Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 223 respecto a la semana anterior
Críticas / altas1373▲ 144 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
28 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.38% | — | Aster-te Terrapack TkservercgiAster-te Terrapack TkwebcorengAster-te Terrapack Tpkwebgis | 20/3/2026 | 5/7/2026 | The Terrapack software, from ASTER TEC / ASTER S.p.A., with the indicated components and versions has a file upload vulnerability that may allow attackers to execute arbitrary code. Vulnerable components include Terrapack TkWebCoreNG:: 1.0.20200914, Terrapack TKServerCGI 2.5.4.150, and Terrapack TpkWebGIS Client 1.0.0. | |
| Aplazada | Crítica (9.3) | 2.7% | — | Kaseya KserverAI | 31/7/2025 | 16/6/2026 | An unrestricted file upload vulnerability exists in Kaseya KServer versions prior to 6.3.0.2. The uploadImage.asp endpoint allows unauthenticated users to upload files to arbitrary paths via a crafted filename parameter in a multipart/form-data POST request. Due to the lack of authentication and input sanitation, an… | |
| Aplazada | Media (6.5) | 0.21% | — | Tinuzz TrackserverAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tinuzz Trackserver trackserver allows DOM-Based XSS.This issue affects Trackserver: from n/a through <= 5.1.0. | |
| Aplazada | Media (6.4) | 0.32% | — | TrackserverAI | 11/1/2025 | 17/6/2026 | The Trackserver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tsmap' shortcode in all versions up to, and including, 5.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (6.7) | 0.23% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+283 | 30/1/2023 | 17/6/2026 | A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Media (4.4) | 0.20% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Thinkcentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+321 | 30/1/2023 | 17/6/2026 | An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. | |
| Modificada | Alta (7.8) | 0.20% | — | Lenovo Ideacentre 510-15ikl FirmwareLenovo Ideacentre 510s-08ikl FirmwareLenovo Ideacentre 300s-11ish FirmwareLenovo Ideacentre 310-15asr Firmware+132 | 26/12/2022 | 17/6/2026 | Realtek Audio Drivers for Windows, as used on the Lenovo ThinkPad X1 Carbon 20A7, 20A8, 20BS, and 20BT before 6.0.8882.1 and 20KH and 20KG before 6.0.8907.1 (and on many other Lenovo and non-Lenovo products), mishandles DLL preloading. | |
| Modificada | Alta (7.5) | 1.1% | — | Freetakserver-ui Project Freetakserver-ui | 11/3/2022 | 17/6/2026 | FreeTAKServer-UI v1.9.8 was discovered to leak sensitive API and Websocket keys. | |
| Modificada | Media (6.5) | 0.74% | — | Freetakserver-ui Project Freetakserver-ui | 11/3/2022 | 17/6/2026 | An issue in the ?filename= argument of the route /DataPackageTable in FreeTAKServer-UI v1.9.8 allows attackers to place arbitrary files anywhere on the system. | |
| Modificada | Alta (8.8) | 1.1% | — | Freetakserver-ui Project Freetakserver-ui | 11/3/2022 | 17/6/2026 | FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges. | |
| Modificada | Alta (7.5) | 1.0% | — | Freetakserver-ui Project Freetakserver-ui | 11/3/2022 | 17/6/2026 | An access control issue in the component /ManageRoute/postRoute of FreeTAKServer v1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. | |
| Modificada | Media (5.4) | 0.49% | — | Freetakserver-ui Project Freetakserver-ui | 11/3/2022 | 17/6/2026 | FreeTAKServer-UI v1.9.8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Callsign parameter. | |
| Modificada | Media (6.5) | 0.88% | — | Freetakserver-ui Project Freetakserver-ui | 11/3/2022 | 17/6/2026 | FreeTAKServer-UI v1.9.8 was discovered to contain a SQL injection vulnerability via the API endpoint /AuthenticateUser. | |
| Modificada | Crítica (9.6) | 2.2% | — | Mock-server MockserverOracle Communications Cloud Native Core Policy | 16/8/2021 | 17/6/2026 | MockServer is open source software which enables easy mocking of any system you integrate with via HTTP or HTTPS. An attacker that can trick a victim into visiting a malicious site while running MockServer locally, will be able to run arbitrary code on the MockServer machine. With an overly broad default CORS… | |
