Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
397 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.73% | — | Stonefly Storage Concentrator | 12/7/2024 | 17/6/2026 | StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows Directory Traversal by authenticated users. Using a crafted path parameter with the Online Help facility can expose sensitive system information. | |
| Aplazada | Alta (8.8) | 1.3% | — | Stonefly Storage ConcentratorAI | 12/7/2024 | 17/6/2026 | StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows remote authenticated users to achieve Command Injection via a Ping URL, leading to remote code execution. | |
| Modificada | Crítica (9.8) | 0.48% | — | Conceptintermedia S@M CMS | 28/6/2024 | 17/6/2026 | Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to a blind SQL Injection executed using the search bar. Only a part of observed services is vulnerable, but since vendor has not investigated the root problem, it is hard to determine when the issue appears. | |
| Modificada | Media (6.1) | 0.33% | — | Conceptintermedia S@M CMS | 28/6/2024 | 17/6/2026 | Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in one of GET header parameters. Only a part of observed services is vulnerable, but since vendor has not investigated the root problem, it is hard to determine when the issue appears. | |
| Modificada | Media (6.1) | 0.29% | — | Conceptintermedia S@M CMS | 28/6/2024 | 17/6/2026 | Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in requested file names. Only a part of observed services is vulnerable, but since vendor has not investigated the root problem, it is hard to determine when the issue appears. | |
| Analizada | Crítica (9.8) | 0.34% | — | Moxa Oncell G3470a-lte-us-t FirmwareMoxa Oncell G3470a-lte-eu FirmwareMoxa Oncell G3470a-lte-eu-t FirmwareMoxa Oncell G3470a-lte-us Firmware | 25/6/2024 | 17/6/2026 | OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to accepting a format string from an external source as an argument. An attacker could modify an externally controlled format string to cause a memory leak and denial of service. | |
| Analizada | Alta (8.2) | 0.39% | — | Moxa Oncell G3470a-lte-us-t FirmwareMoxa Oncell G3470a-lte-eu FirmwareMoxa Oncell G3470a-lte-eu-t FirmwareMoxa Oncell G3470a-lte-us Firmware | 25/6/2024 | 17/6/2026 | OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to missing bounds checking on buffer operations. An attacker could write past the boundaries of allocated buffer regions in memory, causing a program crash. | |
| Analizada | Alta (8.8) | 0.45% | — | Moxa Oncell G3470a-lte-us-t FirmwareMoxa Oncell G3470a-lte-eu FirmwareMoxa Oncell G3470a-lte-eu-t FirmwareMoxa Oncell G3470a-lte-us Firmware | 25/6/2024 | 17/6/2026 | OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in IPSec configuration. An attacker could modify the intended commands sent to target functions, which could cause malicious users to execute unauthorized commands. | |
| Analizada | Alta (8.8) | 0.44% | — | Moxa Oncell G3470a-lte-eu-t FirmwareMoxa Oncell G3470a-lte-eu FirmwareMoxa Oncell G3470a-lte-us FirmwareMoxa Oncell G3470a-lte-us-t Firmware | 25/6/2024 | 17/6/2026 | OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in the web key upload function. An attacker could modify the intended commands sent to target functions, which could cause malicious users to execute unauthorized commands. | |
| Aplazada | Alta (7.5) | 0.42% | — | CPF Concepts LLC BizprintAI | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in BizSwoop a CPF Concepts, LLC Brand BizPrint.This issue affects BizPrint: from n/a through 4.3.39. | |
| Aplazada | Alta (7.1) | 0.19% | — | CPF Concepts LLC BizprintAI | 27/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in BizSwoop a CPF Concepts, LLC Brand BizPrint allows Cross-Site Scripting (XSS).This issue affects BizPrint: from n/a through 4.5.5. | |
| Modificada | Media (5.3) | 0.24% | — | Moxa Oncell G3150a-lte Firmware | 31/12/2023 | 17/6/2026 | A vulnerability has been identified in OnCell G3150A-LTE Series firmware versions v1.3 and prior. The vulnerability results from lack of protection for sensitive information during transmission. An attacker eavesdropping on the traffic between the web browser and server may obtain sensitive information. This type of… | |
