Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2553▼ 349 respecto a la semana anterior
Críticas / altas1314▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)76▼ 451 respecto a la semana anterior
–

883 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaAlta (7.2)0.26%—Strong TestimonialsAI3/10/20263/10/2026
The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'platform_user_photo' Custom Field in all versions up to, and including, 3.3.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
AplazadaMedia (6.5)0.20%—Avez Electronics Learning Management SystemAI2/10/20262/10/2026
Missing Authorization vulnerability in AVEZ Electronics Communication Training and Consultancy Trade Inc. Learning Management System (LMS) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Learning Management System (LMS): through 2026-09-18.
Pendiente de análisisMedia (5.3)0.10%—Itron Mv-90 XIAI30/9/20261/10/2026
Improperly stored passwords in the config file in Itron MV-90 xi 3.0 allows attackers to decode the passwords and password histories to gain access to the MV-90 application as any user.
AplazadaMedia (6.5)0.15%—Strong TestimonialsAI30/9/20262/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Strong Testimonials strong-testimonials allows Stored XSS.This issue affects Strong Testimonials: from n/a through 3.3.11.
AplazadaMedia (5.3)0.26%—Argotronic ArgusmonitorAI29/9/202630/9/2026
Improper Access Control in ArgusMonitor.sys in Argotronic eGbR ArgusMonitor 7.4.02 and earlier allows local, low-privileged users to bypass device handle access restrictions via a TOCTOU condition in IRP_MJ_CREATE and send a crafted IOCTL 0x9C4024A8 request, causing denial-of-service.
En análisisAlta (7.8)0.09%—ElectronAI29/9/20262/10/2026
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.3 until 42.10.0, 43.5.0, and 44.0.0-beta.6, Electron's sandboxed preload code cache did not verify that a cached entry matched the preload it was served for. A compromised renderer could write…
En análisisAlta (8.3)0.45%—ElectronAI29/9/202630/9/2026
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, an Electron <webview> guest could enable nodeIntegrationInWorker for its Web Workers even when the unsandboxed embedder had Node.js integration disabled, allowing…
En análisisAlta (7.4)0.21%—ElectronAI29/9/202630/9/2026
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, responses served through protocol.registerFileProtocol or protocol.registerHttpProtocol for a custom scheme registered with supportFetchAPI enabled but…
En análisisAlta (8.2)0.27%—ElectronAI29/9/202630/9/2026
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, windows opened from a sandboxed top-level document did not inherit that document's active HTML sandbox restrictions. Untrusted content in a sandboxed top-level…
En análisisAlta (8.2)0.15%—ElectronAI29/9/202630/9/2026
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.0, popups opened from a sandboxed iframe through Electron's OpenURLFromTab navigation path, including links using target="_blank" or a middle-click, did not receive the inherited…
AplazadaMedia (5.3)0.30%—Iflytek Astron-agentAI23/9/202623/9/2026
A security vulnerability has been detected in iFlytek astron-agent up to 1.0.6. Affected by this vulnerability is the function UrlCheckTool.checkUrl of the component debugToolV2 API endpoint. The manipulation of the argument endPoint leads to server-side request forgery. The attack can be initiated remotely. Upgrading…
AplazadaMedia (5.3)0.23%—Iflytek Astron-agentAI23/9/202625/9/2026
A weakness has been identified in iFlytek astron-agent up to 1.0.7. Affected is an unknown function of the file console/backend/commons/src/main/resources/mapper/ChatBotMarketMapper.xml of the component getBotList API endpoint. Executing a manipulation of the argument sortDirection can lead to sql injection. It is…
Pendiente de análisisCrítica (9.4)0.70%—Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+222/9/202624/9/2026
Lantronix SLC8000 before firmware v9.7.0.5, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a path traversal vulnerability in the web management portal upload endpoint that allows authenticated attackers to write arbitrary data to…
Pendiente de análisisCrítica (10)1.0%—Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+222/9/202624/9/2026
Lantronix SLC8000 before firmware v9.7.0.5, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain an authentication bypass vulnerability in the web management portal upload endpoint that allows unauthenticated attackers to read sensitive…
Pendiente de análisisAlta (8.9)0.63%—Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+222/9/202624/9/2026
All firmware versions of Lantronix SLC8000, SLC9000, EMG8500, EMG7500, SLB882, SLCx-03, and SLCx-02 contain an authentication bypass vulnerability in the web management portal that allows unauthenticated attackers to derive valid session tokens of logged-in users and bypass source IP and User-Agent validation. Session…
Pendiente de análisisCrítica (9.4)1.7%—Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+222/9/202626/9/2026
Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with the services permission to execute arbitrary shell commands as…
Pendiente de análisisCrítica (9.4)1.7%—Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+222/9/202626/9/2026
Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with the services permission to execute arbitrary shell commands as…
Pendiente de análisisAlta (7.7)0.58%—Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI22/9/202626/9/2026
Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet listener that allows unauthenticated attackers to cause the affected device to…
Pendiente de análisisAlta (7.7)0.58%—Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI22/9/202626/9/2026
Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet listener that allows unauthenticated attackers to cause the affected device to…
Pendiente de análisisAlta (7.7)0.58%—Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI22/9/202626/9/2026
Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet listener that allows unauthenticated attackers to cause the affected device to…
Pendiente de análisisCrítica (9.4)0.46%—Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+222/9/202624/9/2026
Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a stack-based buffer overflow vulnerability that allows authenticated attackers to potentially execute arbitrary code by exploiting an undocumented mfc eeprom write…
Pendiente de análisisCrítica (9.4)0.85%—Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+222/9/202625/9/2026
Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a stack-based buffer overflow vulnerability that allows authenticated attackers to potentially execute arbitrary code by exploiting an undocumented mfc eeprom read…
Pendiente de análisisCrítica (9.4)1.7%—Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+222/9/202624/9/2026
Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with the services permission to execute arbitrary shell commands as root by exploiting the set…
Pendiente de análisisCrítica (9.4)1.5%—Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+222/9/202624/9/2026
Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers to execute arbitrary shell commands as root by exploiting an undocumented mfc eeprom write…
Pendiente de análisisCrítica (9.4)1.5%—Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+222/9/202624/9/2026
Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers to execute arbitrary shell commands as root by exploiting an undocumented mfc eeprom read…