Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

1025 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.56%—Fmemodules B2B Quick Order Form14/3/202417/6/2026
SQL injection vulnerability in FME Modules quickproducttable module for PrestaShop v.1.2.1 and before, allows a remote attacker to escalate privileges and obtain information via the readCsv(), displayAjaxProductChangeAttr, displayAjaxProductAddToCart, getSearchProducts, and displayAjaxProductSku methods.
AplazadaAlta (7.5)0.52%—Siemens Sentron 3KC Atc6 Expansion Module EthernetAI12/3/202417/6/2026
A vulnerability has been identified in SENTRON 3KC ATC6 Expansion Module Ethernet (3KC9000-8TL75) (All versions). Affected devices expose an unused, unstable http service at port 80/tcp on the Modbus-TCP Ethernet. This could allow an attacker on the same Modbus network to create a denial of service condition that…
AnalizadaCrítica (9.8)0.53%—Myprestamodules Product Catalog (csv, Excel) Import3/3/202417/6/2026
SQL Injection vulnerability in MyPrestaModules "Product Catalog (CSV, Excel) Import" (simpleimportproduct) modules for PrestaShop versions 6.5.0 and before, allows attackers to escalate privileges and obtain sensitive information via Send::__construct() and importProducts::_addDataToDb methods.
AnalizadaCrítica (9.1)0.79%—Myprestamodules Product Catalog (csv, Excel) Import27/2/202417/6/2026
In the module "Product Catalog (CSV, Excel) Import" (simpleimportproduct) <= 6.7.0 from MyPrestaModules for PrestaShop, a guest can upload files with extensions .php.
ModificadaAlta (8.8)0.26%—Icingaweb2-module-incubator9/2/202417/6/2026
icingaweb2-module-incubator is a working project of bleeding edge Icinga Web 2 libraries. In affected versions the class `gipfl\Web\Form` is the base for various concrete form implementations [1] and provides protection against cross site request forgery (CSRF) by default. This is done by automatically adding an…
ModificadaAlta (7.8)0.17%—Hidglobal Iclass SE Cp1000 Encoder FirmwareHidglobal Iclass SE Readers FirmwareHidglobal Iclass SE Reader Modules FirmwareHidglobal Iclass SE Processors Firmware+46/2/202417/6/2026
Certain configuration available in the communication channel for encoders could expose sensitive data when reader configuration cards are programmed. This data could include credential and device administration keys.
ModificadaCrítica (9.8)0.67%—Prestashopmodules Sliding Cart Block19/1/202417/6/2026
In the module "Sliding cart block" (blockslidingcart) up to version 2.3.8 from PrestashopModules.eu for PrestaShop, a guest can perform SQL injection.
ModificadaAlta (7.8)0.17%—Dell EMC Idrac Service Module16/1/202417/6/2026
Dell iDRAC Service Module, versions 5.2.0.0 and prior, contain an Incorrect Default Permissions vulnerability. It may allow a local unprivileged user to escalate privileges and execute arbitrary code on the affected system. Dell recommends customers upgrade at the earliest opportunity.
ModificadaCrítica (9.8)0.79%—Camsbiometrics Zkteco, Essl, Cams Biometrics Integration ModuleOdoo Biometric Attendance15/12/202317/6/2026
SQL injection vulnerability in Cams Biometrics Zkteco, eSSL, Cams Biometrics Integration Module with HR Attendance (aka odoo-biometric-attendance) v. 13.0 through 16.0.1 allows a remote attacker to execute arbitrary code and to gain privileges via the db parameter in the controllers/controllers.py component.
ModificadaAlta (7.5)0.59%—Myprestamodules Orders (csv, Excel) Export PRO6/12/202317/6/2026
In the module "Orders (CSV, Excel) Export PRO" (ordersexport) < 5.2.0 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can access exports from the module which can lead to a leak of personal information from…
ModificadaMedia (5.3)0.50%—Blmodules CSV Feeds PRO27/11/202317/6/2026
In the module "CSV Feeds PRO" (csvfeeds) < 2.6.1 from Bl Modules for PrestaShop, a guest can download personal information without restriction. Due to too permissive access control which does not force administrator to use password on feeds, a guest can access exports from the module which can lead to leaks of…
ModificadaCrítica (9.8)0.77%—Myprestamodules Updateproducts27/11/202317/6/2026
In the module "Product Catalog (CSV, Excel) Export/Update" (updateproducts) < 3.8.5 from MyPrestaModules for PrestaShop, a guest can perform SQL injection. The method `productsUpdateModel::getExportIds()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.
