Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
55 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 1.2% | — | Microsoft Asp.net Core Odata | 8/9/2026 | 5/10/2026 | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. | |
| Aplazada | Crítica (9.3) | 0.39% | — | Joodatabase LiteAI | 3/9/2026 | 3/9/2026 | Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0 - The cid parameter is used in queries without validation, allowing SQLi vectors. | |
| Aplazada | Alta (8.7) | 0.31% | — | Innodata Labs PopplerAIPopplerAI | 25/8/2026 | 28/9/2026 | Denial-of-service (DoS) vulnerability in the internal JPEG2000 (JPX) decoding implementation of the Poppler fork developed by Innodata Labs. When an application processes an untrusted PDF file containing specially crafted JPXDecode images, a remote attacker can cause uncontrolled memory consumption. The flaw occurs in… | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft Asp.net Core OdataMicrosoft Odata WEB API | 14/7/2026 | 24/7/2026 | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft Asp.net Core OdataMicrosoft Odata WEB API | 14/7/2026 | 16/7/2026 | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. | |
| Aplazada | Media (6.5) | 0.16% | — | Tormorten WP MicrodataAI | 21/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tormorten WP Microdata wp-microdata allows Stored XSS.This issue affects WP Microdata: from n/a through <= 1.0. | |
| Aplazada | Media (6.9) | 0.33% | — | Iodata Wn-7d36qrAI | 17/9/2025 | 17/6/2026 | Hidden functionality issue exists in WN-7D36QR and WN-7D36QR/UE. If this vulnerability is exploited, SSH may be enabled by a remote authenticated attacker. | |
| Aplazada | Media (6.9) | 0.42% | — | Iodata Hdl-t SeriesAI | 15/5/2025 | 17/6/2026 | Missing authentication for critical function issue exists in I-O DATA network attached hard disk 'HDL-T Series' firmware Ver.1.21 and earlier. If exploited, a remote unauthenticated attacker may change the product settings. | |
| Aplazada | Crítica (9.3) | 1.7% | — | Iodata Hdl-t SeriesAI | 15/5/2025 | 17/6/2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in I-O DATA network attached hard disk 'HDL-T Series' firmware Ver.1.21 and earlier when 'Remote Link3 function' is enabled. If exploited, a remote unauthenticated attacker may execute an arbitrary OS command. | |
| Aplazada | Baja (3.1) | 0.25% | — | SAP FioriAISAP ERPAISAP OdataAI | 11/2/2025 | 17/6/2026 | Cached values belonging to the SAP OData endpoint in SAP Fiori for SAP ERP could be poisoned by modifying the Host header value in an HTTP GET request. An attacker could alter the `atom:link` values in the returned metadata redirecting them from the SAP server to a malicious link set by the attacker. Successful… | |
| Aplazada | Media (6.4) | 0.35% | — | Geodatasource Country Region DropdownAI | 14/12/2024 | 17/6/2026 | The GeoDataSource Country Region DropDown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gds-country-dropdown' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Crítica (9.8) | 2.4% | — | Iodata Wfs-sr03w FirmwareIodata Wfs-sr03k Firmware | 14/4/2023 | 17/6/2026 | WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the pro_stor_canceltrans_handler_part_19 function. | |
| Modificada | Alta (8.8) | 17% | — | Iodata Wfs-sr03w FirmwareIodata Wfs-sr03k Firmware | 14/4/2023 | 17/6/2026 | WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the sys_smb_pwdmod function. | |
| Modificada | Crítica (9.8) | 1.4% | — | Odata4j Project Odata4j | 30/3/2020 | 17/6/2026 | odata4j 0.7.0 allows ExecuteJPQLQueryCommand.java SQL injection. NOTE: this product is apparently discontinued. | |
