Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2806▲ 5 respecto a la semana anterior
Críticas / altas1465▲ 246 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)77▼ 441 respecto a la semana anterior
–

35 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6)0.22%—Tp-link Omada ControllerTp-link Oc200 FirmwareTp-link Oc220 FirmwareTp-link Oc300 Firmware+5223/1/202617/6/2026
An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline…
AnalizadaMedia (6)0.99%—Beam Beta922/1/202617/6/2026
Directory Traversal vulnerability in Beam beta9 v.0.1.521 allows a remote attacker to obtain sensitive information via the joinCleanPath function.
AplazadaAlta (8.5)0.15%—Luidia Ebeam Interactive SuiteAI21/1/202617/6/2026
eBeam Interactive Suite 3.6 contains an unquoted service path vulnerability in the eBeam Stylus Driver service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Luidia\eBeam Stylus Driver\ to inject malicious executables that…
AplazadaAlta (8.5)0.15%—Ebeam Education SuiteAI21/1/202617/6/2026
eBeam Education Suite 2.5.0.9 contains an unquoted service path vulnerability in the eBeam Device Service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem…
AplazadaAlta (8.8)0.38%—Beamsec PhishproAI28/7/202517/6/2026
Incorrect Use of Privileged APIs vulnerability in Beamsec PhishPro allows Privilege Abuse. This issue affects PhishPro: before 7.5.4.2.
AplazadaMedia (5.7)0.19%—WhitebeamAI23/6/202517/6/2026
In WhiteBeam 0.2.0 through 0.2.1 before 0.2.2, a user with local access to a server can bypass the allow-list functionality because a file can be truncated in the OpenFileDescriptor action before the VerifyCanWrite action is performed.
AplazadaMedia (4.8)0.20%—Beamctrl AirianaAI16/5/202517/6/2026
A vulnerability was found in BeamCtrl Airiana up to 11.0. It has been declared as problematic. This vulnerability affects unknown code of the file coef. The manipulation leads to deserialization. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.
AplazadaMedia (6.5)0.54%—Crossbeam-channelAI13/5/202530/6/2026
In crossbeam-channel rust crate, the internal `Channel` type's `Drop` method has a race condition which could, in some circumstances, lead to a double-free that could result in memory corruption.
AplazadaMedia (5.9)0.33%—Outtheboxthemes Beam ME UP ScottyAI1/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Out the Box Beam me up Scotty beam-me-up-scotty allows Stored XSS.This issue affects Beam me up Scotty: from n/a through <= 1.0.23.
AnalizadaMedia (6.1)0.39%—Outtheboxthemes Beam ME UP Scotty25/9/202417/6/2026
The Beam me up Scotty – Back to Top Button plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.0.21. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
AplazadaAlta (7.8)0.39%—Sonos AMPAISonos ARCAISonos ARC SLAISonos BeamAI+312/8/202417/6/2026
In certain Sonos products before S1 Release 11.12 and S2 release 15.9, the mt_7615.ko wireless driver does not properly validate an information element during negotiation of a WPA2 four-way handshake. This lack of validation leads to a stack buffer overflow. This can result in remote code execution within the kernel.…
AplazadaAlta (7.1)0.35%—PTC CodebeamerAI8/5/202417/6/2026
PTC Codebeamer is vulnerable to a cross site scripting vulnerability that could allow an attacker to inject and execute malicious code.
ModificadaMedia (6.1)0.76%—Intland Codebeamer29/8/202317/6/2026
​If an attacker tricks an admin user of PTC Codebeamer into clicking on a malicious link, it may allow the attacker to inject arbitrary code to be executed in the browser on the target device.
ModificadaMedia (5.3)0.43%—UI Airfiber Gigabeam FirmwareUI Airfiber 60-xg FirmwareUI Airfiber 60-hd FirmwareUI Airfiber 60-lr Firmware+223/12/202217/6/2026
An improper access validation vulnerability exists in airMAX AC <8.7.11, airFiber 60/LR <2.6.2, airFiber 60 XG/HD <v1.0.0 and airFiber GBE <1.4.1 that allows a malicious actor to retrieve status and usage data from the UISP device.
ModificadaAlta (8.1)1.2%—Crossbeam Project Crossbeam15/2/202217/6/2026
crossbeam-utils provides atomics, synchronization primitives, scoped threads, and other utilities for concurrent programming in Rust. crossbeam-utils prior to version 0.8.7 incorrectly assumed that the alignment of `{i,u}64` was always the same as `Atomic{I,U}64`. However, the alignment of `{i,u}64` on a 32-bit target…
ModificadaCrítica (9.8)1.9%—Crossbeam Project CrossbeamFedoraproject Fedora2/8/202117/6/2026
crossbeam-deque is a package of work-stealing deques for building task schedulers when programming in Rust. In versions prior to 0.7.4 and 0.8.0, the result of the race condition is that one or more tasks in the worker queue can be popped twice instead of other tasks that are forgotten and never popped. If tasks are…
ModificadaMedia (4.8)0.54%—Intland Codebeamer8/6/202117/6/2026
A cross-site scripting (XSS) issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. It is possible to perform XSS attacks through using the WebDAV functionality to upload files to a project (Authn users), using the users import functionality (Admin only), and changing the login text in the application…
ModificadaAlta (8.8)0.85%—Intland Codebeamer8/6/202117/6/2026
A CSRF issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. Requests sent to the server that trigger actions do not contain a CSRF token and can therefore be entirely predicted allowing attackers to cause the victim's browser to execute undesired actions in the web application through crafted requests.
ModificadaAlta (7.5)0.51%—Intland Codebeamer8/6/202117/6/2026
An insufficiently protected credentials issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The remember-me cookie (CB_LOGIN) issued by the application contains the encrypted user's credentials. However, due to a bug in the application code, those credentials are encrypted using a NULL encryption key.
ModificadaMedia (5.5)0.39%—Crossbeam-channel Project Crossbeam-channel31/12/202017/6/2026
An issue was discovered in the crossbeam-channel crate before 0.4.4 for Rust. It has incorrect expectations about the relationship between the memory allocation and how many iterator elements there are.
ModificadaMedia (5.5)0.92%—Intland Codebeamer7/12/202017/6/2026
An issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The ReqIF XML data, used by the codebeamer ALM application to import projects, is parsed by insecurely configured software components, which can be abused for XML External Entity Attacks.
ModificadaAlta (7)4.4%—Eclipse JettyNetapp Snap Creator FrameworkNetapp SnapcenterNetapp Vasa Provider+1423/10/202017/6/2026
In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like systems, the system's temporary directory is shared between all users on that system. A collocated user can observe the process of creating a temporary sub directory in the shared…
ModificadaCrítica (9.8)2.7%—Crossbeam Project Crossbeam16/10/202017/6/2026
Crossbeam is a set of tools for concurrent programming. In crossbeam-channel before version 0.4.4, the bounded channel incorrectly assumes that `Vec::from_iter` has allocated capacity that same as the number of iterator elements. `Vec::from_iter` does not actually guarantee that and may allocate extra memory. The…
ModificadaMedia (6.1)0.88%—Intland Codebeamer2/4/202017/6/2026
codeBeamer before 9.5.0-RC3 does not properly restrict the ability to execute custom Java code and access the Java class loader via computed fields.
ModificadaMedia (4.8)0.70%—Intland Codebeamer30/3/202017/6/2026
In Intland codeBeamer ALM 9.5 and earlier, there is stored XSS via the Trackers Title parameter.