Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2494▼ 451 respecto a la semana anterior
Críticas / altas1280▼ 7 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
29 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.2) | 0.14% | — | Loglama TurkhotspotAI | 2/10/2026 | 5/10/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in MRV Technology Foreign Trade Ltd. Co. TurkHotspot allows Reflected XSS. This issue affects TurkHotspot: through 2026-10-02. NOTE: The vendor was contacted and it was learned that the product is not supported. | |
| Aplazada | Crítica (9.8) | 0.47% | — | Turkmesh Communication Services INC Turkhotspot 5651 LoglamaAI | 21/7/2026 | 21/7/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Turkmesh Communication Services Inc. Turkhotspot 5651 Loglama allows SQL Injection. This issue affects Turkhotspot 5651 Loglama: from 5.1.2 before 5.1.3. | |
| Aplazada | Alta (8.5) | 0.15% | — | Hotspot ShieldAI | 4/4/2026 | 20/7/2026 | Hotspot Shield 6.0.3 contains an unquoted service path vulnerability in the hshld service binary that allows local attackers to escalate privileges by injecting malicious executables. Attackers can place executable files in the service path and upon service restart or system reboot, the malicious code executes with… | |
| Aplazada | Media (6.4) | 0.19% | — | Devvn Image HotspotAI | 19/2/2026 | 17/6/2026 | The Image Hotspot by DevVN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hotspot_content' custom field meta in all versions up to, and including, 1.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author level access… | |
| Modificada | Alta (8.8) | 0.47% | — | Aida Hotel Guest Hotspot | 22/1/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aida Computer Information Technology Inc. Hotel Guest Hotspot allows SQL Injection. This issue affects Hotel Guest Hotspot: through 22012026. NOTE: The vendor was contacted early about this disclosure but did not… | |
| Modificada | Media (6.1) | 0.22% | — | Aida Hotel Guest Hotspot | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Aida Computer Information Technology Inc. Hotel Guest Hotspot allows Reflected XSS. This issue affects Hotel Guest Hotspot: through 22012026. NOTE: The vendor was contacted early about this disclosure but did… | |
| Aplazada | Alta (8.5) | 0.17% | — | WifihotspotAI | 16/1/2026 | 17/6/2026 | WifiHotSpot 1.0.0.0 contains an unquoted service path vulnerability in its WifiHotSpotService.exe that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path during system startup or reboot to inject and run malicious executables with LocalSystem permissions. | |
| Aplazada | Alta (8.5) | 0.19% | — | Connectify HotspotAI | 13/1/2026 | 17/6/2026 | Connectify Hotspot 2018 contains an unquoted service path vulnerability in its ConnectifyService executable that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Connectify\ConnectifyService.exe' to inject malicious executables and… | |
| Aplazada | Baja (2.3) | 0.32% | — | Hotspot Shield VPN ClientAI | 30/6/2025 | 17/6/2026 | Host Header Injection (HHI) vulnerability in the Hotspot Shield VPN client, which can induce unexpected behaviour when accessing third-party web applications through the VPN tunnel. Although such applications do not present this vulnerability per se, the use of the tunnel, together with a forged Host header, can cause… | |
| Aplazada | Crítica (9.3) | 0.38% | — | Art-in Bilisim Teknolojileri VE Yazilim Hizm. Tic. Ltd. STI Wi-fi Cloud HotspotAI | 24/6/2025 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in Art-in Bilişim Teknolojileri ve Yazılım Hizm. Tic. Ltd. Şti. Wi-Fi Cloud Hotspot allows Authentication Abuse, Authentication Bypass. This issue affects Wi-Fi Cloud Hotspot: before 30.05.2025. | |
| Aplazada | Media (6.5) | 0.34% | — | Bg-tek Coslat HotspotAI | 20/3/2025 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in BG-TEK Coslat Hotspot allows Password Brute Forcing, Authentication Abuse. This issue affects Coslat Hotspot: before 6.26.0.R.20250227. | |
| Aplazada | Alta (7.1) | 0.20% | — | Dpowney Hotspots AnalyticsAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in dpowney Hotspots Analytics hotspots allows Stored XSS.This issue affects Hotspots Analytics: from n/a through <= 4.0.12. | |
