Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

374 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)3.7%—Dlink Di-7200gv2 Firmware4/2/202217/6/2026
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function wget_test.asp. This vulnerability allows attackers to execute arbitrary commands via the url parameter.
ModificadaMedia (4.4)0.21%—Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+13120/11/202117/6/2026
NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to gain access to information from unscrubbed memory, which may lead to information disclosure.
ModificadaMedia (4.4)0.21%—Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+13120/11/202117/6/2026
NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to gain access to information from unscrubbed registers, which may lead to information disclosure.
ModificadaMedia (4.1)0.21%—Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+13120/11/202117/6/2026
NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller, which may allow a user with elevated privileges to access protected information by identifying, exploiting, and loading vulnerable microcode. Such an attack may lead to information disclosure.
ModificadaMedia (4.4)0.20%—Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+10320/11/202117/6/2026
NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to corrupt program data.
ModificadaMedia (4.4)0.21%—Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+13120/11/202117/6/2026
NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to access debug registers during runtime, which may lead to information disclosure.
ModificadaMedia (4.4)0.21%—Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+13120/11/202117/6/2026
NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to utilize debug mechanisms with insufficient access control, which may lead to information disclosure.
ModificadaMedia (4.3)0.48%—Gvectors Wpdiscuz8/11/202117/6/2026
The wpDiscuz WordPress plugin before 7.3.4 does check for CSRF when adding, editing and deleting comments, which could allow attacker to make logged in users such as admin edit and delete arbitrary comment, or the user who made the comment to edit it via a CSRF attack. Attackers could also make logged in users post…
ModificadaCrítica (9.1)3.8%💥 ExploitLegalweb WP Dsgvo Tools5/11/202117/6/2026
WP DSGVO Tools (GDPR) <= 3.1.23 had an AJAX action, ‘admin-dismiss-unsubscribe‘, which lacked a capability check and a nonce check and was available to unauthenticated users, and did not check the post type when deleting unsubscription requests. As such, it was possible for an attacker to permanently delete an…
ModificadaMedia (6.5)1.9%—Nagvis14/10/202117/6/2026
The Manage Backgrounds functionality within NagVis versions prior to 1.9.29 is vulnerable to an authenticated path traversal vulnerability. Exploitation of this results in a malicious actor having the ability to arbitrarily delete files on the local system.
ModificadaMedia (4.8)0.62%—Gvectors Wpdiscuz11/10/202117/6/2026
The Comments – wpDiscuz WordPress plugin through 7.3.0 does not properly sanitise or escape the Follow and Unfollow messages before outputting them in the page, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaMedia (6.1)2.9%💥 ExploitGvectors Wpforo Forum6/7/202117/6/2026
The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum, leading to an open redirect issue after a successful login. Such issue could allow an attacker to induce a user to use a login URL redirecting to a website under their control and being a replica…
ModificadaMedia (6.1)1.2%—Mlfactory Dsgvo ALL IN ONE FOR WP24/5/202117/6/2026
The dsgvoaio_write_log AJAX action of the DSGVO All in one for WP WordPress plugin before 4.0 did not sanitise or escape some POST parameter submitted before outputting them in the Log page in the administrator dashboard (wp-admin/admin.php?page=dsgvoaiofree-show-log). This could allow unauthenticated attackers to…
ModificadaCrítica (9.8)6.9%—Mitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+3719/2/202117/6/2026
Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all…
ModificadaCrítica (9.8)3.9%—Mitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+3719/2/202117/6/2026
Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all versions, FR Configurator SW3…
ModificadaAlta (7.5)1.0%—Hilscher Profinet IO Device FirmwarePepperl-fuchs Pgv100-f200a-b17-v1d FirmwarePepperl-fuchs Pgv150i-f200a-b17-v1d FirmwarePepperl-fuchs Pgv100-f200-b17-v1d-7477 Firmware+2016/2/202117/6/2026
A Denial of Service vulnerability was found in Hilscher PROFINET IO Device V3 in versions prior to V3.14.0.7. This may lead to unexpected loss of cyclic communication or interruption of acyclic communication.
ModificadaAlta (7.7)21%💥 ExploitSpring-boot-actuator-logview Project Spring-boot-actuator-logview5/1/202117/6/2026
spring-boot-actuator-logview in a library that adds a simple logfile viewer as spring boot actuator endpoint. It is maven package "eu.hinsch:spring-boot-actuator-logview". In spring-boot-actuator-logview before version 0.2.13 there is a directory traversal vulnerability. The nature of this library is to expose a log…
ModificadaCrítica (10)95%💥 ExploitGvectors Wpdiscuz24/8/202017/6/2026
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, including PHP files via the wmuUploadFiles AJAX action.
ModificadaAlta (7.5)0.92%—Megvii Koala Firmware14/8/202017/6/2026
Lack of authentication in the network relays used in MEGVII Koala 2.9.1-c3s allows attackers to grant physical access to anyone by sending packet data to UDP port 5000.
ModificadaCrítica (9.8)1.8%—Geovision Gv-as210 FirmwareGeovision Gv-as410 FirmwareGeovision Gv-as810 FirmwareGeovision Gv-gf1921 Firmware+28/7/202017/6/2026
Buffer overflow exists in Geovision Door Access Control device family, an unauthenticated remote attacker can execute arbitrary command.
ModificadaAlta (7.5)1.3%—Mitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric EM ConfiguratorMitsubishielectric GT Designer3+1630/6/202017/6/2026
Uncontrolled resource consumption vulnerability in Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, EM Software Development Kit (EM Configurator) Ver. 1.010L and earlier, GT Designer3 (GOT2000) Ver. 1.221F and earlier,…
ModificadaAlta (7.5)1.4%—Mitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric EM ConfiguratorMitsubishielectric GT Designer3+1630/6/202017/6/2026
Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, EM Software Development Kit (EM Configurator) Ver. 1.010L and earlier, GT Designer3 (GOT2000) Ver. 1.221F and earlier, GX LogViewer Ver. 1.96A and earlier, GX Works2 Ver.…
ModificadaCrítica (9.8)13%💥 ExploitGvectors Wpdiscuz18/6/202017/6/2026
A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the order parameter of a wpdLoadMoreComments request. (No 7.x versions are affected.)
ModificadaMedia (6.1)0.93%—Gvectors Wpforo15/6/202017/6/2026
The wpForo plugin 1.6.5 for WordPress allows XSS involving the wpf-dw-td-value class of dashboard.php.
ModificadaMedia (6.1)0.93%—Gvectors Wpforo15/6/202017/6/2026
The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases langid parameter.