Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
808 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.21% | — | Seedprod Coming Soon Page Under Construction Maintenance ModeAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd.This issue affects Coming Soon Page, Under Construction & Maintenance Mode by SeedProd: from n/a through 6.15.20. | |
| Analizada | Media (4.4) | 0.18% | — | Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M18 R1 Firmware+264 | 10/4/2024 | 17/6/2026 | Dell BIOS contains an Out-of-Bounds Write vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to denial of service. | |
| Modificada | Crítica (9.8) | 1.3% | — | Videowhisper Live Streaming Integration | 3/4/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in VideoWhisper.Com VideoWhisper Live Streaming Integration allows OS Command Injection.This issue affects VideoWhisper Live Streaming Integration: from n/a through 5.5.15. | |
| Aplazada | Crítica (9.8) | 1.1% | — | Huashi Private Cloud CDN Live Streaming Acceleration Server Hgateway-sixportAI | 29/3/2024 | 17/6/2026 | An issue in Huashi Private Cloud CDN Live Streaming Acceleration Server hgateway-sixport v.1.1.2 allows a remote attacker to execute arbitrary code via the manager/ipping.php component. | |
| Aplazada | Media (5.5) | 0.35% | — | Niteothemes CMP Coming Soon MaintenanceAI | 28/3/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in NiteoThemes CMP – Coming Soon & Maintenance.This issue affects CMP – Coming Soon & Maintenance: from n/a through 4.1.10. | |
| Analizada | Alta (8.8) | 0.65% | — | Microsoft Xbox Gaming Services | 21/3/2024 | 17/6/2026 | Xbox Gaming Services Elevation of Privilege Vulnerability | |
| Modificada | Media (5.3) | 0.53% | — | Colorlib Coming Soon & Maintenance Mode | 20/3/2024 | 17/6/2026 | The Coming Soon & Maintenance Mode by Colorlib plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.99 via the REST API. This makes it possible for unauthenticated attackers to obtain post and page contents via REST API thus bypassing maintenance mode protection provided… | |
| Aplazada | Media (5.3) | 0.59% | — | Dazzler Coming Soon Under Construction Maintenance ModeAI | 20/3/2024 | 17/6/2026 | The Coming Soon, Under Construction & Maintenance Mode By Dazzler plugin for WordPress is vulnerable to maintenance mode bypass in all versions up to, and including, 2.1.2. This is due to the plugin relying on the REQUEST_URI to determine if the page being accesses is an admin area. This makes it possible for… | |
| Modificada | Media (6.5) | 0.76% | — | Libming | 29/2/2024 | 17/6/2026 | A memory leak issue discovered in parseSWF_TEXTRECORD in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file. | |
| Modificada | Media (6.5) | 0.77% | — | Libming | 29/2/2024 | 17/6/2026 | A memory leak issue discovered in parseSWF_GLYPHENTRY in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file. | |
| Modificada | Media (6.5) | 0.75% | — | Libming | 29/2/2024 | 17/6/2026 | A memory leak issue discovered in parseSWF_FILLSTYLEARRAY in libming v0.4.8 allows attackers to cause s denial of service via a crafted SWF file. | |
| Modificada | Media (6.5) | 0.75% | — | Libming | 29/2/2024 | 17/6/2026 | A memory leak issue discovered in parseSWF_DEFINEBUTTON in libming v0.4.8 allows attackers to cause s denial of service via a crafted SWF file. | |
| Modificada | Media (5.3) | 0.46% | — | Awplife Coming Soon Maintenance Mode | 29/2/2024 | 17/6/2026 | The Coming Soon Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.5 via the REST API. This makes it possible for unauthenticated attackers to obtain post and page content thus bypassing the protection provided by the plugin. | |
| Analizada | Alta (7.5) | 0.65% | — | Libming | 28/2/2024 | 17/6/2026 | A memory leak issue discovered in parseSWF_FREECHARACTER in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file. | |
| Modificada | Alta (8.8) | 0.21% | — | Bluecoral Advanced Flamingo | 28/2/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Advanced Flamingo.This issue affects Advanced Flamingo: from n/a through 1.0. | |
| Modificada | Media (5.3) | 0.46% | — | Wpshopmart Coming Soon Page & Maintenance Mode | 28/2/2024 | 17/6/2026 | The Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to unauthorized access of data due to an improperly implemented URL check in the wpsm_coming_soon_redirect function in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to view a site with… | |
| Analizada | Media (4.3) | 0.60% | — | Libming | 26/2/2024 | 17/6/2026 | libming 0.4.8 contains a memory leak vulnerability in /libming/src/actioncompiler/listaction.c. | |
| Modificada | Crítica (9.8) | 0.83% | 💥 PoC | Kallidan KD Coming Soon | 12/2/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Kalli Dan. KD Coming Soon.This issue affects KD Coming Soon: from n/a through 1.7. | |
| Modificada | Media (4.4) | 0.16% | — | Dell Optiplex 3000 Micro FirmwareDell Optiplex 3000 Small Form Factor FirmwareDell Optiplex 3000 Tower FirmwareDell Optiplex 5000 Micro Firmware+287 | 6/2/2024 | 17/6/2026 | Dell BIOS contains a Signed to Unsigned Conversion Error vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to denial of service. | |
| Modificada | Media (5.3) | 0.68% | — | Webfactoryltd Minimal Coming Soon & Maintenance Mode | 5/2/2024 | 17/6/2026 | The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to maintenance mode bypass and information disclosure in all versions up to, and including, 2.37. This is due to the plugin improperly validating the request path. This makes it possible for unauthenticated attackers to bypass maintenance… | |
| Modificada | Alta (8.8) | 18% | — | Mingsoft Mcms | 5/2/2024 | 17/6/2026 | File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do. | |
| Modificada | Alta (7.5) | 1.1% | — | Mingsoft Mcms | 16/1/2024 | 17/6/2026 | An issue in mingSoft MCMS v.5.2.4 allows a a remote attacker to obtain sensitive information via a crafted script to the password parameter. | |
| Modificada | Crítica (9.8) | 2.2% | 💥 Exploit | Mingsoft Mcms | 30/12/2023 | 17/6/2026 | Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/list.do. | |
| Modificada | Crítica (9.8) | 1.3% | — | Libming | 20/12/2023 | 17/6/2026 | Buffer Overflow vulnerability in libming version 0.4.8, allows attackers to execute arbitrary code and obtain sensitive information via parser.c component. | |
| Modificada | Alta (7.5) | 0.73% | — | Bosch Monitor WallBosch Videojet Decoder 7513 FirmwareBosch Videojet Decoder 7523 FirmwareBosch Video Recording Manager+1 | 18/12/2023 | 17/6/2026 | An improper handling of a malformed API request to an API server in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. |