Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.30% | — | Solarwinds FTP Voyager | 4/4/2026 | 24/7/2026 | FTP Voyager 16.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by injecting oversized buffer data into the site profile IP field. Attackers can create a malicious site profile containing 500 bytes of repeated characters and paste it into the IP field to trigger a… | |
| Aplazada | Alta (8.7) | 0.65% | — | VoyagerAI | 11/2/2026 | 1/10/2026 | Voyager 1.3.0 contains a directory traversal vulnerability that allows attackers to access sensitive system files by manipulating the asset path parameter. Attackers can exploit the path parameter in /admin/voyager-assets to read arbitrary files like /etc/passwd and .env configuration files. | |
| Aplazada | Crítica (9.1) | 0.56% | — | Devdojo VoyagerAILaravelAI | 14/4/2025 | 17/6/2026 | DevDojo Voyager 1.4.0 through 1.8.0, when Laravel 8 or later is used, allows authenticated administrators to execute arbitrary OS commands via a specific php artisan command. | |
| Analizada | Media (4.3) | 14% | — | Thecontrolgroup Voyager | 30/1/2025 | 17/6/2026 | DevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user uploads a file via /admin/media/upload. An authenticated user can upload a web shell causing arbitrary code execution on the server. | |
| Analizada | Baja (3.5) | 20% | — | Thecontrolgroup Voyager | 30/1/2025 | 17/6/2026 | DevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass. By manipulating an authenticated user to click on a link, arbitrary Javascript can be executed. | |
| Analizada | Media (5.7) | 16% | — | Thecontrolgroup Voyager | 30/1/2025 | 17/6/2026 | DevDojo Voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass. | |
| Modificada | Crítica (9.8) | 1.1% | — | Thecontrolgroup Voyager | 26/4/2023 | 17/6/2026 | Insecure Permission vulnerability found in Yoyager v.1.4 and before allows a remote attacker to execute arbitrary code via a crafted .php file to the media component. | |
| Modificada | Crítica (9.8) | 0.61% | — | Voyager Project Voyager | 11/1/2023 | 17/6/2026 | A vulnerability was found in Nayshlok Voyager. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file Voyager/src/models/DatabaseAccess.java. The manipulation leads to sql injection. The identifier of the patch is f1249f438cd8c39e7ef2f6c8f2ab76b239a02fae. It is… | |
| Modificada | Alta (7.2) | 1.2% | — | Thecontrolgroup Voyager | 30/9/2019 | 17/6/2026 | An issue was discovered in the Voyager package through 1.2.7 for Laravel. An attacker with admin privileges and Compass access can read or delete arbitrary files, such as the .env file. NOTE: a software maintainer has suggested a solution in which Compass is switched off in a production environment. | |
| Modificada | Alta (8.1) | 2.6% | — | Infinixauthority HOT X507 FirmwareInfinixauthority HOT 2 X510 FirmwareInfinixauthority Zero X506 FirmwareInfinixauthority Zero 2 X509 Firmware+15 | 13/7/2018 | 17/6/2026 | Android devices with code from Ragentek contain a privileged binary that performs over-the-air (OTA) update checks. Additionally, there are multiple techniques used to hide the execution of this binary. This behavior could be described as a rootkit. This binary, which resides as /system/bin/debugs, runs with root… | |
| Modificada | Alta (8.8) | 4.4% | — | Solarwinds FTP Voyager | 20/3/2017 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in the Scheduler in SolarWinds (formerly Serv-U) FTP Voyager 16.2.0 allow remote attackers to hijack the authentication of users for requests that (1) change the admin password, (2) terminate the scheduler, or (3) possibly execute… | |
| Modificada | Alta (9.3) | 1.6% | — | Rhinosoft FTP Voyager | 3/11/2010 | 16/6/2026 | Directory traversal vulnerability in Rhino Software, Inc. FTP Voyager 15.2.0.11, and possibly earlier, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename. | |
| Modificada | Alta (7.8) | 3.1% | — | Rhinosoft FTP Voyager | 22/2/2007 | 16/6/2026 | Stack-based buffer overflow in Rhino Software, Inc. FTP Voyager 14.0.0.3 and earlier allows remote servers to cause a denial of service (crash) via a long response to a CWD command, which triggers the overflow when the user aborts the command. | |
| Modificada | Media (5) | 6.7% | — | BT Voyager 2091 Wireless Adsl Router | 13/7/2006 | 16/6/2026 | BT Voyager 2091 Wireless firmware 2.21.05.08m_A2pB018c1.d16d and earlier, and 3.01m and earlier, allow remote attackers to bypass the authentication process and gain sensitive information, such as configuration information via (1) /btvoyager_getconfig.sh, PPP credentials via (2) btvoyager_getpppcreds.sh, and decode… | |
| Modificada | Media (5) | 3.0% | — | BT Voyager 2000 Wireless Adsl Router | 6/12/2004 | 16/6/2026 | The BT Voyager 2000 Wireless ADSL Router has a default public SNMP community name, which allows remote attackers to obtain sensitive information such as the password, which is stored in plaintext. | |
| Modificada | Alta (7.5) | 2.1% | — | Rhinosoft FTP Voyager | 3/3/2001 | 16/6/2026 | FTP Voyager ActiveX control before 8.0, when it is marked as safe for scripting (the default) or if allowed by the IObjectSafety interface, allows remote attackers to execute arbitrary commands. | |
| Modificada | Media (5) | 3.0% | — | QNX Voyager | 19/12/2000 | 23/9/2026 | Directory traversal vulnerability in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to read arbitrary files via a .. (dot dot) attack. | |
| Modificada | Media (5) | 2.1% | — | QNX Voyager | 19/12/2000 | 23/9/2026 | QNX Embedded Resource Manager in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to read sensitive system statistics information via the embedded.html web page. | |
| Modificada | Media (5) | 2.7% | — | QNX Voyager | 19/12/2000 | 23/9/2026 | Voyager web server 2.01B in the demo disks for QNX 405 stores sensitive web client information in the .photon directory in the web document root, which allows remote attackers to obtain that information. |