Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

1025 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)32%💥 ExploitMyprestamodules Product Catalog (csv, Excel) ImportUpdateproducts Project Updateproducts20/9/202317/6/2026
MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInfo information disclosure vulnerability via send.php.
ModificadaCrítica (9.8)0.81%—Blmodules Xmlfeeds PRO15/9/202317/6/2026
Bl Modules xmlfeeds before v3.9.8 was discovered to contain a SQL injection vulnerability via the component SearchApiXml::Xmlfeeds().
ModificadaCrítica (9.8)2.0%—Wibu Codemeter RuntimeTrumpf OseonTrumpf ProgrammingtubeTrumpf Teczonebend+2013/9/202317/6/2026
A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.
ModificadaAlta (8.8)0.99%—Resortdata Internet Reservation Module Next Generation7/9/202317/6/2026
A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary content (such as a web shell component) to the SQL database and execute it with SYSTEM privileges. This vulnerability requires authentication to be exploited but can be paired with…
ModificadaCrítica (9.1)0.56%—Resortdata Internet Reservation Module Next Generation7/9/202317/6/2026
The RDPData.dll file exposes the /irmdata/api/common endpoint that handles session IDs, among other features. By using a UNION SQL operator, an attacker can leak the sessions table, obtain the currently valid sessions and impersonate a currently logged-in user.
ModificadaCrítica (9.8)0.42%—Resortdata Internet Reservation Module Next Generation7/9/202317/6/2026
The /irmdata/api/ endpoints exposed by the IRM Next Generation booking engine authenticates requests using HMAC tokens. These tokens are however exposed in a JavaScript file loaded on the client side, thus rendering this extra safety mechanism useless.
ModificadaAlta (7.7)0.47%—Resortdata Internet Reservation Module Next Generation7/9/202317/6/2026
The RDPWin.dll component as used in the IRM Next Generation booking engine includes a set of hardcoded API keys for third-party services such as Twilio and Vonage. These keys allow unrestricted interaction with these services.
ModificadaAlta (8.8)0.73%—Resortdata Internet Reservation Module Next Generation7/9/202317/6/2026
The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customers with an "admin" account and a corresponding password computed daily by a routine inside the DLL file. Once reverse-engineered, this routine can help an attacker generate the daily password and…
ModificadaMedia (6.5)0.33%—Cisco Video Phone 8875 FirmwareCisco IP Phone 6821 With Multiplatform FirmwareCisco IP Phone 6825 With Multiplatform FirmwareCisco IP Phone 6841 With Multiplatform Firmware+1916/8/202317/6/2026
A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web-based management interface of an affected system. This…
ModificadaAlta (7.8)1.2%—Keep-module-latest Project Keep-module-latest27/5/202317/6/2026
All versions of the package keep-module-latest are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the installModule function. **Note:** To execute the code snippet and potentially exploit the vulnerability, the attacker needs to have the ability to run…
ModificadaCrítica (9.8)0.77%—Rental Module Project Rental Module20/5/202317/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows Authentication Abuse, Authentication Bypass. This issue affects Rental Module: before 23.05.15.
ModificadaCrítica (9.8)1.3%—Rental Module Project Rental Module20/5/202317/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows Command Injection, Using Malicious Files, Upload a Web Shell to a Web Server. This issue affects Rental Module: before 23.05.15.
ModificadaMedia (4.3)0.59%—Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+610/5/202317/6/2026
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to create folders in arbitrary paths of the file system. See SEL Service…
ModificadaMedia (5.4)0.44%—Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+610/5/202317/6/2026
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject and execute arbitrary script code. See SEL Service Bulletin…
ModificadaMedia (5.4)0.44%—Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+610/5/202317/6/2026
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject and execute arbitrary script code. See SEL Service Bulletin…
ModificadaMedia (5.4)0.44%—Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+610/5/202317/6/2026
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject and execute arbitrary script code. See SEL Service Bulletin…
ModificadaMedia (4.3)0.48%—Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+610/5/202317/6/2026
An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to arbitrarily alter the content of a configuration file. See SEL Service Bulletin dated 2022-11-15 for more details.
ModificadaMedia (5.4)0.44%—Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+610/5/202317/6/2026
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject and execute arbitrary script code. See SEL Service Bulletin…
ModificadaMedia (5.4)0.44%—Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+610/5/202317/6/2026
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject and execute arbitrary script code. See SEL Service Bulletin…
ModificadaMedia (5.4)0.44%—Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+610/5/202317/6/2026
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject and execute arbitrary script code. See SEL Service Bulletin…
ModificadaMedia (5.4)0.44%—Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+610/5/202317/6/2026
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject and execute arbitrary script code. See SEL Service Bulletin…
ModificadaMedia (5.4)0.44%—Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+610/5/202317/6/2026
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject and execute arbitrary script code. See SEL Service Bulletin…
ModificadaMedia (5.4)0.44%—Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+610/5/202317/6/2026
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject and execute arbitrary script code. See SEL Service Bulletin…
ModificadaMedia (5.4)0.44%—Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+610/5/202317/6/2026
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject and execute arbitrary script code. See SEL Service Bulletin…
ModificadaMedia (5.4)0.44%—Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+610/5/202317/6/2026
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject and execute arbitrary script code.See SEL Service Bulletin…