Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
–

736 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)2.0%—Expresstechlabs Quiz AND Survey MasterAI26/3/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.4.
AnalizadaMedia (6.1)0.79%—Openjsf Express25/3/202417/6/2026
Express.js minimalist web framework for node. Versions of Express.js prior to 4.19.0 and all pre-release alpha and beta versions of 5.0 are affected by an open redirect vulnerability using malformed URLs. When a user of Express performs a redirect using a user-provided URL Express performs an encode [using…
AnalizadaMedia (6.1)0.57%—Tramyardg Autoexpress21/3/202417/6/2026
Stored Cross-Site Scripting (XSS) vulnerability in tramyardg autoexpress 1.3.0, allows remote unauthenticated attackers to inject arbitrary web script or HTML within parameter "imgType" via in uploadCarImages.php.
AnalizadaCrítica (9.8)1.3%—Tramyardg Autoexpress21/3/202417/6/2026
An issue was discovered in tramyardg autoexpress version 1.3.0, allows unauthenticated remote attackers to escalate privileges, update car data, delete vehicles, and upload car images via authentication bypass in uploadCarImages.php.
AnalizadaCrítica (9.8)1.0%—Tramyardg Autoexpress21/3/202417/6/2026
A SQL injection vulnerability in tramyardg Autoexpress version 1.3.0, allows remote unauthenticated attackers to execute arbitrary SQL commands via the parameter "id" within the getPhotosByCarId function call in details.php.
AplazadaMedia (5.4)0.20%—Expresstechsoftware Quiz AND Survey MasterAI16/3/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.18.
AnalizadaMedia (6.1)0.21%—Mongo-express Project Mongo-express1/3/202417/6/2026
In mongo-express 1.0.2, /admin allows CSRF, as demonstrated by deletion of a Collection.
AplazadaAlta (7.5)0.52%—UI Unifi Access PointsAIUI Unifi SwitchesAIUI Unifi LTE BackupAIUI Unifi ExpressAI20/2/202417/6/2026
A malformed discovery packet sent by a malicious actor with preexisting access to the network could interrupt the functionality of device management and discovery. Affected Products: UniFi Access Points UniFi Switches UniFi LTE Backup UniFi Express (Only Mesh Mode, Router mode is not affected) Mitigation: Update UniFi…
ModificadaAlta (7.5)0.67%—Expressvpn11/2/202417/6/2026
ExpressVPN before 12.73.0 on Windows, when split tunneling is used, sends DNS requests according to the Windows configuration (e.g., sends them to DNS servers operated by the user's ISP instead of to the ExpressVPN DNS servers), which may allow remote attackers to obtain sensitive information about websites visited by…
ModificadaAlta (7.1)0.60%—Cisco Expressway7/2/202417/6/2026
A vulnerability in the SOAP API of Cisco Expressway Series and Cisco TelePresence Video Communication Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web-based…
ModificadaAlta (8.8)0.80%—Cisco Expressway7/2/202417/6/2026
Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks that perform arbitrary actions on an affected device. Note: "Cisco Expressway Series" refers to Cisco…
ModificadaAlta (8.8)0.85%—Cisco Expressway7/2/202417/6/2026
Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks that perform arbitrary actions on an affected device. Note: "Cisco Expressway Series" refers to Cisco…
ModificadaMedia (5.5)0.33%—Munsoft Easy Outlook Express Recovery2/2/202417/6/2026
A vulnerability, which was classified as problematic, has been found in Munsoft Easy Outlook Express Recovery 2.0. This issue affects some unknown processing of the component Registration Key Handler. The manipulation leads to denial of service. Local access is required to approach this attack. The exploit has been…
ModificadaCrítica (10)2.4%—Cisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence ServiceCisco Unity ConnectionCisco Unified Contact Center Express+126/1/202417/6/2026
A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to the improper processing of user-provided data that is being read into memory. An attacker could…
ModificadaAlta (7.5)0.33%—Phoenixcontact Automationworx Software SuitePhoenixcontact AXC 1050 FirmwarePhoenixcontact AXC 1050 XC FirmwarePhoenixcontact AXC 3050 Firmware+1414/12/202317/6/2026
Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC.
ModificadaCrítica (9.8)0.88%—Phoenixcontact Automationworx Software SuitePhoenixcontact AXC 1050 FirmwarePhoenixcontact AXC 1050 XC FirmwarePhoenixcontact AXC 3050 Firmware+1414/12/202317/6/2026
Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthenticated attacker to gain full access of the affected device.
ModificadaAlta (8.8)0.74%—NEC Expresscluster XNEC Expresscluster X Singleserversafe17/11/202317/6/2026
CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary command.
ModificadaAlta (8.8)0.63%—NEC Expresscluster XNEC Expresscluster X Singleserversafe17/11/202317/6/2026
CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary command.
ModificadaAlta (8.8)0.63%—NEC Expresscluster XNEC Expresscluster X Singleserversafe17/11/202317/6/2026
CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary command.
ModificadaAlta (8.8)0.74%—NEC Expresscluster XNEC Expresscluster X Singleserversafe17/11/202317/6/2026
CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary command.
ModificadaAlta (8.8)0.63%—NEC Expresscluster XNEC Expresscluster X Singleserversafe17/11/202317/6/2026
CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary command.
ModificadaAlta (8.8)0.31%—Expresstech Quiz AND Survey Master13/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin <= 8.0.10 versions.
ModificadaCrítica (9.8)0.63%—Icegram Express7/11/202317/6/2026
Improper Neutralization of Formula Elements in a CSV File vulnerability in Icegram Icegram Express – Email Marketing, Newsletters and Automation for WordPress & WooCommerce.This issue affects Icegram Express – Email Marketing, Newsletters and Automation for WordPress & WooCommerce: from n/a through 5.5.2.
ModificadaAlta (7.2)1.0%—Icegram Express20/10/202317/6/2026
The Icegram Express plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.6.23 via the show_es_logs function. This allows administrator-level attackers to read the contents of arbitrary files on the server, which can contain sensitive information including those belonging to…
AnalizadaAlta (7.5)100%⚠ Explotación activaSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.