Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
608 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.37% | — | Marcosteinbrecher WP Browserupdate | 17/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marco Steinbrecher WP BrowserUpdate plugin <= 4.5 versions. | |
| Modificada | Alta (7.3) | 0.17% | — | Intel Server Firmware Update Utility | 11/8/2023 | 17/6/2026 | Unquoted search path in the software installer for the System Firmware Update Utility (SysFwUpdt) for some Intel(R) Server Boards and Intel(R) Server Systems Based on Intel(R) 621A Chipset before version 16.0.7 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.5) | 0.22% | — | Disable Wordpress Update Notifications AND Auto-update Email Notifications Project Disable Wordpress Update Notifications AND Auto-update Email Notifications | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Prem Tiwari Disable WordPress Update Notifications and auto-update Email Notifications plugin <= 2.3.3 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Piwebsolution Pi-woocommerce-order-date-time-and-type | 26/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Order date, Order pickup, Order date time, Pickup Location, delivery date for WooCommerce plugin <= 3.0.19 versions. | |
| Modificada | Alta (7.3) | 0.19% | — | Dell Alienware UpdateDell Command UpdateDell Update | 23/6/2023 | 17/6/2026 | Dell Command | Update, Dell Update, and Alienware Update versions 4.8.0 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability leading to privilege escalation. | |
| Modificada | Alta (7.1) | 0.18% | — | Dell Alienware UpdateDell Command UpdateDell Update | 23/6/2023 | 17/6/2026 | Dell Command | Update, Dell Update, and Alienware Update versions 4.9.0, A01 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability to create arbitrary folder leading to permanent Denial of Service (DOS). | |
| Modificada | Media (6.1) | 0.51% | — | Datev EG Personal-management System Comfort/comfort Plus | 22/6/2023 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in DATEV eG Personal-Management System Comfort/Comfort Plus v15.1.0 to v16.1.1 P4 allows attackers to steal targeted users' login data by sending a crafted link. | |
| Modificada | Media (6.7) | 0.16% | — | Intel ONE Boot Flash Update | 10/5/2023 | 17/6/2026 | Improper access control in kernel mode driver for the Intel(R) OFU software before version 14.1.30 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.18% | — | Intel ONE Boot Flash Update | 10/5/2023 | 17/6/2026 | Improper access control in kernel mode driver for the Intel(R) OFU software before version 14.1.30 may allow an authenticated user to potentially enable escalation of privilege via local access | |
| Modificada | Alta (7.8) | 0.15% | — | Intel NUC Hdmi Firmware Update Tool | 10/5/2023 | 17/6/2026 | Incorrect default permissions for the Intel(R) HDMI Firmware Update Tool for NUC before version 1.79.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.3) | 0.20% | — | Intel NUC Hdmi Firmware Update Tool | 10/5/2023 | 17/6/2026 | Uncontrolled search path for the Intel(R) HDMI Firmware Update tool for NUC before version 1.79.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.1) | 0.38% | — | Mauimarketing Update Image TAG ALT Attribute | 10/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Maui Marketing Update Image Tag Alt Attribute plugin <= 2.4.5 versions. | |
| Modificada | Media (4.8) | 0.44% | — | Byconsole Pickup | Delivery | Dine-in Date Time | 8/5/2023 | 17/6/2026 | The Pickup | Delivery | Dine-in date time WordPress plugin through 1.0.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (7.8) | 0.19% | — | Lenovo System Update | 1/5/2023 | 17/6/2026 | A directory permissions management vulnerability in Lenovo System Update may allow elevation of privileges. | |
| Modificada | Alta (7.8) | 1.9% | 💥 PoC | Linux KernelCanonical Ubuntu LinuxFedoraproject FedoraRedhat Enterprise Linux+9 | 27/3/2023 | 17/6/2026 | A buffer overflow vulnerability was found in the Netfilter subsystem in the Linux Kernel. This issue could allow the leakage of both stack and heap addresses, and potentially allow Local Privilege Escalation to the root user via arbitrary code execution. | |
| Modificada | Alta (7.8) | 0.90% | — | X.org X ServerFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux AUS+14 | 27/3/2023 | 17/6/2026 | A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write into freed memory. This can lead to local privilege elevation on systems where the X server runs privileged and remote… | |
| Modificada | Media (5.4) | 0.89% | 💥 Exploit | Technocrackers Bulk Price Update FOR Woocommerce | 22/3/2023 | 17/6/2026 | The Woo Bulk Price Update WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'page' parameter to the techno_get_products action, which can only be triggered by an authenticated user. | |
| Modificada | Crítica (9.6) | 1.5% | — | Jenkins Update-center2 | 10/3/2023 | 17/6/2026 | Jenkins update-center2 3.13 and 3.14 renders the required Jenkins core version on plugin download index pages without sanitization, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a plugin for hosting. | |
| Modificada | Alta (7.8) | 1.8% | — | Ubuntukylin Kylin-system-updater | 8/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in kylin-system-updater up to 1.4.20kord on Ubuntu Kylin. Affected is the function InstallSnap of the component Update Handler. The manipulation leads to command injection. The attack needs to be approached locally. The exploit has been disclosed to the… | |
| Analizada | Alta (8.8) | 1.6% | ⚠ Explotación activa | WebkitgtkWpewebkit WPE WebkitRedhat Codeready Linux BuilderRedhat Codeready Linux Builder EUS+19 | 6/3/2023 | 17/6/2026 | A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues. | |
| Modificada | Media (6.1) | 0.53% | — | Baremetrics Date Range Picker | 21/2/2023 | 17/6/2026 | The Baremetrics date range picker is a solution for selecting both date ranges and single dates from a single calender view. Versions 1.0.14 and prior are prone to cross-site scripting (XSS) when handling untrusted `placeholder` entries. An attacker who is able to influence the field `placeholder` when creating a… | |
| Modificada | Alta (7.8) | 0.17% | — | Administrative Tools FOR Intel Network AdaptersIntel Non-volatile Memory Update Utility | 16/2/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) Network Adapter installer software may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.31% | 💥 PoC | Intel ONE Boot Flash Update | 16/2/2023 | 17/6/2026 | Improper access control in the Intel(R) OFU software before version 14.1.28 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Alta (7.8) | 0.60% | — | Microsoft Defender Security Intelligence Updates | 14/2/2023 | 19/8/2026 | Microsoft Defender for Endpoint Security Feature Bypass Vulnerability | |
| Modificada | Media (6) | 0.18% | — | Dell System Update | 11/2/2023 | 17/6/2026 | Dell System Update, version 2.0.0 and earlier, contains an Improper Certificate Validation in data parser module. A local attacker with high privileges could potentially exploit this vulnerability, leading to credential theft and/or denial of service. |