Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
–

55 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)1.2%—Microsoft Asp.net Core Odata8/9/20265/10/2026
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
AplazadaCrítica (9.3)0.39%—Joodatabase LiteAI3/9/20263/9/2026
Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0 - The cid parameter is used in queries without validation, allowing SQLi vectors.
AplazadaAlta (8.7)0.31%—Innodata Labs PopplerAIPopplerAI25/8/202628/9/2026
Denial-of-service (DoS) vulnerability in the internal JPEG2000 (JPX) decoding implementation of the Poppler fork developed by Innodata Labs. When an application processes an untrusted PDF file containing specially crafted JPXDecode images, a remote attacker can cause uncontrolled memory consumption. The flaw occurs in…
AnalizadaAlta (7.5)1.2%—Microsoft Asp.net Core OdataMicrosoft Odata WEB API14/7/202624/7/2026
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (7.5)1.2%—Microsoft Asp.net Core OdataMicrosoft Odata WEB API14/7/202616/7/2026
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
AplazadaMedia (6.5)0.16%—Tormorten WP MicrodataAI21/12/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tormorten WP Microdata wp-microdata allows Stored XSS.This issue affects WP Microdata: from n/a through <= 1.0.
AplazadaMedia (6.9)0.33%—Iodata Wn-7d36qrAI17/9/202517/6/2026
Hidden functionality issue exists in WN-7D36QR and WN-7D36QR/UE. If this vulnerability is exploited, SSH may be enabled by a remote authenticated attacker.
AplazadaMedia (6.9)0.42%—Iodata Hdl-t SeriesAI15/5/202517/6/2026
Missing authentication for critical function issue exists in I-O DATA network attached hard disk 'HDL-T Series' firmware Ver.1.21 and earlier. If exploited, a remote unauthenticated attacker may change the product settings.
AplazadaCrítica (9.3)1.7%—Iodata Hdl-t SeriesAI15/5/202517/6/2026
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in I-O DATA network attached hard disk 'HDL-T Series' firmware Ver.1.21 and earlier when 'Remote Link3 function' is enabled. If exploited, a remote unauthenticated attacker may execute an arbitrary OS command.
AplazadaBaja (3.1)0.25%—SAP FioriAISAP ERPAISAP OdataAI11/2/202517/6/2026
Cached values belonging to the SAP OData endpoint in SAP Fiori for SAP ERP could be poisoned by modifying the Host header value in an HTTP GET request. An attacker could alter the `atom:link` values in the returned metadata redirecting them from the SAP server to a malicious link set by the attacker. Successful…
AplazadaMedia (6.4)0.35%—Geodatasource Country Region DropdownAI14/12/202417/6/2026
The GeoDataSource Country Region DropDown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gds-country-dropdown' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
ModificadaCrítica (9.8)2.4%—Iodata Wfs-sr03w FirmwareIodata Wfs-sr03k Firmware14/4/202317/6/2026
WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the pro_stor_canceltrans_handler_part_19 function.
ModificadaAlta (8.8)17%—Iodata Wfs-sr03w FirmwareIodata Wfs-sr03k Firmware14/4/202317/6/2026
WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the sys_smb_pwdmod function.
ModificadaCrítica (9.8)1.4%—Odata4j Project Odata4j30/3/202017/6/2026
odata4j 0.7.0 allows ExecuteJPQLQueryCommand.java SQL injection. NOTE: this product is apparently discontinued.
ModificadaCrítica (9.8)1.4%—Odata4j Project Odata4j30/3/202017/6/2026
odata4j 0.7.0 allows ExecuteCountQueryCommand.java SQL injection. NOTE: this product is apparently discontinued.
ModificadaAlta (7.5)6.4%—Totolink A3002ru FirmwareTotolink A702r FirmwareTotolink N302r FirmwareTotolink N300rt Firmware+1427/1/202017/6/2026
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through…
ModificadaAlta (7.5)8.7%—Totolink A3002ru FirmwareTotolink A702r FirmwareTotolink N302r FirmwareTotolink N300rt Firmware+1427/1/202017/6/2026
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configuration, including sensitive data (usernames and passwords). This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0,…
ModificadaMedia (5.4)0.77%—Totemodata22/10/201917/6/2026
totemodata 3.0.0_b936 has XSS via a folder name.
ModificadaCrítica (9.8)5.3%—Opto22 OptodatalinkOpto22 OptoopcserverOpto22 PAC DisplayOpto22 PAC Project10/5/201917/6/2026
A vulnerable file in Opto 22 PAC Project Professional versions prior to R9.4006, PAC Project Basic versions prior to R9.4006, PAC Display Basic versions prior to R9.4f, PAC Display Professional versions prior to R9.4f, OptoOPCServer versions prior to R9.4c, and OptoDataLink version R9.4d and prior versions that were…
ModificadaAlta (7.8)2.7%—Opto22 OptodatalinkOpto22 OptoopcserverOpto22 PAC DisplayOpto22 PAC Project25/3/201917/6/2026
A specially crafted configuration file could be used to cause a stack-based buffer overflow condition in the OPCTest.exe, which may allow remote code execution on Opto 22 PAC Project Professional versions prior to R9.4008, PAC Project Basic versions prior to R9.4008, PAC Display Basic versions prior to R9.4g, PAC…
ModificadaAlta (7.5)27%—Microsoft.data.odata13/9/201817/6/2026
A denial of service vulnerability exists when OData Library improperly handles web requests, aka "OData Denial of Service Vulnerability." This affects Microsoft.Data.OData.
ModificadaAlta (8.8)1.6%—Iodata Ts-wrlp FirmwareIodata Ts-wrlp/e FirmwareIodata Ts-wrla Firmware7/9/201817/6/2026
Multiple I-O DATA network camera products (TS-WRLP firmware Ver.1.09.04 and earlier, TS-WRLA firmware Ver.1.09.04 and earlier, TS-WRLP/E firmware Ver.1.09.04 and earlier) use hardcoded credentials which may allow an remote authenticated attacker to execute arbitrary OS commands on the device via unspecified vector.
ModificadaMedia (6.8)0.42%—Iodata Ts-wrlp FirmwareIodata Ts-wrlp/e FirmwareIodata Ts-wrla Firmware7/9/201817/6/2026
Multiple I-O DATA network camera products (TS-WRLP firmware Ver.1.09.04 and earlier, TS-WRLA firmware Ver.1.09.04 and earlier, TS-WRLP/E firmware Ver.1.09.04 and earlier) allow an attacker on the same network segment to add malicious files on the device and execute arbitrary code.
ModificadaAlta (8.8)0.64%—Iodata Ts-wrlp FirmwareIodata Ts-wrlp/e FirmwareIodata Ts-wrla Firmware7/9/201817/6/2026
Multiple I-O DATA network camera products (TS-WRLP firmware Ver.1.09.04 and earlier, TS-WRLA firmware Ver.1.09.04 and earlier, TS-WRLP/E firmware Ver.1.09.04 and earlier) allow an attacker on the same network segment to bypass access restriction to add files on a specific directory that may result in executing…
ModificadaMedia (6.8)0.66%—Iodata Hdl-xr FirmwareIodata Hdl-xrw FirmwareIodata Hdl-xr2u FirmwareIodata Hdl-xr2uw Firmware+418/2/201817/6/2026
Devices with IP address setting tool "MagicalFinder" provided by I-O DATA DEVICE, INC. allow authenticated attackers to execute arbitrary OS commands via unspecified vectors.