Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
576 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.32% | — | Proges Sensor NET Connect Firmware V2 | 31/7/2024 | 17/6/2026 | A “CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')” allows malicious users to permanently inject arbitrary Javascript code. | |
| Aplazada | Alta (7.5) | 0.36% | — | Consensu.ioAI | 12/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Consensu.IO Consensu.Io.This issue affects Consensu.Io: from n/a through 1.0.1. | |
| Aplazada | Media (6.5) | 0.35% | — | Sensei PROAI | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sensei Sensei Pro (WC Paid Courses) allows Stored XSS.This issue affects Sensei Pro (WC Paid Courses): from n/a through 4.23.1.1.23.1. | |
| Aplazada | Alta (8.8) | 0.55% | — | Qlik Sense Enterprise FOR WindowsAI | 22/5/2024 | 17/6/2026 | Qlik Sense Enterprise for Windows before 14.187.4 allows a remote attacker to elevate their privilege due to improper validation. The attacker can elevate their privilege to the internal system role, which allows them to execute commands on the server. This affects February 2024 Patch 3 (14.173.3 through 14.173.7),… | |
| Aplazada | Media (4.3) | 0.37% | — | Hidekazu Ishikawa X-t9AIThemeinwp Default MAGAIOUT THE BOX NamahaAIOUT THE BOX CitylogicAI+11 | 10/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Hidekazu Ishikawa X-T9, Hidekazu Ishikawa Lightning, themeinwp Default Mag, Out the Box Namaha, Out the Box CityLogic, Marsian i-max, Jetmonsters Emmet Lite, Macho Themes Decode, Wayneconnor Sliding Door, Out the Box Shopstar!, Modernthemesnet Gridsby, TT Themes… | |
| Aplazada | Crítica (9.8) | 0.81% | — | Canon Satera Mf740cAICanon Satera Mf640cAICanon Satera Lbp660cAICanon Satera Lbp620cAI+22 | 11/3/2024 | 17/6/2026 | Buffer overflow in identifier field of WSD probe request process of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF740C Series/Satera MF640C Series/Satera LBP660C… | |
| Modificada | Media (5.4) | 0.32% | — | Automattic Sensei LMS | 12/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Sensei LMS – Online Courses, Quizzes, & Learning allows Stored XSS.This issue affects Sensei LMS – Online Courses, Quizzes, & Learning: from n/a through 4.17.0. | |
| Modificada | Crítica (9.8) | 1.4% | — | Canon I-sensys Mf754cdw FirmwareCanon I-sensys X C1333if FirmwareCanon Mf755cdw FirmwareCanon Mf753cdw Firmware+3 | 6/2/2024 | 17/6/2026 | Buffer overflow in CPCA PCFAX number process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS… | |
| Modificada | Crítica (9.8) | 1.4% | — | Canon Mf755cdw FirmwareCanon Mf753cdw FirmwareCanon Mf751cdw FirmwareCanon Lbp674c Firmware+25 | 6/2/2024 | 17/6/2026 | Buffer overflow in CPCA Color LUT Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier… | |
| Modificada | Crítica (9.8) | 1.4% | — | Canon Mf755cdw FirmwareCanon Mf753cdw FirmwareCanon Mf751cdw FirmwareCanon Lbp674c Firmware+25 | 6/2/2024 | 17/6/2026 | Buffer overflow in SLP attribute request process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in… | |
| Modificada | Crítica (9.8) | 1.5% | — | Canon Mf755cdw FirmwareCanon Mf753cdw FirmwareCanon Mf751cdw FirmwareCanon Lbp674c Firmware+25 | 6/2/2024 | 17/6/2026 | Buffer overflow in the Address Book username process in authentication of Mobile Device Function of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera… | |
| Modificada | Crítica (9.8) | 1.4% | — | Canon Mf755cdw FirmwareCanon Mf753cdw FirmwareCanon Mf751cdw FirmwareCanon Lbp674c Firmware+25 | 6/2/2024 | 17/6/2026 | Buffer overflow in WSD probe request process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan.… | |
