Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 213 respecto a la semana anterior
Críticas / altas1376▲ 145 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

39 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.30%—Analogwp Style KitsAI24/8/202626/8/2026
Subscriber Broken Access Control in Style Kits <= 2.6.5 versions.
AplazadaAlta (7.1)0.19%—Mitsubishielectric Melsec MX Controller Mx-rAIMitsubishielectric Melsec MX Controller Mx-fAIMitsubishielectric Cc-link IE TSN Interface BoardAIMitsubishielectric Motion ModuleAI+2530/7/202618/9/2026
Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, MELSEC iQ-L Series Motion Module, Motion Control Board,…
AplazadaMedia (6.3)0.26%—Analogwp Style KitsAI23/7/202623/7/2026
Contributor Broken Access Control in Style Kits <= 2.6.5 versions.
AplazadaAlta (7.8)0.17%—Analog WAY Picturall Quad Compact Mark IIAI22/7/202627/7/2026
The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the core firmware. This is due to improper privilege delegation and insufficient input validation in a maintenance script.
AplazadaMedia (6.4)0.26%—Analogwp Style KitsAI27/5/202624/7/2026
The Style Kits – Advanced Theme Styles for Elementor, Elementor Kits & Elementor Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '/wp-json/agwp/v1/tokens/save' endpoint kit title parameter in versions up to, and including, 2.5.0 due to insufficient input sanitization and output…
AplazadaAlta (7.5)0.91%—Mitsubishielectric Cc-link IE TSN Remote IO ModuleAIMitsubishielectric Cc-link IE TSN Analog-digital Converter ModuleAIMitsubishielectric Cc-link IE TSN Digital-analog Converter ModuleAIMitsubishielectric Cc-link IE TSN Fpga ModuleAI+825/4/202527/8/2026
Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module, CC-Link IE TSN Analog-Digital Converter module, CC-Link IE TSN Digital-Analog Converter module, CC-Link IE TSN FPGA module, CC-Link IE TSN Remote Station Communication LSI CP620 with…
AplazadaMedia (6.5)0.22%—Analogic Hi-scan 6040i HitraxAI15/1/202517/6/2026
The HI-SCAN 6040i Hitrax HX-03-19-I was discovered to transmit user credentials in cleartext over the GIOP protocol. This allows attackers to possibly gain access to sensitive information via a man-in-the-middle attack.
AplazadaCrítica (9.8)0.35%—Panabit PanalogAI26/4/202417/6/2026
An issue in Beijing Panabit Network Software Co., Ltd Panalog big data analysis platform v. 20240323 and before allows attackers to execute arbitrary code via the exportpdf.php component.
AnalizadaCrítica (9.8)1.1%—Panabit Panalog21/3/202417/6/2026
A vulnerability classified as critical was found in Panabit Panalog 202103080942. This vulnerability affects unknown code of the file /Maintain/sprog_upstatus.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be…
ModificadaAlta (8.8)0.24%—Sielco Analog FM Transmitter Exc5000gx FirmwareSielco Analog FM Transmitter Exc120gx FirmwareSielco Analog FM Transmitter Exc300gx FirmwareSielco Analog FM Transmitter Exc1600gx Firmware+1126/10/202317/6/2026
The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.
ModificadaMedia (6.5)0.36%—Sielco Analog FM Transmitter Exc5000gx FirmwareSielco Analog FM Transmitter Exc120gx FirmwareSielco Analog FM Transmitter Exc300gx FirmwareSielco Analog FM Transmitter Exc1600gx Firmware+1126/10/202317/6/2026
The application suffers from improper access control when editing users. A user with read permissions can manipulate users, passwords, and permissions by sending a single HTTP POST request with modified parameters.
ModificadaCrítica (9.8)0.79%—Sielco Analog FM Transmitter Exc5000gx FirmwareSielco Analog FM Transmitter Exc120gx FirmwareSielco Analog FM Transmitter Exc300gx FirmwareSielco Analog FM Transmitter Exc1600gx Firmware+1126/10/202317/6/2026
The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, bypass authentication, and manipulate the transmitter.
