Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
41 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.46% | — | PeppermintAI | 3/9/2026 | 9/9/2026 | Peppermint through 0.5.5 contains an authorization bypass vulnerability in the GET /api/v1/auth/user/:id/logout endpoint that allows authenticated attackers to delete sessions for any user by supplying arbitrary user IDs. Attackers can forcibly log out any user including administrators by calling the logout handler… | |
| Aplazada | Crítica (9.3) | 0.64% | — | PeppermintAI | 3/9/2026 | 9/9/2026 | Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary user IDs and access protected endpoints without credentials. | |
| Aplazada | Alta (8.8) | 0.42% | — | PeppermintAI | 11/8/2026 | 3/9/2026 | A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 allows any authenticated non-administrative user to reconfigure the platform global OIDC/SSO settings via an unprotected configuration endpoint. The endpoint performs no administrative role check before applying new OIDC issuer… | |
| Aplazada | Alta (8.1) | 0.37% | — | PeppermintAI | 11/8/2026 | 3/9/2026 | A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 exists because the Config.roles_active flag defaults to false, causing all permission checks on ticket, client, and user handlers to behave as no-ops on default installations. All authenticated users bypass ownership and… | |
| Analizada | Alta (8.4) | 0.24% | — | Dannyvankooten Pepper | 3/12/2025 | 17/6/2026 | A heap buffer overflow in compiler.c and compiler.h in Pepper language 0.1.1commit 961a5d9988c5986d563310275adad3fd181b2bb7. Malicious execution of a pepper source file(.pr) could lead to arbitrary code execution or Denial of Service. | |
| Aplazada | Alta (7.2) | 0.40% | — | Peppermint Ticket ManagementAI | 5/3/2025 | 17/6/2026 | Peppermint Ticket Management 0.4.6 is vulnerable to Incorrect Access Control. A regular registered user is able to elevate his privileges to admin and gain complete access to the system as the authorization mechanism is not validated on the server side and only on the client side. This can result, for example, in… | |
| Analizada | Alta (7.1) | 0.38% | — | Pepperl-fuchs Icdm-rx/tcp Socketserver FirmwarePepperl-fuchs Profinet FirmwarePepperl-fuchs Profinet/modbus FirmwarePepperl-fuchs Modbus Router Firmware+4 | 13/8/2024 | 17/6/2026 | An unauthenticated remote attacker may use a reflected XSS vulnerability to obtain information from a user or reboot the affected device once. | |
| Analizada | Alta (7.1) | 0.34% | — | Pepperl-fuchs Icdm-rx/tcp Socketserver FirmwarePepperl-fuchs Profinet FirmwarePepperl-fuchs Profinet/modbus FirmwarePepperl-fuchs Modbus Router Firmware+4 | 13/8/2024 | 17/6/2026 | An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once. | |
| Analizada | Media (6.1) | 0.33% | — | Pepperl-fuchs Icdm-rx/tcp Socketserver FirmwarePepperl-fuchs Profinet FirmwarePepperl-fuchs Profinet/modbus FirmwarePepperl-fuchs Modbus Router Firmware+4 | 13/8/2024 | 17/6/2026 | An unauthenticated remote attacker may use a HTML injection vulnerability with limited length to inject malicious HTML code and gain low-privileged access on the affected device. | |
| Modificada | Crítica (9.8) | 0.59% | — | Pepperl-fuchs Oit700-f113-b12-cb FirmwarePepperl-fuchs Oit500-f113-b12-cb FirmwarePepperl-fuchs Oit200-f113-b12-cb FirmwarePepperl-fuchs Oit1500-f113-b12-cb Firmware | 10/7/2024 | 17/6/2026 | An unauthenticated remote attacker can manipulate the device via Telnet, stop processes, read, delete and change data. | |
| Modificada | Alta (7.5) | 0.51% | — | Pepperl-fuchs Oit700-f113-b12-cb FirmwarePepperl-fuchs Oit500-f113-b12-cb FirmwarePepperl-fuchs Oit200-f113-b12-cb FirmwarePepperl-fuchs Oit1500-f113-b12-cb Firmware | 10/7/2024 | 17/6/2026 | An unauthenticated remote attacker can read out sensitive device information through a incorrectly configured FTP service. | |
| Modificada | Media (5.3) | 0.66% | — | Peppermint | 30/10/2023 | 17/6/2026 | Peppermint Ticket Management through 0.2.4 allows remote attackers to read arbitrary files via a /api/v1/ticket/1/file/download?filepath=../ POST request. | |
