Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

1007 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.9)0.19%—Supreme Modules LiteAI30/9/202630/9/2026
Author Cross Site Scripting (XSS) in Supreme Modules Lite <= 2.5.63 versions.
AplazadaMedia (5.9)0.17%—Mh-developer Smart Home ModuleAI28/9/202628/9/2026
mH-DEVELOPER smart home module is vulnerable to Denial of Service due to uncontrolled resource consumption. The Express bodyParser is configured with a 250 MB limit for JSON and URL-encoded request bodies. An authenticated attacker on the LAN can send large request bodies that exhausts buffers in RAM, causing…
AplazadaMedia (6.9)0.37%—Mh-developer Smart Home ModuleAI28/9/202628/9/2026
mH-DEVELOPER smart home module ships with an end-of-life, unsupported Debian 8 and Node.js runtime v17.0.1 in its production firmware. This exposes the device to publicly known vulnerabilities that will not receive security patches. An attacker could exploit these known flaws to execute arbitrary code, access…
AplazadaMedia (6)0.21%—Mh-developer Smart Home ModuleAI28/9/202628/9/2026
mH-DEVELOPER smart home module sends its web interface and API traffic over unencrypted HTTP. Passwords, authentication tokens, and device commands are transmitted in cleartext. An attacker on the same network can intercept this traffic, steal credentials and tokens, and hijack sessions. This issue was fixed in…
AplazadaMedia (5.3)0.17%—Mh-developer Smart Home ModuleAI28/9/202628/9/2026
mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, including SSH, HTTP, WebSocket, and Node-RED, fully exposed on the LAN without access control. Any client on the same network can reach every service. This issue was fixed in version 3.0.30
AplazadaMedia (6.4)0.21%—Mh-developer Smart Home ModuleAI28/9/202628/9/2026
mH-DEVELOPER smart home module does not verify tokens in its authorization middleware, leaving all HTTP API and WebSocket endpoints accessible without authentication. An unauthenticated attacker on the LAN can query these endpoints, access system information, and send raw control commands to manipulate building…
AplazadaMedia (6.3)0.24%—Mh-developer Smart Home ModuleAI28/9/202628/9/2026
mH-DEVELOPER smart home module uses the same hard-coded SSH host keys on every device, with no per-device key generation. An attacker who extracts these keys from the firmware can set up a rogue SSH server that clients will trust without warning, enabling man-in-the-middle attacks and credential interception. This…
AplazadaAlta (7.7)0.18%—Mh-developer Smart Home ModuleAI28/9/202628/9/2026
mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts automatically. An attacker with the matching private key can gain a root shell on any affected device, resulting in full…
En análisisAlta (8.5)0.23%—Regularlabs Modules AnywhereAI28/9/202630/9/2026
Joomla Extension - regularlabs.com - LFI / SSRF in Modules Anywhere 1.5.0 - 9.0.5 for Joomla - Modules Anywhere Pro lets additional attributes on a module tag replace arbitrary parameters of the selected module. This feature is enabled by default in affected versions. The overrides are applied without checking who…
AplazadaMedia (6.3)0.32%—Misp ModulesAI25/9/202625/9/2026
The cisco_firesight_manager_ACL_rule_export module in misp-modules generates a shell script (.sh) that authenticates to and calls the Cisco fireSIGHT Manager API. The module interpolates configuration values (IP address, login, password, domain ID, policy ID) and MISP attribute values (destination IPs, URLs, event…
Pendiente de análisisAlta (7.3)0.22%—Environment-modulesAI15/9/202621/9/2026
A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the victim's `MODULEPATH`. When the victim uses Bash completion for `module` or `ml` commands, the malicious module name, containing shell metacharacters, is…
AplazadaMedia (6.9)0.37%—Regularlabs Advanced Module ManagerAIRegularlabs Conditional ContentAIRegularlabs Content TemplaterAIRegularlabs RereplacerAI+114/9/202616/9/2026
Joomla Extension - regularlabs.com - Database data disclosure in Advanced Module Manager (Free, Pro) < 12.1.0, Conditional Content (Free, Pro) < 8.0.0, Content Templater (Pro) < 14.2.0, ReReplacer (Pro) < 16.2.0 for Joomla - The Conditions editor creates a default Condition Set name from the item to which the set is…
