Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
822 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8) | 0.17% | — | Startcharge Artemis AC Charger 7-22 KWAI | 27/10/2025 | 17/6/2026 | An issue in the Web Configuration module of Startcharge Artemis AC Charger 7-22 kW v1.0.4 allows authenticated network-adjacent attackers to upload crafted firmware, leading to arbitrary code execution. | |
| Aplazada | Media (6.5) | 0.45% | — | Starcitizen.tools CitizenAI | 17/10/2025 | 17/6/2026 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Citizen from 3.3.0 to 3.9.0 are vulnerable to stored cross-site scripting in the sticky header button message handling. In stickyHeader.js the copyButtonAttributes function assigns innerHTML from a source element’s textContent when… | |
| Aplazada | Media (6.5) | 0.43% | — | Starnet Communications Corporation FastxAI | 14/10/2025 | 17/6/2026 | A path traversal in StarNet Communications Corporation FastX v.4 through v4.1.51 allows unauthenticated attackers to read arbitrary files. | |
| Aplazada | Alta (8.7) | 0.37% | — | Rockwellautomation Studio 5000 Logix DesignerAIRockwellautomation Armorstart ClassicAI | 14/10/2025 | 17/6/2026 | A security issue exists within the Studio 5000 Logix Designer add-on profile (AOP) for the ArmorStart Classic distributed motor controller, resulting in denial-of-service. This vulnerability is possible due to the input of invalid values into Component Object Model (COM) methods. | |
| Aplazada | Media (4.6) | 0.40% | — | AllstarAI | 9/10/2025 | 17/6/2026 | Allstar is a GitHub App to set and enforce security policies. In versions prior to 4.5, a vulnerability in Allstar’s Reviewbot component caused inbound webhook requests to be validated against a hard-coded, shared secret. The value used for the secret token was compiled into the Allstar binary and could not be… | |
| Aplazada | Alta (7.2) | 0.22% | — | HP Sure StartAIHP BiosAIIntel Flash DescriptorAI | 7/10/2025 | 17/6/2026 | A potential security vulnerability has been identified in HP Sure Start’s protection of the Intel Flash Descriptor in certain HP PC products, which might allow security bypass, arbitrary code execution, loss of integrity or confidentiality, or denial of service. HP is releasing BIOS updates to mitigate the potential… | |
| Aplazada | Alta (7.5) | 0.48% | — | LitestarAI | 6/10/2025 | 17/6/2026 | Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In version 2.17.0, rate limits can be completely bypassed by manipulating the X-Forwarded-For header. This renders IP-based rate limiting ineffective against determined attackers. Litestar's RateLimitMiddleware uses `cache_key_from_request()` to… | |
| Aplazada | Baja (2.1) | 0.34% | — | Allstarlink SupermonAIAllstarlink Allmon2AI | 5/10/2025 | 17/6/2026 | A security vulnerability has been detected in AllStarLink Supermon up to 6.2. This vulnerability affects unknown code of the component AllMon2. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early… | |
| Aplazada | Baja (2) | 0.25% | — | Gstarsoft GstarcadAI | 29/9/2025 | 17/6/2026 | A vulnerability has been found in Gstarsoft GstarCAD up to 9.4.0. This affects an unknown function of the component File Renaming Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Applying a patch is the… | |
| Analizada | Media (5.4) | 0.30% | — | Star-citizen Embedvideo | 25/9/2025 | 17/6/2026 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. In versions 4.0.0 and prior, the EmbedVideo extension allows adding arbitrary attributes to an HTML element, allowing for stored XSS through… | |
| Aplazada | Alta (7.5) | 0.54% | — | Immonex Kickstart TeamAIPHPAI | 22/9/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in immonex immonex Kickstart Team immonex-kickstart-team allows PHP Local File Inclusion.This issue affects immonex Kickstart Team: from n/a through <= 1.6.9. | |
| Aplazada | Crítica (9.1) | 0.36% | — | StarchAI | 20/9/2025 | 17/6/2026 | Starch versions 0.14 and earlier generate session ids insecurely. The default session id generator returns a SHA-1 hash seeded with a counter, the epoch time, the built-in rand function, the PID, and internal Perl reference addresses. The PID will come from a small set of numbers, and the epoch time may be guessed, if… | |
