Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
390 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.26% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware M15 R3 FirmwareDell Alienware M15 R4 Firmware+210 | 9/2/2022 | 17/6/2026 | Select Dell Client Commercial and Consumer platforms contain a pre-boot direct memory access (DMA) vulnerability. An authenticated attacker with physical access to the system may potentially exploit this vulnerability in order to execute arbitrary code on the device. | |
| Analizada | Media (6.4) | 0.24% | — | Dell Precision 5820 Tower FirmwareDell Precision 7510 FirmwareDell Precision 7520 FirmwareDell Precision 7530 Firmware+407 | 24/1/2022 | 7/10/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. | |
| Analizada | Media (6.4) | 0.25% | — | Dell Precision 7510 FirmwareDell Precision 7520 FirmwareDell Precision 7530 FirmwareDell Precision 7540 Firmware+407 | 24/1/2022 | 7/10/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. | |
| Modificada | Media (5.5) | 1.6% | — | Ultrajson Project UltrajsonDebian LinuxFedoraproject Fedora | 1/1/2022 | 17/6/2026 | UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecked (called from encode). Exploitation can, for example, use a large amount of indentation. | |
| Modificada | Alta (8.8) | 2.3% | — | HP Color Laserjet Cm4540 MFP FirmwareHP Color Laserjet Enterprise Flow MFP M880z FirmwareHP Color Laserjet Managed Flow MFP M880zm FirmwareHP Color Laserjet Enterprise M455 Firmware+211 | 9/11/2021 | 17/6/2026 | During installation with certain driver software or application packages an arbitrary code execution could occur. | |
| Modificada | Alta (8.8) | 1.7% | — | Accesspressthemes Access Demo ImporterAccesspressthemes Accesspress-liteAccesspressthemes Accesspress-magAccesspressthemes Accesspress-parallax+39 | 11/10/2021 | 17/6/2026 | A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the… | |
| Modificada | Media (4.2) | 0.41% | — | NXP Mifare Ultralight EV1 FirmwareNXP Mifare Ultralight C FirmwareNXP Mifare Ultralight Nano FirmwareNXP Ntag 210 Firmware+4 | 6/6/2021 | 17/6/2026 | On NXP MIFARE Ultralight and NTAG cards, an attacker can interrupt a write operation (aka conduct a "tear off" attack) over RFID to bypass a Monotonic Counter protection mechanism. The impact depends on how the anti tear-off feature is used in specific applications such as public transportation, physical access… | |
| Modificada | Media (6.1) | 0.69% | — | Blackboard Collaborate Ultra | 2/3/2021 | 17/6/2026 | Blackboard Collaborate Ultra 20.02 is affected by a cross-site scripting (XSS) vulnerability. The XSS payload will execute on the class room, which leads to stealing cookies from users who join the class. NOTE: Third-parties dispute the validity of this entry as a possible false positive during research | |
| Modificada | Media (5.5) | 0.19% | — | LG IpsfullhdLG UltrawideLgpcsuite SetupLG Ultra HD Driver Setup | 14/9/2020 | 17/6/2026 | A vulnerability that can hijack a DLL file that is loaded during products(LGPCSuite_Setup, IPSFULLHD, LG_ULTRAWIDE, ULTRA_HD_Driver Setup) installation into a DLL file that the hacker wants. Missing Support for Integrity Check vulnerability in ____COMPONENT____ of LG Electronics (LGPCSuite_Setup), (IPSFULLHD,… | |
| Modificada | Crítica (9.8) | 1.2% | — | Unisoon Ultralog Express Firmware | 27/3/2020 | 17/6/2026 | UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, attackers can inject arbitrary SQL command. | |
| Modificada | Alta (7.5) | 0.71% | — | Unisoon Ultralog Express Firmware | 27/3/2020 | 17/6/2026 | UltraLog Express device management software stores user’s information in cleartext. Any user can obtain accounts information through a specific page. | |
| Modificada | Alta (8.1) | 0.84% | — | Unisoon Ultralog Express Firmware | 27/3/2020 | 17/6/2026 | UltraLog Express device management interface does not properly perform access authentication in some specific pages/functions. Any user can access the privileged page to manage accounts through specific system directory. | |
