Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▲ 32 respecto a la semana anterior
Críticas / altas1474▲ 364 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 464 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.4) | 0.47% | — | Raspap WebguiAI | 29/9/2026 | 29/9/2026 | A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the function PluginInstaller::addSudoers of the file src/RaspAP/Plugins/PluginInstaller.php of the component sudo Configuration. Performing a manipulation results in improper privilege management. The attack may be initiated… | |
| Aplazada | Baja (2.1) | 1.6% | — | Raspap WebguiAI | 29/9/2026 | 1/10/2026 | A vulnerability has been found in RaspAP raspap-webgui up to 3.5.5. Affected by this vulnerability is the function escapeshellcmd of the file ajax/openvpn/del_ovpncfg.php of the component OpenVPN Configuration Handler. Such manipulation of the argument cfg_id leads to os command injection. The attack can be launched… | |
| Aplazada | Baja (2) | 2.1% | — | Raspap WebguiAI | 29/9/2026 | 29/9/2026 | A flaw has been found in RaspAP raspap-webgui up to 3.5.5. Affected is the function WiFiManager::writeWpaSupplicant of the file src/RaspAP/Networking/Hotspot/WiFiManager.php of the component SSID Processing. This manipulation of the argument ssid causes os command injection. The attack can be initiated remotely. The… | |
| Aplazada | Alta (8.7) | 1.4% | — | Raspap-webguiAI | 2/2/2026 | 17/6/2026 | RaspAP raspap-webgui versions prior to 3.3.6 contain an OS command injection vulnerability. If exploited, an arbitrary OS command may be executed by a user who can log in to the product. | |
| Analizada | Crítica (9.8) | 1.6% | — | Raspap-webgui | 27/8/2025 | 17/6/2026 | In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script. The vulnerability is due to improper sanitizing of user input passed via the interface parameter. | |
| Aplazada | Crítica (9.8) | 0.52% | — | Egware Egos WebguiAI | 26/8/2025 | 17/6/2026 | The JWT secret key is embedded in the egOS WebGUI backend and is readable to the default user. An unauthenticated remote attacker can generate valid HS256 tokens and bypass authentication/authorization due to the use of hard-coded cryptographic key. | |
| Analizada | Media (6.3) | 0.60% | — | Raspap-webgui | 27/6/2025 | 17/6/2026 | RaspAP raspap-webgui 3.3.1 is vulnerable to Directory Traversal in ajax/networking/get_wgkey.php. An authenticated attacker can send a crafted POST request with a path traversal payload in the `entity` parameter to overwrite arbitrary files writable by the web server via abuse of the `tee` command used in shell… | |
| Analizada | Crítica (9.8) | 2.8% | — | Raspap-webgui | 29/11/2024 | 17/6/2026 | In RaspAP raspap-webgui 3.0.9 and earlier, a command injection vulnerability exists in the clearlog.php script. The vulnerability is due to improper sanitization of user input passed via the logfile parameter. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Jazz FOR Service ManagementIBM Tivoli Netcool/omnibus Webgui | 23/9/2021 | 17/6/2026 | IBM Tivoli Netcool/OMNIbus_GUI and IBM Jazz for Service Management 1.1.3.10 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Media (6.5) | 1.1% | — | IBM Tivoli Netcool/omnibus Webgui | 20/9/2021 | 17/6/2026 | IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 could allow an authenticated usre to cause a denial of service through the WebGUI Map Creation page. IBM X-Force ID: 205685. | |
| Modificada | Media (5.4) | 0.54% | — | IBM Tivoli Netcool/omnibus Webgui | 20/9/2021 | 17/6/2026 | IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force… | |
| Modificada | Media (5.4) | 0.54% | — | IBM Tivoli Netcool/omnibus Webgui | 20/9/2021 | 17/6/2026 | IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force… | |
| Modificada | Media (5.4) | 0.54% | — | IBM Tivoli Netcool/omnibus Webgui | 20/9/2021 | 17/6/2026 | IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force… | |
| Modificada | Media (5.4) | 0.54% | — | IBM Tivoli Netcool/omnibus Webgui | 20/9/2021 | 17/6/2026 | IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force… | |
| Modificada | Media (5.4) | 0.54% | — | IBM Tivoli Netcool/omnibus Webgui | 20/9/2021 | 17/6/2026 | IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force… | |
| Modificada | Media (4.9) | 0.97% | — | IBM Tivoli Netcool/omnibus Webgui | 20/9/2021 | 17/6/2026 | IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 stores user credentials in plain clear text which can be read by an authenticated admin user. IBM X-Force ID: 204329. | |
| Modificada | Media (5.4) | 0.54% | — | IBM Tivoli Netcool/omnibus Webgui | 20/9/2021 | 17/6/2026 | IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM… | |
| Modificada | Media (5.4) | 0.54% | — | IBM Tivoli Netcool/omnibus Webgui | 20/9/2021 | 17/6/2026 | IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM… | |
| Modificada | Media (5.4) | 0.54% | — | IBM Tivoli Netcool/omnibus Webgui | 20/9/2021 | 17/6/2026 | IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM… | |
| Modificada | Media (5.4) | 0.54% | — | IBM Tivoli Netcool/omnibus Webgui | 20/9/2021 | 17/6/2026 | IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM… | |
| Modificada | Media (5.4) | 0.56% | — | IBM Tivoli Netcool/omnibus Webgui | 11/3/2021 | 17/6/2026 | IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Media (4.3) | 1.0% | — | Plainblack Webgui | 9/2/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in style-underground/search in Plain Black WebGUI 7.10.29 and earlier allows remote attackers to inject arbitrary web script or HTML via the Search field. | |
| Modificada | Media (6.8) | 0.59% | — | Plainblack Webgui | 26/5/2010 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in WebGUI before 7.7.14 allow remote attackers to hijack the authentication of users for unspecified requests via unknown vectors. | |
| Modificada | Alta (7.5) | 2.3% | — | Muskatli Sofi Webgui | 6/3/2009 | 16/6/2026 | PHP remote file inclusion vulnerability in hu/modules/reg-new/modstart.php in Sofi WebGui 0.6.3 PRE and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mod_dir parameter. | |
| Modificada | Alta (9.3) | 4.0% | — | Webgui | 30/10/2008 | 16/6/2026 | The loadModule function in lib/WebGUI/Asset.pm in WebGUI before 7.5.30 (stable) allows remote attackers to execute arbitrary code by uploading a Perl module and accessing it via a crafted URL. |