Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 6 respecto a la semana anterior
Críticas / altas1451▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
31 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.3) | 0.17% | — | Dell AppsyncAIDell Metro NodeAIDell UCC EdgeAIDell VxrailAI+5 | 18/8/2026 | 20/8/2026 | Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00 and Dell PowerFlex Rack version 4.5.4… | |
| Aplazada | Media (4.3) | 0.21% | — | Rarathemes Metro MagazineAI | 17/6/2026 | 1/10/2026 | Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Metro Magazine: from n/a through 1.3.7. | |
| Aplazada | Media (6.5) | 0.33% | — | Rarathemes Metro MagazineAI | 16/6/2026 | 17/6/2026 | Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Metro Magazine: from n/a through 1.4.1. | |
| Aplazada | Media (4.3) | 0.18% | — | Sparkle WP MetrostoreAI | 11/6/2026 | 26/9/2026 | Missing Authorization vulnerability in Sparkle WP MetroStore metrostore allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MetroStore: from n/a through 1.3.2. | |
| Analizada | Media (6.7) | 0.15% | — | Metronik Mepis RM | 1/4/2026 | 17/6/2026 | A vulnerability was identified in MEPIS RM, an industrial software product developed by Metronik. The application contained a hardcoded cryptographic key within the Mx.Web.ComponentModel.dll component. When the option to store domain passwords was enabled, this key was used to encrypt user passwords before storing… | |
| Aplazada | Alta (8.1) | 0.58% | — | Radiustheme MetroAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Metro metro allows PHP Local File Inclusion.This issue affects Metro: from n/a through <= 2.13. | |
| Aplazada | Alta (7.1) | 0.26% | — | Radiustheme MetroAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RadiusTheme Metro metro allows DOM-Based XSS.This issue affects Metro: from n/a through <= 2.13. | |
| Analizada | Media (4.8) | 0.17% | — | Bordeaux-metropole AT Internet Piano Analytics | 4/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AT Internet Piano Analytics allows Cross-Site Scripting (XSS).This issue affects AT Internet Piano Analytics: from 0.0.0 before 1.0.1, from 2.0.0 before 2.3.1. | |
| Analizada | Media (6.1) | 0.18% | — | Bordeaux-metropole AT Internet Smarttag | 4/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AT Internet SmartTag allows Cross-Site Scripting (XSS).This issue affects AT Internet SmartTag: from 0.0.0 before 1.0.1. | |
| Aplazada | Crítica (9.3) | 0.35% | — | Mmetrodw TplayerAI | 18/12/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mmetrodw tPlayer tplayer-html5-audio-player-with-playlist allows SQL Injection.This issue affects tPlayer: from n/a through <= 1.2.1.6. | |
| Aplazada | Alta (7.1) | 0.21% | — | Mmetrodw MMX Make ME ChristmasAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in mmetrodw MMX – Make Me Christmas mmx-make-me-christmas allows Stored XSS.This issue affects MMX – Make Me Christmas: from n/a through <= 1.0.0. | |
| Aplazada | Media (4.8) | 0.37% | — | Metronic Admin Dashboard TemplateAI | 30/9/2024 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability on the homepage of Metronic Admin Dashboard Template v2.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload. | |
| Modificada | Media (5.3) | 0.43% | — | Qd-metro Qingdao Metro | 28/12/2023 | 17/6/2026 | An issue in the export component AdSdkH5Activity of com.sdjictec.qdmetro v4.2.2 allows attackers to open a crafted URL without any filtering or checking. | |
| Modificada | Alta (7.8) | 0.15% | — | Nokia Wavelite Metro 200 AND FAN FirmwareNokia Wavelite Metro 200 OPS AND Fans FirmwareNokia Wavelite Metro 200 AND F2B Fans FirmwareNokia Wavelite Metro 200 OPS AND F2B Fans Firmware+2 | 4/10/2023 | 17/6/2026 | If Security Hardening guide rules are not followed, then Nokia WaveLite products allow a local user to create new users with administrative privileges by manipulating a web request. This affects (for example) WaveLite Metro 200 and Fan, WaveLite Metro 200 OPS and Fans, WaveLite Metro 200 and F2B fans, WaveLite Metro… | |
| Modificada | Alta (8.8) | 0.83% | — | Dell EMC Metro Node | 18/1/2023 | 17/6/2026 | Dell EMC Metro node, Version(s) prior to 7.1, contain a Code Injection Vulnerability. An authenticated nonprivileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application. | |
| Modificada | Media (6.1) | 0.51% | — | Metroui Metro UI | 11/10/2022 | 17/6/2026 | Metro UI v4.4.0 to v4.5.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Javascript function. | |
| Modificada | Media (5.3) | 5.7% | — | Vmware Spring FrameworkNetapp Active IQ Unified ManagerNetapp Cloud Secure AgentNetapp Metrocluster Tiebreaker+3 | 14/4/2022 | 17/6/2026 | In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and… | |
| Modificada | Media (4.3) | 1.4% | — | Vmware Spring FrameworkNetapp Active IQ Unified ManagerManagement Services FOR Element Software AND Netapp HCINetapp Metrocluster Tiebreaker+4 | 28/10/2021 | 17/6/2026 | In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. | |
| Modificada | Media (6.1) | 0.87% | — | Emetrotel Xain | 20/12/2018 | 17/6/2026 | An XSS issue was discovered in Steve Pallen Xain before 0.6.2 via the order parameter. | |
| Modificada | Alta (8.8) | 0.61% | — | Mediaron Metronet TAG Manager | 26/6/2018 | 17/6/2026 | Metronet Tag Manager version 1.2.7 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page /wp-admin/options-general.php?page=metronet-tag-manager that can result in allows anybody to do almost anything an admin can. This attack appear to be exploitable via Logged in user must follow a link. This… | |
| Modificada | Alta (7.5) | 2.2% | — | Netapp Metrocluster Tiebreaker | 11/1/2017 | 17/6/2026 | MetroCluster Tiebreaker for clustered Data ONTAP in versions before 1.2 discloses sensitive information in cleartext which may be viewed by an unauthenticated user. | |
| Modificada | Media (5.4) | 0.27% | — | Mymetro Project Mymetro | 21/10/2014 | 17/6/2026 | The MyMetro (aka com.myrippleapps.mymetro) application 2.4.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Metroseoul Metro News | 4/10/2014 | 17/6/2026 | The Metro News (aka com.netpia.ha.metro) application 1.6.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.8) | 3.3% | — | Lightwitch MetronomeProsody | 11/4/2014 | 17/6/2026 | plugins/mod_compression.lua in (1) Prosody before 0.9.4 and (2) Lightwitch Metronome through 3.4 negotiates stream compression while a session is unauthenticated, which allows remote attackers to cause a denial of service (resource consumption) via compressed XML elements in an XMPP stream, aka an "xmppbomb" attack. | |
| Modificada | Alta (7.8) | 1.9% | — | Lightwitch Metronome | 11/4/2014 | 17/6/2026 | plugins/mod_compression.lua in Lightwitch Metronome through 3.4 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XMPP stream, aka an "xmppbomb" attack. |