Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2556▼ 352 respecto a la semana anterior
Críticas / altas1335▲ 66 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
–

27 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.54%—Loytec LIP Me201cAILoytec L INXAILoytec L GateAILoytec L ROCAI+424/7/202627/7/2026
Out-of-bounds Read (CWE-125) in BACnet packet parsing (`bacdt_datetime_to_tod`) in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.18 on LINX-A64 allows an unauthenticated remote attacker to crash `linx_a64.exe` and ultimately reboot the device via a malformed BACnet…
AplazadaMedia (6.6)0.54%—Loytec Lip-me201cAILoytec L-inxAILoytec L-gateAILoytec L-rocAI+524/7/202627/7/2026
Unchecked input for loop condition (CWE-606) in the SNMP agent in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an unauthenticated remote attacker to cause persistent denial of service (CPU exhaustion) via a crafted SNMP GETNEXT request with a large OID…
AplazadaBaja (3.8)0.16%—Loytec Lip-me201cAILoytec L-inxAILoytec L-gateAILoytec L-rocAI+424/7/202627/7/2026
Stack-based Buffer Overflow (CWE-121) in `/usr/bin/ltsudo` `cmd_ipaddr_conflict` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a `superadmin`-group attacker to trigger a SUID-root process abort or potentially elevate privileges via an overly long…
AplazadaAlta (8.4)0.19%—Loytec Lip-me201cAILoytec L-inxAILoytec L-gateAILoytec L-rocAI+524/7/202627/7/2026
Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a local attacker to authenticate as a uid=0 account without a password and obtain a root shell via an `/etc/passwd` entry with an empty password field.
AplazadaCrítica (9.2)0.18%—Loytec L-inxAILoytec L-gateAILoytec L-rocAILoytec L-iobAI+324/7/202627/7/2026
Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an authenticated `larmapp` attacker to make `/etc/passwd` writable by the `larmapp` group (leading to root privilege escalation) via a symlink attack on…
AplazadaAlta (8.4)0.15%—Loytec Lip-me201cAILoytec L-inxAILoytec L-gateAILoytec L-rocAI+524/7/202627/7/2026
Improper Privilege Management (CWE-269) in `/usr/bin/ltsudo` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a `superadmin`-group attacker to reset the password of any LARM user (including the `larmapp` service account) via the `set-passwd` subcommand.
AplazadaAlta (8.7)0.61%—Loytec Lip-me201cAILoytec L-inxAILoytec L-gateAILoytec L-rocAI+424/7/202627/7/2026
Stored Cross-Site Scripting (CWE-79) in the OPC XML-DA server statistics in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an unauthenticated remote attacker to execute arbitrary JavaScript in an administrator's browser (session hijacking, credential theft,…
AplazadaMedia (6.4)0.19%—Wpsocialrocket Social RocketAI23/4/202617/6/2026
The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.3.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access…
AplazadaMedia (4.9)0.51%—Totalprocessing Nomupay Payment Processing GatewayAI23/5/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in totalprocessing Nomupay Payment Processing Gateway totalprocessing-card-payments allows Path Traversal.This issue affects Nomupay Payment Processing Gateway: from n/a through <= 7.1.7.
AplazadaAlta (7.1)0.29%—Totalprocessing Nomupay Payment Processing GatewayAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in totalprocessing Nomupay Payment Processing Gateway totalprocessing-card-payments allows Reflected XSS.This issue affects Nomupay Payment Processing Gateway: from n/a through <= 7.1.6.
AplazadaMedia (6.5)0.48%—Totalprocessing Nomupay Payment Processing GatewayAI10/4/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in totalprocessing Nomupay Payment Processing Gateway totalprocessing-card-payments allows Path Traversal.This issue affects Nomupay Payment Processing Gateway: from n/a through <= 7.1.5.
AplazadaMedia (6.5)0.32%—Shenzhen Intellirocks Tech CO LTD Govee HomeAI27/1/202517/6/2026
An issue in Shenzhen Intellirocks Tech Co. Ltd Govee Home iOS 6.5.01 allows attackers to access sensitive user information via supplying a crafted payload.
ModificadaMedia (5.4)0.31%—Wpsocialrocket Social Rocket7/1/202517/6/2026
The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'socialrocket-floating' shortcode in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
ModificadaMedia (5.3)0.39%—Wpsocialrocket Social Rocket7/1/202517/6/2026
The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tweet_settings_save() and tweet_settings_update() functions in all versions up to, and including, 1.3.4. This makes it possible for authenticated attackers, with…
AplazadaAlta (7.5)0.58%—Officialprocoders NblocksAI20/11/202417/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in officialprocoders nBlocks nblocks allows PHP Local File Inclusion.This issue affects nBlocks: from n/a through <= 1.0.2.
ModificadaMedia (6.1)0.31%—Wpsocialrocket Social Rocket22/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Social Rocket allows Reflected XSS.This issue affects Social Rocket: from n/a through 1.3.3.
ModificadaMedia (4.8)0.52%—Wpsocialrocket Social Rocket10/10/202217/6/2026
The Social Rocket WordPress plugin before 1.3.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaAlta (7.5)0.72%—Castlerock Snmpc Online9/4/202017/6/2026
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It includes the username and password values in cleartext within each request's cookie value.
ModificadaMedia (5.4)0.56%—Castlerock Snmpc Online9/4/202017/6/2026
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. There are multiple persistent (stored) and reflected XSS vulnerabilities.
ModificadaAlta (7.5)1.4%—Castlerock Snmpc Online9/4/202017/6/2026
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It allows remote attackers to obtain sensitive credential information from backup files.
ModificadaAlta (7.5)1.5%—Castlerock Snmpc Online9/4/202017/6/2026
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It allows remote attackers to obtain sensitive information via info.php4.
ModificadaAlta (8.8)0.51%—Castlerock Snmpc Online9/4/202017/6/2026
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. There is pervasive CSRF.
ModificadaAlta (7.8)3.9%—Castlerock Simple Network Management Protocol Console12/7/201917/6/2026
nodeimp.exe in Castle Rock SNMPc before 9.0.12.1 and 10.x before 10.0.9 has a stack-based buffer overflow via a long variable string in a Map Objects text file.
ModificadaAlta (8.8)1.1%—Castlerock Snmpc10/4/201717/6/2026
Castle Rock Computing SNMPc before 2015-12-17 has SQL injection via the sc parameter.
ModificadaMedia (6.1)0.78%—Castlerock Snmpc10/4/201717/6/2026
Castle Rock Computing SNMPc before 2015-12-17 has XSS via SNMP.