Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
576 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.42% | — | Sureshkumarmukhiya Anywhere Flash Embed | 22/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Suresh KUMAR Mukhiya Anywhere Flash Embed plugin <= 1.0.5 versions. | |
| Modificada | Media (5.4) | 0.43% | — | Wpembedfb Magic Embeds | 20/11/2023 | 17/6/2026 | The Magic Embeds WordPress plugin before 3.1.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.4) | 0.53% | — | Epiph Embed Privacy | 20/11/2023 | 17/6/2026 | The `Embed Privacy` plugin for WordPress that prevents the loading of embedded external content is vulnerable to Stored Cross-Site Scripting via `embed_privacy_opt_out` shortcode in versions up to, and including, 1.8.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes… | |
| Modificada | Crítica (9.8) | 1.7% | — | Silabs Gecko Software Development KITWeston-embedded Cesium NETWeston-embedded Uc-http | 14/11/2023 | 17/6/2026 | A memory corruption vulnerability exists in the HTTP Server Host header parsing functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 1.5% | — | Silabs Gecko Software Development KITWeston-embedded Cesium NETWeston-embedded Uc-http | 14/11/2023 | 17/6/2026 | A memory corruption vulnerability exists in the HTTP Server header parsing functionality of Weston Embedded uC-HTTP v3.01.01. Specially crafted network packets can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 1.7% | — | Silabs Gecko Software Development KITWeston-embedded Cesium NETWeston-embedded Uc-http | 14/11/2023 | 17/6/2026 | A memory corruption vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 1.8% | — | Silabs Gecko Software Development KITWeston-embedded Cesium NETWeston-embedded Uc-http | 14/11/2023 | 17/6/2026 | A heap-based buffer overflow vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 1.7% | — | Silabs Gecko Software Development KITWeston-embedded Cesium NETWeston-embedded Uc-http | 14/11/2023 | 17/6/2026 | A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted set of network packets can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 1.2% | — | Silabs Gecko Software Development KITWeston-embedded Cesium NETWeston-embedded Uc-http | 14/11/2023 | 17/6/2026 | An out-of-bounds write vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to memory corruption. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Media (6.1) | 0.42% | — | Mpembed WP Matterport Shortcode | 16/10/2023 | 17/6/2026 | The WP Matterport Shortcode WordPress plugin before 2.1.7 does not escape the PHP_SELF server variable when outputting it in attributes, leading to Reflected Cross-Site Scripting issues which could be used against high privilege users such as admin | |
| Modificada | Media (5.4) | 0.47% | — | Mpembed WP Matterport Shortcode | 16/10/2023 | 17/6/2026 | The WP Matterport Shortcode WordPress plugin before 2.1.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.4) | 0.34% | — | Embedcalendly Embed Calendly | 13/10/2023 | 17/6/2026 | The Embed Calendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'calendly' shortcode in versions up to, and including, 3.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above… | |
| Modificada | Crítica (9.8) | 1.1% | — | Oryx-embedded Cyclonetcp | 10/10/2023 | 17/6/2026 | In Oryx CycloneTCP 1.9.6, TCP ISNs are improperly random. | |
| Modificada | Crítica (9.8) | 1.1% | — | Trustedfirmware Mbed TLS | 7/10/2023 | 17/6/2026 | Mbed TLS 3.2.x through 3.4.x before 3.5 has a Buffer Overflow that can lead to remote Code execution. | |
| Modificada | Alta (7.5) | 0.79% | — | ARM Mbed TLSTrustedfirmware Mbed TLSFedoraproject Fedora | 7/10/2023 | 17/6/2026 | Mbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow. | |
| Modificada | Media (4.7) | 0.26% | — | Cisco Wireless LAN Controller SoftwareCisco Catalyst 9800 Embedded Wireless Controller FirmwareCisco Business 150ax FirmwareCisco Business 151axm Firmware | 27/9/2023 | 17/6/2026 | This vulnerability is due to insufficient management of resources when handling certain types of traffic. An attacker could exploit this vulnerability by sending a series of specific wireless packets to an affected device. A successful exploit could allow the attacker to consume resources on an affected device. A… | |
| Modificada | Media (5.4) | 0.43% | — | Mpembed WP Matterport Shortcode | 30/8/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Julien Berthelot / MPEmbed WP Matterport Shortcode plugin <= 2.1.4 versions. | |
| Modificada | Media (6.3) | 0.19% | — | Dell Alienware M15 R7 FirmwareDell Alienware M16 FirmwareDell Alienware M18 FirmwareDell Chengming 3900 Firmware+238 | 16/8/2023 | 17/6/2026 | Dell BIOS contain a Time-of-check Time-of-use vulnerability in BIOS. A local authenticated malicious user with physical access to the system could potentially exploit this vulnerability by using a specifically timed DMA transaction during an SMI in order to gain arbitrary code execution on the system. | |
| Modificada | Media (5.4) | 0.51% | — | Wpdeveloper Embedpress | 10/8/2023 | 17/6/2026 | The EmbedPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embedpress_calendar' shortcode in versions up to, and including, 3.8.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Media (4.3) | 0.52% | — | Wpdeveloper Embedpress | 10/8/2023 | 17/6/2026 | The EmbedPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'admin_post_remove' and 'remove_private_data' functions in versions up to, and including, 3.8.2. This makes it possible for authenticated attackers with subscriber privileges or above, to delete… | |
| Modificada | Crítica (9.8) | 1.0% | — | WIX Embedded Mysql | 28/7/2023 | 17/6/2026 | wix-embedded-mysql v4.6.1 and below was discovered to contain a code injection vulnerability in the component com.wix.mysql.distribution.Setup.apply. This vulnerability is exploited via passing an unchecked argument. | |
| Modificada | Alta (7.8) | 0.17% | — | ARM CompilerARM Compiler FOR Embedded FusaARM Compiler FOR Functional SafetyARM Development Studio+2 | 27/7/2023 | 17/6/2026 | When the directory containing the installer does not have sufficiently restrictive file permissions, an attacker can modify (or replace) the installer to execute malicious code. | |
| Modificada | Alta (7.8) | 0.18% | — | ARM CompilerARM Compiler FOR Embedded FusaARM Compiler FOR Functional SafetyARM Development Studio+7 | 27/7/2023 | 17/6/2026 | When the installation directory does not have sufficiently restrictive file permissions, an attacker can modify files in the installation directory to cause execution of malicious code. | |
| Modificada | Alta (7.5) | 0.54% | — | Secomea Sitemanager Embedded | 17/7/2023 | 17/6/2026 | Use After Free vulnerability in Secomea SiteManager Embedded allows Obstruction. | |
| Modificada | Media (6.5) | 0.80% | — | AMD Epyc 7251 FirmwareAMD Epyc 7281 FirmwareAMD Epyc 7301 FirmwareAMD Epyc 7351 Firmware+84 | 11/7/2023 | 17/6/2026 | A potential power side-channel vulnerability in some AMD processors may allow an authenticated attacker to use the power reporting functionality to monitor a program’s execution inside an AMD SEV VM potentially resulting in a leak of sensitive information. |