Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

49 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.38%—Fs-code BookneticAI6/10/20266/10/2026
Unauthenticated SQL Injection in Booknetic <= 4.8.5 versions.
AplazadaMedia (6.9)0.17%—DarknetAI27/8/202624/9/2026
darknet subscripts its layer array with an index taken from a configuration file without checking it against the array's length. The array is allocated in src-lib/darknet_network.cpp as xcalloc(net.n, sizeof(Darknet::Layer)), sized to exactly the number of layer sections the file declares. The shortcut, scale_channels…
AplazadaAlta (8.5)0.21%—Hank-ai DarknetAI20/8/202624/9/2026
hank-ai/darknet sizes a convolutional layer's weight and output heap buffers by multiplying configuration fields taken from a .cfg file in unchecked 32-bit int arithmetic. In src-lib/convolutional_layer.cpp, l.nweights is computed as (c / groups) * n * size * size and l.outputs as l.out_h * l.out_w * l.out_c, and both…
AplazadaAlta (8.1)0.46%—Fs-code BookneticAI17/6/202617/6/2026
Unauthenticated Broken Authentication in Booknetic <= 4.8.5 versions.
AplazadaMedia (6.1)0.19%—Aryom Software High Technology Systems INC KvknetAI11/11/202517/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Aryom Software High Technology Systems Inc. KVKNET allows Reflected XSS. This issue affects KVKNET: before 2.1.8.
AplazadaMedia (5.3)0.29%—Desknets NEOAI16/10/202517/6/2026
Improper Protection of Alternate Path (CWE-424) in the AppSuite of desknet's NEO V4.0R1.0 to V9.0R2.0 allows an attacker to create malicious AppSuite applications.
AplazadaMedia (4.8)0.29%—Desknet NEOAI16/10/202517/6/2026
Stored cross-site scripting (XSS) vulnerability in desknet's NEO V2.0R1.0 to V9.0R2.0 allow execution of arbitrary JavaScript in a user’s web browser.
AplazadaMedia (4.6)0.30%—Desknet NEOAI16/10/202517/6/2026
Stored cross-site scripting (XSS) vulnerability in desknet's NEO V9.0R2.0 and earlier allow execution of arbitrary JavaScript in a user’s web browser.
AplazadaMedia (4.8)0.29%—Desknet NEOAI16/10/202517/6/2026
Stored cross-site scripting (XSS) vulnerability in desknet's NEO V9.0R2.0 and earlier allow execution of arbitrary JavaScript in a user’s web browser.
AplazadaMedia (5.1)0.32%—Desknet WEB ServerAI16/10/202517/6/2026
Reflected cross-site scripting (XSS) vulnerability in desknet's Web Server allows execution of arbitrary JavaScript in a user’s web browser.
AplazadaMedia (4.8)0.29%—Desknets NEOAI16/10/202517/6/2026
Stored cross-site scripting (XSS) vulnerability in desknet's NEO versions V4.0R1.0–V9.0R2.0 allow execution of arbitrary JavaScript in a user’s web browser.
AplazadaMedia (5.3)0.27%—Desknet NEOAI16/10/202530/9/2026
desknet's NEO V4.0R1.0 to V9.0R2.0 contains a hard-coded cryptographic key, which allows an attacker to create malicious AppSuite applications.
AnalizadaAlta (8.8)0.24%—Fs-code Booknetic26/3/202517/6/2026
The Booknetic WordPress plugin before 4.1.5 does not have CSRF check when creating Staff accounts, which could allow attackers to make logged in admin add arbitrary Staff members via a CSRF attack
AplazadaMedia (4.3)0.16%—Fs-code BookneticAI25/2/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in fs-code Booknetic booknetic.This issue affects Booknetic: from n/a through <= 4.0.9.
AplazadaMedia (5.3)0.53%—Yunknet Online School SystemAI12/9/202417/6/2026
A vulnerability was found in 云课网络科技有限公司 Yunke Online School System up to 3.0.6. It has been declared as problematic. This vulnerability affects the function downfile of the file application/admin/controller/Appadmin.php. The manipulation of the argument url leads to path traversal. The attack can be initiated…
ModificadaBaja (2.3)0.73%—Yunknet Online School System4/9/202417/6/2026
A vulnerability was found in 云课网络科技有限公司 Yunke Online School System up to 1.5.5. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/educloud/videobind.html. The manipulation leads to inclusion of sensitive information in source code. The attack can be initiated remotely. The…
ModificadaMedia (6.1)0.51%—Teknet Project Teknet2/1/202317/6/2026
A vulnerability was found in kirill2485 TekNet. It has been classified as problematic. Affected is an unknown function of the file pages/loggedin.php. The manipulation of the argument statusentery leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is…
ModificadaAlta (8.8)0.57%💥 PoCOptilinknetwork Op-xt71000n Firmware23/11/202217/6/2026
A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to Reset ONU to Factory Default through ' /mgm_dev_reset.asp.' Resetting to default leads to Escalation of Privileges by…
ModificadaCrítica (9.8)1.2%💥 PoCOptilinknetwork Op-xt71000n Firmware23/11/202217/6/2026
A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an attacker to upload arbitrary files through " /mgm_dev_upgrade.asp " which can "delete every file for Denial of Service (using 'rm -rf *.*' in the code), reverse connection (using '.asp' webshell), backdoor.
ModificadaMedia (6.5)0.45%💥 PoCOptilinknetwork Op-xt71000n Firmware23/11/202217/6/2026
A vulnerability in Optilink OP-XT71000N Hardware version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated remote attacker to conduct a cross-site request forgery (CSRF) attack to change the Password for "WLAN SSID" through "wlwpa.asp".
ModificadaMedia (6.5)0.48%💥 PoCOptilinknetwork Op-xt71000n Firmware23/11/202217/6/2026
A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to cause a Denial of Service by Rebooting the router through " /mgm_dev_reboot.asp."
ModificadaMedia (4.3)0.40%💥 PoCOptilinknetwork Op-xt71000n Firmware23/11/202217/6/2026
A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to "Enable or Disable Ports" and to "Change port number" through " /rmtacc.asp ".
ModificadaBaja (3.1)0.33%💥 PoCOptilinknetwork Op-xt71000n Firmware23/11/202217/6/2026
A vulnerability found in the OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to men in the middle attack by adding New Routes in RoutingConfiguration on " /routing.asp ".
ModificadaMedia (4.3)0.37%💥 PoCOptilinknetwork Op-xt71000n Firmware23/11/202217/6/2026
A vulnerability found in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to Add Network Traffic Control Type Rule.
ModificadaCrítica (9.8)41%💥 PoCOptilinknetwork Op-xt71000n Firmware23/11/202217/6/2026
Unauthenticated remote code execution in OPTILINK OP-XT71000N, Hardware Version: V2.2 occurs when the attacker passes arbitrary commands with IP-ADDRESS using " | " to execute commands on " /diag_tracert_admin.asp " in the "PingTest" parameter that leads to command execution.
Orbitaley — Vulnerabilidades