Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
608 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.32% | — | Lenovo System Update | 8/11/2023 | 17/6/2026 | An uncontrolled search path vulnerability was reported in Lenovo System Update that could allow an attacker with local access to execute code with elevated privileges. | |
| Modificada | Alta (7.8) | 0.27% | — | Redhat Insights-clientRedhat Enterprise LinuxRedhat Enterprise Linux AUSRedhat Enterprise Linux Desktop+15 | 1/11/2023 | 17/6/2026 | A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe handling of temporary files and directories that lead to local privilege escalation. Before the insights-client has been registered on the system by root, an unprivileged local user or attacker could… | |
| Modificada | Media (5.4) | 0.38% | — | Prasadkirpekar WP Meta AND Date Remover | 31/10/2023 | 17/6/2026 | The WP Meta and Date Remover WordPress plugin before 2.2.0 provides an AJAX endpoint for configuring the plugin settings. This endpoint has no capability checks and does not sanitize the user input, which is then later output unescaped. Allowing any authenticated users, such as subscriber change them and perform… | |
| Modificada | Media (5.4) | 0.36% | — | Ipushpull Live Updates From Excel | 31/10/2023 | 17/6/2026 | The Live updates from Excel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ipushpull_page' shortcode in versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Modificada | Alta (7.1) | 0.12% | — | Lenovo System Update PluginLenovo Hardware Scan PluginLenovo Hardware Scan Addin | 27/10/2023 | 17/6/2026 | A denial of service vulnerability was reported in Lenovo Vantage HardwareScan Plugin version 1.3.0.5 and earlier that could allow a local attacker to delete contents of an arbitrary directory under certain conditions. | |
| Modificada | Alta (7.8) | 0.12% | — | Lenovo System Update PluginLenovo Hardware Scan PluginLenovo Hardware Scan Addin | 27/10/2023 | 17/6/2026 | A privilege elevation vulnerability was reported in the Lenovo Vantage SystemUpdate plugin version 2.0.0.212 and earlier that could allow a local attacker to execute arbitrary code with elevated privileges. | |
| Modificada | Media (6.3) | 0.10% | — | Lenovo System Update PluginLenovo Hardware Scan PluginLenovo Hardware Scan Addin | 27/10/2023 | 17/6/2026 | A Time of Check Time of Use (TOCTOU) vulnerability was reported in the Lenovo Vantage SystemUpdate Plugin version 2.0.0.212 and earlier that could allow a local attacker to delete arbitrary files. | |
| Modificada | Media (6.5) | 0.36% | — | Jenkins Lambdatest-automation | 25/10/2023 | 17/6/2026 | Jenkins lambdatest-automation Plugin 1.20.10 and earlier logs LAMBDATEST Credentials access token at the INFO level, potentially resulting in its exposure. | |
| Modificada | Media (4.3) | 0.39% | — | Jenkins Lambdatest-automation | 25/10/2023 | 17/6/2026 | A missing permission check in Jenkins lambdatest-automation Plugin 1.20.9 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of LAMBDATEST credentials stored in Jenkins. | |
| Modificada | Alta (7.8) | 0.28% | — | Linux KernelRedhat Codeready Linux BuilderRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder FOR Arm64+18 | 23/10/2023 | 17/6/2026 | The reference count changes made as part of the CVE-2023-33951 and CVE-2023-33952 fixes exposed a use-after-free flaw in the way memory objects were handled when they were being used to store a surface. When running inside a VMware guest with 3D acceleration enabled, a local, unprivileged user could potentially use… | |
| Modificada | Alta (7.5) | 0.54% | — | HP Thinupdate | 13/10/2023 | 17/6/2026 | A potential security vulnerability has been identified in the HP ThinUpdate utility (also known as HP Recovery Image and Software Download Tool) which may lead to information disclosure. HP is releasing mitigation for the potential vulnerability. | |
| Modificada | Alta (8.8) | 0.27% | — | Dineshkarki Block Plugin Update | 10/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dinesh Karki Block Plugin Update plugin <= 3.3 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Tychesoftwares Order Delivery Date FOR Woocommerce | 10/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ashok Rane Order Delivery Date for WP e-Commerce plugin <= 1.2 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Remove/hide Author, Date, Category Like Entry-meta Project Remove/hide Author, Date, Category Like Entry-meta | 6/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Remove/hide Author, Date, Category Like Entry-Meta plugin <= 2.1 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Iwebss Update Theme AND Plugins From ZIP File | 4/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Jeff Sherk Update Theme and Plugins from Zip File plugin <= 2.0.0 versions. | |
| Analizada | Alta (7.8) | 64% | ⚠ Explotación activa💥 Exploit | Netapp Bootstrap OSSiemens Simatic S7-1500 CPU 1518-4 Pn/dp MFP FirmwareSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Siplus S7-1500 CPU 1518-4 Pn/dp MFP Firmware+35 | 3/10/2023 | 17/6/2026 | A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated… | |
| Modificada | Media (4.8) | 0.37% | — | Tychesoftwares Order Delivery Date FOR WP E-commerce | 2/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ashok Rane Order Delivery Date for WP e-Commerce plugin <= 1.2 versions. | |
| Modificada | Media (6.1) | 0.41% | — | Tychesoftwares Order Delivery Date FOR Woocommerce | 25/9/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Tyche Softwares Order Delivery Date for WooCommerce plugin <= 3.20.0 versions. | |
| Modificada | Alta (7.5) | 32% | 💥 Exploit | Myprestamodules Product Catalog (csv, Excel) ImportUpdateproducts Project Updateproducts | 20/9/2023 | 17/6/2026 | MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInfo information disclosure vulnerability via send.php. | |
| Modificada | Alta (7.8) | 0.23% | — | Corecode Macupdater | 20/9/2023 | 17/6/2026 | An XPC misconfiguration vulnerability in CoreCode MacUpdater before 2.3.8, and 3.x before 3.1.2, allows attackers to escalate privileges by crafting malicious .pkg files. | |
| Modificada | Media (5.9) | 1.6% | — | GNU GlibcRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little EndianRedhat Codeready Linux Builder EUS FOR Power Little Endian EUS+18 | 18/9/2023 | 14/7/2026 | A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the _nss_*_gethostbyname2_r and _nss_*_getcanonname_r hooks without implementing the… | |
| Modificada | Media (6.5) | 1.7% | — | GNU GlibcRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little EndianRedhat Codeready Linux Builder EUS FOR Power Little Endian EUS+23 | 18/9/2023 | 17/6/2026 | A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a… | |
| Modificada | Alta (7.8) | 0.66% | — | Microsoft Windows Defender Security Intelligence Updates | 12/9/2023 | 17/6/2026 | Windows Defender Attack Surface Reduction Security Feature Bypass | |
| Modificada | Alta (7.8) | 0.38% | 💥 PoC | Foxconn Live Update Utility | 11/9/2023 | 17/6/2026 | An issue was discovered in MmMapIoSpace routine in Foxconn Live Update Utility 2.1.6.26, allows local attackers to escalate privileges. | |
| Modificada | Alta (7.8) | 0.24% | — | Redhat Subscription-managerFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+16 | 23/8/2023 | 17/6/2026 | A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.redhat.RHSM1 exposes a significant number of methods to all users that could change the state of the registration. By using the com.redhat.RHSM1.Config.SetAll() method, a… |