Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
21.613 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.46% | — | UI Unifi GatewayAI | 22/9/2026 | 22/9/2026 | A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device. | |
| Aplazada | Alta (7.5) | 0.46% | — | UI Unifi GatewayAI | 22/9/2026 | 22/9/2026 | A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device. | |
| Aplazada | Alta (7.5) | 0.46% | — | UI Unifi GatewayAI | 22/9/2026 | 22/9/2026 | A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device. | |
| Aplazada | Alta (7.5) | 0.46% | — | UI Unifi GatewayAI | 22/9/2026 | 22/9/2026 | A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device. | |
| Pendiente de análisis | Alta (8.7) | 0.57% | — | Concretecms Community StoreAI | 22/9/2026 | 25/9/2026 | Concrete CMS Community Store before 2.7.8 derives digital product download tokens from order creation timestamps instead of random values, making tokens predictable. Unauthenticated attackers can enumerate sequential order and file identifiers to calculate valid download tokens and retrieve digital goods purchased by… | |
| Pendiente de análisis | Crítica (9.4) | 0.70% | — | Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+2 | 22/9/2026 | 24/9/2026 | Lantronix SLC8000 before firmware v9.7.0.5, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a path traversal vulnerability in the web management portal upload endpoint that allows authenticated attackers to write arbitrary data to… | |
| Pendiente de análisis | Crítica (10) | 1.0% | — | Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+2 | 22/9/2026 | 24/9/2026 | Lantronix SLC8000 before firmware v9.7.0.5, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain an authentication bypass vulnerability in the web management portal upload endpoint that allows unauthenticated attackers to read sensitive… | |
| Pendiente de análisis | Alta (8.9) | 0.63% | — | Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+2 | 22/9/2026 | 24/9/2026 | All firmware versions of Lantronix SLC8000, SLC9000, EMG8500, EMG7500, SLB882, SLCx-03, and SLCx-02 contain an authentication bypass vulnerability in the web management portal that allows unauthenticated attackers to derive valid session tokens of logged-in users and bypass source IP and User-Agent validation. Session… | |
| Pendiente de análisis | Crítica (9.4) | 1.7% | — | Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+2 | 22/9/2026 | 26/9/2026 | Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with the services permission to execute arbitrary shell commands as… | |
| Pendiente de análisis | Crítica (9.4) | 1.7% | — | Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+2 | 22/9/2026 | 26/9/2026 | Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with the services permission to execute arbitrary shell commands as… | |
| Pendiente de análisis | Alta (7.7) | 0.58% | — | Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI | 22/9/2026 | 26/9/2026 | Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet listener that allows unauthenticated attackers to cause the affected device to… | |
| Pendiente de análisis | Alta (7.7) | 0.58% | — | Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI | 22/9/2026 | 26/9/2026 | Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet listener that allows unauthenticated attackers to cause the affected device to… | |
| Pendiente de análisis | Alta (7.7) | 0.58% | — | Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI | 22/9/2026 | 26/9/2026 | Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet listener that allows unauthenticated attackers to cause the affected device to… | |
| Pendiente de análisis | Crítica (9.4) | 0.46% | — | Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+2 | 22/9/2026 | 24/9/2026 | Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a stack-based buffer overflow vulnerability that allows authenticated attackers to potentially execute arbitrary code by exploiting an undocumented mfc eeprom write… | |
| Pendiente de análisis | Crítica (9.4) | 0.85% | — | Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+2 | 22/9/2026 | 25/9/2026 | Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a stack-based buffer overflow vulnerability that allows authenticated attackers to potentially execute arbitrary code by exploiting an undocumented mfc eeprom read… | |
| Pendiente de análisis | Crítica (9.4) | 1.7% | — | Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+2 | 22/9/2026 | 24/9/2026 | Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with the services permission to execute arbitrary shell commands as root by exploiting the set… | |
| Pendiente de análisis | Crítica (9.4) | 1.5% | — | Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+2 | 22/9/2026 | 24/9/2026 | Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers to execute arbitrary shell commands as root by exploiting an undocumented mfc eeprom write… | |
| Pendiente de análisis | Crítica (9.4) | 1.5% | — | Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+2 | 22/9/2026 | 24/9/2026 | Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers to execute arbitrary shell commands as root by exploiting an undocumented mfc eeprom read… | |
| Aplazada | Crítica (9.8) | 0.32% | — | Karel Electronic Industry AND Trade KarelipsAI | 22/9/2026 | 22/9/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Karel Electronic Industry and Trade Inc. KarelIPS allows Blind SQL Injection. This issue affects KarelIPS: through 22092026. NOTE: The vendor was contacted and it was learned that the product is not supported. | |
| Aplazada | Alta (7.2) | 0.41% | — | Ninjaforms Ninja FormsAI | 22/9/2026 | 22/9/2026 | Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break out of the textarea with stored script. When an Administrator opens the attacker-known direct submission URL, the script runs in the WordPress admin origin. | |
| Aplazada | Alta (8.8) | 0.35% | — | Ninjaforms Ninja FormsAI | 22/9/2026 | 22/9/2026 | The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the submission edit screen in the admin area, which could allow unauthenticated users to submit values through a public form that then execute in the browser of any high-privileged user who reviews the… | |
| Aplazada | Alta (7.5) | 0.30% | — | Ninjaforms Ninja FormsAI | 22/9/2026 | 22/9/2026 | The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, allowing unauthenticated attackers to perform PHP Object Injection; if a suitable POP chain is present via another installed plugin or theme,… | |
| Aplazada | Alta (7.2) | 0.33% | — | Niteothemes CMPAI | 22/9/2026 | 22/9/2026 | The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'cmp_ajax_import_settings' AJAX action in all versions up to, and including, 4.1.17. This makes it possible… | |
| Aplazada | Crítica (9.8) | 0.75% | — | UniverAI | 21/9/2026 | 24/9/2026 | A remote code execution (RCE) vulnerability in the RemoteRegisterFunctionService function (/remote/remote-register-function.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload. | |
| Aplazada | Crítica (9.8) | 0.75% | — | UniverAI | 21/9/2026 | 22/9/2026 | A remote code execution (RCE) vulnerability in the UniscriptExecutionService.execute() function (/services/script-execution.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload. |