Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2721▲ 17 respecto a la semana anterior
Críticas / altas1459▲ 351 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)72▼ 458 respecto a la semana anterior
61 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 1.3% | — | Voltronicpower Snmp WEB PROAI | 4/9/2026 | 10/9/2026 | Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archive without valid credentials. Attackers can supply a malicious tar archive… | |
| Aplazada | Alta (8.6) | 0.30% | — | VoltagentAI | 28/8/2026 | 23/9/2026 | VoltAgent through 2.1.20 fails to validate conversation ownership in memory API handlers, allowing authenticated users to access other users' conversations. Attackers can read, modify, and delete arbitrary conversations and messages by supplying caller-controlled identifiers to memory endpoints. | |
| Aplazada | Alta (7.1) | 0.26% | — | Telefunken Te24553b45v2dzAIVestel Mb181AIVestel Voltron181AITivo OSAI | 7/8/2026 | 28/8/2026 | An improper restriction of URL schemes and destinations in the SmartCenter browserseturl command in the Telefunken TE24553B45V2DZ Smart TV running on the Vestel MB181 / Voltron181 / TiVo OS platform allows an attacker with access to the same local network to cause the embedded browser to issue requests to unintended… | |
| Aplazada | Baja (1.3) | 0.34% | — | VoltagentAI | 28/6/2026 | 29/6/2026 | A vulnerability was determined in VoltAgent up to 2.1.17. Affected by this issue is the function handleGetMemoryConversation of the file packages/server-core/src/handlers/memory.handlers.ts of the component Memory REST API. Executing a manipulation of the argument conversationId can lead to improper authorization. The… | |
| Aplazada | Alta (8.7) | 0.44% | — | Plone VoltoAIFacebook ReactAI | 2/10/2025 | 17/6/2026 | Volto is a ReactJS-based frontend for the Plone Content Management System. Versions 16.34.0 and below, 17.0.0 through 17.22.1, 18.0.0 through 18.27.1, and 19.0.0-alpha.1 through 19.0.0-alpha.5, an anonymous user could cause the NodeJS server part of Volto to quit with an error when visiting a specific URL. This issue… | |
| Aplazada | Alta (7.5) | 0.61% | — | Plone VoltoAINodejsAI | 28/8/2025 | 25/9/2026 | Volto is a React based frontend for the Plone Content Management System. In versions from 19.0.0-alpha.1 to before 19.0.0-alpha.4, 18.0.0 to before 18.24.0, 17.0.0 to before 17.22.1, and prior to 16.34.0, an anonymous user could cause the NodeJS server part of Volto to quit with an error when visiting a specific URL.… | |
| Aplazada | Crítica (9.8) | 0.66% | — | Voltronicpower ViewpowerAIVoltronicpower Powershield NetguardAI | 22/8/2025 | 17/6/2026 | Voltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292 allows a remote attacker to configure the system via an unspecified web interface. An unauthenticated remote attacker can make changes to the system including: changing the web interface admin password, view/change system… | |
| Aplazada | Crítica (10) | 0.80% | — | Voltronicpower ViewpowerAIVoltronicpower Viewpower PROAIVoltronicpower Powershield NetguardAI | 22/8/2025 | 17/6/2026 | Voltronic Power ViewPower through 1.04-24215, ViewPower Pro through 2.0-22165, and PowerShield Netguard before 1.04-23292 allows a remote attacker to run arbitrary code via an unspecified web interface related to detection of a managed UPS shutting down. An unauthenticated attacker can use this to run arbitrary code… | |
| Aplazada | Media (6.4) | 0.30% | — | Voltax Video PlayerAI | 24/7/2025 | 17/6/2026 | The Voltax Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Crítica (9.3) | 0.62% | — | Livewire VoltAI | 5/3/2025 | 17/6/2026 | Volt is an elegantly crafted functional API for Livewire. Malicious, user-crafted request payloads could potentially lead to remote code execution within Volt components. This vulnerability is fixed in 1.7.0. | |
| Aplazada | Media (4.3) | 0.18% | — | Volthemes Patricia BlogAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in VolThemes Patricia Blog allows Cross Site Request Forgery.This issue affects Patricia Blog: from n/a through 1.2. | |
