Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

46 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.3)0.37%—Cerberusftp FTP Server27/4/202617/6/2026
Insecure preserved inherited permissions vulnerability in Cerberus FTP Server on Windows allows Privilege Escalation.This issue has been resolved in Cerberus FTP Server: 2026.1
AnalizadaMedia (5.3)0.35%—Wpcerber Cerber Security Antispam & Malware Scan31/8/202417/6/2026
The WP Cerber Security plugin for WordPress is vulnerable to IP Protection bypass in versions up to, and including 9.4 due to the plugin improperly checking for a visitor's IP address. This makes it possible for an attacker whose IP address has been blocked to bypass this control by setting the X-Forwarded-For: HTTP…
AplazadaAlta (7.5)0.42%—Cerberus EnterpriseAI17/5/202417/6/2026
Denial of Service (DoS) vulnerability for Cerberus Enterprise 8.0.10.3 web administration. The vulnerability exists when the web server, default port 10001, attempts to process a large number of incomplete HTTP requests.
AplazadaAlta (7.5)0.51%—Cerberus PRO EN Engineering ToolAICerberus PRO EN Fire Panel Fc72xAICerberus PRO EN X200 Cloud DistributionAICerberus PRO EN X300 Cloud DistributionAI+1112/3/202417/6/2026
A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions), Cerberus PRO EN Fire Panel FC72x IP6 (All versions), Cerberus PRO EN Fire Panel FC72x IP7 (All versions), Cerberus PRO EN Fire Panel FC72x IP8 (All versions < IP8 SR4), Cerberus PRO EN X200 Cloud Distribution IP7 (All versions),…
AplazadaAlta (7.5)0.83%—Cerberus PRO EN Engineering ToolAICerberus PRO EN Fire Panel Fc72xAICerberus PRO EN X200 Cloud DistributionAICerberus PRO EN X300 Cloud DistributionAI+1112/3/202417/6/2026
A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions), Cerberus PRO EN Fire Panel FC72x IP6 (All versions), Cerberus PRO EN Fire Panel FC72x IP7 (All versions), Cerberus PRO EN Fire Panel FC72x IP8 (All versions < IP8 SR4), Cerberus PRO EN X200 Cloud Distribution IP7 (All versions),…
ModificadaCrítica (9.8)0.81%—Siemens Cerberus PRO EN Engineering ToolSiemens Cerberus PRO EN Fire Panel Fc72xSiemens Cerberus PRO EN X200 Cloud DistributionSiemens Cerberus PRO EN X300 Cloud Distribution+512/3/202417/6/2026
A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions < IP8), Cerberus PRO EN Fire Panel FC72x IP6 (All versions < IP6 SR3), Cerberus PRO EN Fire Panel FC72x IP7 (All versions < IP7 SR5), Cerberus PRO EN X200 Cloud Distribution IP7 (All versions < V3.0.6602), Cerberus PRO EN X200 Cloud…
ModificadaMedia (6.1)0.48%—WP Cerber Security, Anti-spam & Malware Scan20/10/202317/6/2026
The WP Cerber Security plugin for WordPress is vulnerable to stored cross-site scripting via the log parameter when logging in to the site in versions up to, and including, 9.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an…
ModificadaMedia (5.4)0.37%—Palantir Gotham Cerberus12/9/202317/6/2026
The Gotham Cerberus service was found to have a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker with access to Gotham to launch attacks against other users. This vulnerability is resolved in Cerberus 100.230704.0-27-g031dd58 .
ModificadaMedia (5.3)0.67%—WP Cerber Security, Anti-spam & Malware Scan2/1/202317/6/2026
The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 9.3.3 does not properly block access to the REST API users endpoint when the blog is in a subdirectory, which could allow attackers to bypass the restriction in place and list users
ModificadaMedia (5.3)0.86%—WP Cerber Security, Anti-spam & Malware Scan6/9/202217/6/2026
The WP Cerber Security plugin for WordPress is vulnerable to security protection bypass in versions up to, and including 9.0, that makes user enumeration possible. This is due to improper validation on the value supplied through the 'author' parameter found in the ~/cerber-load.php file. In vulnerable versions, the…
ModificadaCrítica (9.8)1.2%—Siemens Cerberus DMSSiemens Desigo CCSiemens Desigo CC CompactSiemens Wincc Open Architecture21/6/202217/6/2026
A vulnerability has been identified in Cerberus DMS (All versions), Desigo CC (All versions), Desigo CC Compact (All versions), SIMATIC WinCC OA V3.16 (All versions in default configuration), SIMATIC WinCC OA V3.17 (All versions in non-default configuration), SIMATIC WinCC OA V3.18 (All versions in non-default…
ModificadaMedia (6.1)1.2%—WP Cerber Security, Anti-spam & Malware Scan7/3/202217/6/2026
The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 8.9.6 does not sanitise the $url variable before using it in an attribute in the Activity tab in the plugins dashboard, leading to an unauthenticated stored Cross-Site Scripting vulnerability.
