Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2719▼ 93 respecto a la semana anterior
Críticas / altas1415▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)101▼ 398 respecto a la semana anterior
–

24 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.39%—Modsetter SurfsenseAI29/9/20261/10/2026
A weakness has been identified in MODSetter SurfSense up to 2.0.3. The affected element is an unknown function of the file surfsense_backend/app/routes/circleback_webhook_route.py of the component circleback Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched remotely. The…
AplazadaBaja (2.1)0.23%—Modsetter SurfsenseAI29/9/202629/9/2026
A security flaw has been discovered in MODSetter SurfSense up to 0.0.36. Impacted is an unknown function of the file surfsense_backend/app/routes/editor_routes.py of the component Document Export Feature. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The…
AplazadaBaja (2.1)1.2%—Modsetter SurfsenseAI29/9/202629/9/2026
A vulnerability was identified in MODSetter SurfSense up to 2.0.3. This issue affects some unknown processing of the file /api/search-source/connectors/mcp/test of the component MCP Connector Integration. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit is…
AplazadaBaja (3.8)0.14%—Data Sortedset SharedAI21/7/202623/7/2026
Data::SortedSet::Shared versions before 0.03 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in sortedset.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable).…
AplazadaCrítica (9.1)0.54%—Data Sortedset SharedAI21/7/202622/7/2026
Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the rank and min/max query paths. The attach-time validator ss_validate_header bounds only the root index against the node pool (node_capacity). The order-statistics and min/max queries then follow…
AplazadaBaja (2.3)0.20%—Mendi Neurofeedback Headset V4AI7/3/202616/8/2026
A vulnerability was detected in Mendi Neurofeedback Headset V4. Affected by this vulnerability is an unknown functionality of the component Bluetooth Low Energy Handler. Performing a manipulation results in cleartext transmission of sensitive information. The attack can only be performed from the local network. The…
AplazadaAlta (8.7)3.9%—Avtech Cloudsetup.cgiAI9/10/202517/6/2026
AVTECH devices that include the CloudSetup.cgi management endpoint are vulnerable to authenticated OS command injection. The `exefile` parameter in CloudSetup.cgi is passed to the underlying system command execution without proper validation or whitelisting. An authenticated attacker who can invoke this endpoint can…
AplazadaAlta (8.8)0.75%—DsetAI11/9/202414/7/2026
Versions of the package dset before 3.1.4 are vulnerable to Prototype Pollution via the dset function due improper user input sanitization. This vulnerability allows the attacker to inject malicious object property using the built-in Object property __proto__, which is recursively assigned to all the objects in the…
ModificadaAlta (8.1)1.8%—Dset Project Dset1/5/202217/6/2026
All versions of package dset are vulnerable to Prototype Pollution via 'dset/merge' mode, as the dset function checks for prototype pollution by validating if the top-level path contains __proto__, constructor or protorype. By crafting a malicious object, it is possible to bypass this check and achieve prototype…
ModificadaCrítica (9.8)3.1%—Dset Project Dset29/12/202017/6/2026
Prototype pollution vulnerability in 'dset' versions 1.0.0 through 2.0.1 allows attacker to cause a denial of service and may lead to remote code execution.
ModificadaAlta (7.8)0.45%—Westerndigital Sandiskssddashboardsetup.exeWesterndigitalssddashboardsetup.exe19/2/202017/6/2026
Western Digital WesternDigitalSSDDashboardSetup.exe before 3.0.2.0 allows DLL Hijacking.
