Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2693▼ 76 respecto a la semana anterior
Críticas / altas1446▲ 304 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

60 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.36%—Schedule Post Changes With Publishpress FutureAI5/5/202617/6/2026
The Schedule Post Changes With PublishPress Future plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wrapper' attribute of the [futureaction] shortcode in all versions up to, and including, 4.10.0. This is due to insufficient input sanitization on the wrapper attribute. The plugin uses…
AnalizadaCrítica (9.3)0.61%—Codefuture Image Hosting Script12/4/202617/6/2026
CF Image Hosting Script 1.6.5 allows unauthenticated attackers to download and decode the application database by accessing the imgdb.db file in the upload/data directory. Attackers can extract delete IDs stored in plaintext from the deserialized database and use them to delete all pictures via the d parameter.
AplazadaCrítica (9.8)3.2%—Slider FutureAI19/2/202617/6/2026
The Slider Future plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'slider_future_handle_image_upload' function in all versions up to, and including, 1.0.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's…
AnalizadaCrítica (10)1.3%—Waterfutures Epyt-flow6/2/202617/6/2026
EPyT-Flow is a Python package designed for the easy generation of hydraulic and water quality scenario data of water distribution networks. Prior to 0.16.1, EPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is…
AplazadaMedia (5.4)0.33%—Publishpress FutureAI9/1/202617/6/2026
The Schedule Post Changes With PublishPress Future plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.9.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with…
AplazadaMedia (4.3)0.19%—Schedule Post Changes With Publishpress FutureAI21/11/202517/6/2026
The Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the "saveFutureActionData" function in all versions up to, and including, 4.9.1. This makes it…
AplazadaMedia (6.9)0.32%—Century Systems Futurenet MAAICentury Systems Ip-k SeriesAI31/10/202517/6/2026
FutureNet MA and IP-K series provided by Century Systems Co., Ltd. put the firmware version and the garbage collection information on the internal web page. With some crafted HTTP request, they can be accessed without authentication.
AplazadaAlta (8.6)1.2%—Century Systems Futurenet MAAICentury Systems Ip-k SeriesAI31/10/202517/6/2026
FutureNet MA and IP-K series provided by Century Systems Co., Ltd. contain an OS command Injection vulnerability. A user who logs in to the Web UI of the product may execute an arbitrary OS command.
AplazadaMedia (5.4)0.29%—Pythoncharmers Python-futureAI14/8/202517/6/2026
A vulnerability in the Python-Future 1.0.0 module allows for arbitrary code execution via the unintended import of a file named test.py. When the module is loaded, it automatically imports test.py, if present in the same directory or in the sys.path. This behavior can be exploited by an attacker who has the ability to…
AplazadaMedia (6.2)0.32%—Futurenet NXRAIFuturenet VXRAIFuturenet WXRAI3/4/202517/6/2026
UNIX symbolic link (Symlink) following issue exists in FutureNet NXR series, VXR series and WXR series routers. Attaching to the affected product an external storage containing malicious symbolic link files, a logged-in administrative user may obtain and/or destroy internal files.
AplazadaMedia (5.3)0.51%—Century Systems Futurenet ASAICentury Systems FAAI3/3/202517/6/2026
Buffer overflow vulnerability exists in FutureNet AS series (Industrial Routers) and FA series (Protocol Conversion Machine) provided by Century Systems Co., Ltd. If this vulnerability is exploited, a remote unauthenticated attacker may reboot the device by sending a specially crafted request.
AplazadaAlta (7.5)0.53%—Century Systems Futurenet ASAI3/3/202517/6/2026
Authentication bypass vulnerability exists in FutureNet AS series (Industrial Routers) provided by Century Systems Co., Ltd. If this vulnerability is exploited, a remote unauthenticated attacker may obtain the device information such as MAC address by sending a specially crafted request.
AnalizadaAlta (8.3)0.97%—HP Futuresmart 3HP Futuresmart 4HP Futuresmart 5HP 499m7a Firmware+9414/2/202517/6/2026
Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remote Code Execution and Elevation of Privilege when processing a PostScript print job.
