Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2624▼ 224 respecto a la semana anterior
Críticas / altas1373▲ 143 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

156 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.2)0.12%—Mitsubishielectric GX Works3AIMitsubishielectric Motion Control SettingAI17/9/202618/9/2026
Incorrect Implementation of Authentication Algorithm Vulnerability in Mitsubishi Electric GX Works3 and Motion Control Setting allows a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modifying part of the executable module in memory, and thereby…
AplazadaMedia (5.3)0.50%—MotioneyeAIMotionAI15/9/202630/9/2026
motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Prior to 0.44.0, the ActionHandler.post() method in motioneye/handlers/action.py lacks the BaseHandler.auth() decorator, allowing an unauthenticated remote attacker to send…
AplazadaCrítica (9.1)0.46%—MotioneyeAIMotion Project MotionAI15/9/202630/9/2026
motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Prior to 0.44.0, motionEye accepts the client-controlled meye_username and meye_password_hash cookies as authentication material without server-side session validation. An…
AplazadaAlta (8.8)0.69%—Bloyal Loyalty AND PromotionsAI15/8/202620/8/2026
The bLoyal: Loyalty & Promotions by bLoyal plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.611.78. This is due to the AJAX actions `save_bloyal_configuration_data` and `save_bloyal_accesskeyverification_data` being registered without any capability or nonce checks,…
AplazadaAlta (7.1)0.19%—Mitsubishielectric Melsec MX Controller Mx-rAIMitsubishielectric Melsec MX Controller Mx-fAIMitsubishielectric Cc-link IE TSN Interface BoardAIMitsubishielectric Motion ModuleAI+2530/7/202618/9/2026
Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, MELSEC iQ-L Series Motion Module, Motion Control Board,…
AplazadaMedia (5.5)2.9%—MotioneyeAI24/6/202625/6/2026
motionEye (mEye) is an online interface for motion software, a video surveillance program with motion detection. Versions prior to 0.44.0 create the configuration file /etc/motioneye/motion.conf with 644 permissions (-rw-r--r--), making it readable by any local user on the system. This file contains sensitive data…
AplazadaMedia (6.5)0.42%—MotioneyeAI24/6/202625/6/2026
motionEye (mEye) is an online interface for motion software, which is a video surveillance program with motion detection. Versions prior to 0.44.0 are vulnerable to path traversal in the picture and movie API endpoints, suhc as /picture/{id}/preview/{filename}. Neither the API handlers, nor the mediafiles.py functions…
AplazadaAlta (7.7)0.62%—MotioneyeAIMotion Project MotionAI24/6/202625/6/2026
motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Versions prior to 0.44.0 contain an absolute path traversal vulnerability in multiple media file handlers that allows an attacker to read arbitrary files from the filesystem.…
AnalizadaCrítica (9.1)0.48%—Remotion15/6/202617/6/2026
remotion-dev remotion v4.0.409 was discovered to contain an arbitrary file write vulnerability.
AnalizadaCrítica (9.8)0.87%—Remotion15/6/202617/6/2026
remotion-dev remotion v4.0.409 was discovered to contain a remote code execution (RCE) vulnerability.
AplazadaMedia (6.5)0.36%—Hedef Media Promotion Interactive Media Marketing INC Related Marketing CloudAI12/6/202617/6/2026
Authentication bypass by spoofing vulnerability in Hedef Media Promotion Interactive Media Marketing Inc. Related Marketing Cloud (RMC) allows Brute Force. This issue affects Related Marketing Cloud (RMC): through 12052026.
AplazadaMedia (5.4)0.26%—Merkulove Motionger FOR ElementorAI22/1/202617/6/2026
Missing Authorization vulnerability in merkulove Motionger for Elementor motionger-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Motionger for Elementor: from n/a through <= 2.0.4.