ModificadaAlta (7.5)6.7%—Sennheiser HeadsetupMicrosoft Windows 10Microsoft Windows 7Microsoft Windows 8.1+59/11/201817/6/2026
Sennheiser HeadSetup 7.3.4903 places Certification Authority (CA) certificates into the Trusted Root CA store of the local system, and publishes the private key in the SennComCCKey.pem file within the public software distribution, which allows remote attackers to spoof arbitrary web sites or software publishers for…
ModificadaCrítica (9.8)1.5%—Mext Ebidsettingchecker7/7/201717/6/2026
Untrusted search path vulnerability in EbidSettingChecker.exe (version 1.0.0.0) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaBaja (3.3)0.73%—Softbank Wi-fi Spot Configuration SoftwareSoftbank Mobile Wi-fi RouterSoftbank NEC 3G HandsetSoftbank Panasonic 3G Handset+917/6/201316/6/2026
SoftBank Wi-Fi Spot Configuration Software, as used on SoftBank SHARP 3G handsets, SoftBank Panasonic 3G handsets, SoftBank NEC 3G handsets, SoftBank Samsung 3G handsets, SoftBank mobile Wi-Fi routers, SoftBank Android smartphones with the Wi-Fi application before 1.7.1, SoftBank Windows Mobile smartphones with the…
ModificadaAlta (9.3)3.1%—Hitachi Ucosminexus/opentp1 WEB WEB Front-endsetHitachi Ucosminexus Application ServerHitachi Ucosminexus ClientHitachi Ucosminexus Collaboration+2121/4/201016/6/2026
Buffer overflow in Hitachi Cosminexus V4 through V8, Processing Kit for XML, and Developer's Kit for Java, as used in products such as uCosminexus, Electronic Form Workflow, Groupmax, and IBM XL C/C++ Enterprise Edition 7 and 8, allows remote attackers to have an unknown impact via vectors related to the use of GIF…
ModificadaAlta (7.5)0.95%—COM Soundset9/10/200916/6/2026
SQL injection vulnerability in the Soundset (com_soundset) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to index.php.
ModificadaAlta (7.2)0.32%—Openhandsetalliance Android SDK17/2/200916/6/2026
Multiple integer overflows in malloc_leak.c in Bionic in Open Handset Alliance Android 1.0 have unknown impact and attack vectors, related to the (1) chk_calloc and (2) leak_calloc functions.
ModificadaAlta (7.2)0.30%—Openhandsetalliance Android SDK17/2/200916/6/2026
The link_image function in linker/linker.c in the dynamic linker in Bionic in Open Handset Alliance Android 1.0 on the T-Mobile G1 phone does not properly handle file descriptors 0, 1, and 2 for a setgid program, which allows local users to create arbitrary files owned by certain groups, possibly a related issue to…
ModificadaMedia (4.3)0.58%—Vocera Wireless Handset3/3/200816/6/2026
Vocera Communications wireless handsets, when using Protected Extensible Authentication Protocol (PEAP), do not validate server certificates, which allows remote wireless access points to steal hashed passwords and conduct man-in-the-middle (MITM) attacks.
ModificadaAlta (7.8)1.5%—Avaya Voip Handset18/10/200716/6/2026
Unspecified vulnerability in the Avaya VoIP Handset allows remote attackers to cause a denial of service (reboot) via crafted packets. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE…
ModificadaAlta (7.8)1.5%—NEC Mobile Handset18/10/200716/6/2026
Unspecified vulnerability in the NEC mobile handset allows remote attackers to cause a denial of service (reboot) via crafted packets. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE…
ModificadaAlta (7.8)1.6%—LG Electronics LG Mobile Handset18/10/200716/6/2026
Integer overflow in the LG Mobile handset allows remote attackers to cause a denial of service (reboot) via a crafted HTTP packet. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier…
ModificadaMedia (5.4)0.56%—Plantronic Headset31/12/200616/6/2026
The Bluetooth stack in the Plantronic Headset does not properly implement Non-pairable mode, which allows remote attackers to conduct unauthorized pair-up operations.
ModificadaMedia (5)1.7%—Nokia 6210 Handset7/3/200316/6/2026
Format string vulnerability in Nokia 6210 handset allows remote attackers to cause a denial of service (crash, lockup, or restart) via a Multi-Part vCard with fields containing a large number of format string specifiers.