Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2624▼ 224 respecto a la semana anterior
Críticas / altas1373▲ 143 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

882 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.4)——Publishpress SeriesAI2/10/20262/10/2026
Authorization Bypass Through User-Controlled Key vulnerability in PublishPress PublishPress Series organize-series allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PublishPress Series: from n/a through 3.1.3.
AplazadaAlta (7.2)0.24%—Johnsoncontrols NEO Series Mvp2AI1/10/20262/10/2026
- On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 allows Collect Data from Common Resource Locations. This issue affects Neo Series MVP2: before 3.3b63.
AplazadaMedia (5.4)0.14%—Publishpress SeriesAI17/9/202617/9/2026
Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions.
AplazadaAlta (7.6)0.38%—Publishpress SeriesAI17/9/202619/9/2026
Administrator SQL Injection in PublishPress Series <= 3.1.3 versions.
AplazadaMedia (6.5)0.22%—Publishpress SeriesAI17/9/202619/9/2026
Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions.
AnalizadaAlta (7.5)0.19%—Qualcomm Q-7790 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p FirmwareQualcomm Qamsrv1h Firmware+37217/9/202622/9/2026
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
Pendiente de análisisAlta (8.6)0.55%—Cisco Secure Firewall Adaptive Security ApplianceAICisco Secure Firewall Threat DefenseAICisco Secure Firewall 3100 SeriesAICisco Secure Firewall 4200 SeriesAI16/9/202618/9/2026
A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Secure Firewall 3100 Series and 4200 Series devices could allow an unauthenticated, remote attacker to cause a denial of service…
AplazadaMedia (4.1)0.18%—Conprosys Nano SeriesAI14/9/202616/9/2026
Plaintext storage of a password issue exists in CONPROSYS nano Series . If this vulnerability is exploited, an attacker with physical access to the product may obtain credentials.
AplazadaMedia (5.3)0.46%—Conprosys Nano SeriesAI14/9/202616/9/2026
Out-of-bounds write vulnerability exists in CONPROSYS nano Series. Receiving a specially crafted request created and sent by a remote attacker may cause a denial-of-service (DoS) condition.
AplazadaMedia (5.1)0.24%—Conprosys Nano SeriesAI14/9/202616/9/2026
Cross-site scripting vulnerability exists in CONPROSYS nano Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
AplazadaAlta (8.7)0.61%—Conprosys TM SeriesAI14/9/202616/9/2026
Unrestricted upload of file with dangerous type issue exists in CONPROSYS TM Series. If a specially crafted file is uploaded by a remote authenticated attacker, an arbitrary command may be executed on the product.
AplazadaAlta (8.7)1.9%—Conprosys TM SeriesAI14/9/202616/9/2026
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS TM Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
AplazadaMedia (5.3)0.45%—Conprosys PAC SeriesAI14/9/202616/9/2026
An exposure of information through directory listing issue exists in CONPROSYS PAC Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication.
AplazadaAlta (8.7)1.9%—Conprosys PAC SeriesAI14/9/202616/9/2026
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
AplazadaMedia (5.1)0.26%—Conprosys PAC SeriesAI14/9/202616/9/2026
Cross-site scripting vulnerability exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
AplazadaMedia (5.3)0.45%—Conprosys M2M Gateway SeriesAIConprosys M2M Controller SeriesAI14/9/202616/9/2026
An exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication.
AplazadaAlta (8.7)1.9%—Conprosys M2M Gateway SeriesAIConprosys M2M Controller SeriesAI14/9/202616/9/2026
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
AplazadaMedia (5.1)0.26%—Conprosys M2M Gateway SeriesAIConprosys M2M Controller SeriesAI14/9/202616/9/2026
Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
AplazadaMedia (4.8)0.24%—Contec Ec1000 SeriesAI14/9/202616/9/2026
Cross-site scripting vulnerability exists in Contec EC1000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
AplazadaMedia (4.8)0.24%—Contec Fx5000 SeriesAIContec Fx4000 SeriesAIContec Fx3000 SeriesAI14/9/202616/9/2026
Cross-site scripting vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
AplazadaAlta (8.7)1.9%—Contec Fx5000 SeriesAIContec Fx4000 SeriesAIContec Fx3000 SeriesAI14/9/202616/9/2026
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
Pendiente de análisisAlta (7.2)0.37%—Paloaltonetworks Pan-osAIPaloaltonetworks Vm-seriesAIPaloaltonetworks Pa-seriesAIPaloaltonetworks PanoramaAI10/9/202611/9/2026
A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root…
Pendiente de análisisAlta (7.5)0.37%—Cisco Desk Phone 9800 SeriesAICisco IP Phone 7800 SeriesAICisco IP Phone 8800 SeriesAICisco Video Phone 8875AI+12/9/20262/9/2026
A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session Initiation Protocol (SIP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is…
Pendiente de análisisMedia (5.4)0.27%—Cisco Industrial Ethernet 1000 Series SwitchesAI19/8/202620/8/2026
A vulnerability in the web-based management interface of Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input…
Pendiente de análisisMedia (5.3)0.51%—Cisco Industrial Ethernet 1000 Series SwitchesAI19/8/202620/8/2026
A vulnerability in the handling of management plane packets by Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an unauthenticated, remote attacker to&nbsp;cause the device manager, SSH, or API to become inaccessible.This vulnerability is due to insufficient protection against management plane flooding…