Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
252 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.97% | — | Pi-hole WEB Interface | 26/1/2023 | 17/6/2026 | Pi-hole®'s Web interface (based off of AdminLTE) provides a central location to manage your Pi-hole. Versions 4.0 and above, prior to 5.18.3 are vulnerable to Insufficient Session Expiration. Improper use of admin WEBPASSWORD hash as "Remember me for 7 days" cookie value makes it possible for an attacker to "pass the… | |
| Modificada | Alta (7.2) | 18% | — | WP Custom Admin Interface Project WP Custom Admin Interface | 9/1/2023 | 17/6/2026 | The WP Custom Admin Interface WordPress plugin before 7.29 unserialize user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present. | |
| Modificada | Media (4.2) | 0.59% | — | Amazon Efs-utilsAmazon Elastic File System Container Storage Interface Driver | 28/12/2022 | 17/6/2026 | efs-utils is a set of Utilities for Amazon Elastic File System (EFS). A potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to… | |
| Modificada | Alta (7.8) | 0.16% | — | Emerson Deltav Distributed Control System SQ Controller FirmwareEmerson Deltav Distributed Control System SX Controller FirmwareEmerson Se4002s1t2b6 High Side 40-pin Mass I/O Terminal Block FirmwareEmerson Se4003s2b4 16-pin Mass I/O Terminal Block Firmware+20 | 26/12/2022 | 17/6/2026 | Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate checksum approach, and no signature). This affects versions before 14.3 of DeltaV M-series, DeltaV S-series, DeltaV P-series, DeltaV SIS, and DeltaV CIOC/EIOC/WIOC IO cards. | |
| Modificada | Alta (7.8) | 0.17% | — | NI Labview Command Line Interface | 1/12/2022 | 17/6/2026 | Incorrect default permissions in the installation folder for NI LabVIEW Command Line Interface (CLI) may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Crítica (9.8) | 1.1% | — | Festo BUS Module Cpx-e-ep FirmwareFesto BUS Node Cpx-fb32 FirmwareFesto BUS Node Cpx-fb33 FirmwareFesto BUS Node Cpx-fb36 Firmware+95 | 1/12/2022 | 17/6/2026 | In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead to a complete loss of confidentiality, integrity and availability. | |
| Modificada | Media (6.1) | 0.29% | — | Hallowelt BluespiceHallowelt Common User Interface | 15/11/2022 | 17/6/2026 | Some UI elements of the Common User Interface Component are not properly sanitizing output and therefore prone to output arbitrary HTML (XSS). | |
| Modificada | Media (6.1) | 0.42% | — | Eyesofnetwork WEB Interface | 8/11/2022 | 17/6/2026 | EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /lilac/main.php. | |
| Modificada | Media (4.8) | 0.40% | — | Eyesofnetwork WEB Interface | 8/11/2022 | 17/6/2026 | EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /module/admin_bp/add_application.php. | |
| Modificada | Media (4.8) | 0.40% | — | Eyesofnetwork WEB Interface | 8/11/2022 | 17/6/2026 | EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /module/report_event/index.php. | |
| Modificada | Crítica (9.8) | 3.5% | — | Microsoft Azure Command-line Interface | 25/10/2022 | 17/6/2026 | Azure CLI is the command-line interface for Microsoft Azure. In versions previous to 2.40.0, Azure CLI contains a vulnerability for potential code injection. Critical scenarios are where a hosting machine runs an Azure CLI command where parameter values have been provided by an external source. The vulnerability is… | |
| Modificada | Media (6) | 0.17% | — | AsusliveupdateAsussoftwaremangerAsus System Control Interface | 18/10/2022 | 17/6/2026 | AsusSoftwareManager.exe in ASUS System Control Interface on ASUS personal computers (running Windows) allows a local user to write into the Temp directory and delete another more privileged file via SYSTEM privileges. This affects ASUS System Control Interface 3 before 3.1.5.0, AsusSoftwareManger.exe before 1.0.53.0,… | |
| Modificada | Alta (7.8) | 0.17% | — | AsusswitchAsus System Control Interface | 18/10/2022 | 17/6/2026 | AsusSwitch.exe on ASUS personal computers (running Windows) sets weak file permissions, leading to local privilege escalation (this also can be used to delete files within the system arbitrarily). This affects ASUS System Control Interface 3 before 3.1.5.0, and AsusSwitch.exe before 1.0.10.0. | |
| Modificada | Crítica (9.8) | 0.68% | — | Trumpf JOB Order InterfaceTrumpf OseonTrumpf Trutops BoostTrumpf Trutops FAB+1 | 17/10/2022 | 17/6/2026 | Multiple Trumpf Products in multiple versions use default privileged Windows users and passwords. An adversary may use these accounts to remotely gain full access to the system. | |
