Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

253 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.94%—Soumu Electronic Reception AND Examination OF Application FOR Radio Licenses17/5/201917/6/2026
Untrusted search path vulnerability in Electronic reception and examination of application for radio licenses Offline 1.0.9.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaAlta (7.8)0.94%—Soumu Electronic Reception AND Examination OF Application FOR Radio Licenses17/5/201917/6/2026
Untrusted search path vulnerability in Installer of Electronic reception and examination of application for radio licenses Online 1.0.9.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaAlta (7.5)40%💥 ExploitEsafenet Electronic Document Security Management System8/3/201917/6/2026
ESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because the InstallationPack parameter is mishandled in a /CDGServer3/ClientAjax request.
ModificadaAlta (8.1)10%💥 ExploitElectronjs Electron23/8/201817/6/2026
GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or "sandbox: true" options, is affected by a WebPreferences vulnerability that can be leveraged to perform remote code execution.
ModificadaMedia (4.8)0.94%—Anelectron Advanced Electron Forum29/6/201817/6/2026
An XSS issue was discovered in Advanced Electron Forum (AEF) v1.0.9. A persistent XSS vulnerability is located in the `FTP Link` element of the `Private Message` module. The editor of the private message module allows inserting links without sanitizing the content. This allows remote attackers to inject malicious…
ModificadaCrítica (9.8)2.7%—Electronjs Electron7/6/201817/6/2026
Based on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google Chromium that affects all recent versions of Electron. Any Electron app that accesses remote content is vulnerable to this exploit, regardless of whether the [sandbox…
ModificadaMedia (5.9)0.94%—Electron-packager Project Electron-packager31/5/201817/6/2026
electron-packager is a command line tool that packages Electron source code into `.app` and `.exe` packages. along with Electron. The `--strict-ssl` command line option in electron-packager >= 5.2.1 <= 6.0.0 || >=6.0.0 <= 6.0.2 defaults to false if not explicitly set to true. This could allow an attacker to perform a…
ModificadaAlta (8.1)5.1%—Electronjs Electron23/3/201817/6/2026
Electron version 1.7 up to 1.7.12; 1.8 up to 1.8.3 and 2.0.0 up to 2.0.0-beta.3 contains an improper handling of values vulnerability in Webviews that can result in remote code execution. This attack appear to be exploitable via an app which allows execution of 3rd party code AND disallows node integration AND has not…
ModificadaAlta (8.8)2.4%—Electronjs Electron7/3/201817/6/2026
Github Electron version Electron 1.8.2-beta.4 and earlier contains a Command Injection vulnerability in Protocol Handler that can result in command execute. This attack appear to be exploitable via the victim opening an electron protocol handler in their browser. This vulnerability appears to have been fixed in…
ModificadaAlta (8.8)84%💥 ExploitAtom Electron24/1/201817/6/2026
GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the protocol handler, specifically Electron apps running on Windows 10, 7 or 2008 that register custom protocol handlers can be tricked in arbitrary command execution if the user clicks on a specially…
ModificadaMedia (4.3)0.98%—Atom Electron2/1/201817/6/2026
Github Electron version 1.6.4 - 1.6.11 and 1.7.0 - 1.7.5 is vulnerable to a URL Spoofing problem when opening PDFs in PDFium resulting loading arbitrary PDFs that a hacker can control.
ModificadaAlta (7.8)1.5%—Moj.go Commercial Registration Electronic Authentication Software29/8/201717/6/2026
Untrusted search path vulnerability in The electronic authentication system based on the commercial registration system "The CRCA user's Software" Ver1.8 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaAlta (8.1)6.7%—Electron6/8/201717/6/2026
GitHub Electron before 1.6.8 allows remote command execution because of a nodeIntegration bypass vulnerability. This also affects all applications that bundle Electron code equivalent to 1.6.8 or earlier. Bypassing the Same Origin Policy (SOP) is a precondition; however, recent Electron versions do not have strict SOP…
ModificadaAlta (7.8)1.4%—Acquisition Technology AND Logistics Agency Installer OF Electronic Tendering7/7/201717/6/2026
Untrusted search path vulnerability in Installer of Electronic tendering and bid opening system available prior to June 12, 2017 allows an attacker to execute arbitrary code via a specially crafted executable file in an unspecified directory.
ModificadaAlta (8.8)1.7%—Atla Electronic Tendering AND BID Opening System9/6/201717/6/2026
Untrusted search path vulnerability in Installer of electronic tendering and bid opening system available prior to May 25, 2017 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaMedia (5.9)0.49%—Electronic Funds Source LLC EFS Mobile Driver Source5/5/201717/6/2026
The Electronic Funds Source (EFS) Mobile Driver Source app 2.5 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.8)1.7%—Delta Electronics IspsoftDelta Electronics PmsoftDelta Electronics Wplsoft13/2/201717/6/2026
An issue was discovered in Delta Electronics WPLSoft, Versions prior to V2.42.11, ISPSoft, Versions prior to 3.02.11, and PMSoft, Versions prior to2.10.10. There are multiple instances of heap-based buffer overflows that may allow malicious files to cause the execution of arbitrary code or a denial of service.
ModificadaAlta (7.8)1.1%—Delta Electronics IspsoftDelta Electronics PmsoftDelta Electronics Wplsoft13/2/201717/6/2026
An issue was discovered in Delta Electronics WPLSoft, Versions prior to V2.42.11, ISPSoft, Versions prior to 3.02.11, and PMSoft, Versions prior to 2.10.10. Multiple instances of out-of-bounds write conditions may allow malicious files to be read and executed by the affected software.
ModificadaAlta (7.8)0.43%—Atom Electron25/4/201617/6/2026
Untrusted search path vulnerability in Atom Electron before 0.33.5 allows local users to gain privileges via a Trojan horse Node.js module in a parent directory of a directory named on a require line.
ModificadaMedia (5.4)0.27%—Magzter Electronics FOR YOU19/10/201417/6/2026
The Electronics For You (aka com.magzter.electronicsforyou) application 3.02 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (10)4.8%—Digital Alert Systems Dasdec EASMonroe Electronics R189 One-net EAS30/6/201316/6/2026
The Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2 have a default password for an administrative account, which makes it easier for remote attackers to obtain access via an IP network.
ModificadaAlta (7.3)1.4%—Digital Alert Systems Dasdec EASMonroe Electronics R189 One-net EAS30/6/201316/6/2026
dasdec_mkuser on the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2 generates predictable passwords, which might make it easier for attackers to obtain non-administrative access via unspecified vectors.
ModificadaAlta (7.5)2.3%—Digital Alert Systems Dasdec EASMonroe Electronics R189 One-net EAS30/6/201316/6/2026
The web server on the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2 allows remote attackers to obtain sensitive configuration and status information by reading log files.
ModificadaAlta (10)3.0%—Digital Alert Systems Dasdec EASMonroe Electronics R189 One-net EAS30/6/201316/6/2026
The administrative web server on the Digital Alert Systems DASDEC EAS device through 2.0-2 and the Monroe Electronics R189 One-Net EAS device through 2.0-2 uses predictable session ID values, which makes it easier for remote attackers to hijack sessions by sniffing the network. NOTE: VU#662676 states "Monroe…
ModificadaAlta (10)13%—Digital Alert Systems Dasdec EASMonroe Electronics R189 One-net EAS30/6/201316/6/2026
The default configuration of the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2 contains a known SSH private key, which makes it easier for remote attackers to obtain root access, and spoof alerts, via an SSH session.
Orbitaley — Vulnerabilidades