AplazadaMedia (5.1)0.30%—Qlomodules QloappAI12/9/202623/9/2026
QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to submit crafted POST requests with malicious payloads to list controllers, executing arbitrary JavaScript in the victim's…
Pendiente de análisisMedia (4)0.45%—Safenet Luna Hardware Security ModuleAIPaloaltonetworks Pan-osAI10/9/202611/9/2026
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI and the device must be configured with a Luna Hardware…
AplazadaAlta (8.8)2.9%—Newfold WP Module DataAINewfold WP Plugin Crazy DomainsAINewfold WP Plugin WEBAINewfold WP Plugin HostgatorAI+19/9/20269/9/2026
Several Newfold plugins are vulnerable to Authentication Bypass. The vulnerability exists because the plugins bundle the wp-module-data module. In the module, the `authenticate()` method — registered on the `rest_authentication_errors` filter and therefore evaluated for every unauthenticated REST API request —…
AplazadaAlta (7.5)0.30%—Paytr Virtual POS Iframe APIAIPaytr Whmcs ModuleAI8/9/20261/10/2026
Observable timing discrepancy vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API WHMCS Module allows Black Box Reverse Engineering. This issue affects PayTR Virtual Pos iFrame API WHMCS Module: from v9.0.0 before v9.0.3.
Pendiente de análisisAlta (7)0.13%—Redundancy Module Configuration ToolAI1/9/20261/9/2026
A security issue exists within the Redundancy Module Configuration Tool. The RMConfigTool.exe binary searches directories in the system path for a required DLL, and one or more of these directories may be writable by standard (non-administrator) users due to incorrect default permissions. If a local attacker places a…
Pendiente de análisisAlta (7)0.13%—Redundancy Module RM3 Config ToolAI1/9/20261/9/2026
A security issue exists within the Redundancy Module Configuration Tool. The RM3ConfigTool.exe binary searches directories in the system path for a required DLL, and one or more of these directories may be writable by standard (non-administrator) users due to incorrect default permissions. If a local attacker places a…
AplazadaMedia (5.3)0.38%—Nasa CFSAINasa SBN TCP ModuleAI30/8/20261/9/2026
A vulnerability was identified in NASA cFS up to 7.0.1. Impacted is the function OS_read of the file modules/protocol/tcp/fsw/src/sbn_tcp_if.c of the component SBN TCP Module. Such manipulation of the argument MsgSz leads to buffer overflow. The attack must be carried out from within the local network. The vendor was…
AnalizadaAlta (7)0.15%—Intel TDX Module11/8/202631/8/2026
Improper authentication in the Intel(R) TDX module for some Intel(R) platforms within Ring 0: Trust Domain may allow an information disclosure and escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may…
AnalizadaMedia (6.8)0.10%—Intel TDX Module11/8/202631/8/2026
Uncaught exception for some Intel(R) TDX modules within Ring 0: Trust Domain may allow a denial of service. System software adversary with a privileged user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are present…
AnalizadaMedia (6.8)0.10%—Intel TDX Module11/8/202631/8/2026
Insecure storage of sensitive information in the Intel(R) TDX module for some Intel(R) platform within Ring 0: Trust Domain may allow information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local…
AplazadaMedia (6.9)0.12%—CSL 1010 M2M 3G Wifi ModuleAI30/7/202631/7/2026
CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak encryption vulnerability that allows unauthenticated attackers to recover all stored secrets in plaintext by reversing a single-byte XOR cipher that uses a static key to obfuscate the configuration backup file. Attackers can trivially decrypt the…
AplazadaAlta (7.1)0.19%—Mitsubishielectric Melsec MX Controller Mx-rAIMitsubishielectric Melsec MX Controller Mx-fAIMitsubishielectric Cc-link IE TSN Interface BoardAIMitsubishielectric Motion ModuleAI+2530/7/202618/9/2026
Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, MELSEC iQ-L Series Motion Module, Motion Control Board,…
AplazadaAlta (8.1)0.19%—Regularlabs Modules AnywhereAI23/7/202624/7/2026
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - The editor popup could expose restricted module data to authenticated users without the required module permissions or valid request tokens.