| Aplazada | Media (4.3) | 0.18% | — | Volthemes Patricia LiteAI | 12/7/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in VolThemes Patricia Lite.This issue affects Patricia Lite: from n/a through 1.2.3. | |
| Analizada | Crítica (9.8) | 48% | — | Voltronicpower Viewpower | 3/5/2024 | 17/6/2026 | Voltronic Power ViewPower Pro selectDeviceListBy SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Voltronic Power ViewPower Pro. Authentication is not required to exploit this vulnerability. The specific flaw exists… | |
| Analizada | Crítica (9.8) | 1.6% | — | Voltronicpower Viewpower | 3/5/2024 | 17/6/2026 | Voltronic Power ViewPower Pro Expression Language Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Voltronic Power ViewPower Pro. Authentication is not required to exploit this vulnerability. The specific flaw exists within… | |
| Analizada | Alta (7.5) | 1.1% | — | Voltronicpower Viewpower | 3/5/2024 | 17/6/2026 | Voltronic Power ViewPower Pro doDocument XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Voltronic Power ViewPower Pro. Authentication is not required to exploit this vulnerability. The… | |
| Analizada | Crítica (9.8) | 1.5% | — | Voltronicpower Viewpower | 3/5/2024 | 17/6/2026 | Voltronic Power ViewPower Pro UpLoadAction Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Voltronic Power ViewPower Pro. Authentication is not required to exploit this vulnerability. The specific flaw… | |
| Analizada | Alta (7.8) | 0.23% | — | Voltronicpower Viewpower | 3/5/2024 | 17/6/2026 | Voltronic Power ViewPower Pro MySQL Use of Hard-coded Credentials Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Voltronic Power ViewPower Pro. An attacker must first obtain the ability to execute low-privileged code on the target… | |
| Analizada | Alta (7.5) | 36% | — | Voltronicpower Viewpower | 3/5/2024 | 17/6/2026 | Voltronic Power ViewPower getModbusPassword Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Voltronic Power ViewPower. Authentication is not required to exploit this vulnerability. The specific flaw… | |
| Analizada | Crítica (9.8) | 1.3% | — | Voltronicpower Viewpower | 3/5/2024 | 17/6/2026 | Voltronic Power ViewPower Pro selectEventConfig SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Voltronic Power ViewPower Pro. Authentication is not required to exploit this vulnerability. The specific flaw exists… | |
| Analizada | Alta (8.8) | 1.4% | — | Voltronicpower Viewpower | 3/5/2024 | 17/6/2026 | Voltronic Power ViewPower USBCommEx shutdown Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Voltronic Power ViewPower Pro. User interaction is required to exploit this vulnerability in that an administrator must… | |
| Analizada | Alta (8.8) | 1.1% | — | Voltronicpower Viewpower | 3/5/2024 | 17/6/2026 | Voltronic Power ViewPower USBCommEx shutdown Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Voltronic Power ViewPower Pro. User interaction is required to exploit this vulnerability in that an administrator… | |
| Analizada | Crítica (9.8) | 1.5% | — | Voltronicpower Viewpower | 3/5/2024 | 17/6/2026 | Voltronic Power ViewPower UpsScheduler Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Voltronic Power ViewPower. Authentication is not required to exploit this vulnerability. The specific flaw exists within… | |
| Analizada | Crítica (9.8) | 1.5% | — | Voltronicpower Viewpower | 3/5/2024 | 17/6/2026 | Voltronic Power ViewPower LinuxMonitorConsole Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Voltronic Power ViewPower. Authentication is not required to exploit this vulnerability. The specific flaw exists… | |
| Analizada | Crítica (9.8) | 1.5% | — | Voltronicpower Viewpower | 3/5/2024 | 17/6/2026 | Voltronic Power ViewPower MacMonitorConsole Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Voltronic Power ViewPower. Authentication is not required to exploit this vulnerability. The specific flaw exists… | |
| Analizada | Alta (7.8) | 0.23% | — | Voltronicpower Viewpower | 3/5/2024 | 17/6/2026 | Voltronic Power ViewPower Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Voltronic Power ViewPower. An attacker must first obtain the ability to execute low-privileged code on the target system in… |