| Modificada | Media (5.5) | 0.18% | — | Emerson Deltav Distributed Control SystemEmerson Deltav Distributed Control System SQ Controller FirmwareEmerson Deltav Distributed Control System SX Controller FirmwareEmerson Se4002s1t2b6 High Side 40-pin Mass I/O Terminal Block Firmware+21 | 26/7/2022 | 17/6/2026 | The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. Access to privileged operations on the maintenance port TELNET interface (23/TCP) on M-series and SIS (CSLS/LSNB/LSNG) nodes is controlled by means of utility passwords. These passwords are generated using… | |
| Modificada | Media (5.5) | 0.24% | — | Emerson Deltav Distributed Control System SQ Controller FirmwareEmerson Deltav Distributed Control System SX Controller FirmwareEmerson Se4002s1t2b6 High Side 40-pin Mass I/O Terminal Block FirmwareEmerson Se4003s2b4 16-pin Mass I/O Terminal Block Firmware+20 | 26/7/2022 | 17/6/2026 | The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. WIOC SSH provides access to a shell as root, DeltaV, or backup via hardcoded credentials. NOTE: this is different from CVE-2014-2350. | |
| Modificada | Media (5.5) | 0.24% | — | Emerson Deltav Distributed Control System SQ Controller FirmwareEmerson Deltav Distributed Control System SX Controller FirmwareEmerson Se4002s1t2b6 High Side 40-pin Mass I/O Terminal Block FirmwareEmerson Se4003s2b4 16-pin Mass I/O Terminal Block Firmware+20 | 26/7/2022 | 17/6/2026 | The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. TELNET on port 18550 provides access to a root shell via hardcoded credentials. This affects S-series, P-series, and CIOC/EIOC nodes. NOTE: this is different from CVE-2014-2350. | |
| Modificada | Media (5.5) | 0.24% | — | Emerson Deltav Distributed Control System SQ Controller FirmwareEmerson Deltav Distributed Control System SX Controller FirmwareEmerson Se4002s1t2b6 High Side 40-pin Mass I/O Terminal Block FirmwareEmerson Se4003s2b4 16-pin Mass I/O Terminal Block Firmware+20 | 26/7/2022 | 17/6/2026 | The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. FTP has hardcoded credentials (but may often be disabled in production). This affects S-series, P-series, and CIOC/EIOC nodes. NOTE: this is different from CVE-2014-2350. | |
| Modificada | Alta (7.8) | 0.19% | — | Dell Powerstore Command Line Interface | 21/7/2022 | 17/6/2026 | Dell EMC PowerStore, Versions prior to v3.0.0.0 contain a DLL Hijacking vulnerability in PSTCLI. A local attacker can potentially exploit this vulnerability to execute arbitrary code, escalate privileges, and bypass software allow list solutions, leading to system takeover or IP exposure. | |
| Modificada | Media (6.1) | 1.7% | — | Collect AND Deliver Interface FOR Woocommerce Project Collect AND Deliver Interface FOR Woocommerce | 17/7/2022 | 17/6/2026 | The CDI WordPress plugin before 5.1.9 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting | |
| Modificada | Crítica (9.3) | 1.3% | — | Mp-m08-interface Project Mp-m08-interface | 11/7/2022 | 17/6/2026 | The joaopedro-fg/mp-m08-interface repository through 2020-12-10 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Media (4.8) | 0.52% | — | 1password1password IN THE Browser1password Command-line1password Command Line Interface+2 | 15/6/2022 | 17/6/2026 | An issue was discovered in AgileBits 1Password, involving the method various 1Password apps and integrations used to create connections to the 1Password service. In specific circumstances, this issue allowed a malicious server to convince a 1Password app or integration it is communicating with the 1Password service. | |
| Modificada | Crítica (9.8) | 0.85% | — | Mitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data TransferMitsubishielectric EM Configurator+25 | 19/5/2022 | 17/6/2026 | Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software Products of various versions could allow an attacker to escalate privilege and execute malicious programs, which could cause a denial-of-service condition, and allow information to be disclosed,… | |
| Modificada | Alta (7) | 1.9% | — | Lenovo System Interface Foundation | 18/5/2022 | 17/6/2026 | A Time of Check Time of Use (TOCTOU) vulnerability was reported in IMController, a software component of Lenovo System Interface Foundation, prior to version 1.1.20.3that could allow a local attacker to elevate privileges. | |
| Modificada | Alta (7) | 1.9% | — | Lenovo System Interface Foundation | 18/5/2022 | 17/6/2026 | A race condition vulnerability was reported in IMController, a software component of Lenovo System Interface Foundation, prior to version 1.1.20.3 that could allow a local attacker to connect and interact with the IMController child process' named pipe. |