Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

889 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.5)0.38%—Aspect-enterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI22/5/202517/6/2026
An escalation of privilege vulnerability in ASPECT could provide an attacker root access to a server when logged in as a "non" root ASPECT user. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.
AplazadaAlta (7.5)0.46%—Aspect-enterpriseAIAspect Nexus SeriesAIAspect Matrix SeriesAI22/5/202517/6/2026
Absolute File Traversal vulnerabilities in ASPECT allows access and modification of unintended resources. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.
AplazadaMedia (6.9)0.42%—Iodata Hdl-t SeriesAI15/5/202517/6/2026
Missing authentication for critical function issue exists in I-O DATA network attached hard disk 'HDL-T Series' firmware Ver.1.21 and earlier. If exploited, a remote unauthenticated attacker may change the product settings.
AplazadaCrítica (9.3)1.7%—Iodata Hdl-t SeriesAI15/5/202517/6/2026
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in I-O DATA network attached hard disk 'HDL-T Series' firmware Ver.1.21 and earlier when 'Remote Link3 function' is enabled. If exploited, a remote unauthenticated attacker may execute an arbitrary OS command.
AplazadaMedia (6.4)0.28%💥 PoCEg-seriesAI15/5/202517/6/2026
The EG-Series plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [series] shortcode in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping on user supplied attributes in the shortcode_title function. This makes it possible for…
AplazadaMedia (6.9)0.15%—Intel Data Center GPU Flex Series DriverAI13/5/202517/6/2026
Improper access control for some Intel(R) Data Center GPU Flex Series for Windows driver before version 31.0.101.4314 may allow an authenticated user to potentially enable denial of service via local access.
AplazadaMedia (5.8)0.13%—Intel Data Center GPU Flex Series Windows DriverAI13/5/202517/6/2026
Improper access control for some Intel(R) Data Center GPU Flex Series for Windows driver software before version 31.0.101.4255 may allow an authenticated user to potentially enable denial of service via local access.
AplazadaAlta (8.2)0.17%—Intel Data Center GPU Flex Series Windows DriverAI13/5/202517/6/2026
Improper buffer restrictions for some Intel(R) Data Center GPU Flex Series for Windows driver before version 31.0.101.4314 may allow an authenticated user to potentially enable denial of service via local access.
AplazadaMedia (5.3)0.21%—Apogee PXC Talon TC SeriesAI13/5/202517/6/2026
A vulnerability has been identified in APOGEE PXC+TALON TC Series (BACnet) (All versions). Affected devices start sending unsolicited BACnet broadcast messages after processing a specific BACnet createObject request. This could allow an attacker residing in the same BACnet network to send a specially crafted message…
AplazadaAlta (8.2)0.35%—Danfoss Ak-sm 8xxa SeriesAI8/5/202517/6/2026
Improper Authentication vulnerability in Danfoss AKSM8xxA Series.This issue affects Danfoss AK-SM 8xxA Series prior to version 4.2
AplazadaBaja (1)0.22%—Silabs Series 2AISilabs EcdhAISilabs EddsaAI29/4/202517/6/2026
DPA countermeasures are unavailable for ECDH key agreement and EdDSA signing operations on Curve25519 and Curve448 on all Series 2 modules and SoCs due to a lack of hardware and software support. A successful DPA attack may result in exposure of confidential information. The best practice is to use the impacted crypto…
AplazadaCrítica (9.8)0.40%—Nautel VX SeriesAI18/4/202517/6/2026
Nautel VX Series transmitters VX SW v6.4.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the firmware update process. This vulnerability allows attackers to execute arbitrary code via supplying a crafted update package to the /#/software/upgrades endpoint.
AplazadaAlta (7.5)0.39%—Soundcraft UI SeriesAI18/4/202517/6/2026
An information disclosure vulnerability in the component /socket.io/1/websocket/ of Soundcraft Ui Series Model(s) Ui12 and Ui16 Firmware v1.0.7x and v1.0.5x allows attackers to access Administrator credentials in plaintext.
AplazadaAlta (7.1)0.57%—Paloaltonetworks Pan-osAIPaloaltonetworks Vm-seriesAI11/4/202517/6/2026
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. This issue is only applicable to PAN-OS VM-Series. This issue does not affect firewalls that are already deployed. Cloud NGFW and…
AplazadaAlta (7.5)0.56%—Wps-11ac SeriesAI9/4/202517/6/2026
Missing authentication for critical function vulnerability exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a remote unauthenticated attacker may obtain the product configuration information including authentication information.
AplazadaAlta (7.7)0.69%—Cisco AnyconnectAICisco Meraki MXAICisco Meraki Z SeriesAI2/4/202517/6/2026
A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series devices could allow an authenticated, remote attacker to cause a denial of service (DoS) condition in the Cisco AnyConnect service on an affected device. To exploit this vulnerability, the attacker must have valid VPN user…
AnalizadaAlta (7.5)0.41%—IBM Txseries FOR Multiplatforms2/4/202517/6/2026
IBM TXSeries for Multiplatforms 9.1 and 11.1 could disclose sensitive information to a remote attacker due to improper neutralization of HTTP headers.
AnalizadaMedia (5.3)0.31%—IBM Txseries FOR Multiplatforms2/4/202517/6/2026
IBM TXSeries for Multiplatforms 9.1 and 11.1 could allow an attacker to enumerate usernames due to an observable login attempt response discrepancy.
AnalizadaMedia (5.4)0.23%—IBM Txseries FOR Multiplatforms2/4/202517/6/2026
IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AnalizadaAlta (8.8)0.18%—IBM Txseries FOR Multiplatforms2/4/202517/6/2026
IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
AplazadaAlta (7.1)0.31%—Chaozh Simple-post-seriesAI26/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in chaozh Simple Post Series simple-post-series allows Reflected XSS.This issue affects Simple Post Series: from n/a through <= 2.4.4.
AplazadaMedia (4.2)0.18%—Silabs Series 2AI17/3/202517/6/2026
The DPA countermeasures on Silicon Labs' Series 2 devices are not reseeded periodically as they should be. This may allow an attacker to eventually extract secret keys through a DPA attack.
AplazadaAlta (8.7)0.52%—Avid Nexis E-seriesAIAvid Nexis F-seriesAIAvid Nexis Pro+AIAvid System Director ApplianceAI12/3/202517/6/2026
Improper Input Validation vulnerability in Avid Avid NEXIS E-series on Linux, Avid Avid NEXIS F-series on Linux, Avid Avid NEXIS PRO+ on Linux, Avid System Director Appliance (SDA+) on Linux allows code execution on underlying operating system with root permissions.This issue affects Avid NEXIS E-series: before…
AplazadaMedia (5.3)0.40%—Cente Middleware TCP IP Network SeriesAI14/2/202517/6/2026
Out-of-bounds read vulnerability caused by improper checking of TCP MSS option values exists in Cente middleware TCP/IP Network Series, which may lead to processing a specially crafted packet to cause the affected product crashed.
AplazadaMedia (5.4)0.19%—Intel Realsense D400 Series UWP DriverAI12/2/202517/6/2026
Uncontrolled search path for the Intel(R) RealSense D400 Series Universal Windows Platform (UWP) Driver for Windows(R) 10 all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
Orbitaley — Vulnerabilidades