Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2528▼ 418 respecto a la semana anterior
Críticas / altas1311▲ 21 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
4 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.21% | — | AVE DominaplusAI | 24/12/2025 | 17/6/2026 | AVE DOMINAplus 1.10.x contains cross-site request forgery and cross-site scripting vulnerabilities that allow attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to exploit login.php parameters and execute arbitrary scripts in user browser sessions. | |
| Modificada | Alta (7.5) | 3.6% | — | AVE DominaplusAVE 53ab-wbs FirmwareAVE Ts01 FirmwareAVE Ts03x-v Firmware+3 | 28/4/2021 | 17/6/2026 | AVE DOMINAplus <=1.10.x suffers from an unauthenticated reboot command execution. Attackers can exploit this issue to cause a denial of service scenario. | |
| Modificada | Crítica (9.8) | 3.7% | — | AVE DominaplusAVE 53ab-wbs FirmwareAVE Ts01 FirmwareAVE Ts03x-v Firmware+3 | 28/4/2021 | 17/6/2026 | AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an unprotected directory that hosts an XML file '/xml/authClients.xml' and obtain administrative login information that allows for a successful authentication bypass attack. | |
| Modificada | Crítica (9.8) | 2.9% | — | AVE DominaplusAVE 53ab-wbs FirmwareAVE Ts01 FirmwareAVE Ts03x-v Firmware+3 | 28/4/2021 | 17/6/2026 | AVE DOMINAplus <=1.10.x suffers from an authentication bypass vulnerability due to missing control check when directly calling the autologin GET parameter in changeparams.php script. Setting the autologin value to 1 allows an unauthenticated attacker to permanently disable the authentication security control and… |