Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
30 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.31% | — | Lakedrops Digital Signage Framework | 2/9/2026 | 16/9/2026 | Missing Authorization vulnerability in Drupal Digital Signage Framework allows Forceful Browsing. This issue affects Digital Signage Framework versions: from 0.0.0 to 2.6.1. | |
| Aplazada | Crítica (9.3) | 0.43% | — | Ids6 Dsspro Digital Signage SystemAI | 16/5/2026 | 17/6/2026 | iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass authentication by requesting the autoLoginVerifyCode object. Attackers can retrieve valid CAPTCHA codes via the login endpoint and use them to perform brute-force attacks against user accounts. | |
| Aplazada | Media (6.9) | 0.43% | — | Red-v Super Digital Signage SystemAI | 6/1/2026 | 17/6/2026 | RED-V Super Digital Signage System 5.1.1 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive webserver log files. Attackers can visit multiple endpoints to retrieve system resources and debug log information without authentication. | |
| Aplazada | Alta (8.7) | 0.37% | — | Ids6 Dsspro Digital Signage SystemAI | 6/1/2026 | 17/6/2026 | iDS6 DSSPro Digital Signage System 6.2 contains an improper access control vulnerability that allows authenticated users to elevate privileges through console JavaScript functions. Attackers can create users, modify roles and permissions, and potentially achieve full application takeover by exploiting insecure direct… | |
| Aplazada | Media (5.1) | 0.17% | — | Ids6 Dsspro Digital Signage SystemAI | 6/1/2026 | 17/6/2026 | iDS6 DSSPro Digital Signage System 6.2 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without request validation. Attackers can craft malicious web pages to trick logged-in administrators into adding unauthorized users by exploiting the lack of CSRF… | |
| Aplazada | Alta (8.6) | 0.31% | — | Ids6 Dsspro Digital Signage SystemAI | 6/1/2026 | 17/6/2026 | iDS6 DSSPro Digital Signage System 6.2 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept authentication credentials through cleartext cookie transmission. Attackers can exploit the autoSave feature to capture user passwords during man-in-the-middle attacks on HTTP… | |
| Aplazada | Alta (8.5) | 0.26% | — | TDM Digital Signage PC PlayerAI | 6/1/2026 | 17/6/2026 | TDM Digital Signage PC Player 4.1.0.4 contains an elevation of privileges vulnerability that allows authenticated users to modify executable files. Attackers can leverage the 'Modify' permissions for authenticated users to replace executable files with malicious binaries and gain elevated system access. | |
| Aplazada | Alta (8.7) | 0.39% | — | Adtec Digital Signedje Digital Signage PlayerAI | 6/1/2026 | 17/6/2026 | Adtec Digital SignEdje Digital Signage Player v2.08.28 contains multiple hardcoded default credentials that allow unauthenticated remote access to web, telnet, and SSH interfaces. Attackers can exploit these credentials to gain root-level access and execute system commands across multiple Adtec Digital product… | |
| Aplazada | Alta (8.6) | 0.31% | — | Qihang Media WEB Digital SignageAI | 6/1/2026 | 17/6/2026 | QiHang Media Web Digital Signage 3.0.9 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept user authentication credentials through cleartext cookie transmission. Attackers can perform man-in-the-middle attacks to capture and potentially misuse stored authentication… | |
| Aplazada | Media (5.1) | 0.43% | — | Plexus Anblick Digital Signage ManagementAI | 6/1/2026 | 17/6/2026 | Plexus anblick Digital Signage Management 3.1.13 contains an open redirect vulnerability in the 'PantallaLogin' script that allows attackers to manipulate the 'pagina' GET parameter. Attackers can craft malicious links that redirect users to arbitrary websites by exploiting improper input validation in the parameter. | |
| Analizada | Crítica (9.3) | 1.1% | — | Medivision Digital Signage Firmware | 10/12/2025 | 17/6/2026 | UBICOD Medivision Digital Signage 1.5.1 contains an authorization bypass vulnerability that allows normal users to escalate privileges by manipulating the 'ft[grp]' parameter. Attackers can send a GET request to /html/user with 'ft[grp]' set to integer value '3' to gain super admin rights without authentication. | |
| Analizada | Alta (8.6) | 0.31% | — | Medivision Digital Signage Firmware | 10/12/2025 | 17/6/2026 | UBICOD Medivision Digital Signage 1.5.1 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without proper request validation. Attackers can craft a malicious web page that submits a form to the /query/user/itSet endpoint to add a new admin user with… | |
| Analizada | Alta (8.6) | 0.27% | — | All-dynamics Digital Signage System | 10/12/2025 | 17/6/2026 | All-Dynamics Digital Signage System 2.0.2 contains a cross-site request forgery vulnerability that allows attackers to create administrative users without proper request validation. Attackers can craft a malicious web page that automatically submits forms to create a new user with global administrative privileges when… | |