ModificadaCrítica (10)1.9%—Siemens Cerberus DMSSiemens Desigo CCSiemens Desigo CC Compact14/9/202117/6/2026
A vulnerability has been identified in Cerberus DMS V4.0 (All versions), Cerberus DMS V4.1 (All versions), Cerberus DMS V4.2 (All versions), Cerberus DMS V5.0 (All versions < v5.0 QU1), Desigo CC Compact V4.0 (All versions), Desigo CC Compact V4.1 (All versions), Desigo CC Compact V4.2 (All versions), Desigo CC…
ModificadaMedia (5.3)2.4%—Wpcerber WP Cerber19/8/202117/6/2026
WP Cerber before 8.9.3 allows bypass of /wp-json access control via a trailing ? character.
ModificadaCrítica (9.8)2.1%—Wpcerber WP Cerber19/8/202117/6/2026
WP Cerber before 8.9.3 allows MFA bypass via wordpress_logged_in_[hash] manipulation.
ModificadaMedia (6.1)1.8%—Cerberusftp FTP Server10/6/202117/6/2026
The Web Client in Cerberus FTP Server Enterprise before 10.0.19 and 11.x before 11.0.4 allows XSS via an SVG document.
ModificadaAlta (8.1)1.2%—Cerberusftp FTP Server14/1/202017/6/2026
Cerberus FTP Server Enterprise Edition prior to versions 11.0.3 and 10.0.18 allows an authenticated attacker to create files, display hidden files, list directories, and list files without the permission to zip and download (or unzip and upload) files. There are multiple ways to bypass certain permissions by utilizing…
ModificadaMedia (5.4)0.68%—Cerberusftp FTP Server14/1/202017/6/2026
The zip API endpoint in Cerberus FTP Server 8 allows an authenticated attacker without zip permission to use the zip functionality via an unrestricted API endpoint. Improper permission verification occurs when calling the file/ajax_download_zip/zip_name endpoint. The result is that a user without permissions can zip…
ModificadaMedia (6.1)1.2%—Cerberusftp FTP Server13/1/202017/6/2026
Reflected XSS through an IMG element in Cerberus FTP Server prior to versions 11.0.1 and 10.0.17 allows a remote attacker to execute arbitrary JavaScript or HTML via a crafted public folder URL. This occurs because of the folder_up.png IMG element not properly sanitizing user-inserted directory paths. The path…
ModificadaMedia (6.1)1.4%—Wpcerber Cerber Security Antispam & Malware Scan17/9/201917/6/2026
The wp-cerber plugin before 2.7 for WordPress has XSS via the X-Forwarded-For HTTP header.
ModificadaAlta (7.5)1.1%—Cerb Coin Project Cerb Coin9/7/201817/6/2026
The mintToken function of a smart contract implementation for CERB_Coin, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaCrítica (9.8)14%—Cerberus FTP Server17/3/201717/6/2026
Buffer overflow in Cerberus FTP Server 8.0.10.3 allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a long MLST command.
ModificadaAlta (7.5)8.6%—Cerberusftp FTP Server14/3/201717/6/2026
In Cerberus FTP Server 8.0.10.1, a crafted HTTP request causes the Windows service to crash. The attack methodology involves a long Host header and an invalid Content-Length header.
ModificadaMedia (6.8)2.6%—Webgroupmedia Cerb3/9/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in ajax.php in Cerb before 7.0.4 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via a saveWorkerPeek action.
ModificadaMedia (4.3)1.2%—Cerberusftp FTP Server31/12/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the administrative web interface in Cerberus FTP Server before 5.0.6.0 allow (1) remote attackers to inject arbitrary web script or HTML via a log entry that is not properly handled within the Log Manager component, and might allow (2) remote authenticated…