Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2604▼ 298 respecto a la semana anterior
Críticas / altas1343▲ 83 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
423 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.77% | — | Kunbus Revolution PI OSAINodered Node-redAI | 1/5/2025 | 17/6/2026 | KUNBUS Revolution Pi OS Bookworm 01/2025 is vulnerable because authentication is not configured by default for the Node-RED server. This can give an unauthenticated remote attacker full access to the Node-RED server where they can run arbitrary commands on the underlying operating system. | |
| Modificada | Media (6.8) | 0.41% | — | Devolutions Remote Desktop Manager | 26/3/2025 | 17/6/2026 | Improper authorization in the variable component in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use the ELEVATED_PASSWORD variable even though not allowed by the "Allow password in variable policy". This issue affects Remote Desktop Manager versions from 2025.1.24 through 2025.1.25,… | |
| Analizada | Media (5.4) | 0.42% | — | Devolutions Remote Desktop Manager | 26/3/2025 | 17/6/2026 | Insufficient logging in the autotyping feature in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use a stored password without generating a corresponding log event, via the use of the autotyping functionality. This issue affects Remote Desktop Manager versions from 2025.1.24 through… | |
| Analizada | Baja (3.6) | 0.17% | — | Devolutions Remote Desktop Manager | 26/3/2025 | 17/6/2026 | Improper authorization in application password policy in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use a configuration different from the one mandated by the system administrators. This issue affects Remote Desktop Manager versions from 2025.1.24 through 2025.1.25, and all versions… | |
| Analizada | Media (5.4) | 0.40% | — | Devolutions Remote Desktop Manager | 26/3/2025 | 17/6/2026 | Client side access control bypass in the permission component in Devolutions Remote Desktop Manager on Windows. An authenticated user can exploit this flaw to bypass certain permission restrictions—specifically View Password, Edit Asset, and Edit Permissions by performing specific actions. This issue affects Remote… | |
| Analizada | Alta (8.1) | 0.50% | — | Devolutions Server | 13/3/2025 | 17/6/2026 | Improper access control in web extension restriction feature in Devolutions Server 2024.3.4.0 and earlier allows an authenticated user to bypass the browser extension restriction feature. | |
| Analizada | Media (6.5) | 0.45% | — | Devolutions Server | 13/3/2025 | 17/6/2026 | Improper access control in temporary access requests and checkout requests endpoints in Devolutions Server 2024.3.13 and earlier allows an authenticated user to access information about these requests via a known request ID. | |
| Analizada | Alta (7.5) | 0.55% | — | Devolutions Server | 13/3/2025 | 17/6/2026 | Exposure of password in web-based SSH authentication component in Devolutions Server 2024.3.13 and earlier allows a user to unadvertently leak his SSH password due to missing password masking. | |
| Analizada | Media (6.5) | 1.7% | — | Devolutions Remote Desktop Manager | 13/3/2025 | 17/6/2026 | Exposure of sensitive information in My Personal Credentials password history component in Devolutions Remote Desktop Manager 2024.3.29 and earlier on Windows allows an authenticated user to inadvertently leak the My Personal Credentials in a shared vault via the clear history feature due to faulty business logic. | |
| Analizada | Media (6.5) | 1.7% | — | Devolutions Remote Desktop Manager | 13/3/2025 | 17/6/2026 | Exposure of sensitive information in hub data source export feature in Devolutions Remote Desktop Manager 2024.3.29 and earlier on Windows allows a user exporting a hub data source to include his authenticated session in the export due to faulty business logic. | |
| Analizada | Alta (8.8) | 0.76% | — | Coderevolution Aiomatic | 8/3/2025 | 17/6/2026 | The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aiomatic_generate_featured_image' function in all versions up to, and including, 2.3.8. This makes it possible for… | |