| Analizada | Alta (8.7) | 0.92% | — | Howfor Qihang Media WEB Digital Signage | 10/12/2025 | 17/6/2026 | QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated file disclosure vulnerability that allows remote attackers to access sensitive files through unverified 'filename' and 'path' parameters. Attackers can exploit the QH.aspx endpoint to read arbitrary files and directory contents without authentication… | |
| Analizada | Alta (8.8) | 1.7% | — | Howfor Qihang Media WEB Digital Signage | 10/12/2025 | 17/6/2026 | QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated file deletion vulnerability in the QH.aspx endpoint that allows remote attackers to delete files without authentication. Attackers can exploit the 'data' parameter by sending a POST request with file paths to delete arbitrary files with web server… | |
| Analizada | Crítica (9.3) | 1.3% | — | Howfor Qihang Media WEB Digital Signage | 10/12/2025 | 17/6/2026 | QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated remote code execution vulnerability in the QH.aspx file that allows attackers to upload malicious ASPX scripts. Attackers can exploit the file upload functionality by using the 'remotePath' and 'fileToUpload' parameters to write and execute arbitrary… | |
| Analizada | Alta (8.7) | 0.88% | — | Howfor Qihang Media WEB Digital Signage | 10/12/2025 | 17/6/2026 | QiHang Media Web Digital Signage 3.0.9 contains a cleartext credentials vulnerability that allows unauthenticated attackers to access administrative login information through an unprotected XML file. Attackers can retrieve hardcoded admin credentials by requesting the '/xml/User/User.xml' file, enabling direct… | |
| Analizada | Alta (8.7) | 0.73% | — | Eibiz I-media Server Digital Signage | 10/12/2025 | 17/6/2026 | EIBIZ i-Media Server Digital Signage 3.8.0 contains an unauthenticated configuration disclosure vulnerability that allows remote attackers to access sensitive configuration files via direct object reference. Attackers can retrieve the SiteConfig.properties file through an HTTP GET request, exposing administrative… | |
| Analizada | Crítica (9.3) | 0.80% | — | Eibiz I-media Server Digital Signage | 10/12/2025 | 17/6/2026 | Eibiz i-Media Server Digital Signage 3.8.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin users through AMF-encoded object manipulation. Attackers can send crafted serialized objects to the /messagebroker/amf endpoint to create administrative users without… | |
| Analizada | Alta (8.7) | 1.6% | — | Eibiz I-media Server Digital Signage | 10/12/2025 | 17/6/2026 | Eibiz i-Media Server Digital Signage 3.8.0 contains a directory traversal vulnerability that allows unauthenticated remote attackers to access files outside the server's root directory. Attackers can exploit the 'oldfile' GET parameter to view sensitive configuration files like web.xml and system files such as win.ini. | |
| Analizada | Crítica (9.3) | 1.1% | — | Eibiz I-media Server Digital Signage | 10/12/2025 | 17/6/2026 | Eibiz i-Media Server Digital Signage 3.8.0 contains an unauthenticated privilege escalation vulnerability in the updateUser object that allows attackers to modify user roles. Attackers can exploit the /messagebroker/amf endpoint to elevate privileges and take over user accounts by manipulating role settings without… | |
| Analizada | Media (6.9) | 0.40% | — | Spinetix Fusion Digital Signage | 10/12/2025 | 17/6/2026 | SpinetiX Fusion Digital Signage 3.4.8 contains a username enumeration vulnerability in its login script that allows attackers to identify valid user accounts. Attackers can send crafted login requests with different usernames to distinguish between existing and non-existing accounts by analyzing the server's error… | |
| Analizada | Alta (8.7) | 0.42% | — | Spinetix Fusion Digital Signage | 10/12/2025 | 17/6/2026 | SpinetiX Fusion Digital Signage 3.4.8 contains an unauthenticated information disclosure vulnerability in the database backup directory. Attackers can access the /content/files/backups/ endpoint to download sensitive backup files containing user credentials and system information. | |
| Analizada | Media (6.9) | 0.27% | — | Spinetix Fusion Digital Signage | 10/12/2025 | 17/6/2026 | SpinetiX Fusion Digital Signage 3.4.8 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without proper request validation. Attackers can craft a malicious web page that automatically submits a form to create a new admin user with full system privileges… | |
| Aplazada | Media (6.9) | 1.1% | 💥 Exploit | Brightsign Digital Signage Diagnostic WEB ServerAI | 10/12/2025 | 17/6/2026 | BrightSign Digital Signage Diagnostic Web Server 8.2.26 and less contains an unauthenticated server-side request forgery vulnerability in the 'url' GET parameter of the Download Speed Test service. Attackers can specify external domains to bypass firewalls and perform network enumeration by forcing the application to… |