Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

610 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.68%—Switchwp WP Client Reports23/11/202317/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SwitchWP WP Client Reports plugin <= 1.0.16 versions.
ModificadaAlta (8.8)0.29%—Jamesmehorter Device Theme Switcher18/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in James Mehorter Device Theme Switcher.This issue affects Device Theme Switcher: from n/a through 3.0.2.
ModificadaMedia (5.4)0.44%—Plugin-planet Theme Switcha20/10/202317/6/2026
The Theme Switcha plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'theme_switcha_list' shortcode in all versions up to, and including, 3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with…
ModificadaAlta (7.5)0.78%—Tapo Mini Smart Wi-fi Plug FirmwareNanoleaf Lightstrip FirmwareGovee LED Strip FirmwareSwitchbot Hub2 Firmware+510/10/202317/6/2026
Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote attacker to cause a denial of service via a…
ModificadaMedia (5.5)0.42%—OpenvswitchRedhat Openshift Container PlatformRedhat VirtualizationRedhat Enterprise Linux+16/10/202317/6/2026
A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect ICMPv6 traffic to arbitrary IP addresses.
ModificadaAlta (8.8)0.25%—Fugu Maintenance Switch6/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Fugu Maintenance Switch plugin <= 1.5.2 versions.
ModificadaMedia (6.5)0.91%—Freeswitch15/9/202317/6/2026
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.10.10, FreeSWITCH allows authorized users to cause a denial of service attack by sending re-INVITE with SDP…
ModificadaAlta (7.5)0.99%—Freeswitch15/9/202317/6/2026
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.10.10, FreeSWITCH allows remote users to trigger out of bounds write by offering an ICE candidate with unknown…
ModificadaMedia (4.3)0.66%—Ericsson Mobile Switching Center Server BC 18A Firmware14/9/202317/6/2026
In Ericsson Mobile Switching Center Server (MSC-S) before IS 3.1 CP22, the SIS web application allows relative path traversal via a specific parameter in the https request after authentication, which allows access to files on the system that are not intended to be accessible via the web application.
ModificadaMedia (4.3)0.50%—Fortinet Fortiswitchmanager7/9/202317/6/2026
An improper access control in Fortinet FortiSwitchManager version 7.2.0 through 7.2.2 7.0.0 through 7.0.1 may allow a remote authenticated read-only user to modify the interface settings via the API.
ModificadaAlta (8.8)0.26%—Startrinity Softswitch3/9/202317/6/2026
StarTrinity Softswitch version 2023-02-16 - Multiple CSRF (CWE-352)
ModificadaMedia (6.1)0.36%—Startrinity Softswitch3/9/202317/6/2026
StarTrinity Softswitch version 2023-02-16 - Open Redirect (CWE-601)
ModificadaMedia (5.4)0.38%—Startrinity Softswitch3/9/202317/6/2026
StarTrinity Softswitch version 2023-02-16 - Persistent XSS (CWE-79)
ModificadaMedia (6.1)0.40%—Startrinity Softswitch3/9/202317/6/2026
StarTrinity Softswitch version 2023-02-16 - Multiple Reflected XSS (CWE-79)
ModificadaCrítica (9.8)0.83%—HPE Arubaos-switch29/8/202317/6/2026
A memory corruption vulnerability in ArubaOS-Switch could lead to unauthenticated remote code execution by receiving specially crafted packets. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.
ModificadaMedia (6.5)0.83%—HPE Arubaos-switch29/8/202317/6/2026
An authenticated remote code execution vulnerability exists in the command line interface in ArubaOS-Switch. Successful exploitation results in a Denial-of-Service (DoS) condition in the switch.
ModificadaMedia (6.1)0.52%—HPE Arubaos-switch29/8/202317/6/2026
A vulnerability in the ArubaOS-Switch web management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface provided certain configuration options are present. A successful exploit could allow an attacker to execute arbitrary…
ModificadaCrítica (9.8)1.4%—UI Unifi UAP FirmwareUI Unifi Switch Firmware10/8/202317/6/2026
A command injection vulnerability in the DHCP Client function of all UniFi Access Points and Switches, excluding the Switch Flex Mini, could allow a Remote Code Execution (RCE). Affected Products: All UniFi Access Points (Version 6.5.53 and earlier) All UniFi Switches (Version 6.5.32 and earlier) -USW Flex Mini…
ModificadaCrítica (9.8)1.0%💥 PoCUI Unifi UAP FirmwareUI Unifi Switch Firmware10/8/202317/6/2026
An integer overflow vulnerability in all UniFi Access Points and Switches, excluding the Switch Flex Mini, with SNMP Monitoring and default settings enabled could allow a Remote Code Execution (RCE). Affected Products: All UniFi Access Points (Version 6.5.50 and earlier) All UniFi Switches (Version 6.5.32 and earlier)…
ModificadaMedia (5.5)0.11%—Samsung Smart Switch PC6/7/202317/6/2026
Improper validation of integrity check vulnerability in Smart Switch PC prior to version 4.3.23052_1 allows local attackers to delete arbitrary directory using directory junction.
ModificadaMedia (5.5)0.15%—Samsung Smart Switch PC6/7/202317/6/2026
Improper privilege management vulnerability in Samsung Smart Switch for Windows Installer prior to version 4.3.23043_3 allows attackers to cause permanent DoS via directory junction.
ModificadaBaja (2.7)0.64%—Fortinet FortiproxyFortinet FortiswitchmanagerFortinet Fortios13/6/202317/6/2026
A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9 and before 6.4.12, FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.7, FortiSwitchManager version 7.2.0 through 7.2.1 and before 7.0.1 allows an privileged attacker to delete…
ModificadaMedia (5.4)0.36%—Pluginus Wordpress Currency Switcher Professional9/6/202317/6/2026
The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcs_current_currency shortcode in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…
ModificadaMedia (4.3)0.41%—Pluginus Wordpress Currency Switcher Professional9/6/202317/6/2026
The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save function in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to…
ModificadaMedia (4.3)0.43%—Pluginus Wordpress Currency Switcher9/6/202317/6/2026
The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the anonymous function for the wpcs_sd_delete action in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with…