Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.46% | — | Epson Sb-h50 FirmwareEpson Tm-h6000v FirmwareEpson Tm-l100 FirmwareEpson Tm-m10 Firmware+20 | 5/3/2026 | 17/6/2026 | ESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and command authorization, does not provide controls to restrict sources or destinations of network communication, and transmits commands without encryption or integrity protection. | |
| Aplazada | Alta (7.3) | 0.25% | — | E-plugins ListihubAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in e-plugins Listihub listihub allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Listihub: from n/a through <= 1.0.6. | |
| Aplazada | Crítica (9.3) | 0.63% | — | Iskra IhubAIIskra Ihub LiteAI | 2/12/2025 | 17/6/2026 | The Iskra iHUB and iHUB Lite smart metering gateway exposes its web management interface without requiring authentication, allowing unauthenticated users to access and modify critical device settings. | |
| Aplazada | Crítica (9.8) | 1.00% | — | AihubAI | 19/4/2025 | 17/6/2026 | The AIHub theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the generate_image function in all versions up to, and including, 1.3.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code… | |
| Modificada | Media (5.5) | 0.33% | — | Electronic Flexihub | 24/5/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in FlexiHub 5.5.14691.0. This affects the function 0x220088 in the library fusbhub.sys of the component IoControlCode Handler. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the… | |
| Modificada | Alta (8.8) | 0.50% | — | Flexihub | 7/12/2021 | 17/6/2026 | FlexiHub For Windows is affected by Integer Overflow. IOCTL Handler 0x22001B in the FlexiHub For Windows above 2.0.4340 below 5.3.14268 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet. | |
| Modificada | Alta (8.8) | 0.48% | — | Flexihub | 7/12/2021 | 17/6/2026 | FlexiHub For Windows is affected by Buffer Overflow. IOCTL Handler 0x22001B in the FlexiHub For Windows above 2.0.4340 below 5.3.14268 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet. | |
| Modificada | Media (5.4) | 0.27% | — | Ctihub CT Ihub | 21/10/2014 | 17/6/2026 | The CT iHub (aka com.concursive.ctihub) application 1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.8% | — | Verlihub-project Verlihub Control Panel | 22/7/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Verlihub Control Panel (VHCP) 1.7e allow remote attackers to inject arbitrary web script or HTML via (1) the nick parameter in a login action to index.php or (2) the URI in a news request to index.html. | |
| Modificada | Media (6.9) | 0.79% | — | Verlihub-project Verlihub | 22/12/2008 | 16/6/2026 | The cTrigger::DoIt function in src/ctrigger.cpp in the trigger mechanism in the daemon in Verlihub 0.9.8d-RC2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the /tmp/trigger.tmp temporary file. | |
| Modificada | Alta (9.3) | 5.4% | — | Verlihub-project Verlihub | 22/12/2008 | 16/6/2026 | The cTrigger::DoIt function in src/ctrigger.cpp in the trigger mechanism in the daemon in Verlihub 0.9.8d-RC2 and earlier, when user triggers are enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in an argument. | |
| Modificada | Media (6.8) | 2.3% | — | Verlihub-project Verlihub Control Panel | 9/10/2007 | 16/6/2026 | Directory traversal vulnerability in index.php in Verlihub Control Panel (VHCP) 1.7 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) in the page parameter. |