ModificadaAlta (8.8)0.60%—Sielco Analog FM Transmitter Exc5000gx FirmwareSielco Analog FM Transmitter Exc120gx FirmwareSielco Analog FM Transmitter Exc300gx FirmwareSielco Analog FM Transmitter Exc1600gx Firmware+1126/10/202317/6/2026
The application suffers from a privilege escalation vulnerability. A user with read permissions can elevate privileges by sending a HTTP POST to set a parameter.
ModificadaCrítica (9.8)0.68%—Sanalogi Turasistan15/9/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sanalogy Turasistan allows SQL Injection. This issue affects Turasistan: before 20230911 .
ModificadaAlta (8.8)0.53%—Analogwp Style Kits1/7/202317/6/2026
The Style Kits plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.0. This is due to missing or incorrect nonce validation on the update_posts_stylekit() function. This makes it possible for unauthenticated attackers to update style kits for posts via a forged request…
ModificadaAlta (7.4)1.2%—Cisco Unified IP Phone 6911 FirmwareCisco Unified IP Phone 6921 FirmwareCisco Unified IP Phone 6941 FirmwareCisco Unified IP Phone 6945 Firmware+715/6/202217/6/2026
A vulnerability in Cisco Unified IP Phones could allow an unauthenticated, remote attacker to impersonate another user's phone if the Cisco Unified Communications Manager (CUCM) is in secure mode. This vulnerability is due to improper key generation during the manufacturing process that could result in duplicated…
ModificadaMedia (6.1)2.5%—Xorbin Analog Flash Clock27/12/201916/6/2026
Xorbin Analog Flash Clock 1.0 extension for Joomia has XSS
ModificadaMedia (4.3)1.0%—Analogic Poste.io24/6/201917/6/2026
The Roundcube component of Analogic Poste.io 2.1.6 uses .htaccess to protect the logs/ folder, which is effective with the Apache HTTP Server but is ineffective with nginx. Attackers can read logs via the webmail/logs/sendmail URI.
ModificadaMedia (6.7)0.61%—Cisco ASA 5500 FirmwareCisco Firepower 2100 FirmwareCisco Firepower 4000 FirmwareCisco Firepower 9000 Firmware+2313/5/201917/6/2026
A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulnerability affects multiple Cisco products that support hardware-based…
ModificadaAlta (9)1.4%—Cisco ATA 187 Analog Telephone Adaptor FirmwareCisco ATA 187 Analog Telephone Adaptor13/2/201316/6/2026
The Cisco ATA 187 Analog Telephone Adaptor with firmware 9.2.1.0 and 9.2.3.1 before ES build 4 does not properly implement access control, which allows remote attackers to execute operating-system commands via vectors involving a session on TCP port 7870, aka Bug ID CSCtz67038.
ModificadaAlta (10)8.4%—Analogx Simpleserver WWW12/2/201016/6/2026
Directory traversal vulnerability in SimpleServer:WWW 1.13 and earlier allows remote attackers to execute arbitrary programs via encoded ../ ("%2E%2E%2F%") sequences in a request to the cgi-bin/ directory, a different vulnerability than CVE-2000-0664.
ModificadaMedia (5)2.9%—KDE KonquerorKDE Konqueror EmbeddedRedhat Analog Real-time SynthesizerRedhat Kdebase+427/8/200316/6/2026
KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites.
ModificadaAlta (10)6.8%—Analogx Proxy30/6/200316/6/2026
Buffer overflow in AnalogX Proxy 4.13 allows remote attackers to execute arbitrary code via a long URL to port 6588.
ModificadaMedia (5)1.7%—Stephen Turner Analog11/10/200216/6/2026
anlgform.pl in Analog before 5.23 does not restrict access to the PROGRESSFREQ progress update command, which allows remote attackers to cause a denial of service (disk consumption) by using the command to report updates more frequently and fill the web server error log.
ModificadaAlta (7.5)3.3%—Analogx Simpleserver Shout4/10/200216/6/2026
Buffer overflow in AnalogX SimpleServer:Shout 1.0 allows remote attackers to cause a denial of service and execute arbitrary code via a long request to TCP port 8001.