| Modificada | Alta (7.5) | 0.85% | — | Peppermint | 30/10/2023 | 17/6/2026 | Peppermint Ticket Management before 0.2.4 allows remote attackers to read arbitrary files via a /api/v1/users/file/download?filepath=./../ POST request. | |
| Modificada | Alta (8.8) | 1.5% | — | Peppermint | 18/9/2023 | 17/6/2026 | An issue in PeppermintLabs Peppermint v.0.2.4 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the hardcoded session cookie. | |
| Modificada | Alta (8.1) | 0.92% | — | Peppermint | 29/3/2023 | 17/6/2026 | An issue in the password reset function of Peppermint v0.2.4 allows attackers to access the emails and passwords of the Tickets page via a crafted request. | |
| Modificada | Crítica (9.8) | 1.0% | — | Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth FirmwarePepperl-fuchs Wha-gw-f2d2-0-as-z2-eth.eip Firmware | 31/8/2021 | 17/6/2026 | In PEPPERL+FUCHS WirelessHART-Gateway 3.0.7 to 3.0.9 the SSH and telnet services are active with hard-coded credentials. | |
| Modificada | Media (5.5) | 0.15% | — | Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth FirmwarePepperl-fuchs Wha-gw-f2d2-0-as- Z2-eth.eip Firmware | 31/8/2021 | 17/6/2026 | Any cookie-stealing vulnerabilities within the application or browser would enable an attacker to steal the user's credentials to the PEPPERL+FUCHS WirelessHART-Gateway 3.0.9. | |
| Modificada | Baja (3.3) | 0.24% | — | Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth FirmwarePepperl-fuchs Wha-gw-f2d2-0-as-z2-eth.eip Firmware | 31/8/2021 | 17/6/2026 | In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 and 3.0.9 the HttpOnly attribute is not set on a cookie. This allows the cookie's value to be read or set by client-side JavaScript. | |
| Modificada | Media (6.1) | 0.58% | — | Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth FirmwarePepperl-fuchs Wha-gw-f2d2-0-as-z2-eth.eip Firmware | 31/8/2021 | 17/6/2026 | In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 it is possible to inject arbitrary JavaScript into the application's response. | |
| Modificada | Alta (8.8) | 0.87% | — | Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth FirmwarePepperl-fuchs Wha-gw-f2d2-0-as-z2-eth.eip Firmware | 31/8/2021 | 17/6/2026 | In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 serious issue exists, if the application is not externally accessible or uses IP-based access restrictions. Attackers can use DNS Rebinding to bypass any IP or firewall based access restrictions that may be in place, by proxying through their target's browser. | |
| Modificada | Media (5.5) | 0.21% | — | Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth FirmwarePepperl-fuchs Wha-gw-f2d2-0-as-z2-eth.eip Firmware | 31/8/2021 | 17/6/2026 | In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored credentials can be captured by an attacker who gains control over the user's computer. Therefore the user must have logged in at least once. | |
| Modificada | Media (5.3) | 0.77% | — | Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth FirmwarePepperl-fuchs Wha-gw-f2d2-0-as-z2-eth.eip Firmware | 31/8/2021 | 17/6/2026 | In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 a vulnerability may allow remote attackers to rewrite links and URLs in cached pages to arbitrary strings. | |
| Modificada | Alta (7.5) | 1.2% | — | Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth FirmwarePepperl-fuchs Wha-gw-f2d2-0-as- Z2-eth.eip Firmware | 31/8/2021 | 17/6/2026 | In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.7 the filename parameter is vulnerable to unauthenticated path traversal attacks, enabling read access to arbitrary files on the server. | |
| Modificada | Alta (7.5) | 0.99% | — | Hilscher RCX RtosPepperl-fuchs Ice1-16di-g60l-v1d FirmwarePepperl-fuchs Ice1-16dio-g60l-c1-v1d FirmwarePepperl-fuchs Ice1-16dio-g60l-v1d Firmware+5 | 13/5/2021 | 17/6/2026 | In Hilscher rcX RTOS versions prios to V2.1.14.1 the actual UDP packet length is not verified against the length indicated by the packet. This may lead to a denial of service of the affected device. | |
| Modificada | Media (4.3) | 0.87% | — | Recruit-holdings HOT Pepper Gourmet | 27/4/2021 | 17/6/2026 | Improper access control vulnerability in Hot Pepper Gourmet App for Android ver.4.111.0 and earlier, and for iOS ver.4.111.0 and earlier allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App. |