AnalizadaMedia (6.3)0.94%—HP Futuresmart 3HP Futuresmart 5HP Futuresmart 414/2/202517/6/2026
Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remote Code Execution and Elevation of Privilege when processing a PostScript print job.
AplazadaMedia (6.5)0.32%—Guangzhou Polar Future Culture Technology University SearchAI27/1/202517/6/2026
An issue in Guangzhou Polar Future Culture Technology Co., Ltd University Search iOS 2.27.0 allows attackers to access sensitive user information via supplying a crafted link.
AplazadaAlta (7.1)0.21%—Brandt-net Display Future PostsAI16/12/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in brandt-net Display Future Posts display-future-posts allows Stored XSS.This issue affects Display Future Posts: from n/a through <= 0.2.3.
AplazadaCrítica (9.8)0.55%—Century Systems Futurenet NXRAI29/11/202417/6/2026
FutureNet NXR series routers provided by Century Systems Co., Ltd. have REST-APIs, which are configured as disabled in the initial (factory default) configuration. But, REST-APIs are unexpectedly enabled when the affected product is powered up, provided either http-server (GUI) or Web authentication is enabled. The…
ModificadaCrítica (9.8)0.65%—Centurysys Futurenet Nxr-1300 FirmwareCenturysys Futurenet Nxr-155/c FirmwareCenturysys Futurenet Nxr-610x FirmwareCenturysys Futurenet Nxr-g050 Firmware+1817/7/202417/6/2026
FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allow an administrative user to execute an arbitrary OS command, obtain and/or alter sensitive information, and cause a denial-of-service (DoS) condition.
ModificadaAlta (8.8)0.62%—Centurysys Futurenet Nxr-1300 FirmwareCenturysys Futurenet Nxr-155/c FirmwareCenturysys Futurenet Nxr-610x FirmwareCenturysys Futurenet Nxr-g050 Firmware+1817/7/202417/6/2026
FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. contain an active debug code vulnerability. If a user who knows how to use the debug function logs in to the product, the debug function may be used and an arbitrary OS command may be executed.
ModificadaCrítica (9.1)0.75%—Centurysys Futurenet Nxr-1300 FirmwareCenturysys Futurenet Nxr-155/c FirmwareCenturysys Futurenet Nxr-610x FirmwareCenturysys Futurenet Nxr-g050 Firmware+1817/7/202417/6/2026
Initialization of a resource with an insecure default vulnerability in FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allows a remote unauthenticated attacker to access telnet service unlimitedly.
AnalizadaMedia (6.5)0.34%—HP Futuresmart 4HP Futuresmart 3HP Futuresmart 521/2/202417/6/2026
Certain HP Enterprise LaserJet, and HP LaserJet Managed Printers are potentially vulnerable to information disclosure, when connections made by the device back to services enabled by some solutions may have been trusted without the appropriate CA certificate in the device's certificate store.
ModificadaMedia (6.1)0.34%—HP Futuresmart 54/10/202317/6/2026
Certain HP Enterprise LaserJet and HP LaserJet Managed Printers are potentially vulnerable to denial of service due to WS-Print request and potential injections of Cross Site Scripting via jQuery-UI.
ModificadaAlta (7.5)0.87%—HP Futuresmart 513/6/202317/6/2026
Certain HP Enterprise LaserJet and HP LaserJet Managed Printers are potentially vulnerable to information disclosure when IPsec is enabled with FutureSmart version 5.6.
ModificadaAlta (7.5)1.9%—Pythoncharmers Python-future23/12/202217/6/2026
An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted Set-Cookie header from malicious web server.
ModificadaCrítica (9.8)0.94%—HP Futuresmart 512/12/202217/6/2026
A potential security vulnerability has been identified for certain HP multifunction printers (MFPs). The vulnerability may lead to Denial of Service when running HP Workpath solutions on potentially affected products.