Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2561▼ 314 respecto a la semana anterior
Críticas / altas1347▲ 83 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
102 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.1) | 0.10% | — | Redpine Signals Rs9116wAIRedpine Signals Siwx917AI | 8/9/2026 | 8/9/2026 | An unencrypted 'pause encryption request' message causes a denial of service in the in the RS9116W/SiWx917. See vulnerability B-E10 in the related paper below. | |
| Pendiente de análisis | Alta (8.8) | 0.35% | — | Redpine Signals Rs9116wAISilabs Siwx917AI | 13/8/2026 | 8/9/2026 | Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. See V1 in BLERP paper below | |
| Pendiente de análisis | Media (6.9) | 0.30% | — | Suzuki SwiftAIAlpsalpine Cwtr53r0AI | 25/6/2026 | 26/6/2026 | Remote Keyless Entry System (RKES), using the 433 MHz key fob bearing FCC ID CWTR53R0 manufactured by ALPS ALPINE CO., LTD., is vulnerable to a roll-back attack against its rolling-code authentication. An attacker within RF range who records two consecutive lock or unlock transmissions from a legitimate key fob can… | |
| Pendiente de análisis | Alta (7.4) | 0.25% | — | Redpine Signals Rs9116AI | 14/5/2026 | 17/6/2026 | Timing limitations of the HRNG in RS9116 when power save mode is enabled results in predictable values | |
| Aplazada | Alta (7.1) | 0.25% | — | Foreverpinetree ThebeAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in foreverpinetree Thebe thebe allows Reflected XSS.This issue affects Thebe: from n/a through <= 1.3.0. | |
| Aplazada | Alta (7.1) | 0.25% | — | Foreverpinetree ThecsAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in foreverpinetree Thecs thecs allows Reflected XSS.This issue affects Thecs: from n/a through <= 1.4.7. | |
| Aplazada | Alta (7.1) | 0.25% | — | Foreverpinetree ThebiAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in foreverpinetree TheBi thebi allows Reflected XSS.This issue affects TheBi: from n/a through <= 1.0.5. | |
| Aplazada | Alta (8.8) | 0.38% | — | Bosch Infotainment ECUAIAlpsalpine Bluetooth StackAI | 15/2/2026 | 17/6/2026 | The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary validation of user-supplied data, which can result in a stack-based buffer overflow when receiving a specific packet on the established upper… | |
| Aplazada | Alta (8.8) | 0.38% | — | Bosch Infotainment ECUAIAlpsalpine Bluetooth StackAI | 15/2/2026 | 17/6/2026 | The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary validation of user-supplied data, which can result in a stack-based buffer overflow when receiving a specific packet on the established upper… | |
| Aplazada | Alta (8.8) | 0.38% | — | Bosch Infotainment ECUAIAlpsalpine Bluetooth StackAI | 15/2/2026 | 17/6/2026 | The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary validation of user-supplied data, which can result in a stack-based buffer overflow when receiving a specific packet on the established upper… | |
| Aplazada | Alta (7.1) | 0.29% | — | Foreverpinetree ThenaAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in foreverpinetree TheNa thena allows Reflected XSS.This issue affects TheNa: from n/a through <= 1.5.5. | |
| Modificada | Alta (8.1) | 0.50% | — | Axiomthemes Pinevale | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Pinevale pinevale allows PHP Local File Inclusion.This issue affects Pinevale: from n/a through <= 1.0.14. | |
| Analizada | Media (6.9) | 0.40% | — | Spinetix Fusion Digital Signage | 10/12/2025 | 17/6/2026 | SpinetiX Fusion Digital Signage 3.4.8 contains a username enumeration vulnerability in its login script that allows attackers to identify valid user accounts. Attackers can send crafted login requests with different usernames to distinguish between existing and non-existing accounts by analyzing the server's error… | |
| Analizada | Alta (8.7) | 0.42% | — | Spinetix Fusion Digital Signage | 10/12/2025 | 17/6/2026 | SpinetiX Fusion Digital Signage 3.4.8 contains an unauthenticated information disclosure vulnerability in the database backup directory. Attackers can access the /content/files/backups/ endpoint to download sensitive backup files containing user credentials and system information. | |
| Analizada | Media (6.9) | 0.27% | — | Spinetix Fusion Digital Signage | 10/12/2025 | 17/6/2026 | SpinetiX Fusion Digital Signage 3.4.8 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without proper request validation. Attackers can craft a malicious web page that automatically submits a form to create a new admin user with full system privileges… | |
| Analizada | Alta (8.8) | 0.90% | — | Spinetix Fusion Digital Signage | 10/12/2025 | 17/6/2026 | SpinetiX Fusion Digital Signage 3.4.8 and lower contains an authenticated path traversal vulnerability that allows attackers to manipulate file backup and deletion operations through unverified input parameters. Attackers can exploit path traversal techniques in index.php to write backup files to arbitrary locations… | |
| Aplazada | Alta (7.1) | 0.18% | — | Redpine Signals Rs9116 Wiseconnect SDKAI | 17/11/2025 | 17/6/2026 | In a Bluetooth device, using RS9116-WiseConnect SDK experiences a Denial of Service, if it receives malformed L2CAP packets, only hard reset will bring the device to normal operation | |
| Analizada | Alta (8) | 0.69% | — | Alpsalpine Ilx-507 Firmware | 1/8/2025 | 17/6/2026 | Alpine iLX-507 Command Injection Remote Code Execution. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Tidal music streaming… | |
| Analizada | Alta (7.4) | 0.28% | — | Alpsalpine Ilx-507 Firmware | 1/8/2025 | 17/6/2026 | Alpine iLX-507 vCard Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Alpine iLX-507 devices. User interaction is required to exploit this vulnerability in that the target must connect to a malicious… | |
| Analizada | Alta (8) | 0.13% | — | Alpsalpine Ilx-507 Firmware | 1/8/2025 | 17/6/2026 | Alpine iLX-507 TIDAL Improper Certificate Validation Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the TIDAL music streaming… | |
| Analizada | Alta (7.4) | 0.29% | — | Alpsalpine Ilx-507 Firmware | 1/8/2025 | 17/6/2026 | Alpine iLX-507 AVRCP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. User interaction is required to exploit this vulnerability in that the target must connect to a… | |
| Analizada | Media (6.8) | 0.25% | — | Alpsalpine Ilx-507 Firmware | 1/8/2025 | 17/6/2026 | Alpine iLX-507 CarPlay Stack-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… | |
| Analizada | Media (6.6) | 0.73% | — | Alpsalpine Ilx-507 Firmware | 1/8/2025 | 17/6/2026 | Alpine iLX-507 UPDM_wstpCBCUpdStart Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… | |
| Analizada | Alta (7.4) | 0.29% | — | Alpsalpine Ilx-507 Firmware | 1/8/2025 | 17/6/2026 | Alpine iLX-507 vCard Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. User interaction is required to exploit this vulnerability in that the target must connect to… | |
| Aplazada | Media (4.3) | 0.23% | — | Sharespine Woocommerce ConnectorAI | 16/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Sharespine Sharespine Woocommerce Connector sharespine-woocommerce-connector allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sharespine Woocommerce Connector: from n/a through <= 4.7.55. |