Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▲ 460 respecto a la semana anterior
Críticas / altas1445▲ 228 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 156 respecto a la semana anterior
61 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.43% | — | Wtv676 Hb6035 WEB InterfaceAIWtv776 Hb6035 WEB InterfaceAI | 16/9/2026 | 18/9/2026 | A vulnerability has been identified in WTV676-HB6035 Web Interface (All versions < V3.94), WTV776-HB6035 Web Interface (All versions < V4.17). Affected devices do not properly validate input received from backend services. This could allow an unauthenticated remote attacker to force the device into protection mode,… | |
| Aplazada | Alta (8.7) | 0.71% | — | Aclara Metrum Cellular WEB InterfaceAI | 24/6/2026 | 25/6/2026 | The Aclara Metrum Cellular Web Interface is vulnerable to unauthorized access due to the absence of authentication controls on critical system functions. This weakness exposes essential configuration settings, allowing attackers to alter operational parameters and trigger system restarts without restriction. Such… | |
| Analizada | Media (4.8) | 0.29% | — | Pi-hole WEB Interface | 6/4/2026 | 17/6/2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. From 6.0 to before 6.5, the formatInfo() function in queries.js renders data.upstream, data.client.ip, and data.ede.text into HTML without escaping when a user expands a query row in the Query… | |
| Analizada | Media (6.1) | 0.37% | — | Pi-hole WEB Interface | 6/4/2026 | 17/6/2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. From 6.0 to before 6.5, configuration values from the /api/config endpoint are placed directly into HTML value="" attributes without escaping in settings-advanced.js, enabling HTML attribute… | |
| Analizada | Media (6.1) | 0.25% | — | Pi-hole WEB Interface | 6/4/2026 | 17/6/2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. From 6.0 to before 6.5, client hostnames and IP addresses from the FTL database are rendered into the DOM without escaping in network.js (Network page) and charts.js/index.js (Dashboard chart… | |
| Analizada | Media (6.1) | 0.32% | — | Pi-hole WEB Interface | 6/4/2026 | 17/6/2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. From 6.0 to before 6.5, a reflected DOM-based XSS vulnerability in taillog.js allows an unauthenticated attacker to inject arbitrary HTML into the Pi-hole admin interface by crafting a… | |
| Analizada | Alta (8.9) | 1.8% | — | Pi-hole WEB Interface | 27/3/2026 | 17/6/2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions prior to 6.0 have a critical OS Command Injection vulnerability in the savesettings.php file. The application takes the user-controlled $_POST['webtheme'] parameter and concatenates… | |
| Analizada | Media (5.4) | 0.42% | — | Pi-hole WEB Interface | 19/2/2026 | 17/6/2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions 6.0 and above have a Stored HTML Injection vulnerability in the active sessions table located on the API settings page, allowing an attacker with valid credentials to inject arbitrary… | |
| Analizada | Media (5.4) | 0.35% | — | Pi-hole WEB Interface | 19/2/2026 | 17/6/2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions 6.4 and below are vulnerable to stored HTML injection through the local DNS records configuration page, which allows an authenticated administrator to inject code that is stored in… | |
| Analizada | Alta (8.2) | 0.44% | — | Pi-hole WEB Interface | 27/10/2025 | 17/6/2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application. Pi-hole Admin Interface before 6.3 is vulnerable to Carriage Return Line Feed (CRLF) injection. When a request is made to a file ending with the .lp extension, the application… | |
| Analizada | Media (5.1) | 0.59% | — | Pi-hole WEB Interface | 27/10/2025 | 17/6/2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application. Pi-hole Admin Interface versions 6.2.1 and earlier are vulnerable to reflected cross-site scripting (XSS) via a malformed URL path. The 404 error page includes the requested path in… | |
| Analizada | Baja (2) | 0.25% | — | Pi-hole WEB Interface | 27/10/2025 | 17/6/2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application. Pi-hole Admin Interface versions prior to 6.3 are vulnerable to cross-site scripting (XSS) via the Address field in the Subscribed Lists group management section. An authenticated… | |
| Aplazada | Media (4.3) | 0.69% | — | DZS Router WEB InterfaceAI | 4/3/2025 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability exists in the WPA/WAPI Passphrase field of the Wireless Security settings (2.4GHz & 5GHz bands) in DZS Router Web Interface. An authenticated attacker can inject malicious JavaScript into the passphrase field, which is stored and later executed when an administrator views the… | |
| Modificada | Crítica (10) | 1.0% | — | Openhab WEB Interface | 12/8/2024 | 5/8/2026 | openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. In versions 3.4.0.M4 through 4.2.0,, the proxy endpoint of openHAB's CometVisu add-on can be accessed without authentication. This proxy-feature can be exploited as Server-Side Request Forgery (SSRF)… | |
| Modificada | Crítica (9.8) | 0.70% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connection | |
| Modificada | Alta (7.5) | 0.57% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable due to exposure of sensitive password information in the URL as a URL search parameter | |
| Modificada | Crítica (9.8) | 0.70% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP strict-transport-security policy | |
| Modificada | Crítica (9.8) | 0.70% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller is vulnerable to Privilege escalation to root due to creation of insecure folders by Web GUI | |
| Modificada | Crítica (9.8) | 0.70% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller is vulnerable to Privilege escalation by taking advantage of the Session prints in the log file | |
| Modificada | Alta (7.5) | 0.83% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable to exposure of private keys used for CIM stored with insecure file permissions | |
| Modificada | Crítica (9.8) | 0.70% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not provide X-Content-Type-Options Headers | |
| Modificada | Crítica (9.8) | 0.70% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable to improper session handling of managed servers on Gateway installation | |
| Modificada | Crítica (9.8) | 0.70% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard cookies with Secure attribute | |
| Modificada | Alta (7.5) | 0.59% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on Linux | |
| Modificada | Alta (7.5) | 0.60% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller Web server (nginx) is serving private files without any authentication |