Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

1437 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.6)0.64%—Arista NG Firewall23/4/202517/6/2026
Arista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG Firewall. Minimal user interaction is required to exploit this vulnerability. The specific flaw exists within the…
AnalizadaBaja (3.5)0.49%—Oracle Solaris15/4/202517/6/2026
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Solaris. Successful attacks require human…
AnalizadaAlta (7.2)0.21%—Oracle Solaris15/4/202517/6/2026
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require…
AplazadaMedia (5.1)0.41%—Softcom IksarisAI14/4/202517/6/2026
Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. An attacker might trick a user into filling a form sent to login panel at /softcom/ with a malicious script, what causes the script to run in user's context. This vulnerability has been patched in…
AplazadaAlta (7.6)0.50%—Aristo Rinjuang WP InquiriesAI9/4/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aristo Rinjuang WP Inquiries wp-inquiries allows SQL Injection.This issue affects WP Inquiries: from n/a through <= 0.2.1.
AplazadaMedia (6)0.25%—Arista Aos-8 InstantAIArista Aos-10 APAI8/4/202517/6/2026
A vulnerability in the file creation process on the command line interface of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacker to perform remote code execution (RCE). Successful exploitation could allow an attacker to execute arbitrary operating system commands on the underlying operating…
AplazadaAlta (7.1)0.31%—Parisneo LollmsAI20/3/202517/6/2026
A Path Traversal vulnerability exists in the `/wipe_database` endpoint of parisneo/lollms version v12, allowing an attacker to delete any directory on the system. The vulnerability arises from improper validation of the `key` parameter, which is used to construct file paths. An attacker can exploit this by sending a…
AplazadaAlta (8.4)0.46%—Parisneo LollmsAI20/3/202517/6/2026
A remote code execution vulnerability exists in the Calculate function of parisneo/lollms version 9.8. The vulnerability arises from the use of Python's `eval()` function to evaluate mathematical expressions within a Python sandbox that disables `__builtins__` and only allows functions from the `math` module. This…
AplazadaAlta (8)0.23%—Parisneo LollmsAI20/3/202517/6/2026
A missing check_access() function in the lollms_binding_infos module of the parisneo/lollms repository, version V14, allows attackers to add, modify, and remove bindings arbitrarily. This vulnerability affects the /install_binding and /reinstall_binding endpoints, among others, enabling unauthorized access and…
AplazadaMedia (5.3)0.36%—Arista EOSAI4/3/202517/6/2026
On affected platforms running Arista EOS with BGP Link State configured, BGP peer flap can cause the BGP agent to leak memory. This may result in BGP routing processing being terminated and route flapping.
AplazadaMedia (5.3)0.20%—Arista EOSAI4/3/202517/6/2026
On affected platforms running Arista EOS with 802.1X configured, certain conditions may occur where a dynamic ACL is received from the AAA server resulting in only the first line of the ACL being installed after an Accelerated Software Upgrade (ASU) restart. Note: supplicants with pending captive-portal authentication…
AplazadaCrítica (9.1)0.44%—Arista EOSAI4/3/202517/6/2026
On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result in unexpected configuration/operations being applied to the switch.
AplazadaAlta (7.7)0.35%—Arista EOSAI4/3/202517/6/2026
On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result in users retrieving data that should not have been available
AnalizadaMedia (6.1)0.59%💥 ExploitParisholley Fantastic Elasticsearch31/1/202517/6/2026
The Fantastic ElasticSearch WordPress plugin through 4.1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
AnalizadaMedia (6)0.19%—Oracle Solaris21/1/202517/6/2026
Vulnerability in the Oracle Solaris product of Oracle Systems (component: File system). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this…
AplazadaAlta (7.1)0.19%—Starise Twitter-shortcodeAI16/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in starise Twitter Shortcode twitter-shortcode allows Stored XSS.This issue affects Twitter Shortcode: from n/a through <= 0.9.
AnalizadaAlta (8.8)0.48%—Arista NG Firewall10/1/202517/6/2026
Specially constructed queries cause cross platform scripting leaking administrator tokens
AnalizadaAlta (8.3)0.62%—Arista NG Firewall10/1/202517/6/2026
Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying operating system with elevated privileges.
AnalizadaMedia (5.6)0.16%—Arista NG Firewall10/1/202517/6/2026
A user with administrator privileges is able to retrieve authentication tokens
AnalizadaCrítica (9.8)0.69%—Arista NG Firewall10/1/202517/6/2026
The administrator is able to configure an insecure captive portal script
AnalizadaAlta (7.2)1.4%—Arista NG Firewall10/1/202517/6/2026
A user with administrator privileges can perform command injection
AplazadaMedia (4.6)0.10%—Arista Cloudvision ApplianceAIArista Dca-350e-cvAI10/1/202517/6/2026
On Arista CloudVision Appliance (CVA) affected releases running on appliances that support hardware disk encryption (DCA-350E-CV only), the disk encryption might not be successfully performed. This results in the disks remaining unsecured and data on them
AnalizadaAlta (7.6)0.41%—Arista NG Firewall10/1/202517/6/2026
A user with advanced report application access rights can perform actions for which they are not authorized
AnalizadaAlta (7.1)0.34%—Arista NG Firewall10/1/202517/6/2026
Backup uploads to ETM subject to man-in-the-middle interception
AnalizadaAlta (7.6)0.43%—Arista NG Firewall10/1/202517/6/2026
Specially constructed queries targeting ETM could discover active remote access sessions