| Aplazada | Alta (8.8) | 0.78% | — | Devvn Image HotspotAI | 24/8/2024 | 17/6/2026 | The Image Hotspot by DevVN plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.5 via deserialization of untrusted input in the 'devvn_ihotspot_shortcode_func' function. This makes it possible for authenticated attackers, with Author-level access and above, to inject a… | |
| Aplazada | Alta (8.8) | 0.47% | — | Kdab HotspotAI | 1/5/2024 | 17/6/2026 | An issue in Wifire Hotspot v.4.5.3 allows a local attacker to execute arbitrary code via a crafted payload to the dst parameter. | |
| Modificada | Alta (7) | 0.29% | — | Kdab Hotspot | 14/3/2023 | 17/6/2026 | KDAB Hotspot 1.3.x and 1.4.x through 1.4.1, in a non-default configuration, allows privilege escalation because of race conditions involving symlinks and elevate_perf_privileges.sh chown calls. | |
| Modificada | Crítica (9.8) | 0.63% | — | Glox Useroam Hotspot | 2/3/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Glox Technology Useroam Hotspot allows SQL Injection. This issue affects Useroam Hotspot: before 5.1.0.15. | |
| Modificada | Alta (7.5) | 1.3% | — | Peplink Balance 20X FirmwarePeplink Balance 310x FirmwarePeplink MBX FirmwarePeplink EPX Firmware+51 | 7/10/2020 | 17/6/2026 | Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php/connector.php) from Web Admin. | |
| Modificada | Alta (7.8) | 0.38% | — | Pango Hotspot Shield | 24/9/2020 | 17/6/2026 | Improper directory permissions in the Hotspot Shield VPN client software for Windows 10.3.0 and earlier may allow an authorized user to potentially enable escalation of privilege via local access. The vulnerability allows a local user to corrupt system files: a local user can create a specially crafted symbolic link… | |
| Modificada | Media (6.5) | 5.3% | — | JIO 4G Hotspot M2S Firmware | 9/8/2018 | 17/6/2026 | JioFi 4G Hotspot M2S devices allow attackers to cause a denial of service (secure configuration outage) via an XSS payload in the SSID name and Security Key fields. | |
| Modificada | Media (6.1) | 0.91% | — | Soconnect Sowifi Hotspot Firmware | 7/3/2018 | 17/6/2026 | Open redirect vulnerability in the SO Connect SO WIFI hotspot web interface, prior to version 140, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL. | |
| Modificada | Alta (7.5) | 11% | — | Anchorfree Hotspot Shield | 31/1/2018 | 17/6/2026 | Hotspot Shield runs a webserver with a static IP address 127.0.0.1 and port 895. The web server uses JSONP and hosts sensitive information including configuration. User controlled input is not sufficiently filtered: an unauthenticated attacker can send a POST request to /status.js with the parameter… | |
| Modificada | Media (5.9) | 1.4% | — | Comcast Xfinity Wifi Hotspot | 31/7/2017 | 17/6/2026 | Comcast XFINITY WiFi Home Hotspot devices allow remote attackers to spoof the identities of Comcast customers via a forged MAC address. | |
| Modificada | Alta (7.6) | 9.6% | — | Cambium Networks Epmp 1000 FirmwareCambium Networks Epmp Elevate FirmwareCambium Networks Epmp 2000 FirmwareCambium Networks Epmp 1000 Hotspot Firmware | 21/6/2017 | 17/6/2026 | An Improper Privilege Management issue was discovered in Cambium Networks ePMP. The privileges for SNMP community strings are not properly restricted, which may allow an attacker to gain access to sensitive information and possibly allow for configuration changes. | |
| Modificada | Media (6.8) | 6.7% | — | Cambium Networks Epmp 1000 FirmwareCambium Networks Epmp Elevate FirmwareCambium Networks Epmp 2000 FirmwareCambium Networks Epmp 1000 Hotspot Firmware | 21/6/2017 | 17/6/2026 | An Improper Access Control issue was discovered in Cambium Networks ePMP. After a valid user has used SNMP configuration export, an attacker is able to remotely trigger device configuration backups using specific MIBs. These backups lack proper access control and may allow access to sensitive information and possibly… | |
| Modificada | Media (5) | 2.8% | — | Hotspotexpress Hotex Billing Manager | 16/4/2015 | 17/6/2026 | Hotspot Express hotEx Billing Manager 73 does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. |