| Modificada | Media (6.1) | 0.25% | — | Moxa Oncell G3150a-lte Firmware | 31/12/2023 | 17/6/2026 | A clickjacking vulnerability has been identified in OnCell G3150A-LTE Series firmware versions v1.3 and prior. This vulnerability is caused by incorrectly restricts frame objects, which can lead to user confusion about which interface the user is interacting with. This vulnerability may lead the attacker to trick the… | |
| Modificada | Crítica (9.8) | 0.52% | — | Dmconcept Configurator | 19/10/2023 | 17/6/2026 | DM Concept configurator before v4.9.4 was discovered to contain a SQL injection vulnerability via the component ConfiguratorAttachment::getAttachmentByToken. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Media (4.3) | 0.48% | — | Wpconcern Coming Soon & Maintenance Mode Page | 12/7/2023 | 17/6/2026 | The Coming Soon & Maintenance Mode Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.57. This is due to missing or incorrect nonce validation on the save_meta_box() function. This makes it possible for unauthenticated attackers to save meta boxes via a forged… | |
| Modificada | Media (4.3) | 0.50% | — | Jenkins Team Concert | 19/6/2023 | 17/6/2026 | Missing permission checks in Jenkins Team Concert Plugin 2.4.1 and earlier allow attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system. | |
| Modificada | Alta (8.8) | 0.45% | — | Wpconcern Nifty Coming Soon & Maintenance Mode Page | 7/6/2023 | 17/6/2026 | The Coming Soon & Maintenance Mode Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.57. This is due to confusing logic functions missing or having incorrect nonce validation. This makes it possible for unauthenticated attackers to gain and perform otherwise… | |
| Modificada | Alta (7.2) | 0.96% | — | Conceptbeans Mapwiz | 13/2/2023 | 17/6/2026 | The Mapwiz WordPress plugin through 1.0.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin. | |
| Modificada | Alta (8.8) | 0.68% | — | Summitmediaconcepts Ucontext FOR Clickbank | 6/9/2022 | 17/6/2026 | The uContext for Clickbank plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including 3.9.1. This is due to missing nonce validation in the ~/app/sites/ajax/actions/keyword_save.php file that is called via the doAjax() function. This makes it possible for… | |
| Modificada | Alta (8.8) | 0.76% | — | Summitmediaconcepts Ucontext FOR Amazon | 6/9/2022 | 17/6/2026 | The uContext for Amazon plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including 3.9.1. This is due to missing nonce validation in the ~/app/sites/ajax/actions/keyword_save.php file that is called via the doAjax() function. This makes it possible for… | |
| Modificada | Alta (7.5) | 0.80% | — | HPE Storeonce 3640 Firmware | 27/6/2022 | 17/6/2026 | A potential security vulnerability has been identified in HPE StoreOnce Software. The SSH server supports weak key exchange algorithms which could lead to remote unauthorized access. HPE has made the following software update to resolve the vulnerability in HPE StoreOnce Software 4.3.2. | |
| Modificada | Media (4.3) | 0.70% | — | IBM Rational Team Concert | 15/3/2022 | 17/6/2026 | IBM Engineering Workflow Management 7.0, 7.0.1, and 7.0.2 and IBM Rational Team Concert 6.0.6 and 6.0.0.1 could allow an authenticated user to obtain sensitive information about build definitions. IBM X-Force ID: 192707. | |
| Modificada | Media (4.3) | 0.70% | — | IBM Engineering Workflow ManagementIBM Rational Team Concert | 11/1/2022 | 17/6/2026 | IBM Engineering Workflow Management 7.0, 7.0.1, and 7.0.2 as well as IBM Rational Team Concert 6.0.6 and 6.0.6.1 could allow an authneticated attacker to obtain sensitive information from build definitions that could aid in further attacks against the system. IBM X-Force ID: 200657. | |
| Modificada | Alta (8.8) | 0.59% | — | IBM Engineering Lifecycle OptimizationIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Workflow ManagementIBM Rational Doors Next Generation+3 | 27/10/2021 | 17/6/2026 | IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. |