| Modificada | Crítica (9.8) | 1.5% | — | Canon Mf755cdw FirmwareCanon Mf753cdw FirmwareCanon Mf751cdw FirmwareCanon Lbp674c Firmware+25 | 6/2/2024 | 17/6/2026 | Buffer overflow in the Address Book password process in authentication of Mobile Device Function of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera… | |
| Modificada | Crítica (9.8) | 1.4% | — | Canon Mf755cdw FirmwareCanon Mf753cdw FirmwareCanon Mf751cdw FirmwareCanon Lbp674c Firmware+25 | 6/2/2024 | 17/6/2026 | Buffer overflow in CPCA PDL Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold… | |
| Modificada | Media (6.5) | 0.58% | — | Machinesense Feverwarn Firmware | 1/2/2024 | 17/6/2026 | The cloud provider MachineSense uses for integration and deployment for multiple MachineSense devices, such as the programmable logic controller (PLC), PumpSense, PowerAnalyzer, FeverWarn, and others is insufficiently protected against unauthorized access. An attacker with access to the internal procedures could view… | |
| Modificada | Crítica (9.1) | 0.80% | — | Machinesense Feverwarn Firmware | 1/2/2024 | 17/6/2026 | The MachineSense application programmable interface (API) is improperly protected and can be accessed without authentication. A remote attacker could retrieve and modify sensitive information without any authentication. | |
| Modificada | Alta (8.1) | 0.39% | — | Machinesense Feverwarn Firmware | 1/2/2024 | 17/6/2026 | MachineSense FeverWarn Raspberry Pi-based devices lack input sanitization, which could allow an attacker on an adjacent network to send a message running commands or could overflow the stack. | |
| Modificada | Alta (7.5) | 0.59% | — | Machinesense Feverwarn Firmware | 1/2/2024 | 17/6/2026 | MachineSense devices use unauthenticated MQTT messaging to monitor devices and remote viewing of sensor data by users. | |
| Modificada | Alta (8.8) | 0.40% | — | Machinesense Feverwarn Firmware | 1/2/2024 | 17/6/2026 | MachineSense FeverWarn devices are configured as Wi-Fi hosts in a way that attackers within range could connect to the device's web services and compromise the device. | |
| Modificada | Crítica (9.8) | 0.65% | — | Machinesense Feverwarn Firmware | 1/2/2024 | 17/6/2026 | Multiple MachineSense devices have credentials unable to be changed by the user or administrator. | |
| Modificada | Media (5.3) | 0.49% | — | Consensys Discovery | 19/1/2024 | 14/7/2026 | Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session. which should ideally be unique for every message. The node's private key isn't compromised, only the session key generated for specific peer communication is exposed. | |
| Modificada | Media (5.9) | 94% | 💥 Exploit | Openbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+64 | 18/12/2023 | 17/6/2026 | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some… | |
| Modificada | Media (6.4) | 0.41% | — | Goodix Fingerprint Sensor Firmware | 9/12/2023 | 17/6/2026 | The Goodix Fingerprint Device, as shipped in Dell Inspiron 15 computers, does not follow the Secure Device Connection Protocol (SDCP) when enrolling via Linux, and accepts an unauthenticated configuration packet to select the Windows template database, which allows bypass of Windows Hello authentication by enrolling… | |
| Modificada | Alta (8.8) | 68% | 💥 PoC | Netgate PfsenseNetgate Pfsense Plus | 6/12/2023 | 17/6/2026 | An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the packet_capture.php file. | |
| Analizada | Crítica (9.9) | 47% | ⚠ Explotación activa | Qlik Sense | 15/11/2023 | 17/6/2026 | Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683. Due to improper validation of HTTP headers, a remote attacker is able to elevate their privilege by tunneling HTTP requests, allowing them to execute HTTP requests on the backend server that hosts… |