Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
–

94 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.4)0.13%—Acer NitrosenseAIAcer PredatorsenseAI17/9/202618/9/2026
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense due to insufficient access controls in a privileged service. An authenticated local user may be able to access the service and perform unauthorized registry modifications, potentially resulting in…
AplazadaBaja (1.2)0.21%—Acer NitrosenseAIAcer PredatorsenseAI17/9/202618/9/2026
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The WebSocket handshake process does not properly require authentication before allowing connections to the service. Under certain circumstances, unauthorized access to service functionality may be…
AplazadaBaja (2.7)0.43%—Acer NitrosenseAIAcer PredatorsenseAI17/9/202618/9/2026
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. A WebSocket service was configured to listen on all network interfaces, which may expose the service to unintended network access.
AplazadaBaja (1.2)0.10%—Acer NitrosenseAIAcer PredatorsenseAI17/9/202618/9/2026
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use the embedded key to access protected…
AplazadaAlta (7.4)0.13%—Acer NitrosenseAIAcer PredatorsenseAI17/9/202618/9/2026
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. Insufficient access controls within a privileged service may allow an authenticated local user to perform unauthorized registry operations. In certain situations, this could lead to privilege escalation…
AplazadaMedia (4.9)0.21%—Acer NitrosenseAIAcer PredatorsenseAI17/9/202618/9/2026
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does not properly require authentication before granting access to the service. Under certain circumstances, an unauthorized connection may be established, potentially…
AplazadaMedia (4.9)0.10%—Acer NitrosenseAIAcer PredatorsenseAI17/9/202618/9/2026
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use the embedded key to access protected…
AplazadaAlta (7.2)0.20%—Fort ValidatorAI21/8/20269/9/2026
FORT Validator is a Resource Public Key Infrastructure (RPKI) relying-party validator that produces validated route-origin data. FORT Validator versions through 1.6.7 contain an origin-validation error in their RRDP processing: a delegated CA under the same Trust Anchor Locator (TAL) can reference a victim CA’s public…
AnalizadaCrítica (10)2.2%—Acer Predator Connect W6X Firmware29/5/202621/7/2026
Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device.
AnalizadaAlta (8.3)0.34%—Acer Predator Connect W6X Firmware29/5/202621/7/2026
Improper access control in the MQTT broker allows wildcard topic subscriptions, exposing all MQTT traffic to unauthorized actors.
AnalizadaCrítica (10)0.53%—Acer Predator Connect W6X Firmware29/5/202621/7/2026
Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requests when Base64 decoding fails.
AnalizadaAlta (8.6)0.66%—Acer Predator Connect W6X Firmware29/5/202621/7/2026
The Wi-Fi device blocking feature fails to sanitize MAC address input, allowing injection and execution of arbitrary shell commands.
AnalizadaAlta (8.7)0.37%—Acer Predator Connect W6X Firmware29/5/202621/7/2026
Unauthenticated Debug Service. The /sbin/mtk_dut binary is exposed on TCP port 9000 without authentication, allowing any LAN-based attacker to execute arbitrary UCC commands.
AnalizadaAlta (8.5)0.17%—Acer NitrosenseAcer Predatorsense8/5/202612/8/2026
PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigured, allowing any authenticated local user to execute arbitrary code with NT…
AplazadaMedia (4.4)0.19%—Mandatory FieldAI21/3/202617/6/2026
The Mandatory Field plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject…
AplazadaMedia (4.8)0.41%—Dato CMSAIDato WEB PreviewsAI27/2/202617/6/2026
Authenticated Iframe Injection in Dato CMS Web Previews plugin. This vulnerability permits a malicious authenticated user to circumvent the restriction enforced on the configured frontend URL, enabling the loading of arbitrary external resources or origins. This issue affects Web Previews < v1.0.31.
AplazadaMedia (5.3)0.31%—Clickdatos Proteccion DE Datos RgpdAI23/1/202617/6/2026
Missing Authorization vulnerability in ABCdatos Protección de datos – RGPD proteccion-datos-rgpd allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Protección de datos – RGPD: from n/a through <= 0.68.
AplazadaAlta (7.5)0.37%—Antideo Email ValidatorAI22/1/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Antideo Antideo Email Validator antideo-email-validator allows Blind SQL Injection.This issue affects Antideo Email Validator: from n/a through <= 1.0.10.
AnalizadaMedia (6.9)0.47%—Validator16/1/202617/6/2026
Nu Html Checker (validator.nu) contains a restriction bypass that allows remote attackers to make the server perform arbitrary HTTP/HTTPS requests to internal resources, including localhost services. While the validator implements hostname-based protections to block direct access to localhost and 127.0.0.1, these…
AplazadaMedia (4.3)0.15%—Leav Last Email Address ValidatorAI16/1/202617/6/2026
The LEAV Last Email Address Validator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions <= 1.7.1. This is due to missing or incorrect nonce validation on the display_settings_page function. This makes it possible for unauthenticated attackers to modify plugin settings via a forged request…
AplazadaMedia (5.4)0.20%—Vollstart Serial Codes Generator AND ValidatorAI31/12/202517/6/2026
Missing Authorization vulnerability in Vollstart Serial Codes Generator and Validator with WooCommerce Support serial-codes-generator-and-validator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Serial Codes Generator and Validator with WooCommerce Support: from n/a through…
ModificadaAlta (7.7)0.52%—Validator Project Validator27/11/202514/7/2026
Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take into account Unicode variation selectors (\uFE0F, \uFE0E) appearing in a sequence which lead to improper string length calculation. This…
ModificadaMedia (6.1)0.32%—Validator Project Validator30/9/20255/7/2026
A URL validation bypass vulnerability exists in validator.js through version 13.15.15. The isURL() function uses '://' as a delimiter to parse protocols, while browsers use ':' as the delimiter. This parsing difference allows attackers to bypass protocol and domain validation by crafting URLs leading to XSS and Open…
AnalizadaMedia (6.9)0.75%—Redhat Hibernate Validator3/6/202517/6/2026
Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation message with Expression Language. This could allow an attacker to access sensitive information or execute arbitrary Java code. Hibernate Validator as of 6.2.0 and 7.0.0 no…
AplazadaAlta (7.1)0.29%—Debounce Email ValidatorAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in debounce DeBounce Email Validator debounce-io-email-validator allows Reflected XSS.This issue affects DeBounce Email Validator: from n/a through <= 5.6.5.