| Analizada | Media (5.4) | 0.24% | — | Coderevolution Aiomatic | 8/3/2025 | 17/6/2026 | The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability checks on multiple functions in all versions up to, and including, 2.3.6. This makes it possible for… | |
| Analizada | Alta (7.1) | 0.44% | — | Devolutions Server | 5/3/2025 | 17/6/2026 | Incorrect authorization in PAM vaults in Devolutions Server 2024.3.12 and earlier allows an authenticated user to bypass the 'add in root' permission. | |
| Aplazada | Alta (7.1) | 0.39% | — | Socialevolution WP Find Your NearestAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SocialEvolution WP Find Your Nearest wp-find-your-nearest allows Reflected XSS.This issue affects WP Find Your Nearest: from n/a through <= 0.3.1. | |
| Analizada | Media (5.4) | 0.35% | — | Devolutions Server | 11/2/2025 | 17/6/2026 | Improper password reset in PAM Module in Devolutions Server 2024.3.10.0 and earlier allows an authenticated user to reuse the oracle user password after check-in due to crash in the password reset functionality. | |
| Analizada | Alta (8.1) | 0.39% | — | Devolutions Remote Desktop Manager | 10/2/2025 | 17/6/2026 | Improper host validation in the certificate validation component in Devolutions Remote Desktop Manager on 2024.3.19 and earlier on Windows allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack by presenting a certificate for a different host. | |
| Analizada | Alta (8.8) | 0.23% | — | Devolutions Remote Desktop ManagerDevolutions Remote Desktop Manager Powershell | 10/2/2025 | 17/6/2026 | Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack. Versions affected are : Remote Desktop Manager macOS 2024.3.9.0 and earlier Remote Desktop Manager Linux 2024.3.2.5 and… | |
| Aplazada | Media (4.3) | 0.48% | — | Kunbus Gmbh Revolution PIAI | 10/2/2025 | 17/6/2026 | Path-Traversal vulnerability in Revolution Pi version 2022-07-28-revpi-buster from KUNBUS GmbH. This vulnerability could allow an authenticated attacker to list device directories via the ‘/pictory/php/getFileList.php’ endpoint in the ‘dir’ parameter. | |
| Aplazada | Alta (8.3) | 1.2% | — | Kunbus Revolution PIAI | 10/2/2025 | 17/6/2026 | OS Command Injection vulnerability in Revolution Pi version 2022-07-28-revpi-buster from KUNBUS GmbH. This vulnerability could allow an authenticated attacker to execute OS commands on the device via the ‘php/dal.php’ endpoint, in the ‘arrSaveConfig’ parameter. | |
| Aplazada | Media (6.5) | 0.32% | — | Agentevolution Impress ListingsAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in IDX IMPress Listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IMPress Listings: from n/a through 2.6.2. | |
| Aplazada | Alta (8.6) | 0.66% | — | Directadmin Evolution SkinAI | 20/12/2024 | 17/6/2026 | Ticket management system in DirectAdmin Evolution Skin is vulnerable to XSS (Cross-site Scripting), which allows a low-privileged user to inject and store malicious JavaScript code. If an admin views the ticket, the script might perform actions with their privileges, including command execution. This issue has been… | |
| Analizada | Media (6.5) | 0.46% | — | Devolutions Server | 4/12/2024 | 17/6/2026 | Incorrect authorization in the permission component in Devolutions Server 2024.3.7.0 and earlier allows an authenticated user to view the password history of an entry without the view password permission. | |
| Analizada | Media (5) | 0.28% | — | Devolutions Server | 4/12/2024 | 17/6/2026 | Incorrect permission assignment in the user migration feature in Devolutions Server 2024.3.8.0 and earlier allows users to retain their old permission sets. | |
| Analizada | Alta (8.1) | 0.60% | — | Devolutions Remote Desktop Manager | 4/12/2024 | 17/6/2026 | Incorrect permission assignment in temporary access requests component in Devolutions Remote Desktop Manager 2024.3.19.0 and earlier on Windows allows an authenticated user that request temporary permissions on an entry to obtain more privileges than requested. | |
| Analizada | Media (4.3) | 0.37% | — | Devolutions Server | 4/12/2024 | 17/6/2026 | Incorrect authorization in permission validation component in Devolutions Server 2024.3.6.0 and earlier allows an authenticated user to access some reporting endpoints. |