Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
42 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6) | 0.25% | — | Teltonika-networks RutosAI | 13/8/2026 | 8/9/2026 | In Teltonika Networks RUTOS devices, a vulnerability exists in modbusgwd due to improper handling of Modbus TCP request data. A remote, unauthenticated attacker with access to the affected service could trigger a heap-based buffer overflow, resulting in a denial of service. | |
| Aplazada | Media (6.9) | 0.29% | — | Teltonika-networks RutosAITeltonika-networks TswosAI | 13/8/2026 | 8/9/2026 | In Teltonika Networks RUTOS devices running versions 7.07.1 through 7.24.1 and TSWOS devices running versions 1.03 through 1.10, a vulnerability exists whereby a lower privileged user can escalate privileges to administrative level due to unsafe calls to an execl function. | |
| Aplazada | Crítica (9.3) | 0.44% | — | Nefteprodukttekhnika BUK Ts-gAI | 13/6/2026 | 10/8/2026 | Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-287) in the system configuration module. | |
| Pendiente de análisis | Alta (8.4) | 0.62% | — | Teltonika-networks RutosAITeltonika-networks TswosAI | 5/6/2026 | 17/6/2026 | In Teltonika Networks RUTOS devices, running versions 7.22 through 7.23.2 and TSWOS devices running versions 1.09 through 1.09.1, due to unsafe calls to an eval function in rpc-profile, a vulnerability exists where a lower privileged user could perform command injection as the root user. | |
| Aplazada | Media (6.1) | 0.18% | — | Manikandan580 School Management SystemAI | 14/4/2026 | 17/6/2026 | In manikandan580 School-management-system 1.0, a reflected XSS vulnerability exists in /studentms/admin/contact-us.php via the pagedes POST parameter. | |
| Aplazada | Crítica (9.8) | 0.29% | — | Manikandan580 School-management-systemAI | 14/4/2026 | 17/6/2026 | In manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists in /studentms/admin/between-date-reprtsdetails.php through the fromdate POST parameter. | |
| Aplazada | Media (6.1) | 0.18% | — | Manikandan580 School-management-systemAI | 14/4/2026 | 17/6/2026 | In manikandan580 School-management-system 1.0, a reflected cross-site scripting (XSS) vulnerability exists in /studentms/admin/contact-us.php via the email POST parameter. | |
| Aplazada | Crítica (9.8) | 0.53% | — | Manikandan580 School Management SystemAI | 14/4/2026 | 17/6/2026 | A SQL injection vulnerability exists in the School Management System (version 1.0) by manikandan580. An unauthenticated or authenticated remote attacker can supply a crafted HTTP request to the affected endpoint to manipulate SQL query logic and extract sensitive database information. | |
| Aplazada | Alta (8.7) | 0.27% | — | KlinikaxpAIKlinikaxp InsertinoAI | 23/3/2026 | 17/6/2026 | Use of hard-coded credentials in Klinika XP and KlinikaXP Insertino allowed an unauthorized attacker access to several internal services. Critically, this included access to the FTP server that hosted the application's update packages. The attacker with these credentials could upload a malicious update file, which… | |
| Aplazada | Alta (8.1) | 0.52% | — | Thembay NikaAI | 20/2/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Nika nika allows PHP Local File Inclusion.This issue affects Nika: from n/a through <= 1.2.14. | |
| Aplazada | Alta (7.5) | 0.36% | — | Thembay NikaAI | 23/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Nika nika allows PHP Local File Inclusion.This issue affects Nika: from n/a through <= 1.2.14. | |
| Aplazada | Alta (7.1) | 0.13% | — | Nikanwp WC Reports LiteAI | 27/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in NikanWP NikanWP WooCommerce Reporting wc-reports-lite allows Stored XSS.This issue affects NikanWP WooCommerce Reporting: from n/a through <= 1.0.0. | |
| Aplazada | Alta (8.1) | 0.58% | — | Thembay NikaAI | 17/6/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Nika nika allows PHP Local File Inclusion.This issue affects Nika: from n/a through <= 1.2.8. | |
| Aplazada | Alta (7.2) | 0.45% | — | Teltonika-networks Remote Management SystemAI | 29/5/2025 | 17/6/2026 | In Teltonika Networks Remote Management System (RMS), it is possible to perform account pre-hijacking by misusing the invite functionality. If a victim has a pending invite and registers to the platform directly, they are added to the attackers company without their knowledge. The victims account and their company can… | |
