Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
413 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.1) | 0.34% | — | Rockwellautomation Factorytalk Services Platform | 24/2/2022 | 17/6/2026 | A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to access local or remote content. A successful exploit could potentially cause a denial-of-service condition and allow the attacker to arbitrarily read any local file via system-level services. | |
| Modificada | Alta (7.8) | 0.50% | — | Cobbler Project CobblerOpensuse FactoryOpensuse BackportsSuse Linux Enterprise Server+1 | 19/2/2022 | 17/6/2026 | An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines beginning with #import are blocked.) | |
| Modificada | Alta (7.8) | 0.29% | — | Opensuse Factory Watchman | 26/1/2022 | 17/6/2026 | A UNIX Symbolic Link (Symlink) Following vulnerability in the systemd service file for watchman of openSUSE Backports SLE-15-SP3, Factory allows local attackers to escalate to root. This issue affects: openSUSE Backports SLE-15-SP3 watchman versions prior to 4.9.0. openSUSE Factory watchman versions prior to 4.9.0-9.1. | |
| Modificada | Media (4.4) | 0.21% | — | Opensuse Factory | 14/1/2022 | 17/6/2026 | A Incorrect Default Permissions vulnerability in the parsec package of openSUSE Factory allows local attackers to imitate the service leading to DoS or clients talking to an imposter service. This issue affects: openSUSE Factory parsec versions prior to 0.8.1-1.1. | |
| Modificada | Media (5.5) | 1.1% | — | Uriparser Project UriparserFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraDebian Linux+3 | 6/1/2022 | 17/6/2026 | An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax. | |
| Modificada | Media (5.5) | 1.1% | — | Uriparser Project UriparserFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraDebian Linux+3 | 6/1/2022 | 17/6/2026 | An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner. | |
| Modificada | Alta (7.5) | 2.9% | — | Ruby-lang CGIRuby-lang RubyRedhat Software CollectionsRedhat Enterprise Linux+5 | 1/1/2022 | 17/6/2026 | CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby. | |
| Modificada | Alta (7.5) | 3.2% | — | Ruby-lang DateRuby-lang RubyRedhat Software CollectionsRedhat Enterprise Linux+5 | 1/1/2022 | 17/6/2026 | Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1. | |
| Modificada | Alta (7.1) | 1.6% | — | VIMRedhat Enterprise LinuxOpensuse FactorySuse Linux Enterprise+4 | 25/12/2021 | 17/6/2026 | vim is vulnerable to Out-of-bounds Read | |
| Modificada | Alta (8.8) | 1.00% | — | Jfrog Artifactory | 20/12/2021 | 17/6/2026 | JFrog Artifactory before 7.25.4 (Enterprise+ deployments only), is vulnerable to Blind SQL Injection by a low privileged authenticated user due to incomplete validation when performing an SQL query. | |
| Modificada | Alta (8.1) | 1.9% | — | Webfactoryltd WP Reset PRO | 18/11/2021 | 17/6/2026 | Authenticated Database Reset vulnerability in WordPress WP Reset PRO Premium plugin (versions <= 5.98) allows any authenticated user to wipe the entire database regardless of their authorization. It leads to a complete website reset and takeover. | |
| Modificada | Alta (8.8) | 0.71% | — | Webfactoryltd WP Reset PRO | 18/11/2021 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WebFactory Ltd. WP Reset PRO plugin <= 5.98 versions. | |
| Modificada | Media (6.3) | 0.61% | — | Azeotech Daqfactory | 5/11/2021 | 17/6/2026 | An attacker could prepare a specially crafted project file that, if opened, would attempt to connect to the cloud and trigger a man in the middle (MiTM) attack. This could allow an attacker to obtain credentials and take over the user’s cloud account. | |
| Modificada | Media (5.9) | 0.51% | — | Azeotech Daqfactory | 5/11/2021 | 17/6/2026 | The affected product is vulnerable to cookie information being transmitted as cleartext over HTTP. An attacker can capture network traffic, obtain the user’s cookie and take over the account. | |
| Modificada | Alta (7.8) | 0.81% | — | Azeotech Daqfactory | 5/11/2021 | 17/6/2026 | Project files are stored memory objects in the form of binary serialized data that can later be read and deserialized again to instantiate the original objects in memory. Malicious manipulation of these files may allow an attacker to corrupt memory. | |
| Modificada | Alta (7.8) | 0.81% | — | Azeotech Daqfactory | 5/11/2021 | 17/6/2026 | The affected application uses specific functions that could be abused through a crafted project file, which could lead to code execution, system reboot, and system shutdown. | |
| Modificada | Media (6.1) | 5.8% | 💥 Exploit | Myfactory FMS | 18/10/2021 | 17/6/2026 | myfactory.FMS before 7.1-912 allows XSS via the Error parameter. | |
| Modificada | Media (6.1) | 5.8% | 💥 Exploit | Myfactory FMS | 18/10/2021 | 17/6/2026 | myfactory.FMS before 7.1-912 allows XSS via the UID parameter. | |
| Modificada | Media (4.8) | 0.62% | — | Dfactory Post Views Counter | 20/9/2021 | 17/6/2026 | The Post Views Counter WordPress plugin before 1.3.5 does not sanitise or escape its Post Views Label settings, which could allow high privilege users to perform Cross-Site Scripting attacks in the frontend even when the unfiltered_html capability is disallowed | |
| Modificada | Media (4.8) | 0.62% | — | Webfactoryltd Maintenance | 23/8/2021 | 17/6/2026 | The Maintenance WordPress plugin before 4.03 does not sanitise or escape some of its settings, allowing high privilege users such as admin to se Cross-Site Scripting payload in them (even when the unfiltered_html capability is disallowed), which will be triggered in the frontend | |
| Modificada | Alta (7.1) | 0.30% | — | Suse Linux Enterprise ServerOpensuse Factory | 28/7/2021 | 17/6/2026 | A UNIX Symbolic Link (Symlink) Following vulnerability in the clone-master-clean-up.sh script of clone-master-clean-up in SUSE Linux Enterprise Server 12 SP3, SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allows local attackers to delete arbitrary files. This issue affects: SUSE Linux Enterprise Server 12 SP3… | |
| Modificada | Media (5.4) | 0.63% | — | Webfactoryltd WP Reset | 12/7/2021 | 17/6/2026 | The WP Reset – Most Advanced WordPress Reset Tool WordPress plugin before 1.90 did not sanitise or escape its extra_data parameter when creating a snapshot via the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue | |
| Modificada | Alta (7.8) | 0.37% | — | Samsung Factorycamerafb | 8/7/2021 | 17/6/2026 | Improper access control vulnerability in FactoryCameraFB prior to version 3.4.74 allows untrusted applications to access arbitrary files with an escalated privilege. | |
| Modificada | Media (6.1) | 1.2% | — | Mlfactory Dsgvo ALL IN ONE FOR WP | 24/5/2021 | 17/6/2026 | The dsgvoaio_write_log AJAX action of the DSGVO All in one for WP WordPress plugin before 4.0 did not sanitise or escape some POST parameter submitted before outputting them in the Log page in the administrator dashboard (wp-admin/admin.php?page=dsgvoaiofree-show-log). This could allow unauthenticated attackers to… | |
| Modificada | Alta (7.8) | 0.26% | — | Opensuse Factory | 5/5/2021 | 17/6/2026 | A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to escalate to root. This issue affects: openSUSE Factory virtualbox version 6.1.20-1.1 and prior versions. |