Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
1920 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.15% | 💥 PoC | F5 Nginx PlusF5 Nginx Open Source | 24/3/2026 | 17/6/2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake to succeed even after an OCSP check identifies the certificate as revoked.… | |
| Analizada | Media (6.3) | 0.26% | — | F5 Nginx PlusF5 Nginx Open Source | 24/3/2026 | 17/6/2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary headers into SMTP upstream requests, leading to potential request manipulation. Note: Software… | |
| Modificada | Alta (8.8) | 25% | 💥 PoC | F5 Nginx PlusF5 Nginx Open Source | 24/3/2026 | 15/7/2026 | NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or destination file names outside the… | |
| Modificada | Alta (8.7) | 0.94% | — | F5 Nginx Open SourceF5 Nginx Plus | 24/3/2026 | 15/7/2026 | When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header.… | |
| Aplazada | Alta (8.8) | 0.33% | — | Matrimony Website Script M-plusAI | 24/3/2026 | 17/6/2026 | Matrimony Website Script M-Plus contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting SQL code through various POST parameters. Attackers can inject malicious SQL payloads into parameters like txtGender, religion, Fage, and cboCountry across… | |
| Pendiente de análisis | Crítica (9.3) | 0.80% | — | Speedbit Download Accelerator PlusAI | 24/3/2026 | 17/6/2026 | Download Accelerator Plus DAP 10.0.6.0 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by crafting malicious URLs. Attackers can create specially crafted URLs with overflowing buffer data that overwrites SEH pointers and executes embedded… | |
| Pendiente de análisis | Crítica (10) | 0.43% | — | Timeplus-io ProtonAI | 24/3/2026 | 17/6/2026 | Out-of-bounds Write vulnerability in timeplus-io proton (base/poco/Foundation/src modules). This vulnerability is associated with program files inflate.C. This issue affects proton: before 1.6.16. | |
| Analizada | Alta (7.7) | 0.67% | — | Nexxtsolutions Nebula300plus Firmware | 23/3/2026 | 17/6/2026 | Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout mechanisms on authentication interfaces. An attacker can perform unlimited authentication attempts against endpoints that rely on credential validation, enabling brute-force attacks to guess… | |
| Analizada | Media (6.8) | 0.27% | — | Nexxtsolutions Nebula300plus Firmware | 23/3/2026 | 17/6/2026 | Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 stores sensitive information, including administrative credentials and WiFi pre-shared keys, in plaintext within exported configuration backup files. These backup files can be obtained through legitimate functionality or other weaknesses and do not apply… | |
| Analizada | Alta (7.2) | 0.17% | — | Nexxtsolutions Nebula300plus Firmware | 23/3/2026 | 17/6/2026 | Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement CSRF protections on state-changing endpoints such as /goform/setSysTools and other administrative interfaces. As a result, an attacker can craft malicious web requests that are executed in the context of an authenticated… | |
| Modificada | Alta (8.7) | 0.46% | — | Nexxtsolutions Nebula300plus Firmware | 23/3/2026 | 10/8/2026 | Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_pw cookie for authentication, which contains Base64-encoded credential data combined with a static suffix. Because the encoding is reversible and lacks integrity protection, an attacker can reconstruct or forge a valid cookie value without… | |
| Modificada | Alta (8.5) | 0.68% | — | Nexxtsolutions Nebula300plus Firmware | 23/3/2026 | 10/8/2026 | Hidden functionality in the /goform/setSysTools endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows remote enablement of a Telnet service. By sending a crafted POST request with parameters such as telnetManageEn=true and telnetPwd, an authenticated attacker can activate a Telnet service… | |
| Aplazada | Baja (1.3) | 0.19% | — | Shenzhen HCC Technology Mpos M6 PlusAI | 23/3/2026 | 17/6/2026 | A flaw has been found in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. This affects an unknown part of the component Cardholder Data Handler. Executing a manipulation can lead to cleartext transmission of sensitive information. The attack requires access to the local network. The attack requires a high level of… | |
