Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

26 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.1)1.2%—Chengdu Feiyuxing Technology Feiyu Star Router B-mb5e202AI21/9/202622/9/2026
A weakness has been identified in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. Affected is an unknown function of the file /send_order.cgi?parameter=loginout of the component Cookie Handler. This manipulation of the argument session_id causes command injection. Remote exploitation of the…
AplazadaBaja (2)2.1%—Chengdu Feiyuxing Technology Feiyu Star Router B-mb5e202-210322-r11656AI21/9/202621/9/2026
A security flaw has been discovered in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. This impacts an unknown function of the file /send_order.cgi?parameter=del_expmac. The manipulation of the argument mac results in command injection. The attack may be launched remotely. The exploit has been…
AplazadaCrítica (9.3)0.52%—Xing Cptrans-me-xAI4/9/20268/9/2026
XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the credential may log in to the affected device.
AplazadaCrítica (9.3)0.52%—Xing Cptrans-me-xAI4/9/20268/9/2026
XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the credential may log in to the affected device.
AplazadaAlta (8.7)0.44%—Xing Cptrans-me-xAI4/9/20268/9/2026
XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497). Sensitive system information may be leaked.
AplazadaCrítica (9.3)2.0%—Xing Cptrans-me-xAI4/9/20268/9/2026
XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected.
AplazadaCrítica (9.8)0.43%—Zuoxingdong LagomAI17/6/20266/10/2026
Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection. This issue affects Lagom: from n/a through 2.0.
AplazadaBaja (1.9)0.38%—Xingfuggz BaykeshopAI23/2/202617/6/2026
A security vulnerability has been detected in xingfuggz BaykeShop up to 1.3.20. Impacted is an unknown function of the file src/baykeshop/contrib/article/templates/baykeshop/sidebar/custom.html of the component Article Sidebar Module. Such manipulation of the argument sidebar.content leads to cross site scripting. The…
AnalizadaAlta (7.5)0.57%—Axing Dev7113 Firmware26/12/202517/6/2026
Incorrect access control in DEV Systemtechnik GmbH DEV 7113 RF over Fiber Distribution System 32-0078 H.01 allows unauthenticated attackers to access an administrative endpoint.
AplazadaBaja (2.1)0.31%—Guanxinglu VlarlAIZeromqAI25/9/202517/6/2026
A vulnerability was found in GuanxingLu vlarl up to 31abc0baf53ef8f5db666a1c882e1ea64def2997. This vulnerability affects the function experiments.robot.bridge.reasoning_server::run_reasoning_server of the file experiments/robot/bridge/reasoning_server.py of the component ZeroMQ. Performing manipulation of the argument…
AnalizadaAlta (7.5)0.38%—Zykzhangyukang Xinguan5/5/202517/6/2026
Incorrect access control in the /system/user/findUserList API of Xinguan v0.0.1-SNAPSHOT allows attackers to access sensitive information via a crafted payload.
AplazadaCrítica (9.8)0.76%—Wanxing Technology Yitu Project Management Kirin EditionAI15/10/202417/6/2026
An issue in Wanxing Technology Yitu Project Management Kirin Edition 2.3.6 allows a remote attacker to execute arbitrary code via a specially constructed so file/opt/EdrawProj-2/plugins/imageformat.
AplazadaCrítica (9.8)0.81%—Wanxing Technology Yitu Project Management SoftwareAI15/10/202417/6/2026
An issue in Wanxing Technology's Yitu project Management Software 3.2.2 allows a remote attacker to execute arbitrary code via the platformpluginpath parameter to specify that the qt plugin loads the directory.
AplazadaCrítica (9.1)0.37%—Renwoxing Enterprise Intelligent Management SystemAI10/9/202417/6/2026
Renwoxing Enterprise Intelligent Management System before v3.0 was discovered to contain a SQL injection vulnerability via the parid parameter at /fx/baseinfo/SearchInfo.
AplazadaAlta (8)0.54%—Shenzhen Haichangxing Technology HCX H822 4G LTE RouterAI10/9/20245/7/2026
Shenzhen Haichangxing Technology Co., Ltd HCX H822 4G LTE Router M7628NNxISPxUIv2_v1.0.1557.15.35_P0 is vulnerable to Incorrect Access Control. Unauthenticated factory mode reset and command injection leads to information exposure and root shell access.
AplazadaCrítica (9.8)0.61%—Tongtianxing Technology CO LTD Cmsv6AI29/3/202417/6/2026
SQL Injection vulnerability in Tongtianxing Technology Co., Ltd CMSV6 v.7.31.0.2 through v.7.31.0.3 allows a remote attacker to escalate privileges and obtain sensitive information via the ids parameter.
AnalizadaMedia (6.6)0.31%—Zuoxingdong Lagom21/3/202417/6/2026
An issue in zuoxingdong lagom v.0.1.2 allows a local attacker to execute arbitrary code via the pickle_load function of the serialize.py file.
ModificadaCrítica (9.8)0.71%—Ontall Longxing Industrial Development Zone Project27/10/202317/6/2026
A vulnerability was found in Nanning Ontall Longxing Industrial Development Zone Project Construction and Installation Management System up to 20231026. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file login.aspx. The manipulation of the argument tbxUserName…
ModificadaAlta (7.5)19%—Feiyuxing Vec40g Firmware12/6/202317/6/2026
A vulnerability classified as problematic was found in Chengdu VEC40G 3.0. Affected by this vulnerability is an unknown functionality of the file /send_order.cgi?parameter=restart. The manipulation of the argument restart with the input reboot leads to denial of service. The attack can be launched remotely. The…
ModificadaAlta (7.2)34%—Feiyuxing Vec40g Firmware4/5/202317/6/2026
A vulnerability was found in Chengdu VEC40G 3.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /send_order.cgi?parameter=access_detect of the component Network Detection. The manipulation of the argument COUNT with the input 3 | netstat -an leads to os command…
ModificadaMedia (5.4)0.60%—Kluks Xingwall6/1/202317/6/2026
A vulnerability, which was classified as critical, has been found in kassi xingwall. This issue affects some unknown processing of the file app/controllers/oauth.js. The manipulation leads to session fixiation. The patch is named e9f0d509e1408743048e29d9c099d36e0e1f6ae7. It is recommended to apply a patch to fix this…
ModificadaMedia (4.3)1.1%—Peter Proell Xing7/10/201116/6/2026
Cross-site scripting (XSS) vulnerability in the XING Button (xing) extension before 1.0.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (10)97%💥 ExploitMicrosoft Index ServerMicrosoft Indexing ServiceMicrosoft Internet Information Server21/7/200116/6/2026
Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to execute arbitrary commands via a long argument to Internet Data Administration (.ida) and Internet Data Query (.idq) files such as default.ida, as commonly exploited by Code…
ModificadaMedia (5)14%—Microsoft Index ServerMicrosoft Indexing Service27/6/200116/6/2026
Microsoft Index Server 2.0 in Windows NT 4.0, and Indexing Service in Windows 2000, allows remote attackers to read server-side include files via a malformed search request, aka a new variant of the "Malformed Hit-Highlighting" vulnerability.
ModificadaMedia (4.3)11%💥 ExploitMicrosoft Indexing Service9/1/200116/6/2026
The ixsso.query ActiveX Object is marked as safe for scripting, which allows malicious web site operators to embed a script that remotely determines the existence of files on visiting Windows 2000 systems that have Indexing Services enabled.
Orbitaley — Vulnerabilidades