Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
1437 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.6) | 0.64% | — | Arista NG Firewall | 23/4/2025 | 17/6/2026 | Arista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG Firewall. Minimal user interaction is required to exploit this vulnerability. The specific flaw exists within the… | |
| Analizada | Baja (3.5) | 0.49% | — | Oracle Solaris | 15/4/2025 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Solaris. Successful attacks require human… | |
| Analizada | Alta (7.2) | 0.21% | — | Oracle Solaris | 15/4/2025 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require… | |
| Aplazada | Media (5.1) | 0.41% | — | Softcom IksarisAI | 14/4/2025 | 17/6/2026 | Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. An attacker might trick a user into filling a form sent to login panel at /softcom/ with a malicious script, what causes the script to run in user's context. This vulnerability has been patched in… | |
| Aplazada | Alta (7.6) | 0.50% | — | Aristo Rinjuang WP InquiriesAI | 9/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aristo Rinjuang WP Inquiries wp-inquiries allows SQL Injection.This issue affects WP Inquiries: from n/a through <= 0.2.1. | |
| Aplazada | Media (6) | 0.25% | — | Arista Aos-8 InstantAIArista Aos-10 APAI | 8/4/2025 | 17/6/2026 | A vulnerability in the file creation process on the command line interface of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacker to perform remote code execution (RCE). Successful exploitation could allow an attacker to execute arbitrary operating system commands on the underlying operating… | |
| Aplazada | Alta (7.1) | 0.31% | — | Parisneo LollmsAI | 20/3/2025 | 17/6/2026 | A Path Traversal vulnerability exists in the `/wipe_database` endpoint of parisneo/lollms version v12, allowing an attacker to delete any directory on the system. The vulnerability arises from improper validation of the `key` parameter, which is used to construct file paths. An attacker can exploit this by sending a… | |
| Aplazada | Alta (8.4) | 0.46% | — | Parisneo LollmsAI | 20/3/2025 | 17/6/2026 | A remote code execution vulnerability exists in the Calculate function of parisneo/lollms version 9.8. The vulnerability arises from the use of Python's `eval()` function to evaluate mathematical expressions within a Python sandbox that disables `__builtins__` and only allows functions from the `math` module. This… | |
| Aplazada | Alta (8) | 0.23% | — | Parisneo LollmsAI | 20/3/2025 | 17/6/2026 | A missing check_access() function in the lollms_binding_infos module of the parisneo/lollms repository, version V14, allows attackers to add, modify, and remove bindings arbitrarily. This vulnerability affects the /install_binding and /reinstall_binding endpoints, among others, enabling unauthorized access and… | |
| Aplazada | Media (5.3) | 0.36% | — | Arista EOSAI | 4/3/2025 | 17/6/2026 | On affected platforms running Arista EOS with BGP Link State configured, BGP peer flap can cause the BGP agent to leak memory. This may result in BGP routing processing being terminated and route flapping. | |
| Aplazada | Media (5.3) | 0.20% | — | Arista EOSAI | 4/3/2025 | 17/6/2026 | On affected platforms running Arista EOS with 802.1X configured, certain conditions may occur where a dynamic ACL is received from the AAA server resulting in only the first line of the ACL being installed after an Accelerated Software Upgrade (ASU) restart. Note: supplicants with pending captive-portal authentication… | |
| Aplazada | Crítica (9.1) | 0.44% | — | Arista EOSAI | 4/3/2025 | 17/6/2026 | On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result in unexpected configuration/operations being applied to the switch. | |
| Aplazada | Alta (7.7) | 0.35% | — | Arista EOSAI | 4/3/2025 | 17/6/2026 | On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result in users retrieving data that should not have been available | |
| Analizada | Media (6.1) | 0.59% | 💥 Exploit | Parisholley Fantastic Elasticsearch | 31/1/2025 | 17/6/2026 | The Fantastic ElasticSearch WordPress plugin through 4.1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Analizada | Media (6) | 0.19% | — | Oracle Solaris | 21/1/2025 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: File system). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this… | |
| Aplazada | Alta (7.1) | 0.19% | — | Starise Twitter-shortcodeAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in starise Twitter Shortcode twitter-shortcode allows Stored XSS.This issue affects Twitter Shortcode: from n/a through <= 0.9. | |
| Analizada | Alta (8.8) | 0.48% | — | Arista NG Firewall | 10/1/2025 | 17/6/2026 | Specially constructed queries cause cross platform scripting leaking administrator tokens | |
| Analizada | Alta (8.3) | 0.62% | — | Arista NG Firewall | 10/1/2025 | 17/6/2026 | Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying operating system with elevated privileges. | |
| Analizada | Media (5.6) | 0.16% | — | Arista NG Firewall | 10/1/2025 | 17/6/2026 | A user with administrator privileges is able to retrieve authentication tokens | |
| Analizada | Crítica (9.8) | 0.69% | — | Arista NG Firewall | 10/1/2025 | 17/6/2026 | The administrator is able to configure an insecure captive portal script | |
| Analizada | Alta (7.2) | 1.4% | — | Arista NG Firewall | 10/1/2025 | 17/6/2026 | A user with administrator privileges can perform command injection | |
| Aplazada | Media (4.6) | 0.10% | — | Arista Cloudvision ApplianceAIArista Dca-350e-cvAI | 10/1/2025 | 17/6/2026 | On Arista CloudVision Appliance (CVA) affected releases running on appliances that support hardware disk encryption (DCA-350E-CV only), the disk encryption might not be successfully performed. This results in the disks remaining unsecured and data on them | |
| Analizada | Alta (7.6) | 0.41% | — | Arista NG Firewall | 10/1/2025 | 17/6/2026 | A user with advanced report application access rights can perform actions for which they are not authorized | |
| Analizada | Alta (7.1) | 0.34% | — | Arista NG Firewall | 10/1/2025 | 17/6/2026 | Backup uploads to ETM subject to man-in-the-middle interception | |
| Analizada | Alta (7.6) | 0.43% | — | Arista NG Firewall | 10/1/2025 | 17/6/2026 | Specially constructed queries targeting ETM could discover active remote access sessions |