Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

390 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)0.26%—Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware M15 R3 FirmwareDell Alienware M15 R4 Firmware+2109/2/202217/6/2026
Select Dell Client Commercial and Consumer platforms contain a pre-boot direct memory access (DMA) vulnerability. An authenticated attacker with physical access to the system may potentially exploit this vulnerability in order to execute arbitrary code on the device.
AnalizadaMedia (6.4)0.24%—Dell Precision 5820 Tower FirmwareDell Precision 7510 FirmwareDell Precision 7520 FirmwareDell Precision 7530 Firmware+40724/1/20227/10/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
AnalizadaMedia (6.4)0.25%—Dell Precision 7510 FirmwareDell Precision 7520 FirmwareDell Precision 7530 FirmwareDell Precision 7540 Firmware+40724/1/20227/10/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
ModificadaMedia (5.5)1.6%—Ultrajson Project UltrajsonDebian LinuxFedoraproject Fedora1/1/202217/6/2026
UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecked (called from encode). Exploitation can, for example, use a large amount of indentation.
ModificadaAlta (8.8)2.3%—HP Color Laserjet Cm4540 MFP FirmwareHP Color Laserjet Enterprise Flow MFP M880z FirmwareHP Color Laserjet Managed Flow MFP M880zm FirmwareHP Color Laserjet Enterprise M455 Firmware+2119/11/202117/6/2026
During installation with certain driver software or application packages an arbitrary code execution could occur.
ModificadaAlta (8.8)1.7%—Accesspressthemes Access Demo ImporterAccesspressthemes Accesspress-liteAccesspressthemes Accesspress-magAccesspressthemes Accesspress-parallax+3911/10/202117/6/2026
A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the…
ModificadaMedia (4.2)0.41%—NXP Mifare Ultralight EV1 FirmwareNXP Mifare Ultralight C FirmwareNXP Mifare Ultralight Nano FirmwareNXP Ntag 210 Firmware+46/6/202117/6/2026
On NXP MIFARE Ultralight and NTAG cards, an attacker can interrupt a write operation (aka conduct a "tear off" attack) over RFID to bypass a Monotonic Counter protection mechanism. The impact depends on how the anti tear-off feature is used in specific applications such as public transportation, physical access…
ModificadaMedia (6.1)0.69%—Blackboard Collaborate Ultra2/3/202117/6/2026
Blackboard Collaborate Ultra 20.02 is affected by a cross-site scripting (XSS) vulnerability. The XSS payload will execute on the class room, which leads to stealing cookies from users who join the class. NOTE: Third-parties dispute the validity of this entry as a possible false positive during research
ModificadaMedia (5.5)0.19%—LG IpsfullhdLG UltrawideLgpcsuite SetupLG Ultra HD Driver Setup14/9/202017/6/2026
A vulnerability that can hijack a DLL file that is loaded during products(LGPCSuite_Setup, IPSFULLHD, LG_ULTRAWIDE, ULTRA_HD_Driver Setup) installation into a DLL file that the hacker wants. Missing Support for Integrity Check vulnerability in ____COMPONENT____ of LG Electronics (LGPCSuite_Setup), (IPSFULLHD,…
ModificadaCrítica (9.8)1.2%—Unisoon Ultralog Express Firmware27/3/202017/6/2026
UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, attackers can inject arbitrary SQL command.
ModificadaAlta (7.5)0.71%—Unisoon Ultralog Express Firmware27/3/202017/6/2026
UltraLog Express device management software stores user’s information in cleartext. Any user can obtain accounts information through a specific page.
ModificadaAlta (8.1)0.84%—Unisoon Ultralog Express Firmware27/3/202017/6/2026
UltraLog Express device management interface does not properly perform access authentication in some specific pages/functions. Any user can access the privileged page to manage accounts through specific system directory.
ModificadaAlta (7.8)0.37%—Ultraedit2/3/202017/6/2026
An issue was discovered in IDM UltraEdit through 24.10.0.32. To exploit the vulnerability, on unpatched Windows systems, an attacker could include in the same directory as the affected executable a DLL using the name of a Windows DLL. This DLL must be preloaded by the executable (for example, "ntmarta.dll"). When the…
ModificadaAlta (7.8)0.45%—Asus Zenfone 3 Ultra Firmware14/11/201917/6/2026
The Asus ZenFone 3 Ultra Android device with a build fingerprint of asus/WW_Phone/ASUS_A001:7.0/NRD90M/14.1010.1804.75-20180612:user/release-keys contains a pre-installed app with a package name of com.asus.splendidcommandagent app (versionCode=1510200105, versionName=1.2.0.21_180605) that allows other pre-installed…
ModificadaAlta (7.8)0.45%—Asus Zenfone 3 Ultra Firmware14/11/201917/6/2026
The Asus ZenFone 3 Ultra Android device with a build fingerprint of asus/WW_Phone/ASUS_A001:7.0/NRD90M/14.1010.1804.75-20180612:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000020, versionName=7.0.0.4_170901) that allows other pre-installed apps…
ModificadaAlta (8.8)2.2%—Western Digital MY Cloud EX2 Ultra Firmware13/11/201917/6/2026
Western Digital My Cloud EX2 Ultra firmware 2.31.195 allows a Buffer Overflow with Extended Instruction Pointer (EIP) control via crafted GET/POST parameters.
ModificadaAlta (8.8)3.2%—Western Digital MY Cloud EX2 Ultra Firmware13/11/201917/6/2026
Western Digital My Cloud EX2 Ultra firmware 2.31.183 allows web users (including guest account) to remotely execute arbitrary code via a stack-based buffer overflow. There is no size verification logic in one of functions in libscheddl.so, and download_mgr.cgi makes it possible to enter large-sized f_idx inputs.
ModificadaAlta (8.8)2.9%—Western Digital MY Cloud EX2 Ultra Firmware13/11/201917/6/2026
Western Digital My Cloud EX2 Ultra firmware 2.31.183 allows web users (including guest accounts) to remotely execute arbitrary code via a download_mgr.cgi stack-based buffer overflow.
ModificadaAlta (8.8)2.0%—Usersultra Users Ultra Membership20/9/201917/6/2026
The users-ultra plugin before 1.5.59 for WordPress has uultra-form-cvs-form-conf arbitrary file upload.
ModificadaAlta (8.8)1.7%—Usersultra Users Ultra Membership20/9/201917/6/2026
The users-ultra plugin before 1.5.64 for WordPress has SQL Injection via an ajax action.
ModificadaAlta (8.8)0.67%—Usersultra Users Ultra Membership20/9/201917/6/2026
The users-ultra plugin before 1.5.63 for WordPress has CSRF via action=package_add_new to wp-admin/admin-ajax.php.
ModificadaMedia (5.4)0.71%—Usersultra Users Ultra Membership20/9/201917/6/2026
The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_desc parameter.
ModificadaMedia (5.4)1.2%—Usersultra Users Ultra Membership20/9/201917/6/2026
The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_name parameter.
ModificadaAlta (8.8)0.85%—Ultra-prod Wordpress Ultra Simple Paypal Shopping Cart12/9/201917/6/2026
Cross-site request forgery (CSRF) vulnerability in WordPress Ultra Simple Paypal Shopping Cart v4.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
ModificadaAlta (8)1.5%—Yealink Ultra-elegant IP Phone Sip-t41p Firmware29/5/201917/6/2026
The diagnostics web interface in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) does not validate (escape) the path information (path traversal), which allows an authenticated remote attacker to get access to privileged information (e.g., /etc/passwd) via path traversal (relative path information…