| Aplazada | Media (6.3) | 0.25% | — | Saysis Computer Systems Trade Ltd. CO Starcities E-municipality ManagementAI | 19/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saysis Computer Systems Trade Ltd. Co. StarCities E-Municipality Management allows Cross-Site Scripting (XSS). This issue affects StarCities E-Municipality Management: before 20250825. | |
| Aplazada | Alta (7.5) | 0.42% | — | Immonex KickstartAI | 3/9/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in immonex immonex Kickstart immonex-kickstart allows PHP Local File Inclusion.This issue affects immonex Kickstart: from n/a through <= 1.11.6. | |
| Analizada | Media (6.5) | 0.25% | — | Modstart Mostartcms | 2/9/2025 | 17/6/2026 | ModStartCMS v9.5.0 has an arbitrary file write vulnerability, which allows attackers to write malicious files and execute malicious commands to obtain sensitive data on the server. | |
| Aplazada | Alta (8.4) | 0.15% | — | Mitrastar Gpt-2741gnac-n2AI | 26/8/2025 | 5/7/2026 | Mitrastar GPT-2741GNAC-N2 devices are provided with access through ssh into a restricted default shell.The command "deviceinfo show file" is supposed to be used from restricted shell to show files and directories. By providing " /bin/sh" (quotes included) to the argument of this command will drop a root shell. | |
| Aplazada | Media (4.3) | 0.13% | — | Jeff Starr Simple Statistics FOR FeedsAI | 22/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Jeff Starr Simple Statistics for Feeds simple-feed-stats allows Cross Site Request Forgery.This issue affects Simple Statistics for Feeds: from n/a through <= 20250322. | |
| Aplazada | Media (4.3) | 0.24% | — | Pixel Makers Creative INC APP Saas AND Software Startup Tech Theme StratusAI | 14/8/2025 | 14/9/2026 | Missing Authorization vulnerability in Pixel Makers Creative INC. App, SaaS & Software Startup Tech Theme - Stratus allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects App, SaaS & Software Startup Tech Theme - Stratus: from n/a before 4.2.11. | |
| Aplazada | Media (5.2) | 0.18% | — | Instar 2K+AIInstar 4KAI | 13/8/2025 | 17/6/2026 | A vulnerability was found in INSTAR 2K+ and 4K 3.11.1 Build 1124. This issue affects some unknown processing of the component UART Interface. The manipulation leads to improper physical access control. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and may be… | |
| Aplazada | Alta (7.7) | 8.0% | — | Instar 2K+AIInstar 4KAI | 13/8/2025 | 17/6/2026 | A vulnerability has been found in INSTAR 2K+ and 4K 3.11.1 Build 1124. This vulnerability affects unknown code of the component Backend IPC Server. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Crítica (9.3) | 0.78% | 💥 PoC | Instar 2K PlusAIInstar 4KAI | 13/8/2025 | 17/6/2026 | A vulnerability was identified in INSTAR 2K+ and 4K 3.11.1 Build 1124. This affects the function base64_decode of the component fcgi_server. The manipulation of the argument Authorization leads to buffer overflow. It is possible to initiate the attack remotely. | |
| Aplazada | Alta (8.5) | 0.18% | — | Siemens Simatic S7-plcsimAISiemens Simatic Step 7AISiemens Simatic WinccAISiemens Simocode ESAI+5 | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 V17 (All versions < V17 Update 9), SIMATIC STEP 7 V18 (All versions), SIMATIC STEP 7 V19 (All versions < V19 Update 4), SIMATIC STEP 7 V20 (All versions < V20 Update 4), SIMATIC WinCC V17 (All versions < V17 Update 9), SIMATIC… | |
| Aplazada | Media (6.8) | 0.17% | — | Siemens Simotion Scout TIAAISiemens Simotion ScoutAISiemens Sinamics StarterAI | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in SIMOTION SCOUT TIA V5.4 (All versions), SIMOTION SCOUT TIA V5.5 (All versions), SIMOTION SCOUT TIA V5.6 (All versions < V5.6 SP1 HF7), SIMOTION SCOUT TIA V5.7 (All versions < V5.7 SP1 HF1), SIMOTION SCOUT V5.4 (All versions), SIMOTION SCOUT V5.5 (All versions), SIMOTION SCOUT… | |
| Aplazada | Alta (8.6) | 0.17% | — | Siemens Simatic PCS NEOAISiemens Simatic S7-plcsimAISiemens Simatic Step 7AISiemens Simatic WinccAI+7 | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions < V6.0 SP1 Update 1), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 V17 (All versions < V17 Update 9), SIMATIC STEP 7 V18 (All versions), SIMATIC STEP 7 V19 (All… | |
| Aplazada | Media (4.7) | 0.39% | — | StardictAIYoudao PluginAI | 4/8/2025 | 17/6/2026 | The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers via cleartext HTTP. |