Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

374 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)23%💥 ExploitGeovision Gv-aswebAI27/2/202517/6/2026
GeoVision GV-ASWeb with the version 6.1.2.0 or less (fixed in 6.2.0), contains a Remote Code Execution (RCE) vulnerability within its Notification Settings feature. An authenticated attacker with "System Settings" privileges in ASWeb can exploit this flaw to execute arbitrary commands on the server, leading to a full…
AplazadaAlta (7.2)1.3%—CheckmkAINagvisAI4/2/202517/6/2026
The "NagVis" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrative level privileges is able to upload a malicious PHP file and modify specific settings to execute the contents of the file as PHP.
AplazadaMedia (5.4)0.58%—Checkmk NagvisAI4/2/202517/6/2026
The "NagVis" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the context of the browser once clicked. The attack can be performed on both authenticated and unauthenticated users.
AplazadaAlta (7.2)1.1%—Netgear Fvs336gv2AINetgear Fvs336gv3AI4/2/202517/6/2026
The end-of-life Netgear FVS336Gv2 and FVS336Gv3 are affected by a command injection vulnerability in the Telnet interface. An authenticated and remote attacker can execute arbitrary OS commands as root over Telnet by sending crafted "util backup_configuration" commands.
AnalizadaMedia (6.5)0.23%—Dsgvo-for-wp Dsgvo ALL IN ONE FOR WP4/2/202517/6/2026
The DSGVO All in one for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6. This is due to missing or incorrect nonce validation in the user_remove_form.php file. This makes it possible for unauthenticated attackers to delete admin user accounts via a forged…
AplazadaAlta (8.1)0.36%—Geovision Gv-aswebAI3/2/202517/6/2026
Geovision GV-ASWeb with the version 6.1.1.0 or less allows attackers to modify POST request method with the GET against critical functionalities, such as account management. This vulnerability is used in chain with CVE-2024-56901 for a successful CSRF attack.
AplazadaAlta (7.5)23%💥 ExploitGeovision Gv-asmanagerAI3/2/202517/6/2026
Information disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which discloses account information, including cleartext password.
AplazadaAlta (8.8)1.8%💥 ExploitGeovision Gv-aswebAI3/2/202517/6/2026
A Cross-Site Request Forgery (CSRF) vulnerability in Geovision GV-ASWeb application with the version 6.1.1.0 or less that allows attackers to arbitrarily create Administrator accounts via a crafted GET request method. This vulnerability is used in chain with CVE-2024-56903 for a successful CSRF attack.
AplazadaAlta (8.8)2.6%💥 ExploitGeovision Gv-aswebAI3/2/202517/6/2026
Broken access control vulnerability in Geovision GV-ASWeb with version v6.1.0.0 or less. This vulnerability allows low privilege users perform actions that they aren't authorized to, which can be leveraged to escalate privileges, create, modify or delete accounts.
AnalizadaMedia (6.3)0.27%—Google Gvisor30/1/202517/6/2026
Weaknesses in the generation of TCP/UDP source ports and some other header values in Google's gVisor allowed them to be predicted by an external attacker in some circumstances.
AnalizadaMedia (6.3)0.22%—Google Gvisor30/1/202517/6/2026
A weak hashing algorithm and small sizes of seeds/secrets in Google's gVisor allowed for a remote attacker to calculate a local IP address and a per-boot identifier that could aid in tracking of a device in certain circumstances.
AplazadaAlta (7.1)0.30%—E Marten EU Dsgvo HelperAI22/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E. Marten EU DSGVO Helper dsgvo allows Reflected XSS.This issue affects EU DSGVO Helper: from n/a through <= 1.0.6.1.
AplazadaCrítica (9.8)0.59%—Pingvin ShareAI8/1/202517/6/2026
Pingvin Share is a self-hosted file sharing platform and an alternative for WeTransfer. This vulnerability allows an authenticated or unauthenticated (if anonymous shares are allowed) user to overwrite arbitrary files on the server, including sensitive system files, via HTTP POST requests. The issue has been patched…
ModificadaAlta (7.3)0.35%—Gvectors Wpdiscuz2/1/202517/6/2026
Missing Authorization vulnerability in AdvancedCoding wpDiscuz wpdiscuz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpDiscuz: from n/a through <= 7.6.10.
ModificadaAlta (8.8)0.41%—Gvectors Wpdiscuz2/1/202517/6/2026
Missing Authorization vulnerability in AdvancedCoding wpDiscuz wpdiscuz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpDiscuz: from n/a through <= 7.6.3.
AplazadaAlta (8.8)0.43%—PlugversionsAI24/12/202417/6/2026
The PlugVersions – Easily rollback to previous versions of your plugins plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the eos_plugin_reviews_restore_version() function in all versions up to, and including, 0.0.7. This makes it possible for authenticated attackers,…
ModificadaMedia (6.1)0.53%—Nagvis19/12/202417/6/2026
Improper neutralization of input in Nagvis before version 1.9.42 which can lead to XSS
AnalizadaMedia (6.5)0.60%—Geovision Gv-asmanager13/12/202417/6/2026
GeoVision GV-ASManager Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of GeoVision GV-ASManager. Although authentication is required to exploit this vulnerability, default guest credentials may be used.…
ModificadaMedia (5.4)0.30%—Gvectors Wpforo Forum9/12/202417/6/2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in gVectors Team wpForo Forum allows Code Injection.This issue affects wpForo Forum: from n/a through 2.2.5.
AnalizadaCrítica (9.8)28%⚠ Explotación activaGeovision Gv-vs12 FirmwareGeovision Gv-vs11 FirmwareGeovision Gv-dsp LPR FirmwareGeovision Gvlx 4 Firmware15/11/202417/6/2026
Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we have received related reports.
AnalizadaCrítica (9.8)0.81%—Gvectors Wpdiscuz25/10/202417/6/2026
The Comments – wpDiscuz plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.6.24. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the…
AplazadaAlta (8.8)12%—Dlink Di-7003gAIDlink Di-7003gv2AIDlink Di-7100g+v2AIDlink Di-7100gv2AI+39/9/202417/6/2026
D-Link DI-7003G v19.12.24A1, DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution (RCE) via version_upgrade.asp.
AplazadaAlta (8.8)32%—Dlink Di-7003gv2AIDlink Di-7100g+v2AIDlink Di-7100gv2AIDlink Di-7200gv2AI+29/9/202417/6/2026
D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution due to insufficient parameter filtering in the CGI handling function of upgrade_filter.asp.
AplazadaAlta (8.8)12%—Dlink Di-7003gv2AIDlink Di-7100g+v2AIDlink Di-7100gv2AIDlink Di-7200gv2AI+29/9/202417/6/2026
D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution. An attacker can achieve arbitrary command execution by sending a carefully crafted malicious string to the CGI…
AnalizadaMedia (5.4)0.26%—Dsgvo-for-wp Dsgvo ALL IN ONE FOR WP29/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Leithold DSGVO All in one for WP allows Stored XSS.This issue affects DSGVO All in one for WP: from n/a through 4.5.