| Modificada | Alta (7.2) | 2.4% | — | Lenovo Thinkserver Rd340 FirmwareLenovo Thinkserver Rd440 FirmwareLenovo Thinkserver Rd640 FirmwareLenovo Thinkserver Td340 Firmware | 16/11/2018 | 17/6/2026 | In some Lenovo ThinkServer-branded servers, a command injection vulnerability exists in the BMC firmware download command. This allows a privileged user to download and execute arbitrary code inside the BMC. This can only be exploited by authorized privileged users. | |
| Modificada | Alta (7.5) | 2.0% | — | Quickserver Project Quickserver | 7/6/2018 | 17/6/2026 | quickserver is a simple static file server. quickserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |
| Modificada | Crítica (9.8) | 3.8% | — | OpenslpDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+34 | 23/4/2018 | 17/6/2026 | OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability. | |
| Modificada | Media (6.8) | 0.52% | — | Lenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish FirmwareLenovo Ideacentre 510s-08ish FirmwareLenovo Ideacentre 700 Firmware+107 | 10/8/2017 | 17/6/2026 | A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnerability, conditions exist where an attacker with administrative privileges or physical access to a system may be able to run specially crafted code that can allow them to… | |
| Modificada | Alta (7.5) | 0.82% | — | Lenovo Thinkserver Firmware | 3/3/2017 | 17/6/2026 | Reset to default settings may occur in Lenovo ThinkServer TSM RD350, RD450, RD550, RD650, TD350 during a prolonged broadcast storm in TSM versions earlier than 3.77. | |
| Modificada | Media (5.9) | 5.1% | — | Intel Ethernet Controller X710 FirmwareIntel Ethernet Controller Xl710 FirmwareHP Ethernet 10gb 2-port 562flr-sfp+HP Ethernet 10gb 2-port 562sfp++24 | 9/1/2017 | 17/6/2026 | A Denial of Service in Intel Ethernet Controller's X710/XL710 with Non-Volatile Memory Images before version 5.05 allows a remote attacker to stop the controller from processing network traffic working under certain network use conditions. | |
| Modificada | Media (4.4) | 0.30% | — | Lenovo BiosLenovo Notebook 110 14ibr BiosLenovo Notebook 110 15ibr BiosLenovo Notebook B70 80 Bios+25 | 29/11/2016 | 17/6/2026 | A vulnerability has been identified in some Lenovo Notebook and ThinkServer systems where an attacker with administrative privileges on a system could install a program that circumvents Intel Management Engine (ME) protections. This could result in a denial of service or privilege escalation attack on the system. | |
| Modificada | Media (4.3) | 0.47% | — | Lenovo Thinkserver System Manager Baseboard Management Controller Firmware | 16/4/2015 | 17/6/2026 | The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350 does not validate server certificates during an "encrypted remote KVM session," which allows man-in-the-middle attackers to spoof servers. | |
| Modificada | Media (5) | 1.3% | — | Lenovo Thinkserver System Manager Baseboard Management Controller Firmware | 16/4/2015 | 17/6/2026 | The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350 allows remote attackers to cause a denial of service (web interface crash) via a malformed HTTP request during authentication. | |
| Modificada | Media (5) | 0.71% | — | Lenovo Thinkserver Rd650 FirmwareLenovo Thinkserver Rd650Lenovo Thinkserver Td350 FirmwareLenovo Thinkserver Td350+6 | 16/4/2015 | 17/6/2026 | Lenovo ThinkServer RD350, RD450, RD550, RD650, and TD350 servers before 1.26.0 use weak encryption to store (1) user and (2) administrator BIOS passwords, which allows attackers to decrypt the passwords via unspecified vectors. | |
| Modificada | Media (5) | 2.8% | — | Fersch Formbankserver | 9/1/2007 | 16/6/2026 | formbankcgi.exe in Fersch Formbankserver 1.9, when the PATH_INFO begins with (1) AbfrageForm or (2) EingabeForm, allows remote attackers to cause a denial of service (daemon crash) via multiple requests containing many /../ sequences in the Name parameter. NOTE: The provenance of this information is unknown; the… |