Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

883 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.6)0.39%—Lantronix Eds5032 FirmwareLantronix Eds5008 FirmwareLantronix Eds5016 Firmware11/3/20264/9/2026
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The Log Info page allows users to see log files by specifying their names. Due to a missing sanitization in the file name parameter, an authenticated attacker can inject arbitrary OS commands that are executed with root privileges.
ModificadaAlta (8.6)0.41%—Lantronix Eds5032 FirmwareLantronix Eds5008 FirmwareLantronix Eds5016 Firmware11/3/20264/9/2026
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The SSH Client and SSH Server pages are affected by multiple OS injection vulnerabilities due to missing sanitization of input parameters. An attacker can inject arbitrary commands in delete actions of various objects, such as server keys, users, and known hosts.…
ModificadaAlta (8.6)0.50%—Lantronix Eds5032 FirmwareLantronix Eds5008 FirmwareLantronix Eds5016 Firmware11/3/20264/9/2026
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "name" parameter when deleting SSL credentials through the management interface. Injected commands are executed with root privileges.
AnalizadaAlta (7.1)0.84%—Wanderingastronomer Vociferous11/3/202617/6/2026
Vociferous provides cross-platform, offline speech-to-text with local AI refinement. Prior to 4.4.2, the vulnerability exists in src/api/system.py within the export_file route. The application accepts a JSON payload containing a filename and content. While the developer intended for a native UI dialog to handle the…
AplazadaMedia (5.5)0.80%—Unigroup Electronic Archives SystemAI8/3/202617/6/2026
A vulnerability was identified in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). This issue affects some unknown processing of the file /System/Cms/downLoad. The manipulation of the argument path leads to path traversal. The attack can be initiated remotely. The exploit is publicly available and might…
AplazadaMedia (6.5)0.30%—Wisdomgarden TronclassAI23/2/202617/6/2026
Tronclass developed by WisdomGarden has a Insecure Direct Object Reference vulnerability. After obtaining a course ID, authenticated remote attackers to modify a specific parameter to obtain a course invitation code, thereby joining any course.
AnalizadaBaja (2)0.25%—Detronetdip E-commerce20/2/202617/6/2026
A weakness has been identified in detronetdip E-commerce 1.0.0. This affects the function get_safe_value of the file utility/function.php. Executing a manipulation can lead to cross site scripting. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The…
AnalizadaBaja (2.1)0.36%—Detronetdip E-commerce20/2/202617/6/2026
A security flaw has been discovered in detronetdip E-commerce 1.0.0. The impacted element is the function Delete/Update of the component Product Management Module. Performing a manipulation of the argument ID results in authorization bypass. Remote exploitation of the attack is possible. The exploit has been released…
AplazadaAlta (8.1)0.48%—Ancorathemes Impacto PatronusAI20/2/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Impacto Patronus impacto-patronus allows PHP Local File Inclusion.This issue affects Impacto Patronus: from n/a through <= 1.2.3.
