Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2667▼ 241 respecto a la semana anterior
Críticas / altas1361▲ 103 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.8) | 0.42% | — | Digi Portserver TSAIDigi ONE SPAIDigi ONE SP IAAIDigi ONE IAAI | 7/7/2026 | 13/7/2026 | A stored cross-site scripting (XSS) vulnerability in the web management interface of the Digi PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA allows a remote, authenticated administrator to inject script into certain system configuration fields. The script subsequently executes in the browser of a user who… | |
| Aplazada | Alta (8.6) | 0.42% | — | MoneyspaceAI | 7/1/2026 | 17/6/2026 | The MoneySpace plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.13.9. This is due to the plugin storing full payment card details (PAN, card holder name, expiry month/year, and CVV) in WordPress post_meta using base64_encode(), and then embedding these values… | |
| Aplazada | Crítica (9.4) | 0.31% | — | Digi Portserver TSAIDigi ONE SPAIDigi ONE SP IAAIDigi ONE IAAI+1 | 12/5/2025 | 17/6/2026 | Improper authentication handling was identified in a set of HTTP POST requests affecting the following product families: A specially crafted POST request to the device’s web interface may allow an unauthenticated attacker to modify configuration settings. | |
| Modificada | Alta (8.1) | 0.68% | — | Digi RealportDigi Connectport TS 8/16 FirmwareDigi Passport FirmwareDigi Connectport LTS 8/16/32 Firmware+16 | 31/8/2023 | 17/6/2026 | Digi RealPort Protocol is vulnerable to a replay attack that may allow an attacker to bypass authentication to access connected equipment. | |
| Modificada | Media (5.4) | 0.27% | — | Sparkpay Capital ONE Spark | 11/9/2014 | 17/6/2026 | The Capital One Spark Pay (aka com.capitalone.sparkpay) application 0.9.81 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |