Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
838 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.22% | — | Tomas Cordero Safety ExitAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tomas Cordero Safety Exit safety-exit allows Stored XSS.This issue affects Safety Exit: from n/a through <= 1.8.0. | |
| Aplazada | Alta (7.5) | 0.41% | — | Stefan Keller Woocommerce Payment Gateway FOR SaferpayAI | 5/9/2025 | 5/10/2026 | Path Traversal: '.../...//' vulnerability in Stefan Keller WooCommerce Payment Gateway for Saferpay woocommerce-payment-gateway-for-saferpay allows Path Traversal.This issue affects WooCommerce Payment Gateway for Saferpay: from n/a through <= 0.4.9. | |
| Analizada | Media (6.9) | 0.50% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+22 | 13/8/2025 | 17/6/2026 | An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset Attack). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.7) | 0.34% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 13/8/2025 | 17/6/2026 | When a BIG-IP LTM Client SSL profile is configured on a virtual server with SSL Forward Proxy enabled and Anonymous Diffie-Hellman (ADH) ciphers enabled, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are… | |
| Aplazada | Alta (8.5) | 0.18% | — | Siemens Simatic S7-plcsimAISiemens Simatic Step 7AISiemens Simatic WinccAISiemens Simocode ESAI+5 | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 V17 (All versions < V17 Update 9), SIMATIC STEP 7 V18 (All versions), SIMATIC STEP 7 V19 (All versions < V19 Update 4), SIMATIC STEP 7 V20 (All versions < V20 Update 4), SIMATIC WinCC V17 (All versions < V17 Update 9), SIMATIC… | |
| Aplazada | Alta (8.6) | 0.17% | — | Siemens Simatic PCS NEOAISiemens Simatic S7-plcsimAISiemens Simatic Step 7AISiemens Simatic WinccAI+7 | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions < V6.0 SP1 Update 1), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 V17 (All versions < V17 Update 9), SIMATIC STEP 7 V18 (All versions), SIMATIC STEP 7 V19 (All… | |
| Analizada | Media (5.5) | 0.22% | — | Openquantumsafe Liboqs | 10/7/2025 | 17/6/2026 | liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Multiple secret-dependent branches have been identified in the reference implementation of the HQC key encapsulation mechanism when it is compiled with Clang for optimization levels above -O0 (-O1, -O2,… | |
| Aplazada | Baja (2.1) | 0.28% | — | Safecam X300AI | 1/7/2025 | 17/6/2026 | A vulnerability classified as problematic was found in SAFECAM X300 up to 20250611. This vulnerability affects unknown code of the component FTP Service. The manipulation leads to use of default credentials. Access to the local network is required for this attack to succeed. The exploit has been disclosed to the… | |
| Analizada | Media (6.5) | 0.33% | 💥 PoC | Netease Neacsafe64 | 27/6/2025 | 17/6/2026 | An issue in NetEase (Hangzhou) Network Co., Ltd NeacSafe64 Driver before v1.0.0.8 allows attackers to escalate privileges via sending crafted IOCTL commands to the NeacSafe64.sys component. | |
| Analizada | Baja (2.4) | 0.15% | — | Flocksafety License Plate Reader Firmware | 27/6/2025 | 17/6/2026 | Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have cleartext storage of code. | |
| Analizada | Media (4.6) | 0.24% | — | Flocksafety License Plate Reader Firmware | 27/6/2025 | 17/6/2026 | Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have a hardcoded password for a system. | |
| Analizada | Media (6.8) | 0.25% | — | Flocksafety License Plate Reader Firmware | 27/6/2025 | 17/6/2026 | Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have an on-chip debug interface with improper access control. | |
| Analizada | Media (4.6) | 0.23% | — | Flocksafety Gunshot Detection Firmware | 27/6/2025 | 17/6/2026 | Flock Safety Gunshot Detection devices before 1.3 have a hardcoded password for a system. | |
| Analizada | Baja (2.4) | 0.16% | — | Flocksafety Gunshot Detection Firmware | 27/6/2025 | 17/6/2026 | Flock Safety Gunshot Detection devices before 1.3 have cleartext storage of code. | |
| Analizada | Media (6.8) | 0.26% | — | Flocksafety Gunshot Detection Firmware | 27/6/2025 | 17/6/2026 | Flock Safety Gunshot Detection devices before 1.3 have an on-chip debug interface with improper access control. | |
| Analizada | Media (4.6) | 0.24% | — | Flocksafety Gunshot Detection Firmware | 27/6/2025 | 17/6/2026 | Flock Safety Gunshot Detection devices before 1.3 have a hard-coded password for a connection. | |
| Analizada | Baja (3.7) | 0.24% | — | Openquantumsafe Liboqs | 30/5/2025 | 17/6/2026 | liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. liboqs prior to version 0.13.0 supports the HQC algorithm, an algorithm with a theoretical design flaw which leads to large numbers of malformed ciphertexts sharing the same implicit rejection value.… | |
| Analizada | Alta (7.1) | 0.18% | — | Abitgone Commentsafe | 15/5/2025 | 17/6/2026 | The aBitGone CommentSafe WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. | |
| Aplazada | Alta (8.2) | 0.41% | — | Siemens Sirius 3rk3 Modular Safety SystemAISiemens Sirius 3sk2 Safety RelaysAI | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2 (All versions). The affected devices do not require authentication to access critical resources. An attacker with network access could retrieve sensitive information from certain data records,… | |
| Aplazada | Alta (8.7) | 0.26% | — | Siemens Sirius 3rk3 Modular Safety SystemAISiemens Sirius Safety Relays 3sk2AI | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2 (All versions). The affected devices do not encrypt data in transit. An attacker with network access could eavesdrop the connection and retrieve sensitive information, including obfuscated safety… | |
| Aplazada | Alta (8.7) | 0.29% | — | Siemens Sirius 3rk3 Modular Safety SystemAISiemens Sirius Safety Relays 3sk2AI | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2 (All versions). Affected devices only provide weak password obfuscation. An attacker with network access could retrieve and de-obfuscate the safety password used for protection against inadvertent… | |
| Analizada | Alta (8.7) | 0.44% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 7/5/2025 | 17/6/2026 | When a Session Initiation Protocol (SIP) message routing framework (MRF) application layer gateway (ALG) profile is configured on a Message Routing virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support… | |
| Analizada | Alta (8.7) | 0.43% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+19 | 7/5/2025 | 17/6/2026 | When HTTP/2 client and server profile is configured on a virtual server, undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | |
| Analizada | Alta (8.7) | 0.43% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+20 | 7/5/2025 | 17/6/2026 | When a Stream Control Transmission Protocol (SCTP) profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.7) | 0.44% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+20 | 7/5/2025 | 17/6/2026 | When a BIG-IP HTTP/2 httprouter profile is configured on a virtual server, undisclosed responses can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |