Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
69 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (10) | 0.49% | — | Kognetiks ChatbotAI | 6/10/2026 | 6/10/2026 | Unauthenticated Arbitrary File Upload in Kognetiks Chatbot for WordPress <= 2.4.9 versions. | |
| Aplazada | Baja (1.3) | 0.31% | — | Lognet Grpc-spring-boot-starterAI | 31/8/2026 | 31/8/2026 | A vulnerability has been found in LogNet grpc-spring-boot-starter up to 5.2.0. Affected is an unknown function of the component Annotation Processing. Such manipulation leads to improper authorization. The attack may be performed from remote. A high complexity level is associated with this attack. The exploitability… | |
| Analizada | Media (6.9) | 0.19% | — | Magnetosoft Megaping | 26/3/2026 | 17/6/2026 | MegaPing contains a local buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload to the Destination Address List field in the Finger function. Attackers can paste a crafted buffer exceeding expected input limits into the vulnerable field and trigger the… | |
| Aplazada | Media (5.4) | 0.30% | — | Zoho CRM Lead MagnetAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in zohocrm Zoho CRM Lead Magnet zoho-crm-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zoho CRM Lead Magnet: from n/a through <= 1.8.1.9. | |
| Aplazada | Media (5.3) | 0.38% | — | Kognetiks ChatbotAI | 18/10/2025 | 17/6/2026 | The Kognetiks Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.3.5. This makes it possible for unauthenticated attackers to upload limited safe files and erase conversations. | |
| Aplazada | Alta (7.3) | 0.22% | — | Magnetism Studios EnduranceAI | 24/9/2025 | 25/9/2026 | A flaw has been found in Magnetism Studios Endurance up to 3.3.0 on macOS. This affects the function loadModuleNamed:WithReply of the file /Applications/Endurance.app/Contents/Library/LaunchServices/com.MagnetismStudios.endurance.helper of the component NSXPC Interface. Executing manipulation can lead to missing… | |
| Aplazada | Media (5.8) | 0.24% | — | Vignette Content ManagementAI | 11/9/2025 | 17/6/2026 | In Content Management versions 20.4- 25.3 authenticated attackers may exploit a complex cache poisoning technique to download unprotected files from the server if the filenames are known. | |
| Aplazada | Media (6.7) | 0.10% | — | Aveva PI Connector FOR CygnetAI | 12/6/2025 | 17/6/2026 | An improper validation of integrity check value vulnerability exists in AVEVA PI Connector for CygNet Versions 1.6.14 and prior that, if exploited, could allow a miscreant with elevated privileges to modify PI Connector for CygNet local data files (cache and buffers) in a way that causes the connector service to… | |
| Aplazada | Media (6.9) | 0.15% | — | Aveva PI Connector FOR CygnetAI | 12/6/2025 | 17/6/2026 | A cross-site scripting vulnerability exists in AVEVA PI Connector for CygNet Versions 1.6.14 and prior that, if exploited, could allow an administrator miscreant with local access to the connector admin portal to persist arbitrary JavaScript code that will be executed by other users who visit affected pages. | |
| Aplazada | Media (4.3) | 0.17% | — | Syedbalkhi Beacon Lead Magnets AND Lead CaptureAI | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Beacon Lead Magnets and Lead Capture beacon-by allows Cross Site Request Forgery.This issue affects Beacon Lead Magnets and Lead Capture: from n/a through <= 1.5.8. | |
| Aplazada | Alta (7.1) | 0.29% | — | Syedbalkhi Beacon Lead Magnets AND Lead CaptureAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi Beacon Lead Magnets and Lead Capture beacon-by allows Reflected XSS.This issue affects Beacon Lead Magnets and Lead Capture: from n/a through <= 1.5.7. | |
| Analizada | Alta (7.5) | 0.36% | — | Gnetsystem G-onx Firmware | 18/3/2025 | 17/6/2026 | An issue was discovered on G-Net Dashcam BB GONX devices. A Public Domain name is Used for the Internal Domain Name. It uses an unregistered public domain name as an internal domain, creating a security risk. This domain was not owned by GNET originally, allowing an attacker to register it and potentially intercept… | |
| Analizada | Alta (8.1) | 0.28% | — | Gnetsystem G-onx Firmware | 18/3/2025 | 17/6/2026 | An issue was discovered on G-Net Dashcam BB GONX devices. Bypassing of Device Pairing can occur. It uses MAC address verification as the sole mechanism for recognizing paired devices, allowing attackers to bypass authentication. By capturing the MAC address of an already-paired device through ARP scanning or other… | |
| Analizada | Alta (7.5) | 0.35% | — | Gnetsystem G-onx Firmware | 18/3/2025 | 17/6/2026 | An issue was discovered on G-Net Dashcam BB GONX devices. One can Remotely Dump Video Footage and the Live Video Stream. It exposes API endpoints on ports 9091 and 9092 that allow remote access to recorded and live video feeds. An attacker who connects to the dashcam's network can retrieve all stored recordings and… | |
| Analizada | Crítica (9.8) | 0.41% | — | Gnetsystem G-onx Firmware | 18/3/2025 | 17/6/2026 | An issue was discovered on G-Net Dashcam BB GONX devices. Default credentials for SSID cannot be changed. It broadcasts a fixed SSID with default credentials that cannot be changed. This allows any nearby attacker to connect to the dashcam's network without restriction. Once connected, an attacker can sniff on… | |
| Analizada | Media (4.6) | 0.18% | — | Gnetsystem G-onx Firmware | 18/3/2025 | 17/6/2026 | An issue was discovered on G-Net Dashcam BB GONX devices. Managing Settings and Obtaining Sensitive Data and Sabotaging Car Battery can be performed by unauthorized persons. It allows unauthorized users to modify critical system settings once connected to its network. Attackers can extract sensitive car and driver… | |
| Aplazada | Crítica (9.8) | 0.46% | — | G-net GnetAI | 18/3/2025 | 17/6/2026 | An issue was discovered in the G-Net GNET APK 2.6.2. Hardcoded credentials exist in in APK for ports 9091 and 9092. The GNET mobile application contains hardcoded credentials that provide unauthorized access to the dashcam's API endpoints on ports 9091 and 9092. Once the GNET SSID is connected to, the attacker sends a… | |
| Aplazada | Alta (7.1) | 0.14% | — | Topplugins Vignette ADSAI | 7/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in topplugins Vignette Ads vignete-ads allows Stored XSS.This issue affects Vignette Ads: from n/a through <= 0.2. | |
| Modificada | Media (6.9) | 0.48% | — | Oringnet Iap-420 Firmware | 10/12/2024 | 17/6/2026 | Improper check of password character lenght in ORing IAP-420 allows a forced deadlock. This issue affects IAP-420: through 2.01e. | |
| Modificada | Crítica (9.3) | 17% | — | Oringnet Iap-420 Firmware | 10/12/2024 | 17/6/2026 | SNMP objects in NET-SNMP used in ORing IAP-420 allows Command Injection. This issue affects IAP-420: through 2.01e. | |
| Modificada | Alta (7.1) | 0.29% | — | Oringnet Iap-420 Firmware | 10/12/2024 | 17/6/2026 | Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below. | |
| Modificada | Alta (7.1) | 0.31% | — | Oringnet Iap-420 Firmware | 10/12/2024 | 17/6/2026 | Missing input validation in the ORing IAP-420 web-interface allows Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below. | |
| Modificada | Alta (8.7) | 12% | — | Oringnet Iap-420 Firmware | 10/12/2024 | 17/6/2026 | Missing input validation in the ORing IAP-420 web-interface allows authenticated Command Injections on OS level.This issue affects IAP-420 version 2.01e and below. | |
| Aplazada | Media (6.5) | 0.39% | — | Magnetic Creative Inline Click TO TweetAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magnetic Creative Inline Click To Tweet inline-click-to-tweet allows DOM-Based XSS.This issue affects Inline Click To Tweet: from n/a through <= 1.0.0. | |
| Analizada | Media (4.3) | 0.25% | — | Kognetiks Chatbot | 13/11/2024 | 17/6/2026 | The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.8. This is due to missing or incorrect nonce validation on the update_assistant, add_new_assistant, and delete_assistant functions. This makes it possible for unauthenticated… |