| Modificada | Crítica (9.8) | 1.4% | — | Odata4j Project Odata4j | 30/3/2020 | 17/6/2026 | odata4j 0.7.0 allows ExecuteCountQueryCommand.java SQL injection. NOTE: this product is apparently discontinued. | |
| Modificada | Alta (7.5) | 6.4% | — | Totolink A3002ru FirmwareTotolink A702r FirmwareTotolink N302r FirmwareTotolink N300rt Firmware+14 | 27/1/2020 | 17/6/2026 | A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through… | |
| Modificada | Alta (7.5) | 8.7% | — | Totolink A3002ru FirmwareTotolink A702r FirmwareTotolink N302r FirmwareTotolink N300rt Firmware+14 | 27/1/2020 | 17/6/2026 | A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configuration, including sensitive data (usernames and passwords). This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0,… | |
| Modificada | Media (5.4) | 0.77% | — | Totemodata | 22/10/2019 | 17/6/2026 | totemodata 3.0.0_b936 has XSS via a folder name. | |
| Modificada | Crítica (9.8) | 5.3% | — | Opto22 OptodatalinkOpto22 OptoopcserverOpto22 PAC DisplayOpto22 PAC Project | 10/5/2019 | 17/6/2026 | A vulnerable file in Opto 22 PAC Project Professional versions prior to R9.4006, PAC Project Basic versions prior to R9.4006, PAC Display Basic versions prior to R9.4f, PAC Display Professional versions prior to R9.4f, OptoOPCServer versions prior to R9.4c, and OptoDataLink version R9.4d and prior versions that were… | |
| Modificada | Alta (7.8) | 2.7% | — | Opto22 OptodatalinkOpto22 OptoopcserverOpto22 PAC DisplayOpto22 PAC Project | 25/3/2019 | 17/6/2026 | A specially crafted configuration file could be used to cause a stack-based buffer overflow condition in the OPCTest.exe, which may allow remote code execution on Opto 22 PAC Project Professional versions prior to R9.4008, PAC Project Basic versions prior to R9.4008, PAC Display Basic versions prior to R9.4g, PAC… | |
| Modificada | Alta (7.5) | 27% | — | Microsoft.data.odata | 13/9/2018 | 17/6/2026 | A denial of service vulnerability exists when OData Library improperly handles web requests, aka "OData Denial of Service Vulnerability." This affects Microsoft.Data.OData. | |
| Modificada | Alta (8.8) | 1.6% | — | Iodata Ts-wrlp FirmwareIodata Ts-wrlp/e FirmwareIodata Ts-wrla Firmware | 7/9/2018 | 17/6/2026 | Multiple I-O DATA network camera products (TS-WRLP firmware Ver.1.09.04 and earlier, TS-WRLA firmware Ver.1.09.04 and earlier, TS-WRLP/E firmware Ver.1.09.04 and earlier) use hardcoded credentials which may allow an remote authenticated attacker to execute arbitrary OS commands on the device via unspecified vector. | |
| Modificada | Media (6.8) | 0.42% | — | Iodata Ts-wrlp FirmwareIodata Ts-wrlp/e FirmwareIodata Ts-wrla Firmware | 7/9/2018 | 17/6/2026 | Multiple I-O DATA network camera products (TS-WRLP firmware Ver.1.09.04 and earlier, TS-WRLA firmware Ver.1.09.04 and earlier, TS-WRLP/E firmware Ver.1.09.04 and earlier) allow an attacker on the same network segment to add malicious files on the device and execute arbitrary code. | |
| Modificada | Alta (8.8) | 0.64% | — | Iodata Ts-wrlp FirmwareIodata Ts-wrlp/e FirmwareIodata Ts-wrla Firmware | 7/9/2018 | 17/6/2026 | Multiple I-O DATA network camera products (TS-WRLP firmware Ver.1.09.04 and earlier, TS-WRLA firmware Ver.1.09.04 and earlier, TS-WRLP/E firmware Ver.1.09.04 and earlier) allow an attacker on the same network segment to bypass access restriction to add files on a specific directory that may result in executing… | |
| Modificada | Media (6.8) | 0.66% | — | Iodata Hdl-xr FirmwareIodata Hdl-xrw FirmwareIodata Hdl-xr2u FirmwareIodata Hdl-xr2uw Firmware+41 | 8/2/2018 | 17/6/2026 | Devices with IP address setting tool "MagicalFinder" provided by I-O DATA DEVICE, INC. allow authenticated attackers to execute arbitrary OS commands via unspecified vectors. |