Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
2287 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.40% | — | Cisco Adaptive Security Appliance Software | 4/3/2026 | 17/6/2026 | A vulnerability in the implementation of the proprietary SSH stack with SSH key-based authentication in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to log in to a Cisco Secure Firewall ASA device and execute commands as a specific user. This… | |
| Analizada | Media (6) | 0.14% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 4/3/2026 | 11/8/2026 | A vulnerability in a small subset of CLI commands that are used on Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to craft Lua code that could be used on the underlying operating system as root.… | |
| Analizada | Crítica (9.3) | 1.5% | 💥 PoC | Insat Masterscada | 24/2/2026 | 17/6/2026 | All versions of InSAT MasterSCADA BUK-TS are susceptible to OS command injection through a field in its MMadmServ web interface. Malicious users that use the vulnerable endpoint are potentially able to cause remote code execution. | |
| Analizada | Crítica (9.3) | 0.55% | — | Insat Masterscada | 24/2/2026 | 17/6/2026 | InSAT MasterSCADA BUK-TS is susceptible to SQL Injection through its main web interface. Malicious users that use the vulnerable endpoint are potentially able to cause remote code execution. | |
| Aplazada | Media (5.3) | 0.22% | — | Sveltejs Adapter-vercelAI | 20/2/2026 | 17/6/2026 | SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Versions of @sveltejs/adapter-vercel prior to 6.3.2 are vulnerable to cache poisoning. An internal query parameter intended for Incremental Static Regeneration (ISR) is accessible on all routes, allowing an attacker to… | |
| Aplazada | Crítica (9.3) | 0.24% | — | Shahjada Download Manager Addons FOR ElementorAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjada Download Manager Addons for Elementor wpdm-elementor allows Blind SQL Injection.This issue affects Download Manager Addons for Elementor: from n/a through <= 1.3.0. | |
| Aplazada | Alta (8.8) | 0.37% | — | Kamleshyadav Miraculous ElementorAI | 20/2/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in kamleshyadav Miraculous Elementor miraculous-el allows Authentication Abuse.This issue affects Miraculous Elementor: from n/a through <= 2.0.7. | |
| Aplazada | Media (4.6) | 0.25% | — | ScadaappAI | 18/2/2026 | 17/6/2026 | ScadaApp for iOS 1.1.4.0 contains a denial of service vulnerability that allows attackers to crash the application by inputting an oversized buffer in the Servername field. Attackers can paste a 257-character buffer during login to trigger an application crash on iOS devices. | |
| Analizada | Alta (7.5) | 0.15% | — | IBM Qradar EDR | 17/2/2026 | 17/6/2026 | IBM Security QRadar EDR 3.12 through 3.12.23 IBM Security ReaQta uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | |
| Analizada | Alta (8.8) | 0.20% | — | IBM Qradar EDR | 17/2/2026 | 17/6/2026 | IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an authenticated user to impersonate another user on the system. | |
| Analizada | Alta (8.8) | 0.20% | — | IBM Security Qradar EDR | 17/2/2026 | 17/6/2026 | IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an authenticated user to impersonate another user on the system. | |
| Analizada | Alta (7.7) | 0.23% | — | Tp-link AginetTp-link DecoTp-link FestaTp-link Kasa+10 | 13/2/2026 | 17/6/2026 | A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS communication. An attacker in a privileged network position may be able to intercept or modify traffic if they can position themselves within the communication channel.… | |
| Analizada | Baja (2) | 0.36% | — | Tp-link AginetTp-link DecoTp-link FestaTp-link Kasa+10 | 13/2/2026 | 17/6/2026 | A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances. Exploitation requires the presence of an existing client-side injection vulnerability and user access to the affected web interface. Successful exploitation could allow… | |
| Analizada | Alta (7.6) | 0.36% | — | Open-metadata Openmetadata | 11/2/2026 | 17/6/2026 | OpenMetadata is a unified metadata platform. Prior to 1.11.8, calls issued by the UI against /api/v1/ingestionPipelines leak JWTs used by ingestion-bot for certain services (Glue / Redshift / Postgres). Any read-only user can gain access to a highly privileged account, typically which has the Ingestion Bot Role. This… | |
| Analizada | Media (5.8) | 0.45% | — | Faraday Project Faraday | 9/2/2026 | 17/6/2026 | Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Prior to 2.14.1, Faraday's build_exclusive_url method (in lib/faraday/connection.rb) uses Ruby's URI#merge to combine the connection's base URL with a user-supplied path. Per RFC 3986, protocol-relative URLs (e.g.… | |
| Aplazada | Media (4.6) | 0.38% | — | Proficy ScadaAI | 5/2/2026 | 17/6/2026 | ProficySCADA for iOS 5.0.25920 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the password input field. Attackers can overwrite the password field with 257 bytes of repeated characters to trigger an application crash and prevent successful authentication. | |
| Aplazada | Alta (8.5) | 0.17% | — | Lavasoft Adaware WEB CompanionAI | 5/2/2026 | 17/6/2026 | Adaware Web Companion version 4.8.2078.3950 contains an unquoted service path vulnerability in the WCAssistantService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Lavasoft\Web Companion\Application\ to inject malicious… | |
| Aplazada | Alta (8.5) | 0.14% | — | Adaware WEB CompanionAI | 3/2/2026 | 17/6/2026 | Adaware Web Companion 4.9.2159 contains an unquoted service path vulnerability in the WCAssistantService that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be run with LocalSystem privileges during service startup. | |
| Aplazada | Crítica (10) | 0.29% | — | Cadaver Turso3dAI | 27/1/2026 | 17/6/2026 | Out-of-bounds Write, Divide By Zero, NULL Pointer Dereference, Use of Uninitialized Resource, Out-of-bounds Read, Reachable Assertion vulnerability in cadaver turso3d.This issue affects . | |
| Analizada | Media (5.1) | 0.28% | — | Tp-link Omada Controller | 26/1/2026 | 17/6/2026 | Blind Server-Side Request Forgery (SSRF) in Omada Controllers through webhook functionality, enabling crafted requests to internal services, which may lead to enumeration of information. | |
| Analizada | Baja (2.1) | 0.32% | — | Tp-link Omada Controller | 26/1/2026 | 17/6/2026 | Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypass secondary verification, and change the user’s password without proper confirmation, leading to weakened account security. | |
| Analizada | Alta (8.3) | 0.45% | — | Tp-link Omada Controller | 26/1/2026 | 17/6/2026 | An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate requests and potentially hijack the Owner account. | |
| Analizada | Media (6) | 0.22% | — | Tp-link Omada ControllerTp-link Oc200 FirmwareTp-link Oc220 FirmwareTp-link Oc300 Firmware+52 | 22/1/2026 | 6/10/2026 | An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline… | |
| Analizada | Media (5.7) | 0.20% | — | Tp-link Omada ControllerTp-link Oc200 FirmwareTp-link Oc220 FirmwareTp-link Oc300 Firmware+1 | 22/1/2026 | 17/6/2026 | A Cross-Site Scripting (XSS) vulnerability was identified in a parameter in Omada Controllers due to improper input sanitization. Exploitation requires advanced conditions, such as network positioning or emulating a trusted entity, and user interaction by an authenticated administrator. If successful, an attacker… | |
| Aplazada | Alta (7.1) | 0.30% | — | Adamlabs Wordpress Photo GalleryAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in adamlabs WordPress Photo Gallery photo-gallery-portfolio allows Reflected XSS.This issue affects WordPress Photo Gallery: from n/a through <= 1.1.0. |