Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
81 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.9) | 0.29% | — | Moxa NportAI | 16/6/2026 | 17/6/2026 | A denial-of-service vulnerability exists in NPort devices because of improper access control on the command port. The command interface does not properly validate whether a sender is associated with a valid data port session before accepting break signal commands. A remote attacker with network access can send crafted… | |
| Pendiente de análisis | Alta (8.6) | 0.47% | — | Moxa Nport W2150a-w4AIMoxa Nport W2250a-w4AI | 16/6/2026 | 17/6/2026 | A stack-based buffer overflow vulnerability has been found in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and earlier. This vulnerability stems from insufficient input validation of user-supplied input in the "Server location" parameter on the Basic settings page. An attacker could exploit this vulnerability by… | |
| Pendiente de análisis | Media (6.9) | 0.31% | — | Moxa Nport W2150a-w4AIMoxa Nport W2250a-w4AI | 16/6/2026 | 17/6/2026 | A format string vulnerability has been found in the "alias" parameter of the Serial Param configuration page in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and prior. This vulnerability stems from insufficient input validation and improper handling of externally supplied format strings. An attacker could exploit… | |
| Analizada | Media (6.1) | 0.27% | — | Plone Isurlinportal | 5/3/2026 | 17/6/2026 | Products.isurlinportal is a replacement for isURLInPortal method in Plone. Prior to versions 2.1.0, 3.1.0, and 4.0.0, a url /login?came_from=////evil.example may redirect to an external website after login. This issue has been patched in versions 2.1.0, 3.1.0, and 4.0.0. | |
| Aplazada | Alta (7.1) | 0.41% | — | Moxa Nport 6100-g2AIMoxa Nport 6200-g2AI | 31/12/2025 | 17/6/2026 | The NPort 6100-G2/6200-G2 Series is affected by a high-severity vulnerability (CVE-2025-2026) that allows remote attackers to execute a null byte injection through the device’s web API. This may lead to an unexpected device reboot and result in a denial-of-service (DoS) condition. An authenticated remote attacker with… | |
| Aplazada | Alta (7.7) | 0.35% | — | Moxa Nport 6100-g2AIMoxa Nport 6200-g2AI | 31/12/2025 | 17/6/2026 | The NPort 6100-G2/6200-G2 Series is affected by an execution with unnecessary privileges vulnerability (CVE-2025-1977) that allows an authenticated user with read-only access to perform unauthorized configuration changes through the MCC (Moxa CLI Configuration) tool. The issue can be exploited remotely over the… | |
| Aplazada | Alta (8.1) | 0.60% | — | DavenportAI | 27/6/2025 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in Creanncy Davenport - Versatile Blog and Magazine WordPress Theme davenport allows PHP Local File Inclusion.This issue affects Davenport - Versatile Blog and Magazine WordPress Theme: from n/a through <= 1.3. | |
| Modificada | Media (5.4) | 0.38% | — | Averta Auxinportfolio | 29/8/2024 | 17/6/2026 | The Premium Portfolio Features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'aux_recent_portfolios_grid' shortcode in all versions up to, and including, 2.3.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Modificada | Media (5.4) | 0.38% | — | Averta Auxinportfolio | 16/7/2024 | 17/6/2026 | The Premium Portfolio Features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Grid Portfolios Widget in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Alta (8.3) | 0.38% | — | Moxa Nport 5100a FirmwareAI | 6/5/2024 | 17/6/2026 | The NPort 5100A Series firmware version v1.6 and prior versions are affected by web server XSS vulnerability. The vulnerability is caused by not correctly neutralizing user-controllable input before placing it in output. Malicious users may use the vulnerability to get sensitive information and escalate privileges. | |
| Analizada | Alta (7.5) | 0.66% | — | Moxa Nport W2150a FirmwareMoxa Nport W2250a FirmwareMoxa Nport W2150a-t FirmwareMoxa Nport W2250a-t Firmware | 6/3/2024 | 17/6/2026 | A stack-based buffer overflow in the built-in web server in Moxa NPort W2150A/W2250A Series firmware version 2.3 and prior allows a remote attacker to exploit the vulnerability by sending crafted payload to the web service. Successful exploitation of the vulnerability could result in denial of service. | |
| Modificada | Crítica (9.8) | 0.71% | — | Cisco Ironport Email Security ApplianceCisco Secure Email Gateway Firmware | 10/1/2024 | 17/6/2026 | Hyland Perceptive Filters releases before 2023-12-08 (e.g., 11.4.0.2647), as used in Cisco IronPort Email Security Appliance Software, Cisco Secure Email Gateway, and various non-Cisco products, allow attackers to trigger a segmentation fault and execute arbitrary code via a crafted document. | |
