Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

608 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.9)0.20%—Akbr UpdateAI17/6/202417/6/2026
akbr update 1.0.0 is vulnerable to Prototype Pollution via update/index.js.
ModificadaMedia (5.4)0.31%—Datenverwurstungszentrale Shariff Wrapper15/6/202417/6/2026
The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortcode in all versions up to, and including, 4.6.13 due to insufficient input sanitization and output escaping on user supplied attributes such as 'borderradius', 'services' and 'timestamp'. This makes…
ModificadaAlta (8.1)2.1%💥 PoCRedhat Enterprise LinuxRedhat Enterprise Linux AUSRedhat Enterprise Linux EUSRedhat Enterprise Linux TUS+112/6/202417/6/2026
A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypted using the client’s session key. This key is different for each new session, which protects it from brute force attacks. However, the ticket it contains is encrypted using the target principal key directly. For user principals, this key…
AplazadaMedia (4.3)0.37%—Minoji MJ Update HistoryAI11/6/202417/6/2026
Missing Authorization vulnerability in Minoji MJ Update History.This issue affects MJ Update History: from n/a through 1.0.4.
ModificadaAlta (7.8)0.15%—Google Updater7/6/202417/6/2026
Inappropriate implementation in Google Updator prior to 1.3.36.351 in Google Chrome allowed a local attacker to bypass discretionary access control via a malicious file. (Chromium security severity: High)
ModificadaAlta (7.8)0.16%💥 PoCGoogle Updater7/6/202417/6/2026
Inappropriate implementation in Google Updator prior to 1.3.36.351 in Google Chrome allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: High)
ModificadaMedia (5.9)0.53%—Clusterlabs BoothRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR ARM 64+46/6/202417/6/2026
A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server.
AnalizadaMedia (4.9)0.25%—Dell Openmanage Enterprise Update Manager8/5/202417/6/2026
Dell Update Manager Plugin, versions 1.4.0 through 1.5.0, contains a Plain-text Password Storage Vulnerability in Log file. A remote high privileged attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to…
ModificadaAlta (8.8)0.91%—Androidbubbles WP Datepicker2/5/202417/6/2026
The WP Datepicker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpdp_add_new_datepicker_ajax() function in all versions up to, and including, 2.1.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to update…
AplazadaCrítica (9.8)0.67%—Helloshop DeliveryorderautoupdateAI29/4/202417/6/2026
SQL Injection vulnerability in Helloshop deliveryorderautoupdate v.2.8.1 and before allows an attacker to run arbitrary SQL commands via the DeliveryorderautoupdateOrdersModuleFrontController::initContent function.
ModificadaAlta (7.1)1.0%—Fedoraproject SssdRedhat Codeready Linux BuilderRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder FOR Arm64+1918/4/202417/6/2026
A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.
AplazadaAlta (7.1)0.35%—Minoji MJ Update HistoryAI17/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Minoji MJ Update History allows Reflected XSS.This issue affects MJ Update History: from n/a through 1.0.4.
AnalizadaMedia (6.5)1.1%—Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+1116/4/202417/6/2026
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-only credentials can use a malformed OID in a `GET-NEXT` to the `nsVacmAccessTable` to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong SNMPv3…
AnalizadaMedia (6.5)1.1%—Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+1116/4/202417/6/2026
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a `SET` request to `NET-SNMP-AGENT-MIB::nsLogTable` to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong…
AnalizadaMedia (6.5)1.0%—Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+1116/4/202417/6/2026
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a malformed OID in a SET request to `SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable` can cause an out-of-bounds memory access. A user with read-write credentials can exploit the issue. Version 5.9.2 contains a patch.…
AnalizadaMedia (5.3)1.1%—Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+1116/4/202417/6/2026
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can exploit an Improper Input Validation vulnerability when SETing malformed OIDs in master agent and subagent simultaneously. Version 5.9.2 contains a patch. Users should use…
AnalizadaAlta (8.8)1.3%—Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+1116/4/202417/6/2026
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a buffer overflow in the handling of the `INDEX` of `NET-SNMP-VACM-MIB` can cause an out-of-bounds memory access. A user with read-only credentials can exploit the issue. Version 5.9.2 contains a patch. Users…
AplazadaMedia (4.3)0.21%—Tychesoftwares Order Delivery Date FOR WoocommerceAI15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Tyche Softwares Order Delivery Date for WooCommerce.This issue affects Order Delivery Date for WooCommerce: from n/a through 3.20.2.
AplazadaMedia (6.7)0.18%—Lenovo Bios Update Tool DriverAI5/4/202417/6/2026
A potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart Edge, Smart Office, and ThinkStation products that could allow a local user with elevated privileges to execute arbitrary code.
ModificadaMedia (5.4)0.50%—Datenverwurstungszentrale Shariff Wrapper21/3/202417/6/2026
The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortcode in all versions up to, and including, 4.6.10 due to insufficient input sanitization and output escaping on user supplied attributes such as 'align'. This makes it possible for authenticated…
ModificadaMedia (5.4)0.50%—Datenverwurstungszentrale Shariff Wrapper21/3/202417/6/2026
The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortcode in all versions up to, and including, 4.6.9 due to insufficient input sanitization and output escaping on user supplied attributes like 'info_text'. This makes it possible for authenticated…
ModificadaMedia (5.4)0.39%—Datenverwurstungszentrale Shariff Wrapper21/3/202417/6/2026
The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortcode in all versions up to, and including, 4.6.9 due to insufficient input sanitization and output escaping on user supplied attributes such as 'secondarycolor' and 'maincolor'. This makes it possible…
ModificadaMedia (5.4)0.31%—Datenverwurstungszentrale Shariff Wrapper19/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jan-Peter Lambeck & 3UU Shariff Wrapper allows Stored XSS.This issue affects Shariff Wrapper: from n/a through 4.6.10.
AnalizadaAlta (7.8)0.99%—Microsoft Azure AutomationMicrosoft Azure Automation Update ManagementMicrosoft Azure Security CenterMicrosoft Azure Sentinel+412/3/202417/6/2026
Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability
AplazadaMedia (5.1)0.16%—Motorola OTA Update ApplicationAI4/3/202417/6/2026
An improper export vulnerability was reported in the Motorola OTA update application, that could allow a malicious, local application to inject an HTML-based message on screen UI.
Orbitaley — Vulnerabilidades