| Modificada | Alta (7.8) | 0.37% | — | Ultraedit | 2/3/2020 | 17/6/2026 | An issue was discovered in IDM UltraEdit through 24.10.0.32. To exploit the vulnerability, on unpatched Windows systems, an attacker could include in the same directory as the affected executable a DLL using the name of a Windows DLL. This DLL must be preloaded by the executable (for example, "ntmarta.dll"). When the… | |
| Modificada | Alta (7.8) | 0.45% | — | Asus Zenfone 3 Ultra Firmware | 14/11/2019 | 17/6/2026 | The Asus ZenFone 3 Ultra Android device with a build fingerprint of asus/WW_Phone/ASUS_A001:7.0/NRD90M/14.1010.1804.75-20180612:user/release-keys contains a pre-installed app with a package name of com.asus.splendidcommandagent app (versionCode=1510200105, versionName=1.2.0.21_180605) that allows other pre-installed… | |
| Modificada | Alta (7.8) | 0.45% | — | Asus Zenfone 3 Ultra Firmware | 14/11/2019 | 17/6/2026 | The Asus ZenFone 3 Ultra Android device with a build fingerprint of asus/WW_Phone/ASUS_A001:7.0/NRD90M/14.1010.1804.75-20180612:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000020, versionName=7.0.0.4_170901) that allows other pre-installed apps… | |
| Modificada | Alta (8.8) | 2.2% | — | Western Digital MY Cloud EX2 Ultra Firmware | 13/11/2019 | 17/6/2026 | Western Digital My Cloud EX2 Ultra firmware 2.31.195 allows a Buffer Overflow with Extended Instruction Pointer (EIP) control via crafted GET/POST parameters. | |
| Modificada | Alta (8.8) | 3.2% | — | Western Digital MY Cloud EX2 Ultra Firmware | 13/11/2019 | 17/6/2026 | Western Digital My Cloud EX2 Ultra firmware 2.31.183 allows web users (including guest account) to remotely execute arbitrary code via a stack-based buffer overflow. There is no size verification logic in one of functions in libscheddl.so, and download_mgr.cgi makes it possible to enter large-sized f_idx inputs. | |
| Modificada | Alta (8.8) | 2.9% | — | Western Digital MY Cloud EX2 Ultra Firmware | 13/11/2019 | 17/6/2026 | Western Digital My Cloud EX2 Ultra firmware 2.31.183 allows web users (including guest accounts) to remotely execute arbitrary code via a download_mgr.cgi stack-based buffer overflow. | |
| Modificada | Alta (8.8) | 2.0% | — | Usersultra Users Ultra Membership | 20/9/2019 | 17/6/2026 | The users-ultra plugin before 1.5.59 for WordPress has uultra-form-cvs-form-conf arbitrary file upload. | |
| Modificada | Alta (8.8) | 1.7% | — | Usersultra Users Ultra Membership | 20/9/2019 | 17/6/2026 | The users-ultra plugin before 1.5.64 for WordPress has SQL Injection via an ajax action. | |
| Modificada | Alta (8.8) | 0.67% | — | Usersultra Users Ultra Membership | 20/9/2019 | 17/6/2026 | The users-ultra plugin before 1.5.63 for WordPress has CSRF via action=package_add_new to wp-admin/admin-ajax.php. | |
| Modificada | Media (5.4) | 0.71% | — | Usersultra Users Ultra Membership | 20/9/2019 | 17/6/2026 | The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_desc parameter. | |
| Modificada | Media (5.4) | 1.2% | — | Usersultra Users Ultra Membership | 20/9/2019 | 17/6/2026 | The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_name parameter. | |
| Modificada | Alta (8.8) | 0.85% | — | Ultra-prod Wordpress Ultra Simple Paypal Shopping Cart | 12/9/2019 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in WordPress Ultra Simple Paypal Shopping Cart v4.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |
| Modificada | Alta (8) | 1.5% | — | Yealink Ultra-elegant IP Phone Sip-t41p Firmware | 29/5/2019 | 17/6/2026 | The diagnostics web interface in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) does not validate (escape) the path information (path traversal), which allows an authenticated remote attacker to get access to privileged information (e.g., /etc/passwd) via path traversal (relative path information… |