AplazadaAlta (7.8)0.51%—Tencent MimicmotionAI23/12/202517/6/2026
Tencent MimicMotion create_pipeline Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent MimicMotion. User interaction is required to exploit this vulnerability in that the target must visit a…
ModificadaMedia (6.9)0.42%—Genymotion Scrcpy18/12/202530/9/2026
Genymobile/scrcpy versions up to and including 3.3.3, prior to commit 3e40b24, contain a buffer overflow vulnerability in the sc_device_msg_deserialize() function. A compromised device can send crafted messages that cause out-of-bounds reads, which may result in memory corruption or a denial-of-service condition. This…
AnalizadaAlta (7.3)0.11%—Samsung Motionphoto2/12/202517/6/2026
Improper access control in MPLocalService of MotionPhoto prior to version 4.1.51 allows local attackers to start privileged service.
AnalizadaAlta (7.8)0.11%—Samsung Motionphoto2/12/202517/6/2026
Improper access control in MPRemoteService of MotionPhoto prior to version 4.1.51 allows local attackers to start privileged service.
ModificadaAlta (7.2)18%—Motioneye Project Motioneye3/10/20255/7/2026
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. Unsanitized user input is written to Motion configuration files, allowing remote authenticated attackers with admin access to achieve code execution when Motion is restarted.
AplazadaMedia (6.1)0.17%—Linux Promotional PluginAI16/8/202517/6/2026
The Linux Promotional Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the 'inux-promotional-plugin.php' page. This makes it possible for unauthenticated attackers to update settings and inject…
AplazadaAlta (8.5)0.18%—Siemens Simatic S7-plcsimAISiemens Simatic Step 7AISiemens Simatic WinccAISiemens Simocode ESAI+512/8/202517/6/2026
A vulnerability has been identified in SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 V17 (All versions < V17 Update 9), SIMATIC STEP 7 V18 (All versions), SIMATIC STEP 7 V19 (All versions < V19 Update 4), SIMATIC STEP 7 V20 (All versions < V20 Update 4), SIMATIC WinCC V17 (All versions < V17 Update 9), SIMATIC…
AplazadaMedia (6.8)0.17%—Siemens Simotion Scout TIAAISiemens Simotion ScoutAISiemens Sinamics StarterAI12/8/202517/6/2026
A vulnerability has been identified in SIMOTION SCOUT TIA V5.4 (All versions), SIMOTION SCOUT TIA V5.5 (All versions), SIMOTION SCOUT TIA V5.6 (All versions < V5.6 SP1 HF7), SIMOTION SCOUT TIA V5.7 (All versions < V5.7 SP1 HF1), SIMOTION SCOUT V5.4 (All versions), SIMOTION SCOUT V5.5 (All versions), SIMOTION SCOUT…
AplazadaAlta (8.6)0.17%—Siemens Simatic PCS NEOAISiemens Simatic S7-plcsimAISiemens Simatic Step 7AISiemens Simatic WinccAI+712/8/202517/6/2026
A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions < V6.0 SP1 Update 1), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 V17 (All versions < V17 Update 9), SIMATIC STEP 7 V18 (All versions), SIMATIC STEP 7 V19 (All…
AplazadaMedia (4.1)0.25%—SAP CMC Promotion ManagementAI8/7/202517/6/2026
SAP CMC Promotion Management allows an authenticated attacker to enumerate internal network systems by submitting crafted requests during job source configuration. By analysing response times for various IP addresses and ports, the attacker can infer valid network endpoints. Successful exploitation may lead to…
AplazadaAlta (8.9)0.49%—MotioneyeAIMotion Project MotionAI14/5/202517/6/2026
motionEye is an online interface for the software motion, a video surveillance program with motion detection. In versions 0.43.1b1 through 0.43.1b3, using a constructed (camera) device path with the `add`/`add_camera` motionEye web API allows an attacker with motionEye admin user credentials to execute any command…
AplazadaAlta (7.9)0.16%—Promotion Management WizardAI13/5/202517/6/2026
Under certain conditions Promotion Management Wizard (PMW) allows an attacker to access information which would otherwise be restricted.This has High impact on Confidentiality with Low impact on Integrity and Availability of the application.
AplazadaAlta (7.1)0.29%—Commotion Course Booking SystemAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ComMotion Course Booking System course-booking-system allows Reflected XSS.This issue affects Course Booking System: from n/a through <= 6.1.2.