Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1025 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.56% | — | Fmemodules B2B Quick Order Form | 14/3/2024 | 17/6/2026 | SQL injection vulnerability in FME Modules quickproducttable module for PrestaShop v.1.2.1 and before, allows a remote attacker to escalate privileges and obtain information via the readCsv(), displayAjaxProductChangeAttr, displayAjaxProductAddToCart, getSearchProducts, and displayAjaxProductSku methods. | |
| Aplazada | Alta (7.5) | 0.52% | — | Siemens Sentron 3KC Atc6 Expansion Module EthernetAI | 12/3/2024 | 17/6/2026 | A vulnerability has been identified in SENTRON 3KC ATC6 Expansion Module Ethernet (3KC9000-8TL75) (All versions). Affected devices expose an unused, unstable http service at port 80/tcp on the Modbus-TCP Ethernet. This could allow an attacker on the same Modbus network to create a denial of service condition that… | |
| Analizada | Crítica (9.8) | 0.53% | — | Myprestamodules Product Catalog (csv, Excel) Import | 3/3/2024 | 17/6/2026 | SQL Injection vulnerability in MyPrestaModules "Product Catalog (CSV, Excel) Import" (simpleimportproduct) modules for PrestaShop versions 6.5.0 and before, allows attackers to escalate privileges and obtain sensitive information via Send::__construct() and importProducts::_addDataToDb methods. | |
| Analizada | Crítica (9.1) | 0.79% | — | Myprestamodules Product Catalog (csv, Excel) Import | 27/2/2024 | 17/6/2026 | In the module "Product Catalog (CSV, Excel) Import" (simpleimportproduct) <= 6.7.0 from MyPrestaModules for PrestaShop, a guest can upload files with extensions .php. | |
| Modificada | Alta (8.8) | 0.26% | — | Icingaweb2-module-incubator | 9/2/2024 | 17/6/2026 | icingaweb2-module-incubator is a working project of bleeding edge Icinga Web 2 libraries. In affected versions the class `gipfl\Web\Form` is the base for various concrete form implementations [1] and provides protection against cross site request forgery (CSRF) by default. This is done by automatically adding an… | |
| Modificada | Alta (7.8) | 0.17% | — | Hidglobal Iclass SE Cp1000 Encoder FirmwareHidglobal Iclass SE Readers FirmwareHidglobal Iclass SE Reader Modules FirmwareHidglobal Iclass SE Processors Firmware+4 | 6/2/2024 | 17/6/2026 | Certain configuration available in the communication channel for encoders could expose sensitive data when reader configuration cards are programmed. This data could include credential and device administration keys. | |
| Modificada | Crítica (9.8) | 0.67% | — | Prestashopmodules Sliding Cart Block | 19/1/2024 | 17/6/2026 | In the module "Sliding cart block" (blockslidingcart) up to version 2.3.8 from PrestashopModules.eu for PrestaShop, a guest can perform SQL injection. | |
| Modificada | Alta (7.8) | 0.17% | — | Dell EMC Idrac Service Module | 16/1/2024 | 17/6/2026 | Dell iDRAC Service Module, versions 5.2.0.0 and prior, contain an Incorrect Default Permissions vulnerability. It may allow a local unprivileged user to escalate privileges and execute arbitrary code on the affected system. Dell recommends customers upgrade at the earliest opportunity. | |
| Modificada | Crítica (9.8) | 0.79% | — | Camsbiometrics Zkteco, Essl, Cams Biometrics Integration ModuleOdoo Biometric Attendance | 15/12/2023 | 17/6/2026 | SQL injection vulnerability in Cams Biometrics Zkteco, eSSL, Cams Biometrics Integration Module with HR Attendance (aka odoo-biometric-attendance) v. 13.0 through 16.0.1 allows a remote attacker to execute arbitrary code and to gain privileges via the db parameter in the controllers/controllers.py component. | |
| Modificada | Alta (7.5) | 0.59% | — | Myprestamodules Orders (csv, Excel) Export PRO | 6/12/2023 | 17/6/2026 | In the module "Orders (CSV, Excel) Export PRO" (ordersexport) < 5.2.0 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can access exports from the module which can lead to a leak of personal information from… | |
| Modificada | Media (5.3) | 0.50% | — | Blmodules CSV Feeds PRO | 27/11/2023 | 17/6/2026 | In the module "CSV Feeds PRO" (csvfeeds) < 2.6.1 from Bl Modules for PrestaShop, a guest can download personal information without restriction. Due to too permissive access control which does not force administrator to use password on feeds, a guest can access exports from the module which can lead to leaks of… | |
