Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

413 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.1)0.34%—Rockwellautomation Factorytalk Services Platform24/2/202217/6/2026
A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to access local or remote content. A successful exploit could potentially cause a denial-of-service condition and allow the attacker to arbitrarily read any local file via system-level services.
ModificadaAlta (7.8)0.50%—Cobbler Project CobblerOpensuse FactoryOpensuse BackportsSuse Linux Enterprise Server+119/2/202217/6/2026
An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines beginning with #import are blocked.)
ModificadaAlta (7.8)0.29%—Opensuse Factory Watchman26/1/202217/6/2026
A UNIX Symbolic Link (Symlink) Following vulnerability in the systemd service file for watchman of openSUSE Backports SLE-15-SP3, Factory allows local attackers to escalate to root. This issue affects: openSUSE Backports SLE-15-SP3 watchman versions prior to 4.9.0. openSUSE Factory watchman versions prior to 4.9.0-9.1.
ModificadaMedia (4.4)0.21%—Opensuse Factory14/1/202217/6/2026
A Incorrect Default Permissions vulnerability in the parsec package of openSUSE Factory allows local attackers to imitate the service leading to DoS or clients talking to an imposter service. This issue affects: openSUSE Factory parsec versions prior to 0.8.1-1.1.
ModificadaMedia (5.5)1.1%—Uriparser Project UriparserFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraDebian Linux+36/1/202217/6/2026
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.
ModificadaMedia (5.5)1.1%—Uriparser Project UriparserFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraDebian Linux+36/1/202217/6/2026
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.
ModificadaAlta (7.5)2.9%—Ruby-lang CGIRuby-lang RubyRedhat Software CollectionsRedhat Enterprise Linux+51/1/202217/6/2026
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
ModificadaAlta (7.5)3.2%—Ruby-lang DateRuby-lang RubyRedhat Software CollectionsRedhat Enterprise Linux+51/1/202217/6/2026
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.
ModificadaAlta (7.1)1.6%—VIMRedhat Enterprise LinuxOpensuse FactorySuse Linux Enterprise+425/12/202117/6/2026
vim is vulnerable to Out-of-bounds Read
ModificadaAlta (8.8)1.00%—Jfrog Artifactory20/12/202117/6/2026
JFrog Artifactory before 7.25.4 (Enterprise+ deployments only), is vulnerable to Blind SQL Injection by a low privileged authenticated user due to incomplete validation when performing an SQL query.
ModificadaAlta (8.1)1.9%—Webfactoryltd WP Reset PRO18/11/202117/6/2026
Authenticated Database Reset vulnerability in WordPress WP Reset PRO Premium plugin (versions <= 5.98) allows any authenticated user to wipe the entire database regardless of their authorization. It leads to a complete website reset and takeover.
ModificadaAlta (8.8)0.71%—Webfactoryltd WP Reset PRO18/11/202117/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WebFactory Ltd. WP Reset PRO plugin <= 5.98 versions.
ModificadaMedia (6.3)0.61%—Azeotech Daqfactory5/11/202117/6/2026
An attacker could prepare a specially crafted project file that, if opened, would attempt to connect to the cloud and trigger a man in the middle (MiTM) attack. This could allow an attacker to obtain credentials and take over the user’s cloud account.
ModificadaMedia (5.9)0.51%—Azeotech Daqfactory5/11/202117/6/2026
The affected product is vulnerable to cookie information being transmitted as cleartext over HTTP. An attacker can capture network traffic, obtain the user’s cookie and take over the account.
ModificadaAlta (7.8)0.81%—Azeotech Daqfactory5/11/202117/6/2026
Project files are stored memory objects in the form of binary serialized data that can later be read and deserialized again to instantiate the original objects in memory. Malicious manipulation of these files may allow an attacker to corrupt memory.
ModificadaAlta (7.8)0.81%—Azeotech Daqfactory5/11/202117/6/2026
The affected application uses specific functions that could be abused through a crafted project file, which could lead to code execution, system reboot, and system shutdown.
ModificadaMedia (6.1)5.8%💥 ExploitMyfactory FMS18/10/202117/6/2026
myfactory.FMS before 7.1-912 allows XSS via the Error parameter.
ModificadaMedia (6.1)5.8%💥 ExploitMyfactory FMS18/10/202117/6/2026
myfactory.FMS before 7.1-912 allows XSS via the UID parameter.
ModificadaMedia (4.8)0.62%—Dfactory Post Views Counter20/9/202117/6/2026
The Post Views Counter WordPress plugin before 1.3.5 does not sanitise or escape its Post Views Label settings, which could allow high privilege users to perform Cross-Site Scripting attacks in the frontend even when the unfiltered_html capability is disallowed
ModificadaMedia (4.8)0.62%—Webfactoryltd Maintenance23/8/202117/6/2026
The Maintenance WordPress plugin before 4.03 does not sanitise or escape some of its settings, allowing high privilege users such as admin to se Cross-Site Scripting payload in them (even when the unfiltered_html capability is disallowed), which will be triggered in the frontend
ModificadaAlta (7.1)0.30%—Suse Linux Enterprise ServerOpensuse Factory28/7/202117/6/2026
A UNIX Symbolic Link (Symlink) Following vulnerability in the clone-master-clean-up.sh script of clone-master-clean-up in SUSE Linux Enterprise Server 12 SP3, SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allows local attackers to delete arbitrary files. This issue affects: SUSE Linux Enterprise Server 12 SP3…
ModificadaMedia (5.4)0.63%—Webfactoryltd WP Reset12/7/202117/6/2026
The WP Reset – Most Advanced WordPress Reset Tool WordPress plugin before 1.90 did not sanitise or escape its extra_data parameter when creating a snapshot via the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue
ModificadaAlta (7.8)0.37%—Samsung Factorycamerafb8/7/202117/6/2026
Improper access control vulnerability in FactoryCameraFB prior to version 3.4.74 allows untrusted applications to access arbitrary files with an escalated privilege.
ModificadaMedia (6.1)1.2%—Mlfactory Dsgvo ALL IN ONE FOR WP24/5/202117/6/2026
The dsgvoaio_write_log AJAX action of the DSGVO All in one for WP WordPress plugin before 4.0 did not sanitise or escape some POST parameter submitted before outputting them in the Log page in the administrator dashboard (wp-admin/admin.php?page=dsgvoaiofree-show-log). This could allow unauthenticated attackers to…
ModificadaAlta (7.8)0.26%—Opensuse Factory5/5/202117/6/2026
A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to escalate to root. This issue affects: openSUSE Factory virtualbox version 6.1.20-1.1 and prior versions.
Orbitaley — Vulnerabilidades