Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
444 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.0% | — | School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification | 16/9/2022 | 17/6/2026 | School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/event/index.php?view=edit&id=. | |
| Modificada | Alta (7.2) | 1.0% | — | School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification | 16/9/2022 | 17/6/2026 | School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/modstudent/index.php?view=view&id=. | |
| Modificada | Alta (7.2) | 1.0% | — | School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification | 16/9/2022 | 17/6/2026 | School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/department/index.php?view=edit&id=. | |
| Modificada | Alta (7.2) | 0.88% | — | School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification | 8/9/2022 | 17/6/2026 | School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the component /modules/modstudent/index.php?view=edit&id=. | |
| Modificada | Alta (7.2) | 0.88% | — | School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification | 8/9/2022 | 17/6/2026 | School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the component /modules/autonumber/index.php?view=edit&id=. | |
| Modificada | Alta (7.2) | 0.88% | — | School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification | 8/9/2022 | 17/6/2026 | School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the component /modules/user/index.php?view=edit&id=. | |
| Modificada | Alta (7.8) | 0.19% | — | Dell Alienware UpdateDell Command UpdateDell Update | 2/9/2022 | 17/6/2026 | Dell Command Update, Dell Update and Alienware Update versions prior to 4.6.0 contains a Local Privilege Escalation Vulnerability in the custom catalog configuration. A local malicious user may potentially exploit this vulnerability in order to elevate their privileges. | |
| Modificada | Media (5.5) | 0.29% | — | Linux KernelIBM Spectrum Copy Data ManagementIBM Spectrum Protect PlusDebian Linux+19 | 26/8/2022 | 17/6/2026 | A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS. | |
| Modificada | Media (6.5) | 1.5% | 💥 PoC | Redhat LibvirtCanonical Ubuntu LinuxFedoraproject FedoraRedhat Enterprise Linux+10 | 23/8/2022 | 17/6/2026 | A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the guest is shutting down. An unprivileged… | |
| Modificada | Alta (7.8) | 0.39% | — | LibarchiveFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux EUS+10 | 23/8/2022 | 17/6/2026 | An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may… | |
| Modificada | Alta (7.8) | 0.39% | — | LibarchiveFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux EUS+9 | 23/8/2022 | 17/6/2026 | An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to change the ACL… | |
| Modificada | Crítica (9.8) | 0.63% | — | Update BY Case Project Update BY Case | 12/8/2022 | 17/6/2026 | This Rails gem adds two methods to the ActiveRecord::Base class that allow you to update many records on a single database hit, using a case sql statement for it. Before version 0.1.3 `update_by_case` gem used custom sql strings, and it was not sanitized, making it vulnerable to sql injection. Upgrade to version >=… | |
| Analizada | Media (6.5) | 0.38% | — | Easy Username Updater Project Easy Username Updater | 8/8/2022 | 17/6/2026 | The Easy Username Updater WordPress plugin before 1.0.5 does not implement CSRF checks, which could allow attackers to make a logged in admin change any user's username includes the admin | |
| Modificada | Alta (7.8) | 0.19% | — | Samsung Update | 5/8/2022 | 17/6/2026 | DLL hijacking vulnerability in Samsung Update Setup prior to version 2.2.9.50 allows attackers to execute arbitrary code. | |
| Modificada | Media (4.8) | 0.59% | — | Linkedin Company Updates Project Linkedin Company Updates | 17/7/2022 | 17/6/2026 | The LinkedIn Company Updates WordPress plugin through 1.5.3 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Alta (7) | 0.46% | — | GNU Grub2Redhat Developer ToolsRedhat OpenshiftRedhat Enterprise Linux+8 | 6/7/2022 | 17/6/2026 | A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a malicious format and payload. This vulnerability can lead to data… | |
| Modificada | Media (4.5) | 0.47% | — | GNU Grub2Redhat Developer ToolsRedhat OpenshiftRedhat Enterprise Linux+9 | 6/7/2022 | 17/6/2026 | A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it's very complex to an attacker control the encoding and positioning of corrupted Huffman… | |
| Modificada | Media (4.5) | 0.46% | — | GNU Grub2Fedoraproject FedoraRedhat Developer ToolsRedhat Openshift+10 | 6/7/2022 | 17/6/2026 | A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue has a high complexity to be exploited as an attacker needs to perform… | |
| Modificada | Alta (7.8) | 0.92% | — | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure DiagnosticsMicrosoft Azure Security Center+6 | 15/6/2022 | 17/6/2026 | Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability | |
| Modificada | Alta (8.1) | 0.52% | — | ONE Click Plugin Updater Project ONE Click Plugin Updater | 13/6/2022 | 17/6/2026 | The One Click Plugin Updater WordPress plugin through 2.4.14 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and disable / hide the badge of the available updates and the related check. | |
| Modificada | Alta (8.8) | 0.57% | — | Theupdateframework Go-tuf | 5/5/2022 | 17/6/2026 | go-tuf is a Go implementation of The Update Framework (TUF). go-tuf does not correctly implement the client workflow for updating the metadata files for roles other than the root role. Specifically, checks for rollback attacks are not implemented correctly meaning an attacker can cause clients to install software that… | |
| Modificada | Alta (8.8) | 4.2% | 💥 PoC | Podman Project PodmanPsgo Project PsgoRedhat Developer ToolsRedhat Enterprise Linux Server Update Services FOR SAP Solutions+12 | 29/4/2022 | 17/6/2026 | A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem,… | |
| Modificada | Alta (7.8) | 0.26% | — | Lenovo System Update | 22/4/2022 | 17/6/2026 | A vulnerability was reported in Lenovo System Update that could allow a local user with interactive system access the ability to execute code with elevated privileges only during the installation of a System Update package released before 2022-02-25 that displays a command prompt window. | |
| Modificada | Alta (7.8) | 1.0% | — | Schneider-electric Software Update | 13/4/2022 | 17/6/2026 | A CWE-502: Deserialization of Untrusted Data vulnerability exists which could allow an attacker to execute arbitrary code on the targeted system with SYSTEM privileges when placing a malicious user to be authenticated for this vulnerability to be successfully exploited. Affected Product: Schneider Electric Software… | |
| Modificada | Alta (7.8) | 0.39% | — | Samsung Update | 11/4/2022 | 17/6/2026 | Uncontrolled search path element vulnerability in Samsung Update prior to version 3.0.77.0 allows attackers to execute arbitrary code as Samsung Update permission. |