ModificadaCrítica (9.8)0.71%—Myprestamodules Cross Selling IN Modal Cart22/11/202317/6/2026
In the module "Cross Selling in Modal Cart" (motivationsale) < 3.5.0 from MyPrestaModules for PrestaShop, a guest can perform SQL injection. The method `motivationsaleDataModel::getProductsByIds()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.
ModificadaCrítica (9.8)0.71%—Myprestamodules Exportproducts17/11/202317/6/2026
In the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 5.0.0 from MyPrestaModules for PrestaShop, a guest can perform SQL injection via `exportProduct::_addDataToDb().`
AnalizadaAlta (8.8)0.67%—Myprestamodules Orders (csv, Excel) Export PRO15/11/202317/6/2026
MyPrestaModules ordersexport before v5.0 was discovered to contain multiple SQL injection vulnerabilities at send.php via the key and save_setting parameters.
ModificadaMedia (6.7)0.24%—Intel Server Board M70klp2sb FirmwareIntel Server System M70klp4s2uhh FirmwareIntel Server Board M20ntp2sb FirmwareIntel Server System M20ntp1ur304 Firmware+2914/11/202317/6/2026
Improper input validation in some Intel(R) Server Board BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access
ModificadaMedia (6.7)0.23%—Intel Server Board M70klp2sb FirmwareIntel Server System M70klp4s2uhh FirmwareIntel Server Board M20ntp2sb FirmwareIntel Server System M20ntp1ur304 Firmware+2914/11/202317/6/2026
Improper input validation in some Intel(R) Server board and Intel(R) Server System BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.19%—Intel Compute Module Hns2600bp FirmwareIntel Compute Module Hns2600bpb FirmwareIntel Compute Module Hns2600bpb24 FirmwareIntel Compute Module Hns2600bpb24r Firmware+3214/11/202317/6/2026
Improper buffer restrictions in some Intel(R) Server Board M10JNP2SB BIOS firmware before version 7.219 may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.21%—Intel Server Board M70klp2sb FirmwareIntel Server System M70klp4s2uhh FirmwareIntel Server Board M20ntp2sb FirmwareIntel Server System M20ntp1ur304 Firmware+2914/11/202317/6/2026
Improper buffer restrictions in some Intel(R) Server Board BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.5)0.47%—Smartmodules Facebookconversiontrackingplus2/11/202317/6/2026
In the module "Pixel Plus: Events + CAPI + Pixel Catalog for Facebook Module" (facebookconversiontrackingplus) up to version 2.4.9 from Smart Modules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can access exports from the module which can…
ModificadaCrítica (9.8)0.64%—Blmodules CSV Feeds PRO31/10/202317/6/2026
In the module "CSV Feeds PRO" (csvfeeds) before 2.6.1 from Bl Modules for PrestaShop, a guest can perform SQL injection. The method `SearchApiCsv::getProducts()` has sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitApache ActivemqApache Activemq Legacy Openwire ModuleDebian LinuxNetapp E-series Santricity Unified Manager+227/10/202317/6/2026
The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or…
ModificadaAlta (7.5)0.80%—Myprestamodules Exportproducts25/10/202317/6/2026
In the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 4.1.1 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the path name…
ModificadaMedia (6.6)0.96%—Netmodule Router Software22/10/202317/6/2026
The web administration interface in NetModule Router Software (NRSW) 4.6 before 4.6.0.106 and 4.8 before 4.8.0.101 executes an OS command constructed with unsanitized user input: shell metacharacters in the /admin/gnssAutoAlign.php device_id parameter. This occurs because another thread can be started before the trap…
ModificadaCrítica (9.8)0.98%—Myprestamodules Product Catalog (csv, Excel) Import20/9/202317/6/2026
SimpleImportProduct Prestashop Module v6.2.9 was discovered to contain a SQL injection vulnerability via the key parameter at send.php.
Orbitaley — Vulnerabilidades