stack stubs (in the NodeSets) do not handle all error cases. This can lead to a NULL pointer dereference. |