Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2553▼ 349 respecto a la semana anterior
Críticas / altas1314▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)76▼ 451 respecto a la semana anterior
883 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.2) | 0.26% | — | Strong TestimonialsAI | 3/10/2026 | 3/10/2026 | The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'platform_user_photo' Custom Field in all versions up to, and including, 3.3.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Media (6.5) | 0.20% | — | Avez Electronics Learning Management SystemAI | 2/10/2026 | 2/10/2026 | Missing Authorization vulnerability in AVEZ Electronics Communication Training and Consultancy Trade Inc. Learning Management System (LMS) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Learning Management System (LMS): through 2026-09-18. | |
| Pendiente de análisis | Media (5.3) | 0.10% | — | Itron Mv-90 XIAI | 30/9/2026 | 1/10/2026 | Improperly stored passwords in the config file in Itron MV-90 xi 3.0 allows attackers to decode the passwords and password histories to gain access to the MV-90 application as any user. | |
| Aplazada | Media (6.5) | 0.15% | — | Strong TestimonialsAI | 30/9/2026 | 2/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Strong Testimonials strong-testimonials allows Stored XSS.This issue affects Strong Testimonials: from n/a through 3.3.11. | |
| Aplazada | Media (5.3) | 0.26% | — | Argotronic ArgusmonitorAI | 29/9/2026 | 30/9/2026 | Improper Access Control in ArgusMonitor.sys in Argotronic eGbR ArgusMonitor 7.4.02 and earlier allows local, low-privileged users to bypass device handle access restrictions via a TOCTOU condition in IRP_MJ_CREATE and send a crafted IOCTL 0x9C4024A8 request, causing denial-of-service. | |
| En análisis | Alta (7.8) | 0.09% | — | ElectronAI | 29/9/2026 | 2/10/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.3 until 42.10.0, 43.5.0, and 44.0.0-beta.6, Electron's sandboxed preload code cache did not verify that a cached entry matched the preload it was served for. A compromised renderer could write… | |
| En análisis | Alta (8.3) | 0.45% | — | ElectronAI | 29/9/2026 | 30/9/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, an Electron <webview> guest could enable nodeIntegrationInWorker for its Web Workers even when the unsandboxed embedder had Node.js integration disabled, allowing… | |
| En análisis | Alta (7.4) | 0.21% | — | ElectronAI | 29/9/2026 | 30/9/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, responses served through protocol.registerFileProtocol or protocol.registerHttpProtocol for a custom scheme registered with supportFetchAPI enabled but… | |
| En análisis | Alta (8.2) | 0.27% | — | ElectronAI | 29/9/2026 | 30/9/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, windows opened from a sandboxed top-level document did not inherit that document's active HTML sandbox restrictions. Untrusted content in a sandboxed top-level… | |
| En análisis | Alta (8.2) | 0.15% | — | ElectronAI | 29/9/2026 | 30/9/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.0, popups opened from a sandboxed iframe through Electron's OpenURLFromTab navigation path, including links using target="_blank" or a middle-click, did not receive the inherited… | |
| Aplazada | Media (5.3) | 0.30% | — | Iflytek Astron-agentAI | 23/9/2026 | 23/9/2026 | A security vulnerability has been detected in iFlytek astron-agent up to 1.0.6. Affected by this vulnerability is the function UrlCheckTool.checkUrl of the component debugToolV2 API endpoint. The manipulation of the argument endPoint leads to server-side request forgery. The attack can be initiated remotely. Upgrading… | |
| Aplazada | Media (5.3) | 0.23% | — | Iflytek Astron-agentAI | 23/9/2026 | 25/9/2026 | A weakness has been identified in iFlytek astron-agent up to 1.0.7. Affected is an unknown function of the file console/backend/commons/src/main/resources/mapper/ChatBotMarketMapper.xml of the component getBotList API endpoint. Executing a manipulation of the argument sortDirection can lead to sql injection. It is… | |
| Pendiente de análisis | Crítica (9.4) | 0.70% | — | Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+2 | 22/9/2026 | 24/9/2026 | Lantronix SLC8000 before firmware v9.7.0.5, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a path traversal vulnerability in the web management portal upload endpoint that allows authenticated attackers to write arbitrary data to… | |
| Pendiente de análisis | Crítica (10) | 1.0% | — | Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+2 | 22/9/2026 | 24/9/2026 | Lantronix SLC8000 before firmware v9.7.0.5, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain an authentication bypass vulnerability in the web management portal upload endpoint that allows unauthenticated attackers to read sensitive… | |
| Pendiente de análisis | Alta (8.9) | 0.63% | — | Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+2 | 22/9/2026 | 24/9/2026 | All firmware versions of Lantronix SLC8000, SLC9000, EMG8500, EMG7500, SLB882, SLCx-03, and SLCx-02 contain an authentication bypass vulnerability in the web management portal that allows unauthenticated attackers to derive valid session tokens of logged-in users and bypass source IP and User-Agent validation. Session… | |
| Pendiente de análisis | Crítica (9.4) | 1.7% | — | Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+2 | 22/9/2026 | 26/9/2026 | Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with the services permission to execute arbitrary shell commands as… | |
| Pendiente de análisis | Crítica (9.4) | 1.7% | — | Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+2 | 22/9/2026 | 26/9/2026 | Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with the services permission to execute arbitrary shell commands as… | |
| Pendiente de análisis | Alta (7.7) | 0.58% | — | Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI | 22/9/2026 | 26/9/2026 | Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet listener that allows unauthenticated attackers to cause the affected device to… | |
| Pendiente de análisis | Alta (7.7) | 0.58% | — | Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI | 22/9/2026 | 26/9/2026 | Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet listener that allows unauthenticated attackers to cause the affected device to… | |
| Pendiente de análisis | Alta (7.7) | 0.58% | — | Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI | 22/9/2026 | 26/9/2026 | Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet listener that allows unauthenticated attackers to cause the affected device to… | |
| Pendiente de análisis | Crítica (9.4) | 0.46% | — | Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+2 | 22/9/2026 | 24/9/2026 | Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a stack-based buffer overflow vulnerability that allows authenticated attackers to potentially execute arbitrary code by exploiting an undocumented mfc eeprom write… | |
| Pendiente de análisis | Crítica (9.4) | 0.85% | — | Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+2 | 22/9/2026 | 25/9/2026 | Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a stack-based buffer overflow vulnerability that allows authenticated attackers to potentially execute arbitrary code by exploiting an undocumented mfc eeprom read… | |
| Pendiente de análisis | Crítica (9.4) | 1.7% | — | Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+2 | 22/9/2026 | 24/9/2026 | Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with the services permission to execute arbitrary shell commands as root by exploiting the set… | |
| Pendiente de análisis | Crítica (9.4) | 1.5% | — | Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+2 | 22/9/2026 | 24/9/2026 | Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers to execute arbitrary shell commands as root by exploiting an undocumented mfc eeprom write… | |
| Pendiente de análisis | Crítica (9.4) | 1.5% | — | Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+2 | 22/9/2026 | 24/9/2026 | Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers to execute arbitrary shell commands as root by exploiting an undocumented mfc eeprom read… |