Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2686▼ 84 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
145 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.20% | — | Eagle BookingAI | 26/6/2026 | 29/9/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1.3.4.3 versions. | |
| Pendiente de análisis | Crítica (9.3) | 0.50% | — | Hirschmann HiosAIHirschmann RSPAIHirschmann RspeAIHirschmann RspsAI+9 | 3/4/2026 | 21/7/2026 | Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administrative access by crafting specially formed HTTP requests. Attackers can exploit… | |
| Analizada | Alta (8.7) | 0.44% | — | Beldan Eaglesdv Firmware | 2/4/2026 | 24/7/2026 | Hirschmann EagleSDV version 05.4.01 prior to 05.4.02 contains a denial-of-service vulnerability that causes the device to crash during session establishment when using TLS 1.0 or TLS 1.1. Attackers can trigger a crash by initiating TLS connections with these protocol versions to disrupt service availability. | |
| Pendiente de análisis | Alta (8.7) | 0.43% | — | Hirschmann EaglesdvAI | 2/4/2026 | 24/7/2026 | Hirschmann EagleSDV firmware prior to 05.4.02 contains a denial-of-service vulnerability in TLS session establishment. Attackers can crash the device during TLS handshake by exploiting protocol downgrades to TLS 1.0 or TLS 1.1, interrupting service availability. | |
| Aplazada | Alta (8.5) | 0.37% | — | Eagle-themes Eagle-bookingAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eagle-Themes Eagle Booking eagle-booking allows SQL Injection.This issue affects Eagle Booking: from n/a through <= 1.3.4.3. | |
| Aplazada | Media (6.4) | 0.16% | — | Eaglevisionit Rise BlocksAI | 25/2/2026 | 17/6/2026 | The Rise Blocks – A Complete Gutenberg Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘logoTag’ Site Identity block attribute in all versions up to, and including, 3.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (5.4) | 0.25% | — | Eagle-themes Eagle BookingAI | 30/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Eagle-Themes Eagle Booking eagle-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eagle Booking: from n/a through <= 1.3.4.3. | |
| Aplazada | Media (4.3) | 0.31% | — | Eagle-themes Eagle BookingAI | 30/12/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Eagle-Themes Eagle Booking eagle-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eagle Booking: from n/a through <= 1.3.4.3. | |
| Analizada | Alta (7.5) | 0.39% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux ARM SL+13 | 1/12/2025 | 17/6/2026 | An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition. | |
| Aplazada | Alta (8.4) | 0.16% | — | Tylertech EagleAI | 29/10/2025 | 17/6/2026 | The installer of WTW EAGLE (for Windows) 3.0.8.0 contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privileges of the running application. | |
| Analizada | Media (5.4) | 0.19% | — | Smseagle | 19/9/2025 | 17/6/2026 | SMSEagle before 6.11 allows reflected XSS via a username or contact phone number. | |
| Analizada | Alta (8.8) | 0.27% | — | Avtech Eagleeyes(lite) | 15/9/2025 | 17/6/2026 | An issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes 2.0.0. The custom X509TrustManager used in checkServerTrusted only checks the certificate's expiration date, skipping proper TLS chain validation. | |
| Aplazada | Alta (8.8) | 0.27% | — | Avtech Eagleeyes LiteAI | 15/9/2025 | 17/6/2026 | An issue was discovered in the method push.lite.avtech.com.AvtechLib.GetHttpsResponse in AVTECH EagleEyes Lite 2.0.0, the GetHttpsResponse method transmits sensitive information - including internal server URLs, account IDs, passwords, and device tokens - as plaintext query parameters over HTTPS | |
| Analizada | Crítica (9.8) | 0.66% | — | Avtech Eagleeyes(lite) | 15/9/2025 | 17/6/2026 | An issue was discovered in the methods push.lite.avtech.com.AvtechLib.GetHttpsResponse and push.lite.avtech.com.Push_HttpService.getNewHttpClient in AVTECH EagleEyes 2.0.0. The methods set ALLOW_ALL_HOSTNAME_VERIFIER, bypassing domain validation. | |
| Aplazada | Media (6.3) | 0.14% | — | WTW Eagle APPAI | 12/9/2025 | 17/6/2026 | WTW-EAGLE App does not properly validate server certificates, which may allow a man-in-the-middle attacker to monitor encrypted traffic. | |
| Aplazada | Media (5.3) | 0.23% | — | SmseagleAI | 9/9/2025 | 17/6/2026 | A SQL injection vulnerability has been identified in the SMPP server component of the SMSEagle firmware, specifically affecting the handling of certain parameters within the server's database interactions. The vulnerability is isolated to the SMPP server, which operates with its own dedicated database, separate from… | |
| Modificada | Media (5.4) | 0.34% | — | Eaglevisionit Rise Blocks | 12/2/2025 | 17/6/2026 | The Rise Blocks – A Complete Gutenberg Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the titleTag parameter in all versions up to, and including, 3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (6.1) | 0.25% | — | Smseagle | 23/8/2024 | 17/6/2026 | A stored Cross-Site Scripting (XSS) vulnerability has been identified in SMSEagle software version < 6.0. The vulnerability arises because the application did not properly sanitize user input in the SMS messages in the inbox. This could allow an attacker to inject malicious JavaScript code into an SMS message, which… | |
| Modificada | Alta (7.8) | 2.1% | — | Jensenofscandinavia Eagle 1200ac Firmware | 22/1/2024 | 9/7/2026 | Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a command injection vulnerability in the function formWriteFacMac. This vulnerability allows attackers to execute arbitrary commands via manipulation of the mac parameter. | |
| Modificada | Alta (8.8) | 0.22% | — | Eaglevisionit Rise Blocks | 29/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Rise Themes Rise Blocks – A Complete Gutenberg Page Builder.This issue affects Rise Blocks – A Complete Gutenberg Page Builder: from n/a through 3.1. | |
| Modificada | Alta (8.8) | 0.96% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000 SLCodesys Control FOR Linux ARM SL+7 | 5/12/2023 | 17/6/2026 | A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the attacker full control of the device. | |
| Modificada | Alta (8.8) | 0.88% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+10 | 3/8/2023 | 17/6/2026 | In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow an remote attacker with user privileges to gain full access of the device. | |
| Modificada | Media (6.5) | 0.63% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+12 | 3/8/2023 | 17/6/2026 | After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability… | |
| Modificada | Media (6.5) | 0.63% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+12 | 3/8/2023 | 17/6/2026 | After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability… | |
| Modificada | Media (6.5) | 0.63% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+12 | 3/8/2023 | 17/6/2026 | After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted remote communication requests can cause the CmpAppBP component to overwrite a heap-based buffer, which can lead to a denial-of-service condition. |