Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2744▼ 71 respecto a la semana anterior
Críticas / altas1416▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)106▼ 394 respecto a la semana anterior
–

73 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.25%—Wired Impact Volunteer ManagementAI4/8/202626/8/2026
The Wired Impact Volunteer Management WordPress plugin before 2.8.2 does not have authorisation checks in one of its AJAX actions, and does not verify that the RSVP being removed belongs to the requesting user, allowing users with a role as low as Subscriber to remove arbitrary users' RSVPs from any volunteer…
AnalizadaMedia (5.5)0.16%—IBM Tivoli Netcool/impact8/4/202624/7/2026
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.37 stores sensitive information in log files that could be read by a local user.
AnalizadaAlta (8.8)0.24%—Nokia Impact Mobile3/3/202617/6/2026
An issue was discovered in Nokia Impact before Mobile 23_FP1. In Impact DM 19.11 onwards, a remote authenticated user, using the Add Campaign functionality, can inject a malicious payload within the Campaign Name. This data can be exported to a CSV file. Attackers can populate data fields that may attempt data…
AnalizadaAlta (8.1)0.19%—Nokia Impact Mobile3/3/202617/6/2026
A Cross-Site Request Forgery (CSRF) vulnerability in Nokia IMPACT through 19.11.2.10-20210118042150283 allows a remote attacker to import and overwrite the entire application configuration. Specifically, in /ui/rest-proxy/entity/import, neither the X-CSRF-NONCE HTTP header nor the CSRF-NONCE cookie is validated.
AnalizadaAlta (8)0.24%—Nokia Impact3/3/202617/6/2026
The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload server-side executable files via the /ui/rest-proxy/application fileupload parameter. This can occur during the adding of a new application, or during the editing of an existing…
AnalizadaAlta (8.2)0.24%—Nokia Impact3/3/202617/6/2026
Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user to perform a Time-based Boolean Blind SQL Injection attack on the endpoint /ui/rest-proxy/campaign/statistic (for the View Campaign page) via the sortColumn HTTP GET parameter. This allows an attacker to access sensitive data from the…
AnalizadaMedia (4.1)0.23%—Nokia Impact3/3/202617/6/2026
The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload JavaScript files via the /ui/rest-proxy/application fileupload parameter. This can occur during the adding of a new application, or during the editing of an existing one. If an…
AplazadaAlta (8.1)0.48%—Ancorathemes Impacto PatronusAI20/2/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Impacto Patronus impacto-patronus allows PHP Local File Inclusion.This issue affects Impacto Patronus: from n/a through <= 1.2.3.
AplazadaMedia (5.3)0.19%—Wired Impact Volunteer ManagementAI3/2/202617/6/2026
Missing Authorization vulnerability in Wired Impact Wired Impact Volunteer Management wired-impact-volunteer-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wired Impact Volunteer Management: from n/a through <= 2.8.
ModificadaAlta (8.5)4.2%—Sound4 Impact FirmwareSound4 Pulse FirmwareSound4 First FirmwareSound4 Impact ECO Firmware+530/12/202517/6/2026
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory. Unauthenticated attackers can execute commands by making a single HTTP POST request to the traceroute.php script, which triggers the…
AnalizadaCrítica (9.3)3.7%—Sound4 Impact FirmwareSound4 Pulse FirmwareSound4 First FirmwareSound4 Impact ECO Firmware+530/12/202517/6/2026
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the username parameter. Attackers can exploit index.php and login.php scripts by injecting arbitrary shell commands through the HTTP POST 'username' parameter to execute system commands.
AnalizadaAlta (8.7)3.1%—Sound4 Impact FirmwareSound4 Pulse FirmwareSound4 First FirmwareSound4 Impact ECO Firmware+530/12/202517/6/2026
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an authenticated command injection vulnerability in the www-data-handler.php script that allows attackers to inject system commands through the 'services' POST parameter. Attackers can exploit this vulnerability by crafting malicious 'services' parameter values to execute…
ModificadaAlta (8.7)1.6%—Sound4 Impact FirmwareSound4 Pulse FirmwareSound4 First FirmwareSound4 Impact ECO Firmware+530/12/202517/6/2026
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated file disclosure vulnerability that allows remote attackers to access sensitive system files. Attackers can exploit the vulnerability by manipulating the 'file' GET parameter to disclose arbitrary files on the affected device.