AnalizadaAlta (8.7)0.27%—Strongswan Strongman19/2/202617/6/2026
strongMan is a management interface for strongSwan, an OpenSource IPsec-based VPN. When storing credentials in the database (private keys, EAP secrets), strongMan encrypts the corresponding database fields. So far it used AES in CTR mode with a global database key. Together with an initialization vector (IV), a key…
AnalizadaMedia (5.5)0.72%—Unigroup Electronic Archives System19/2/202617/6/2026
A vulnerability was determined in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). The impacted element is an unknown function of the file /Archive/ErecordManage/uploadFile.html. Executing a manipulation of the argument File can lead to unrestricted upload. The attack may be launched remotely. The…
AnalizadaBaja (2.1)0.71%—Unigroup Electronic Archives System18/2/202617/6/2026
A vulnerability was found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). The affected element is an unknown function of the file /Using/Subject/downLoad.html. Performing a manipulation of the argument path results in path traversal. The attack may be initiated remotely. The exploit has been made…
AnalizadaBaja (2.1)0.52%—Unigroup Electronic Archives System18/2/202617/6/2026
A vulnerability has been found in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). Impacted is an unknown function of the file /mine/PublicReport/prinReport.html?token=java. Such manipulation of the argument comid leads to sql injection. The attack can be launched remotely. The exploit has been…
AnalizadaBaja (2.1)0.77%—Unigroup Electronic Archives System18/2/202617/6/2026
A security flaw has been discovered in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this vulnerability is the function Download of the file /Search/Subject/downLoad. Performing a manipulation of the argument path results in path traversal. The attack is possible to be carried out…
AnalizadaAlta (7.8)0.21%—Nvidia Nemo Megatron Bridge18/2/20262/7/2026
NVIDIA Megatron Bridge contains a vulnerability in a data shuffling tutorial, where malicious input could cause a code injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
AnalizadaAlta (7.8)0.21%—Nvidia Nemo Megatron Bridge18/2/20262/7/2026
NVIDIA Megatron Bridge contains a vulnerability in a data merging tutorial, where malicious input could cause a code injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
AplazadaMedia (5.3)0.39%—Shenzhen Zhibotong Electronics ZBT We2001AI11/2/202617/6/2026
A path-traversal vulnerability in the logout functionality of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote attackers to delete arbitrary files on the host by supplying a crafted session cookie value.
AplazadaAlta (8.1)0.26%—Shenzhen Zhibotong Electronics ZBT We2001AI11/2/202617/6/2026
A missing authentication mechanism in the web management API components of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows unauthenticated attackers on the local network to modify router and network configurations. By invoking operations whose names end with "*_nocommit" and supplying the parameters expected…
AplazadaMedia (6.5)0.32%—Shenzhen Zhibotong Electronics ZBT We2001AI11/2/202617/6/2026
A lack of session validation in the web API component of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote unauthenticated attackers to access administrative information-retrieval functions intended for authenticated users. By invoking "get_*" operations, attackers can obtain device configuration data,…
AplazadaCrítica (10)0.75%—Shenzhen Zhibotong Electronics ZBT We2001AI11/2/202617/6/2026
A path traversal vulnerability in the check_token function of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote attackers to bypass authentication and perform administrative actions by supplying a crafted session cookie value.
AplazadaMedia (5.4)0.10%—Electronhub AI PlaygroundAI10/2/202617/6/2026
Uncontrolled search path for some AI Playground before version 2.6.1 beta within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via…
ModificadaMedia (4.8)0.18%—Hitrontech Hi3120 Firmware9/2/202617/6/2026
Hitron HI3120 v7.2.4.5.2b1 allows stored XSS via the Parental Control option when creating a new filter. The device fails to properly handle inputs, allowing an attacker to inject and execute JavaScript.
AnalizadaMedia (5.5)0.64%—Detronetdip E-commerce8/2/202617/6/2026
A weakness has been identified in detronetdip E-commerce 1.0.0. Impacted is an unknown function of the file /Admin/assets/backend/seller/add_seller.php of the component Account Creation Endpoint. Executing a manipulation of the argument email can lead to missing authentication. The attack can be executed remotely. The…
AnalizadaMedia (5.5)0.51%—Detronetdip E-commerce8/2/202617/6/2026
A security flaw has been discovered in detronetdip E-commerce 1.0.0. This issue affects some unknown processing of the file /seller/assets/backend/profile/addadhar.php. Performing a manipulation of the argument File results in unrestricted upload. Remote exploitation of the attack is possible. The exploit has been…
AnalizadaAlta (8.7)0.54%—Devtron4/2/202617/6/2026
Devtron is an open source tool integration platform for Kubernetes. In version 2.0.0 and prior, a vulnerability exists in Devtron's Attributes API interface, allowing any authenticated user (including low-privileged CI/CD Developers) to obtain the global API Token signing key by accessing the…