| Aplazada | Media (5.9) | 0.20% | — | Teltonika-networks RutosAITeltonika-networks TswosAI | 10/12/2024 | 17/6/2026 | In Teltonika Networks RUTOS devices, running on versions 7.0 to 7.8 (excluding) and TSWOS devices running on versions 1.0 to 1.3 (excluding), due to incorrect permission handling a vulnerability exists which allows a lower privileged user with default permissions to access critical device resources via the API. | |
| Analizada | Alta (8.3) | 0.33% | — | Teltonika Trb140 FirmwareTeltonika Trb141 FirmwareTeltonika Trb142 FirmwareTeltonika Trb143 Firmware+1 | 17/2/2024 | 17/6/2026 | Teltonika TRB1-series devices with firmware before TRB1_R_00.07.05.2 allow attackers to exploit a firmware vulnerability via Ethernet LAN or USB. | |
| Analizada | Alta (7) | 0.20% | — | Teltonika-networks Rut240 Firmware | 17/2/2024 | 17/6/2026 | Teltonika RUT240 devices with firmware before 07.04.2, when bridge mode is used, sometimes make SSH and HTTP services available on the IPv6 WAN interface even though the UI shows that they are only available on the LAN interface. | |
| Modificada | Alta (8.8) | 1.5% | — | Teltonika-networks Rut200 FirmwareTeltonika-networks Rut240 FirmwareTeltonika-networks Rut241 FirmwareTeltonika-networks Rut300 Firmware+14 | 22/5/2023 | 17/6/2026 | Versions 00.07.00 through 00.07.03 of Teltonika’s RUT router firmware contain an operating system (OS) command injection vulnerability in a Lua service. An attacker could exploit a parameter in the vulnerable function that calls a user-provided package name by instead providing a package with a malicious name that… | |
| Modificada | Alta (8.8) | 1.1% | — | Teltonika-networks Rut200 FirmwareTeltonika-networks Rut240 FirmwareTeltonika-networks Rut241 FirmwareTeltonika-networks Rut300 Firmware+14 | 22/5/2023 | 17/6/2026 | Version 00.07.03.4 and prior of Teltonika’s RUT router firmware contain a packet dump utility that contains proper validation for filter parameters. However, variables for validation checks are stored in an external configuration file. An authenticated attacker could use an exposed UCI configuration utility to change… | |
| Modificada | Media (5.8) | 0.53% | — | Teltonika Remote Management System | 22/5/2023 | 17/6/2026 | Teltonika’s Remote Management System versions prior to 4.10.0 contain a virtual private network (VPN) hub feature for cross-device communication that uses OpenVPN. It connects new devices in a manner that allows the new device to communicate with all Teltonika devices connected to the VPN. The OpenVPN server also… | |
| Modificada | Alta (8.8) | 1.1% | — | Teltonika Remote Management System | 22/5/2023 | 17/6/2026 | Teltonika’s Remote Management System versions prior to 4.10.0 have a feature allowing users to access managed devices’ local secure shell (SSH)/web management services over the cloud proxy. A user can request a web proxy and obtain a URL in the Remote Management System cloud subdomain. This URL could be shared with… | |
| Modificada | Alta (8.3) | 0.92% | — | Teltonika Remote Management System | 22/5/2023 | 17/6/2026 | Teltonika’s Remote Management System versions prior to 4.10.0 contain a cross-site scripting (XSS) vulnerability in the main page of the web interface. An attacker with the MAC address and serial number of a connected device could send a maliciously crafted JSON file with an HTML object to trigger the vulnerability.… | |
| Modificada | Crítica (9.8) | 1.0% | — | Teltonika Remote Management System | 22/5/2023 | 17/6/2026 | Teltonika’s Remote Management System versions 4.14.0 is vulnerable to an unauthorized attacker registering previously unregistered devices through the RMS platform. If the user has not disabled the "RMS management feature" enabled by default, then an attacker could register that device to themselves. This could enable… | |
| Modificada | Crítica (9.8) | 0.66% | — | Teltonika Remote Management System | 22/5/2023 | 17/6/2026 | Teltonika’s Remote Management System versions prior to 4.10.0 use device serial numbers and MAC addresses to identify devices from the user perspective for device claiming and from the device perspective for authentication. If an attacker obtained the serial number and MAC address of a device, they could authenticate… | |
| Modificada | Media (5.3) | 0.54% | — | Teltonika Remote Management System | 22/5/2023 | 17/6/2026 | Teltonika’s Remote Management System versions prior to 4.10.0 contain a function that allows users to claim their devices. This function returns information based on whether the serial number of a device has already been claimed, the MAC address of a device has already been claimed, or whether the attempt to claim a… |