ModificadaAlta (8.5)3.8%—Sound4 Impact FirmwareSound4 Pulse FirmwareSound4 First FirmwareSound4 Impact ECO Firmware+530/12/202517/6/2026
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory. Unauthenticated attackers can execute commands by making a single HTTP POST request to the vulnerable ping.php script, which triggers the…
ModificadaMedia (6.9)0.79%—Sound4 Impact FirmwareSound4 Pulse FirmwareSound4 First FirmwareSound4 Impact ECO Firmware+530/12/202517/6/2026
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated vulnerability that allows remote attackers to access live radio stream information through webplay or ffmpeg scripts. Attackers can exploit the vulnerability by calling specific web scripts to disclose radio stream details without…
ModificadaAlta (8.5)4.2%—Sound4 Impact FirmwareSound4 Pulse FirmwareSound4 First FirmwareSound4 Impact ECO Firmware+530/12/202517/6/2026
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory with .dns.pid extension. Unauthenticated attackers can execute the malicious commands by making a single HTTP POST request to the vulnerable dns.php…
AnalizadaMedia (6.9)0.83%—Sound4 First FirmwareSound4 Impact ECO FirmwareSound4 Pulse ECO FirmwareSound4 BIG Voice4 Firmware+530/12/202517/6/2026
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive log files. Attackers can directly browse the /log directory to retrieve system and sensitive information without authentication.
AnalizadaMedia (5.3)0.44%—Sound4 First FirmwareSound4 Impact ECO FirmwareSound4 Pulse ECO FirmwareSound4 BIG Voice4 Firmware+530/12/202517/6/2026
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains an unauthenticated stored cross-site scripting vulnerability in the username parameter that allows attackers to inject malicious scripts. Attackers can exploit the unvalidated username input to execute arbitrary HTML and JavaScript code in victim browser sessions…
ModificadaCrítica (9.3)0.60%—Sound4 First FirmwareSound4 Impact ECO FirmwareSound4 Pulse ECO FirmwareSound4 BIG Voice4 Firmware+530/12/202517/6/2026
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cannot be modified through normal device operations. Attackers can leverage these static credentials to gain unauthorized access to the device across Linux and Windows distributions without requiring…
ModificadaAlta (8.7)0.80%—Sound4 Impact FirmwareSound4 Pulse FirmwareSound4 First FirmwareSound4 Impact ECO Firmware+530/12/202517/6/2026
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains a network vulnerability that allows unauthenticated attackers to send ICMP signals to arbitrary hosts through network command scripts. Attackers can abuse ping.php, traceroute.php, and dns.php to generate network flooding attacks targeting external hosts.
ModificadaAlta (8.8)0.89%—Sound4 Impact FirmwareSound4 Pulse FirmwareSound4 First FirmwareSound4 Impact ECO Firmware+530/12/202517/6/2026
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an SQL injection vulnerability in the 'username' POST parameter of index.php that allows attackers to manipulate database queries. Attackers can inject arbitrary SQL code through the username parameter to bypass authentication and potentially access unauthorized database…
AnalizadaMedia (6.9)0.58%—Sound4 Stream ExtensionSound4 WM2 FirmwareSound4 BIG Voice2 FirmwareSound4 BIG Voice4 Firmware+530/12/202517/6/2026
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an insufficient session expiration vulnerability that allows attackers to reuse old session credentials. Attackers can exploit weak session management to potentially hijack active user sessions and gain unauthorized access to the application.
ModificadaCrítica (9.3)1.6%—Sound4 Impact FirmwareSound4 Pulse FirmwareSound4 First FirmwareSound4 Impact ECO Firmware+530/12/202524/9/2026
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware upload functionality with path traversal flaw. Attackers can exploit the upload.cgi script to write malicious files to the system with www-data permissions, enabling unauthorized access and code…
AnalizadaAlta (8.6)0.24%—Sound4 Playout Ula8 FirmwareSound4 Stream X8 FirmwareSound4 Stream X4 FirmwareSound4 Stream X2 Firmware+1122/12/202517/6/2026
SOUND4 Server Service 4.1.102 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted binary path by inserting malicious code in the system root path that could execute with LocalSystem…
ModificadaAlta (8.8)0.98%—Sound4 Impact FirmwareSound4 Pulse FirmwareSound4 First FirmwareSound4 Impact ECO Firmware+522/12/202517/6/2026
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated vulnerability in the /usr/cgi-bin/restorefactory.cgi endpoint that allows remote attackers to reset device configuration. Attackers can send a POST request to the endpoint with specific data to trigger a factory reset and bypass authentication, gaining…