| Aplazada | Baja (1.3) | 0.41% | — | Shenzhen HCC Technology Mpos M6 PlusAI | 23/3/2026 | 17/6/2026 | A vulnerability was detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this issue is some unknown functionality of the component Bluetooth Handler. Performing a manipulation results in authentication bypass by capture-replay. The attack must originate from the local network. The attack is considered… | |
| Aplazada | Baja (1.3) | 0.39% | — | Shenzhen HCC Technology Mpos M6 PlusAI | 23/3/2026 | 17/6/2026 | A security vulnerability has been detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this vulnerability is an unknown functionality of the component Bluetooth. Such manipulation leads to missing authentication. The attack must be carried out from within the local network. Attacks of this nature are… | |
| Analizada | Media (6.9) | 0.17% | — | Sandboxie-plus Sandboxie | 21/3/2026 | 17/6/2026 | Sandboxie 5.30 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Program Alerts configuration field. Attackers can paste a buffer of 5000 characters into the 'Select or enter a program' field during program alert configuration… | |
| Aplazada | Media (6.1) | 0.25% | 💥 PoC | Zucchetti Axess XA4AIZucchetti Axess X3AIZucchetti Axess X3bioAIZucchetti Axess X4AI+4 | 18/3/2026 | 5/7/2026 | A Cross-Site Scripting (XSS) vulnerability exists in the web-based configuration interface of Zucchetti Axess access control devices, including XA4, X3/X3BIO, X4, X7, and XIO / i-door / i-door+. The vulnerability is caused by improper sanitization of user-supplied input in the dirBrowse parameter of the… | |
| Aplazada | Crítica (9.8) | 0.94% | — | Hms-networks Ewon FlexyAIHms-networks Cosy PlusAI | 13/3/2026 | 17/6/2026 | HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have a stack buffer overflow that leads to a Denial of Service, which can also be exploited to achieve Unauthenticated Remote Code Execution. | |
| Aplazada | Alta (7.5) | 0.63% | — | Hms-networks Ewon FlexyAIHms-networks Cosy PlusAI | 13/3/2026 | 17/6/2026 | HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 allows unauthenticated attackers to cause a Denial of Service by using a specially crafted HTTP request that leads to a reboot of the device, provided they have access to the… | |
| Aplazada | Crítica (9.1) | 0.20% | — | Hms-networks Ewon FlexyAIHms-networks Cosy PlusAI | 13/3/2026 | 17/6/2026 | HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have weak entropy for authentication cookies, allowing an attacker with a stolen session cookie to find the user password by brute-forcing an encryption parameter. | |
| Aplazada | Alta (8.8) | 0.85% | — | Hms-networks Ewon FlexyAIHms-networks Cosy PlusAI | 13/3/2026 | 17/6/2026 | HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have improper neutralization of special elements used in an OS command allowing remote code execution by attackers with low privilege access on the gateway, provided the attacker… | |
| Aplazada | Crítica (9.3) | 0.76% | — | Netgain EM PlusAI | 11/3/2026 | 17/6/2026 | NetGain EM Plus 10.1.68 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious parameters to the script_test.jsp endpoint. Attackers can send POST requests with shell commands embedded in the 'content' parameter to execute code… | |
| Aplazada | Alta (7.5) | 1.6% | 💥 Exploit | Ioncube Tester PlusAI | 5/3/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Robert Seyfriedsberger ionCube tester plus ioncube-tester-plus allows Path Traversal.This issue affects ionCube tester plus: from n/a through <= 1.3. | |
| Analizada | Alta (7.8) | 0.15% | — | Unitree GO2 EDU Plus FirmwareUnitree GO1 PRO FirmwareUnitree GO1 AIR FirmwareUnitree GO2 X Firmware+3 | 27/2/2026 | 17/6/2026 | Since the encryption algorithm used to protect firmware updates is itself encrypted using key material available to an attacker (or anyone paying attention), the firmware updates may be altered by an unauthorized user, and then trusted by a Unitree product, such as the Unitree Go2 and other models. This issue appears… | |
| Analizada | Crítica (9.8) | 1.1% | — | Zyxel Wx5610-b0 FirmwareZyxel Lte3301-plus FirmwareZyxel Nebula Lte3301-plus FirmwareZyxel Nr7101 Firmware+14 | 24/2/2026 | 17/6/2026 | A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attacker to execute operating system (OS) commands on an affected device by sending specially crafted UPnP SOAP requests. |