| Modificada | Crítica (9.8) | 0.77% | — | Myprestamodules Updateproducts | 27/11/2023 | 17/6/2026 | In the module "Product Catalog (CSV, Excel) Export/Update" (updateproducts) < 3.8.5 from MyPrestaModules for PrestaShop, a guest can perform SQL injection. The method `productsUpdateModel::getExportIds()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection. | |
| Modificada | Crítica (9.8) | 0.71% | — | Myprestamodules Cross Selling IN Modal Cart | 22/11/2023 | 17/6/2026 | In the module "Cross Selling in Modal Cart" (motivationsale) < 3.5.0 from MyPrestaModules for PrestaShop, a guest can perform SQL injection. The method `motivationsaleDataModel::getProductsByIds()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection. | |
| Modificada | Crítica (9.8) | 0.71% | — | Myprestamodules Exportproducts | 17/11/2023 | 17/6/2026 | In the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 5.0.0 from MyPrestaModules for PrestaShop, a guest can perform SQL injection via `exportProduct::_addDataToDb().` | |
| Analizada | Alta (8.8) | 0.67% | — | Myprestamodules Orders (csv, Excel) Export PRO | 15/11/2023 | 17/6/2026 | MyPrestaModules ordersexport before v5.0 was discovered to contain multiple SQL injection vulnerabilities at send.php via the key and save_setting parameters. | |
| Modificada | Media (6.7) | 0.24% | — | Intel Server Board M70klp2sb FirmwareIntel Server System M70klp4s2uhh FirmwareIntel Server Board M20ntp2sb FirmwareIntel Server System M20ntp1ur304 Firmware+29 | 14/11/2023 | 17/6/2026 | Improper input validation in some Intel(R) Server Board BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access | |
| Modificada | Media (6.7) | 0.23% | — | Intel Server Board M70klp2sb FirmwareIntel Server System M70klp4s2uhh FirmwareIntel Server Board M20ntp2sb FirmwareIntel Server System M20ntp1ur304 Firmware+29 | 14/11/2023 | 17/6/2026 | Improper input validation in some Intel(R) Server board and Intel(R) Server System BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.19% | — | Intel Compute Module Hns2600bp FirmwareIntel Compute Module Hns2600bpb FirmwareIntel Compute Module Hns2600bpb24 FirmwareIntel Compute Module Hns2600bpb24r Firmware+32 | 14/11/2023 | 17/6/2026 | Improper buffer restrictions in some Intel(R) Server Board M10JNP2SB BIOS firmware before version 7.219 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.21% | — | Intel Server Board M70klp2sb FirmwareIntel Server System M70klp4s2uhh FirmwareIntel Server Board M20ntp2sb FirmwareIntel Server System M20ntp1ur304 Firmware+29 | 14/11/2023 | 17/6/2026 | Improper buffer restrictions in some Intel(R) Server Board BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.5) | 0.47% | — | Smartmodules Facebookconversiontrackingplus | 2/11/2023 | 17/6/2026 | In the module "Pixel Plus: Events + CAPI + Pixel Catalog for Facebook Module" (facebookconversiontrackingplus) up to version 2.4.9 from Smart Modules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can access exports from the module which can… | |
| Modificada | Crítica (9.8) | 0.64% | — | Blmodules CSV Feeds PRO | 31/10/2023 | 17/6/2026 | In the module "CSV Feeds PRO" (csvfeeds) before 2.6.1 from Bl Modules for PrestaShop, a guest can perform SQL injection. The method `SearchApiCsv::getProducts()` has sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Apache ActivemqApache Activemq Legacy Openwire ModuleDebian LinuxNetapp E-series Santricity Unified Manager+2 | 27/10/2023 | 17/6/2026 | The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or… | |
| Modificada | Alta (7.5) | 0.80% | — | Myprestamodules Exportproducts | 25/10/2023 | 17/6/2026 | In the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 4.1.1 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the path name… | |
| Modificada | Media (6.6) | 0.96% | — | Netmodule Router Software | 22/10/2023 | 17/6/2026 | The web administration interface in NetModule Router Software (NRSW) 4.6 before 4.6.0.106 and 4.8 before 4.8.0.101 executes an OS command constructed with unsanitized user input: shell metacharacters in the /admin/gnssAutoAlign.php device_id parameter. This occurs because another thread can be started before the trap… | |
| Modificada | Crítica (9.8) | 0.98% | — | Myprestamodules Product Catalog (csv, Excel) Import | 20/9/2023 | 17/6/2026 | SimpleImportProduct Prestashop Module v6.2.9 was discovered to contain a SQL injection vulnerability via the key parameter at send.php. |