Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2699▼ 550 respecto a la semana anterior
Críticas / altas1265▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 242 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.37% | — | Comelit Multi User GatewayAI | 1/10/2026 | 5/10/2026 | Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 expose a network-accessible management interface that does not require authentication. Through this interface, sensitive device configuration data - including the Remote Configuration Password - can be read in cleartext by a… | |
| Aplazada | Alta (8.8) | 0.25% | — | Comelit Multi User GatewayAI | 1/10/2026 | 5/10/2026 | Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 fail to enforce server-side authorization on an administrative password-change function. An authenticated user level can invoke this function to overwrite the installer (administrator) account password. | |
| Aplazada | Baja (2.1) | 0.35% | — | SUI Shang Information Technology Suishang Enterprise-level B2b2c Multi-user Mall SystemAI | 27/10/2025 | 17/6/2026 | A vulnerability has been found in Sui Shang Information Technology Suishang Enterprise-Level B2B2C Multi-User Mall System 1.0. Affected by this issue is some unknown functionality of the file /i/359. The manipulation of the argument keywords leads to cross site scripting. The attack is possible to be carried out… | |
| Aplazada | Baja (2.1) | 0.35% | — | SUI Shang Information Technology Suishang Enterprise-level B2b2c Multi-user Mall SystemAI | 27/10/2025 | 17/6/2026 | A flaw has been found in Sui Shang Information Technology Suishang Enterprise-Level B2B2C Multi-User Mall System 1.0. Affected by this vulnerability is an unknown functionality of the file /Point/index/activity_state/1/category_id/1001. Executing manipulation of the argument category_id can lead to cross site… | |
| Modificada | Media (5.4) | 0.99% | — | Nendeb Fudousan PluginNendeb Fudousan Plugin PRO Multi-userNendeb Fudousan Plugin PRO Single-user | 28/6/2021 | 17/6/2026 | Cross-site scripting vulnerability in Fudousan plugin ver5.7.0 and earlier, Fudousan Plugin Pro Single-User Type ver5.7.0 and earlier, and Fudousan Plugin Pro Multi-User Type ver5.7.0 and earlier allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Alta (8.8) | 0.82% | — | Multi User Project Multi User | 25/9/2020 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability in the Multi User plugin 1.8.2 for GetSimple CMS allows remote attackers to add admin (or other) users after an authenticated admin visits a third-party site or clicks on a URL. | |
| Modificada | Alta (10) | 3.8% | 💥 Exploit | Plusphp Short URL Multi-user Script | 28/5/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in plus.php in plusPHP Short URL Multi-User Script 1.6 allows remote attackers to execute arbitrary PHP code via a URL in the _pages_dir parameter. | |
| Modificada | Media (6.8) | 4.0% | 💥 Exploit | PHP Multi User Randomizer | 13/5/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in PHP Multi User Randomizer (phpMUR) 2006.09.13 allow remote attackers to inject arbitrary web script or HTML via (1) the edit_plugin parameter to configure_plugin.tpl.php, or (2) certain array parameters to web/phpinfo.php, as demonstrated by 1[] or a[]. |