Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
444 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.38% | — | Mauimarketing Update Image TAG ALT Attribute | 10/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Maui Marketing Update Image Tag Alt Attribute plugin <= 2.4.5 versions. | |
| Modificada | Alta (7.8) | 0.19% | — | Lenovo System Update | 1/5/2023 | 17/6/2026 | A directory permissions management vulnerability in Lenovo System Update may allow elevation of privileges. | |
| Modificada | Alta (7.8) | 1.9% | 💥 PoC | Linux KernelCanonical Ubuntu LinuxFedoraproject FedoraRedhat Enterprise Linux+9 | 27/3/2023 | 17/6/2026 | A buffer overflow vulnerability was found in the Netfilter subsystem in the Linux Kernel. This issue could allow the leakage of both stack and heap addresses, and potentially allow Local Privilege Escalation to the root user via arbitrary code execution. | |
| Modificada | Alta (7.8) | 0.90% | — | X.org X ServerFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux AUS+14 | 27/3/2023 | 17/6/2026 | A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write into freed memory. This can lead to local privilege elevation on systems where the X server runs privileged and remote… | |
| Modificada | Media (5.4) | 0.89% | 💥 Exploit | Technocrackers Bulk Price Update FOR Woocommerce | 22/3/2023 | 17/6/2026 | The Woo Bulk Price Update WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'page' parameter to the techno_get_products action, which can only be triggered by an authenticated user. | |
| Modificada | Crítica (9.6) | 1.5% | — | Jenkins Update-center2 | 10/3/2023 | 17/6/2026 | Jenkins update-center2 3.13 and 3.14 renders the required Jenkins core version on plugin download index pages without sanitization, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a plugin for hosting. | |
| Modificada | Alta (7.8) | 1.8% | — | Ubuntukylin Kylin-system-updater | 8/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in kylin-system-updater up to 1.4.20kord on Ubuntu Kylin. Affected is the function InstallSnap of the component Update Handler. The manipulation leads to command injection. The attack needs to be approached locally. The exploit has been disclosed to the… | |
| Modificada | Alta (8.8) | 1.6% | ⚠ Explotación activa | WebkitgtkWpewebkit WPE WebkitRedhat Codeready Linux BuilderRedhat Codeready Linux Builder EUS+19 | 6/3/2023 | 7/10/2026 | A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues. | |
| Modificada | Alta (7.8) | 0.17% | — | Administrative Tools FOR Intel Network AdaptersIntel Non-volatile Memory Update Utility | 16/2/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) Network Adapter installer software may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.31% | 💥 PoC | Intel ONE Boot Flash Update | 16/2/2023 | 17/6/2026 | Improper access control in the Intel(R) OFU software before version 14.1.28 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Alta (7.8) | 0.60% | — | Microsoft Defender Security Intelligence Updates | 14/2/2023 | 19/8/2026 | Microsoft Defender for Endpoint Security Feature Bypass Vulnerability | |
| Modificada | Media (6) | 0.18% | — | Dell System Update | 11/2/2023 | 17/6/2026 | Dell System Update, version 2.0.0 and earlier, contains an Improper Certificate Validation in data parser module. A local attacker with high privileges could potentially exploit this vulnerability, leading to credential theft and/or denial of service. | |
| Modificada | Alta (7.8) | 0.23% | — | Dell Alienware UpdateDell Command UpdateDell Supportassist FOR Business PCSDell Supportassist FOR Home PCS+1 | 11/2/2023 | 17/6/2026 | Dell SupportAssist Client Consumer (version 3.11.1 and prior), SupportAssist Client Commercial (version 3.2 and prior), Dell Command | Update, Dell Update, and Alienware Update versions before 4.5 contain a Local Privilege Escalation Vulnerability in the Advanced Driver Restore component. A local malicious user may… | |
| Modificada | Alta (7.1) | 0.18% | — | Dell Alienware UpdateDell Command Update | 10/2/2023 | 17/6/2026 | Dell Command | Update, Dell Update, and Alienware Update versions before 4.6.0 and 4.7.1 contain Insecure Operation on Windows Junction in the installer component. A local malicious user may potentially exploit this vulnerability leading to arbitrary file delete. | |
| Modificada | Alta (8.8) | 0.95% | — | Fedoraproject SssdRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux FOR IBM Z Systems+9 | 1/2/2023 | 17/6/2026 | sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters | |
| Modificada | Alta (7.8) | 0.15% | — | Dell Alienware UpdateDell Command UpdateDell Update | 1/2/2023 | 17/6/2026 | Dell Command | Update, Dell Update, and Alienware Update versions prior to 4.7 contain a improper verification of cryptographic signature in get applicable driver component. A local malicious user could potentially exploit this vulnerability leading to malicious payload execution. | |
| Modificada | Media (5.5) | 0.18% | — | Dell Alienware UpdateDell Command UpdateDell Update | 1/2/2023 | 17/6/2026 | Dell Command | Update, Dell Update, and Alienware Update versions prior to 4.7 contain a Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in download operation component. A local malicious user could potentially exploit this vulnerability leading to the disclosure of… | |
| Modificada | Media (5.5) | 0.20% | — | Jenkins Testquality Updater | 26/1/2023 | 17/6/2026 | Jenkins TestQuality Updater Plugin 1.3 and earlier stores the TestQuality Updater password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system. | |
| Modificada | Media (6.5) | 0.72% | — | Jenkins Testquality Updater | 26/1/2023 | 17/6/2026 | A missing check in Jenkins TestQuality Updater Plugin 1.3 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified username and password. | |
| Modificada | Alta (8.8) | 0.52% | — | Jenkins Testquality Updater | 26/1/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins TestQuality Updater Plugin 1.3 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified username and password. | |
| Modificada | Media (5.3) | 0.65% | — | Nsupdate.info | 27/12/2022 | 17/6/2026 | A vulnerability classified as problematic has been found in nsupdate.info. This affects an unknown part of the file src/nsupdate/settings/base.py of the component CSRF Cookie Handler. The manipulation of the argument CSRF_COOKIE_HTTPONLY leads to cookie without 'httponly' flag. It is possible to initiate the attack… | |
| Modificada | Alta (8.6) | 0.51% | — | GNU Grub2Fedoraproject FedoraRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR Power Little Endian EUS+4 | 14/12/2022 | 17/6/2026 | A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size value, allocating a smaller than needed buffer for the glyph, this further leads to a buffer overflow and a heap based out-of-bounds write. An attacker may use this… | |
| Modificada | Crítica (9.8) | 0.90% | — | School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification | 27/10/2022 | 17/6/2026 | School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /modules/announcement/index.php?view=edit&id=. | |
| Modificada | Media (5.5) | 0.29% | — | Pulpproject Pulp AnsibleRedhat Ansible Automation PlatformRedhat SatelliteRedhat Update Infrastructure | 25/10/2022 | 17/6/2026 | The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only. | |
| Modificada | Media (6) | 0.17% | — | AsusliveupdateAsussoftwaremangerAsus System Control Interface | 18/10/2022 | 17/6/2026 | AsusSoftwareManager.exe in ASUS System Control Interface on ASUS personal computers (running Windows) allows a local user to write into the Temp directory and delete another more privileged file via SYSTEM privileges. This affects ASUS System Control Interface 3 before 3.1.5.0, AsusSoftwareManger.exe before 1.0.53.0,… |