Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

576 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.32%—Proges Sensor NET Connect Firmware V231/7/202417/6/2026
A “CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')” allows malicious users to permanently inject arbitrary Javascript code.
AplazadaAlta (7.5)0.36%—Consensu.ioAI12/6/202417/6/2026
Missing Authorization vulnerability in Consensu.IO Consensu.Io.This issue affects Consensu.Io: from n/a through 1.0.1.
AplazadaMedia (6.5)0.35%—Sensei PROAI8/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sensei Sensei Pro (WC Paid Courses) allows Stored XSS.This issue affects Sensei Pro (WC Paid Courses): from n/a through 4.23.1.1.23.1.
AplazadaAlta (8.8)0.55%—Qlik Sense Enterprise FOR WindowsAI22/5/202417/6/2026
Qlik Sense Enterprise for Windows before 14.187.4 allows a remote attacker to elevate their privilege due to improper validation. The attacker can elevate their privilege to the internal system role, which allows them to execute commands on the server. This affects February 2024 Patch 3 (14.173.3 through 14.173.7),…
AplazadaMedia (4.3)0.37%—Hidekazu Ishikawa X-t9AIThemeinwp Default MAGAIOUT THE BOX NamahaAIOUT THE BOX CitylogicAI+1110/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Hidekazu Ishikawa X-T9, Hidekazu Ishikawa Lightning, themeinwp Default Mag, Out the Box Namaha, Out the Box CityLogic, Marsian i-max, Jetmonsters Emmet Lite, Macho Themes Decode, Wayneconnor Sliding Door, Out the Box Shopstar!, Modernthemesnet Gridsby, TT Themes…
AplazadaCrítica (9.8)0.81%—Canon Satera Mf740cAICanon Satera Mf640cAICanon Satera Lbp660cAICanon Satera Lbp620cAI+2211/3/202417/6/2026
Buffer overflow in identifier field of WSD probe request process of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF740C Series/Satera MF640C Series/Satera LBP660C…
ModificadaMedia (5.4)0.32%—Automattic Sensei LMS12/2/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Sensei LMS – Online Courses, Quizzes, & Learning allows Stored XSS.This issue affects Sensei LMS – Online Courses, Quizzes, & Learning: from n/a through 4.17.0.
ModificadaCrítica (9.8)1.4%—Canon I-sensys Mf754cdw FirmwareCanon I-sensys X C1333if FirmwareCanon Mf755cdw FirmwareCanon Mf753cdw Firmware+36/2/202417/6/2026
Buffer overflow in CPCA PCFAX number process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS…
ModificadaCrítica (9.8)1.4%—Canon Mf755cdw FirmwareCanon Mf753cdw FirmwareCanon Mf751cdw FirmwareCanon Lbp674c Firmware+256/2/202417/6/2026
Buffer overflow in CPCA Color LUT Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier…
ModificadaCrítica (9.8)1.4%—Canon Mf755cdw FirmwareCanon Mf753cdw FirmwareCanon Mf751cdw FirmwareCanon Lbp674c Firmware+256/2/202417/6/2026
Buffer overflow in SLP attribute request process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in…
ModificadaCrítica (9.8)1.5%—Canon Mf755cdw FirmwareCanon Mf753cdw FirmwareCanon Mf751cdw FirmwareCanon Lbp674c Firmware+256/2/202417/6/2026
Buffer overflow in the Address Book username process in authentication of Mobile Device Function of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera…
ModificadaCrítica (9.8)1.4%—Canon Mf755cdw FirmwareCanon Mf753cdw FirmwareCanon Mf751cdw FirmwareCanon Lbp674c Firmware+256/2/202417/6/2026
Buffer overflow in WSD probe request process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan.…
ModificadaCrítica (9.8)1.5%—Canon Mf755cdw FirmwareCanon Mf753cdw FirmwareCanon Mf751cdw FirmwareCanon Lbp674c Firmware+256/2/202417/6/2026
Buffer overflow in the Address Book password process in authentication of Mobile Device Function of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera…
ModificadaCrítica (9.8)1.4%—Canon Mf755cdw FirmwareCanon Mf753cdw FirmwareCanon Mf751cdw FirmwareCanon Lbp674c Firmware+256/2/202417/6/2026
Buffer overflow in CPCA PDL Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold…
ModificadaMedia (6.5)0.58%—Machinesense Feverwarn Firmware1/2/202417/6/2026
The cloud provider MachineSense uses for integration and deployment for multiple MachineSense devices, such as the programmable logic controller (PLC), PumpSense, PowerAnalyzer, FeverWarn, and others is insufficiently protected against unauthorized access. An attacker with access to the internal procedures could view…
ModificadaCrítica (9.1)0.80%—Machinesense Feverwarn Firmware1/2/202417/6/2026
The MachineSense application programmable interface (API) is improperly protected and can be accessed without authentication. A remote attacker could retrieve and modify sensitive information without any authentication.
ModificadaAlta (8.1)0.39%—Machinesense Feverwarn Firmware1/2/202417/6/2026
MachineSense FeverWarn Raspberry Pi-based devices lack input sanitization, which could allow an attacker on an adjacent network to send a message running commands or could overflow the stack.
ModificadaAlta (7.5)0.59%—Machinesense Feverwarn Firmware1/2/202417/6/2026
MachineSense devices use unauthenticated MQTT messaging to monitor devices and remote viewing of sensor data by users.
ModificadaAlta (8.8)0.40%—Machinesense Feverwarn Firmware1/2/202417/6/2026
MachineSense FeverWarn devices are configured as Wi-Fi hosts in a way that attackers within range could connect to the device's web services and compromise the device.
ModificadaCrítica (9.8)0.65%—Machinesense Feverwarn Firmware1/2/202417/6/2026
Multiple MachineSense devices have credentials unable to be changed by the user or administrator.
ModificadaMedia (5.3)0.49%—Consensys Discovery19/1/202414/7/2026
Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session. which should ideally be unique for every message. The node's private key isn't compromised, only the session key generated for specific peer communication is exposed.
ModificadaMedia (5.9)94%💥 ExploitOpenbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+6418/12/202317/6/2026
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some…
ModificadaMedia (6.4)0.41%—Goodix Fingerprint Sensor Firmware9/12/202317/6/2026
The Goodix Fingerprint Device, as shipped in Dell Inspiron 15 computers, does not follow the Secure Device Connection Protocol (SDCP) when enrolling via Linux, and accepts an unauthenticated configuration packet to select the Windows template database, which allows bypass of Windows Hello authentication by enrolling…
ModificadaAlta (8.8)68%💥 PoCNetgate PfsenseNetgate Pfsense Plus6/12/202317/6/2026
An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the packet_capture.php file.
AnalizadaCrítica (9.9)47%⚠ Explotación activaQlik Sense15/11/202317/6/2026
Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683. Due to improper validation of HTTP headers, a remote attacker is able to elevate their privilege by tunneling HTTP requests, allowing them to execute HTTP requests on the backend server that hosts…