| Modificada | Alta (7.5) | 0.31% | — | Moxa Nport 6150-t FirmwareMoxa Nport 6150 FirmwareMoxa Nport 6250-m-sc-t FirmwareMoxa Nport 6250-m-sc Firmware+23 | 1/11/2023 | 17/6/2026 | A vulnerability has been identified in NPort 6000 Series, making the authentication mechanism vulnerable. This vulnerability arises from the incorrect implementation of sensitive information protection, potentially allowing malicious users to gain unauthorized access to the web service. | |
| Modificada | Alta (8.8) | 0.31% | — | Moxa Nport 5150ai-m12-ct-t FirmwareMoxa Nport 5250ai-m12-ct-t FirmwareMoxa Nport 5150ai-m12-t FirmwareMoxa Nport 5250ai-m12-t Firmware+104 | 3/10/2023 | 17/6/2026 | All firmware versions of the NPort 5000 Series are affected by an improper validation of integrity check vulnerability. This vulnerability results from insufficient checks on firmware updates or upgrades, potentially allowing malicious users to manipulate the firmware and gain control of devices. | |
| Modificada | Crítica (9.8) | 0.39% | — | Moxa Nport Iaw5000a-i/o Firmware | 16/8/2023 | 17/6/2026 | NPort IAW5000A-I/O Series firmware version v2.2 and prior is affected by a hardcoded credential vulnerabilitywhich poses a potential risk to the security and integrity of the affected device. This vulnerability is attributed to the presence of a hardcoded key, which could potentially facilitate firmware manipulation. | |
| Modificada | Alta (8.2) | 0.69% | — | Moxa Nport 5110 Firmware | 31/8/2022 | 17/6/2026 | MOXA NPort 5110: Firmware Versions 2.10 is vulnerable to an out-of-bounds write that may allow an attacker to overwrite values in memory, causing a denial-of-service condition or potentially bricking the device. | |
| Modificada | Alta (7.5) | 0.81% | — | Moxa Nport 5110 Firmware | 31/8/2022 | 17/6/2026 | MOXA NPort 5110: Firmware Versions 2.10 is vulnerable to an out-of-bounds write that can cause the device to become unresponsive. | |
| Modificada | Crítica (9.8) | 2.8% | — | Moxa Nport Iaw5150a-6i/o FirmwareMoxa Nport Iaw5150a-12i/o FirmwareMoxa Nport Iaw5250a-6i/o FirmwareMoxa Nport Iaw5250a-12i/o Firmware | 1/4/2022 | 17/6/2026 | Five buffer overflows in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier may allow a remote attacker to initiate a denial-of-service attack and execute arbitrary code. | |
| Modificada | Crítica (9.8) | 2.7% | — | Moxa Nport Iaw5150a-6i/o FirmwareMoxa Nport Iaw5150a-12i/o FirmwareMoxa Nport Iaw5250a-6i/o FirmwareMoxa Nport Iaw5250a-12i/o Firmware | 1/4/2022 | 17/6/2026 | Improper input validation in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier may allow a remote attacker to execute commands. | |
| Modificada | Alta (7.5) | 1.7% | — | Moxa Nport Iaw5150a-6i/o FirmwareMoxa Nport Iaw5150a-12i/o FirmwareMoxa Nport Iaw5250a-6i/o FirmwareMoxa Nport Iaw5250a-12i/o Firmware | 1/4/2022 | 17/6/2026 | Data can be copied without validation in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier, which may allow a remote attacker to cause denial-of-service conditions. | |
| Modificada | Alta (7.5) | 1.7% | — | Moxa Nport Iaw5150a-6i/o FirmwareMoxa Nport Iaw5150a-12i/o FirmwareMoxa Nport Iaw5250a-6i/o FirmwareMoxa Nport Iaw5250a-12i/o Firmware | 1/4/2022 | 17/6/2026 | Two buffer overflows in the built-in web server in Moxa NPort IAW5000A-I/O Series firmware version 2.2 or earlier may allow a remote attacker to cause a denial-of-service condition. | |
| Modificada | Alta (8.6) | 1.7% | — | Cisco Ironport WEB Security ApplianceCisco Secure Firewall Management CenterCisco Firepower Management Center Virtual Appliance Firmware | 18/8/2021 | 17/6/2026 | A vulnerability in Server Name Identification (SNI) request filtering of Cisco Web Security Appliance (WSA), Cisco Firepower Threat Defense (FTD), and the Snort detection engine could allow an unauthenticated, remote attacker to bypass filtering technology on an affected device and exfiltrate data from a compromised… | |
| Modificada | Media (6.1) | 1.0% | — | Plone Isurlinportal | 2/8/2021 | 17/6/2026 | Products.isurlinportal is a replacement for isURLInPortal method in Plone. Versions of Products.isurlinportal prior to 1.2.0 have an Open Redirect vulnerability. Various parts of Plone use the 'is url in portal' check for security, mostly to see if it is safe to redirect to a url. A url like `https://example.org` is… | |
| Modificada | Alta (7.5) | 0.73% | — | Moxa Nport Ia5150a FirmwareMoxa Nport Ia5250a FirmwareMoxa Nport Ia5450a Firmware | 14/5/2021 | 17/6/2026 | Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices. Successfully exploiting the vulnerability could enable attackers to read authentication data, device configuration, and other sensitive data transmitted over Moxa Service. | |
| Modificada | Media (5.9) | 0.32% | — | Moxa Nport Ia5150a FirmwareMoxa Nport Ia5250a FirmwareMoxa Nport Ia5450a Firmware | 14/5/2021 | 17/6/2026 | The NPort IA5000A Series devices use Telnet as one of the network device management services. Telnet does not support the encryption of client-server communications, making it vulnerable to Man-in-the-Middle attacks. |