Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

1829 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.2)0.34%—Eaton Intelligent Power Protector16/4/202617/6/2026
Due to improper input validation in one of the Eaton Intelligent Power Protector (IPP) XML, it is possible for an attacker with admin privileges and access to the local system to inject malicious code resulting in arbitrary command execution. This security issue has been fixed in the latest version of Eaton IPP…
AnalizadaMedia (5.5)0.13%—Dell Powerprotect Data Manager8/4/202624/7/2026
Dell PowerProtect Agent Service, version(s) prior to 20.1, contain(s) an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
AplazadaAlta (7.2)0.64%—Spam Protect FOR Contact Form 7AI2/4/202617/6/2026
The Spam Protect for Contact Form 7 WordPress plugin before 1.2.10 allows logging to a PHP file, which could allow an attacker with editor access to achieve Remote Code Execution by using a crafted header
AnalizadaAlta (8.8)0.25%—IBM Storage Protect Server1/4/202617/6/2026
IBM Storage Protect Server 8.2.0 IBM Storage Protect Plus Server is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
AnalizadaMedia (6.1)0.33%—Libops Captcha Protect31/3/202624/7/2026
Captcha Protect is a Traefik middleware to add an anti-bot challenge to individual IPs in a subnet when traffic spikes are detected from that subnet. Prior to version 1.12.2, a reflected cross-site scripting (XSS) vulnerability exists in github.com/libops/captcha-protect. The challenge page accepted a client-supplied…
Pendiente de análisisMedia (5.3)0.15%—Eset ProtectAI30/3/202617/6/2026
User enumeration in ESET Protect (on-prem) via Response Timing.
AplazadaMedia (6.8)0.54%—Nysl Spam Protect FOR Contact Form 7AI25/3/202617/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NYSL Spam Protect for Contact Form 7 wp-contact-form-7-spam-blocker allows Path Traversal.This issue affects Spam Protect for Contact Form 7: from n/a through <= 1.2.9.
AnalizadaMedia (6.6)0.47%—Qnap Hyper Data Protector12/3/202617/6/2026
A use of hard-coded password vulnerability has been reported to affect Hyper Data Protector. The remote attackers can then exploit the vulnerability to gain unauthorized access. We have already fixed the vulnerability in the following version: Hyper Data Protector 2.3.1.455 and later
AplazadaAlta (7.5)0.34%—ZIP Code Based Content ProtectionAI7/3/202617/6/2026
The ZIP Code Based Content Protection plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.0.2 via the 'zipcode' parameter. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
ModificadaAlta (7.8)0.15%—Acronis AgentAcronis Cyber Protect6/3/202617/6/2026
Local privilege escalation due to insecure Unix socket permissions. The following products are affected: Acronis Cyber Protect 17 (macOS) before build 41186, Acronis Cyber Protect Cloud Agent (macOS) before build 41124, Acronis True Image (macOS) before build 42902.
AnalizadaMedia (4.3)0.28%—Acronis Cyber Protect6/3/202617/6/2026
Sensitive information disclosure due to improper access control. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.
AnalizadaMedia (5.5)0.16%—Acronis Cyber Protect6/3/202617/6/2026
Sensitive information disclosure due to improper configuration of a headless browser. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.
AnalizadaMedia (4.3)0.28%—Acronis Cyber Protect6/3/202617/6/2026
Unauthorized data access due to insufficient access control validation. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.
AnalizadaMedia (4.3)0.27%—Acronis Cyber Protect6/3/202617/6/2026
Unauthorized report deletion due to insufficient access control. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.
AnalizadaAlta (7.3)0.16%—Acronis Cyber Protect6/3/202617/6/2026
Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186.
AnalizadaAlta (7.3)0.16%—Acronis Cyber Protect6/3/202617/6/2026
Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186.
AnalizadaMedia (4.3)0.27%—Acronis Cyber Protect6/3/202617/6/2026
Unauthorized modification of settings due to insufficient authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.
AnalizadaMedia (4.3)0.27%—Acronis Cyber Protect6/3/202617/6/2026
Unauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.
AnalizadaAlta (7.5)0.64%—Acronis Cyber Protect6/3/202617/6/2026
Denial of service due to insufficient input validation in authentication logging. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.
AnalizadaMedia (5)0.13%—Acronis Cyber Protect6/3/202617/6/2026
Local privilege escalation due to improper directory permissions. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186.
AnalizadaMedia (4.4)0.14%—Acronis Cyber Protect6/3/202617/6/2026
Information disclosure and manipulation due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.
AnalizadaMedia (6.5)0.36%—Acronis Cyber Protect6/3/202617/6/2026
Sensitive information disclosure due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.
AnalizadaMedia (4.8)0.19%—Acronis Cyber Protect6/3/202617/6/2026
Unnecessary transmission of sensitive cryptographic material. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.
AnalizadaAlta (7.1)0.29%—Acronis AgentAcronis Cyber Protect6/3/202617/6/2026
Default credentials set for local privileged user in Virtual Appliance. The following products are affected: Acronis Cyber Protect Cloud Agent (VMware) before build 36943, Acronis Cyber Protect 17 (VMware) before build 41186.
AnalizadaMedia (6.3)0.13%—Acronis Cyber Protect6/3/202617/6/2026
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186.
Orbitaley — Vulnerabilidades