Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

307 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.0%—22lixian Project 22lixian7/6/201817/6/2026
22lixian is a simple file server. 22lixian is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
ModificadaCrítica (9.8)2.9%—Alchemist-elixir Alchemist-server17/11/201717/6/2026
Elixir's vim plugin, alchemist.vim is vulnerable to remote code execution in the bundled alchemist-server. A malicious website can execute requests against an ephemeral port on localhost that are then evaluated as elixir code.
ModificadaAlta (7.8)0.38%—Lenovo Thinkpad 10 Ella 2 BiosLenovo Thinkpad 11E Beema BiosLenovo Thinkpad 11E Braswell BiosLenovo Thinkpad 11E Broadwell Bios+14418/8/201717/6/2026
A privilege escalation vulnerability was identified in Lenovo Active Protection System for ThinkPad systems versions earlier than 1.82.0.17. An attacker with local privileges could execute code with administrative privileges via an unquoted service path.
ModificadaAlta (7.5)1.5%—Netflix Lemur9/8/201717/6/2026
Lemur 0.1.4 does not use sufficient entropy in its IV when encrypting AES in CBC mode.
ModificadaMedia (6.1)0.97%—Netflix Security Monkey26/3/201717/6/2026
Netflix Security Monkey before 0.8.0 has an Open Redirect. The logout functionality accepted the "next" parameter which then redirects to any domain irrespective of the Host header.
ModificadaMedia (5.9)1.7%—Sleekxmpp Project SleekxmppSlixmpp Project SlixmppPoezio9/2/201717/6/2026
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for SleekXMPP up to 1.3.1 and Slixmpp all versions…
ModificadaMedia (4.4)0.30%—Lenovo Thinkpad 10 Ella 2 BiosLenovo Thinkpad 11E Beema BiosLenovo Thinkpad 11E Braswell BiosLenovo Thinkpad 11E Broadwell Bios+7030/11/201617/6/2026
A vulnerability has been identified in a signed kernel driver for the BIOS of some ThinkPad systems that can allow an attacker with Windows administrator-level privileges to call System Management Mode (SMM) services. This could lead to a denial of service attack or allow certain BIOS variables or settings to be…
ModificadaBaja (3.3)1.00%—Lixil MY Satis Genius Toilet16/4/201516/6/2026
The LIXIL Corporation My SATIS Genius Toilet application for Android has a hardcoded Bluetooth PIN, which allows physically proximate attackers to trigger physical resource consumption (water or heat) or user discomfort.
ModificadaMedia (6.4)1.4%—Scalix WEB Access10/12/201417/6/2026
XML external entity (XXE) vulnerability in Scalix Web Access 11.4.6.12377 and 12.2.0.14697 allows remote attackers to read arbitrary files and trigger requests to intranet servers via a crafted request.
ModificadaMedia (4.3)1.1%—Scalix WEB Access9/12/201417/6/2026
Cross-site scripting (XSS) vulnerability in the mail administration login panel in Scalix Web Access 11.4.6.12377 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.6)0.39%—Tedfelix Acpid229/8/201216/6/2026
event.c in acpid (aka acpid2) before 2.0.11 does not have an appropriate umask setting during execution of event-handler scripts, which might allow local users to (1) perform write operations within directories created by a script, or (2) read files created by a script, via standard filesystem system calls.
ModificadaMedia (4.4)0.61%💥 ExploitTedfelix Acpid229/8/201216/6/2026
samples/powerbtn/powerbtn.sh in acpid (aka acpid2) 2.0.16 and earlier uses the pidof program incorrectly, which allows local users to gain privileges by running a program with the name kded4 and a DBUS_SESSION_BUS_ADDRESS environment variable containing commands.
ModificadaMedia (4.3)1.7%—Ematia Elixir26/8/201216/6/2026
Elixir 0.8.0 uses Blowfish in CFB mode without constructing a unique initialization vector (IV), which makes it easier for context-dependent users to obtain sensitive information and decrypt the database.
ModificadaMedia (5)1.6%—Realnetworks Helix ServerRealnetworks Helix Mobile Server17/4/201216/6/2026
master.exe in the SNMP Master Agent in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allows remote attackers to cause a denial of service (unhandled exception and daemon crash) via a crafted Open-PDU request that triggers incorrect DisplayString processing, a different vulnerability than…
ModificadaMedia (5)1.6%—Realnetworks Helix ServerRealnetworks Helix Mobile Server17/4/201216/6/2026
master.exe in the SNMP Master Agent in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allows remote attackers to cause a denial of service (daemon crash) by establishing and closing a port-705 TCP connection, a different vulnerability than CVE-2012-1923.
ModificadaMedia (6.8)0.97%—Realnetworks Helix ServerRealnetworks Helix Mobile Server17/4/201216/6/2026
Cross-site request forgery (CSRF) vulnerability in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allows remote attackers to hijack the authentication of administrators for requests that cause a denial of service (stack consumption and daemon crash) via a malformed URL.
ModificadaMedia (4.3)1.8%—Realnetworks Helix ServerRealnetworks Helix Mobile Server17/4/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaBaja (2.1)38%—Realnetworks Helix ServerRealnetworks Helix Mobile Server17/4/201216/6/2026
RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x store passwords in cleartext under adm_b_db\users\, which allows local users to obtain sensitive information by reading a database.
ModificadaAlta (7.5)4.1%—Realnetworks Helix ServerRealnetworks Helix Mobile Server17/4/201216/6/2026
Buffer overflow in rn5auth.dll in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allows remote attackers to execute arbitrary code via crafted authentication credentials.
ModificadaMedia (4.3)1.1%—Clixint Image Hosting Script DPI2/2/201216/6/2026
Cross-site scripting (XSS) vulnerability in misc.php in Image Hosting Script DPI 1.0, 1.3, and earlier allows remote attackers to inject arbitrary web script or HTML via the showseries parameter.
ModificadaBaja (2.1)1.1%💥 ExploitTedfelix Acpid5/10/201116/6/2026
acpid.c in acpid before 2.0.9 does not properly handle a situation in which a process has connected to acpid.socket but is not reading any data, which allows local users to cause a denial of service (daemon hang) via a crafted application that performs a connect system call but no read system calls.
ModificadaAlta (9.3)5.0%—Realnetworks Helix ServerRealnetworks Helix Mobile Server4/4/201116/6/2026
Stack-based buffer overflow in RealNetworks Helix Server 12.x, 13.x, and 14.x before 14.2, and Helix Mobile Server 12.x, 13.x, and 14.x before 14.2, allows remote attackers to execute arbitrary code via a long string in an RTSP request.
ModificadaAlta (10)4.1%—Realnetworks Helix ServerRealnetworks Helix Mobile Server4/4/201116/6/2026
Format string vulnerability in RealNetworks Helix Server 12.x, 13.x, and 14.x before 14.2, and Helix Mobile Server 12.x, 13.x, and 14.x before 14.2, allows remote attackers to execute arbitrary code via vectors related to the x-wap-profile HTTP header.
ModificadaMedia (6.9)0.38%—Mistelix20/10/201016/6/2026
Mistelix 0.31 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
ModificadaAlta (10)5.1%—Realnetworks Helix Mobile ServerRealnetworks Helix ServerRealnetworks Helix Server Mobile20/4/201016/6/2026
Integer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Server and Helix Mobile Server 11.x through 13.x and other products, allows remote attackers to execute arbitrary code via a request with a crafted payload length.
Orbitaley — Vulnerabilidades