Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

25 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.8)0.19%—Axelerant Testimonials WidgetAI26/9/202628/9/2026
The Testimonials Widget WordPress plugin through 4.0.4 does not validate a user-supplied URL before fetching it server-side and storing the response as a public file, allowing unauthenticated users to make the server issue requests to internal services and read the responses.
AplazadaAlta (7.5)0.21%—Axelerant Testimonials WidgetAI26/9/202628/9/2026
The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling its front-end testimonial submission form, allowing unauthenticated users to modify or create arbitrary posts, including overwriting the title, content and author of any existing post.
AplazadaAlta (8.7)0.54%—Axelor Open PlatformAI16/7/202617/7/2026
Axelor Open Platform versions 8.x prior to 8.2.2 contains an authorization bypass vulnerability that allows authenticated non-admin users to escalate privileges by exploiting unenforced field restrictions on nested relational save operations. Attackers can modify sensitive User record fields such as roles and group by…
AnalizadaCrítica (9.8)0.75%—Axeltechnology Streamermax MK II Firmware19/11/202517/6/2026
The Axel Technology StreamerMAX MK II devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authentication on the /cgi-bin/gstFcgi.fcgi endpoint. Unauthenticated remote attackers can list user accounts, create new administrative users, delete users, and modify system…
AnalizadaCrítica (9.1)0.53%—Axeltechnology Puma Firmware19/11/202517/6/2026
The Axel Technology puma devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authentication on the /cgi-bin/gstFcgi.fcgi endpoint. Unauthenticated remote attackers can list user accounts, create new administrative users, delete users, and modify system settings, leading to…
AnalizadaCrítica (9.8)0.64%—Axeltechnology Wolf1ms FirmwareAxeltechnology Wolf2ms Firmware19/11/202517/6/2026
The Axel Technology WOLF1MS and WOLF2MS devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authentication on the /cgi-bin/gstFcgi.fcgi endpoint. Unauthenticated remote attackers can list user accounts, create new administrative users, delete users, and modify system…
AplazadaAlta (7.1)0.13%—Aaron Axelsen Wpmu Ldap AuthenticationAI28/8/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Aaron Axelsen WPMU Ldap Authentication wpmuldap allows Stored XSS.This issue affects WPMU Ldap Authentication: from n/a through <= 5.0.1.
AplazadaCrítica (9.8)0.44%💥 PoCAxelorAI4/8/20255/7/2026
A Boolean-based SQL injection vulnerability was discovered in Axelor 5.2.4 via the _domain parameter. An attacker can manipulate the SQL query logic and determine true/false conditions, potentially leading to data exposure or further exploitation.
ModificadaMedia (4.9)0.51%—Axelkeller GPX Viewer3/3/202517/6/2026
Path Traversal: '.../...//' vulnerability in axelkeller GPX Viewer gpx-viewer allows Path Traversal.This issue affects GPX Viewer: from n/a through <= 2.2.11.
AplazadaAlta (8.8)1.7%💥 PoCAxelkeller GPX ViewerAI13/11/202417/6/2026
The GPX Viewer plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check and file type validation in the gpxv_file_upload() function in all versions up to, and including, 2.2.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to create…
ModificadaMedia (5.4)0.28%—Axelerant Testimonials Widget6/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Axelerant Testimonials Widget allows Stored XSS.This issue affects Testimonials Widget: from n/a through 4.0.4.
ModificadaMedia (5.4)0.28%—Axelerant Testimonials Widget6/6/202417/6/2026
The Testimonials Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's testimonials shortcode in all versions up to, and including, 4.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
ModificadaMedia (5.4)0.60%—Axelor Open Suite3/3/202217/6/2026
Axelor Open Suite v5.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Name parameter.
ModificadaMedia (5.4)0.82%—Axelerant Testimonials Widget18/3/202117/6/2026
Unvalidated input and lack of output encoding in the Testimonials Widget WordPress plugin, versions before 4.0.0, lead to multiple Cross-Site Scripting vulnerabilities, allowing remote attackers to inject arbitrary JavaScript code or HTML via the below parameters: - Author - Job Title - Location - Company - Email - URL
ModificadaMedia (5.9)1.9%—Axel Project AxelFedoraproject FedoraOpensuse Backports SLEOpensuse Leap26/5/202017/6/2026
An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verification.
ModificadaMedia (6.8)0.43%—Apollotechnologiesinc Momentum Axel 720pApollotechnologiesinc Momentum Axel 720p Firmware13/6/201817/6/2026
An issue was discovered on Momentum Axel 720P 5.1.8 devices. A password of EHLGVG is hard-coded for the root and admin accounts, which makes it easier for physically proximate attackers to login at the console.
ModificadaMedia (4.4)0.33%—Apollotechnologiesinc Momentum Axel 720p Firmware12/6/201817/6/2026
An issue was discovered on Momentum Axel 720P 5.1.8 devices. All processes run as root.
ModificadaMedia (6.7)0.38%—Apollotechnologiesinc Momentum Axel 720p Firmware12/6/201817/6/2026
An issue was discovered on Momentum Axel 720P 5.1.8 devices. The root password can be obtained in cleartext by issuing the command 'showKey' from the root CLI. This password may be the same on all devices
ModificadaMedia (6.8)0.43%—Apollotechnologiesinc Momentum Axel 720p Firmware12/6/201817/6/2026
An issue was discovered on Momentum Axel 720P 5.1.8 devices. Root access can be obtained via UART pins without any restrictions, which leads to full system compromise.
ModificadaMedia (6.8)0.45%—Apollotechnologiesinc Momentum Axel 720p Firmware12/6/201817/6/2026
An issue was discovered on Momentum Axel 720P 5.1.8 devices. Custom Firmware Upgrade is possible via an SD Card. With physical access, an attacker can upgrade the firmware in under 60 seconds by inserting an SD card containing the firmware with name 'ezviz.dav' and rebooting.
ModificadaMedia (4.4)0.35%—Apollotechnologiesinc Momentum Axel 720p Firmware12/6/201817/6/2026
An issue was discovered on Momentum Axel 720P 5.1.8 devices. There is Authenticated Custom Firmware Upgrade via DNS Hijacking. An authenticated root user with CLI access is able to remotely upgrade firmware to a custom image due to lack of SSL validation by changing the nameservers in /etc/resolv.conf to the…
ModificadaAlta (7.4)0.55%—Momentum Axel 720p Firmware24/4/201817/6/2026
Momentum Axel 720P 5.1.8 devices have a hardcoded password of streaming for the appagent account, which allows remote attackers to view the RTSP video stream.
ModificadaMedia (4.3)1.2%—Axel Jung JS CSS Optimizer23/8/201316/6/2026
Cross-site scripting (XSS) vulnerability in the Javascript and CSS Optimizer extension before 1.1.14 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)0.93%💥 ExploitIrcmaxell Tech Article4/2/200916/6/2026
SQL injection vulnerability in the Tech Articles (com_tech_article) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the item parameter to index.php.
ModificadaAlta (7.5)3.4%—Axel2/5/200516/6/2026
Buffer overflow in the HTTP redirection capability in conn.c for Axel before 1.0b may allow remote attackers to execute arbitrary code.
Orbitaley — Vulnerabilidades