Vulnerabilidades CVE

A continuación la lista de las últimas vulnerabilidades publicadas por el instituto NIST:

CVE ID Publicado Severidad CVSS Descripción
CVE-2025-7404 2025-07-24 N/A 0.0 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind…
CVE-2025-6260 2025-07-24 CRITICAL 9.8 The embedded web server on the thermostat listed version ranges contain a vulnerability that allows unauthenticated attackers, either on the…
CVE-2025-31955 2025-07-24 HIGH 7.6 HCL iAutomate is affected by a sensitive data exposure vulnerability. This issue may allow unauthorized access to sensitive information within…
CVE-2025-31953 2025-07-24 HIGH 7.1 HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted or accessed by unauthorized…
CVE-2025-31952 2025-07-24 HIGH 7.1 HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless manually revoked, increasing…
CVE-2025-6998 2025-07-24 N/A 0.0 ReDoS in strip_whitespaces() function in cps/string_helper.py in Calibre Web and Autocaliweb allows unauthenticated remote attackers to cause denial of service via…
CVE-2025-8115 2025-07-24 LOW 3.5 A vulnerability has been found in PHPGurukul Taxi Stand Management System 1.0 and classified as problematic. Affected by this vulnerability…
CVE-2025-5039 2025-07-24 HIGH 7.8 A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary…
CVE-2025-45702 2025-07-24 MEDIUM 6.5 SoftPerfect Pty Ltd Connection Quality Monitor v1.1 was discovered to store all credentials in plaintext.
CVE-2025-53084 2025-07-24 CRITICAL 9.0 A cross-site scripting (xss) vulnerability exists in the videosList page parameter functionality of WWBN AVideo 14.4 and dev master commit…
CVE-2025-50128 2025-07-24 CRITICAL 9.6 A cross-site scripting (xss) vulnerability exists in the videoNotFound 404ErrorMsg parameter functionality of WWBN AVideo 14.4 and dev master commit…
CVE-2025-48732 2025-07-24 HIGH 7.3 An incomplete blacklist exists in the .htaccess sample of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted…
CVE-2025-47061 2025-07-24 MEDIUM 5.4 Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused…
CVE-2025-46996 2025-07-24 MEDIUM 5.4 Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused…
CVE-2025-46993 2025-07-24 MEDIUM 5.4 Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused…
CVE-2025-46410 2025-07-24 CRITICAL 9.6 A cross-site scripting (xss) vulnerability exists in the managerPlaylists PlaylistOwnerUsersId parameter functionality of WWBN AVideo 14.4 and dev master commit…
CVE-2025-41420 2025-07-24 CRITICAL 9.6 A cross-site scripting (xss) vulnerability exists in the userLogin cancelUri parameter functionality of WWBN AVideo 14.4 and dev master commit…
CVE-2025-36548 2025-07-24 HIGH 8.3 A cross-site scripting (xss) vulnerability exists in the LoginWordPress loginForm cancelUri parameter functionality of WWBN AVideo 14.4 and dev master…
CVE-2025-25214 2025-07-24 HIGH 8.8 A race condition vulnerability exists in the aVideoEncoder.json.php unzip functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A…
CVE-2025-54369 2025-07-24 N/A 0.0 Rejected reason: Reason: This candidate was issued in error.
CVE-2025-51089 2025-07-24 MEDIUM 6.5 Tenda AC8V4 V16.03.34.06` was discovered to contain heap overflow at /goform/GetParentControlInfo.The manipulation of the argument `mac` leads to heap-based buffer…
CVE-2025-51088 2025-07-24 MEDIUM 5.3 Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/WifiGuestSet. The manipulation of the argument `shareSpeed` leads to stack-based…
CVE-2025-51085 2025-07-24 MEDIUM 5.3 Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/SetSysTimeCfg. The manipulation of the argument `timeZone` and `timeType` leads…
CVE-2025-51082 2025-07-24 MEDIUM 5.3 Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/fast_setting_wifi_set. The manipulation of the argument `timeZone` leads to stack-based…
CVE-2025-45731 2025-07-24 MEDIUM 6.5 A group deletion race condition in 2FAuth v5.5.0 causes data inconsistencies and orphaned accounts when a group is deleted while…
CVE-2025-41240 2025-07-24 CRITICAL 10.0 Three Bitnami Helm charts mount Kubernetes Secrets under a predictable path (/opt/bitnami/*/secrets) that is located within the web server document…
CVE-2025-8114 2025-07-24 MEDIUM 4.7 A flaw was found in libssh, a library that implements the SSH protocol. When calculating the session ID during the…
CVE-2025-51087 2025-07-24 HIGH 8.6 Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/saveParentControlInfo. The manipulation of the argument time leads to stack-based…
CVE-2025-36005 2025-07-24 MEDIUM 5.9 IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1,…
CVE-2025-33109 2025-07-24 HIGH 7.5 IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to a privilege escalation caused by an invalid database authority…
CVE-2025-33013 2025-07-24 MEDIUM 6.2 IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1,…
CVE-2025-54365 2025-07-23 N/A 0.0 fastapi-guard is a security library for FastAPI that provides middleware to control IPs, log requests, detect penetration attempts and more.…
CVE-2025-4784 2025-07-24 CRITICAL 9.8 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Moderec Tourtella allows SQL Injection.This issue…
CVE-2016-15044 2025-07-23 N/A 0.0 A remote code execution vulnerability exists in Kaltura versions prior to 11.1.0-2 due to unsafe deserialization of user-controlled data within…
CVE-2025-5243 2025-07-24 CRITICAL 10.0 Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…
CVE-2025-4822 2025-07-24 CRITICAL 9.8 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bayraktar Solar Energies ScadaWatt Otopilot allows…
CVE-2025-40680 2025-07-24 N/A 0.0 Lack of sensitive data encryption in CapillaryScope v2.5.0 of Capillary io, which stores both the proxy credentials and the JWT…
CVE-2025-7745 2025-07-24 MEDIUM 5.8 Buffer Over-read vulnerability in ABB AC500 V2.This issue affects AC500 V2: through 2.5.2.
CVE-2025-8071 2025-07-24 MEDIUM 6.4 Mine CloudVod plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘audio’ parameter in all versions up to,…
CVE-2025-7966 2025-07-24 MEDIUM 6.4 The Get Youtube Subs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘channel', 'layout', and 'subs_count’ parameters…
CVE-2025-7959 2025-07-24 MEDIUM 6.4 The Station Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width' and 'height’ parameter in all…
CVE-2025-7835 2025-07-24 MEDIUM 4.3 The iThoughts Advanced Code Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and…
CVE-2025-7822 2025-07-24 MEDIUM 4.3 The WP Wallcreeper plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on…
CVE-2025-7780 2025-07-24 MEDIUM 6.5 The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4.…
CVE-2025-7695 2025-07-24 HIGH 8.8 The Dataverse Integration plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks within its reset_password_link REST…
CVE-2025-7690 2025-07-24 MEDIUM 6.1 The Affiliate Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.2.…
CVE-2025-7640 2025-07-24 HIGH 8.1 The hiWeb Export Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,…
CVE-2025-6588 2025-07-24 MEDIUM 6.1 The FunnelCockpit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘error’ parameter in all versions up to,…
CVE-2025-6539 2025-07-24 MEDIUM 6.4 The Voltax Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions…
CVE-2025-6441 2025-07-24 CRITICAL 9.8 The Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin for WordPress is vulnerable to unauthenticated login…
« Anterior Página 24 de 3363 Siguiente »