Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

608 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.37%—Marcosteinbrecher WP Browserupdate17/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marco Steinbrecher WP BrowserUpdate plugin <= 4.5 versions.
ModificadaAlta (7.3)0.17%—Intel Server Firmware Update Utility11/8/202317/6/2026
Unquoted search path in the software installer for the System Firmware Update Utility (SysFwUpdt) for some Intel(R) Server Boards and Intel(R) Server Systems Based on Intel(R) 621A Chipset before version 16.0.7 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.5)0.22%—Disable Wordpress Update Notifications AND Auto-update Email Notifications Project Disable Wordpress Update Notifications AND Auto-update Email Notifications11/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Prem Tiwari Disable WordPress Update Notifications and auto-update Email Notifications plugin <= 2.3.3 versions.
ModificadaMedia (4.8)0.37%—Piwebsolution Pi-woocommerce-order-date-time-and-type26/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Order date, Order pickup, Order date time, Pickup Location, delivery date for WooCommerce plugin <= 3.0.19 versions.
ModificadaAlta (7.3)0.19%—Dell Alienware UpdateDell Command UpdateDell Update23/6/202317/6/2026
Dell Command | Update, Dell Update, and Alienware Update versions 4.8.0 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability leading to privilege escalation.
ModificadaAlta (7.1)0.18%—Dell Alienware UpdateDell Command UpdateDell Update23/6/202317/6/2026
Dell Command | Update, Dell Update, and Alienware Update versions 4.9.0, A01 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability to create arbitrary folder leading to permanent Denial of Service (DOS).
ModificadaMedia (6.1)0.51%—Datev EG Personal-management System Comfort/comfort Plus22/6/202317/6/2026
A reflected cross-site scripting (XSS) vulnerability in DATEV eG Personal-Management System Comfort/Comfort Plus v15.1.0 to v16.1.1 P4 allows attackers to steal targeted users' login data by sending a crafted link.
ModificadaMedia (6.7)0.16%—Intel ONE Boot Flash Update10/5/202317/6/2026
Improper access control in kernel mode driver for the Intel(R) OFU software before version 14.1.30 may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.18%—Intel ONE Boot Flash Update10/5/202317/6/2026
Improper access control in kernel mode driver for the Intel(R) OFU software before version 14.1.30 may allow an authenticated user to potentially enable escalation of privilege via local access
ModificadaAlta (7.8)0.15%—Intel NUC Hdmi Firmware Update Tool10/5/202317/6/2026
Incorrect default permissions for the Intel(R) HDMI Firmware Update Tool for NUC before version 1.79.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.3)0.20%—Intel NUC Hdmi Firmware Update Tool10/5/202317/6/2026
Uncontrolled search path for the Intel(R) HDMI Firmware Update tool for NUC before version 1.79.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.1)0.38%—Mauimarketing Update Image TAG ALT Attribute10/5/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Maui Marketing Update Image Tag Alt Attribute plugin <= 2.4.5 versions.
ModificadaMedia (4.8)0.44%—Byconsole Pickup | Delivery | Dine-in Date Time8/5/202317/6/2026
The Pickup | Delivery | Dine-in date time WordPress plugin through 1.0.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaAlta (7.8)0.19%—Lenovo System Update1/5/202317/6/2026
A directory permissions management vulnerability in Lenovo System Update may allow elevation of privileges.
ModificadaAlta (7.8)1.9%💥 PoCLinux KernelCanonical Ubuntu LinuxFedoraproject FedoraRedhat Enterprise Linux+927/3/202317/6/2026
A buffer overflow vulnerability was found in the Netfilter subsystem in the Linux Kernel. This issue could allow the leakage of both stack and heap addresses, and potentially allow Local Privilege Escalation to the root user via arbitrary code execution.
ModificadaAlta (7.8)0.90%—X.org X ServerFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux AUS+1427/3/202317/6/2026
A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write into freed memory. This can lead to local privilege elevation on systems where the X server runs privileged and remote…
ModificadaMedia (5.4)0.89%💥 ExploitTechnocrackers Bulk Price Update FOR Woocommerce22/3/202317/6/2026
The Woo Bulk Price Update WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'page' parameter to the techno_get_products action, which can only be triggered by an authenticated user.
ModificadaCrítica (9.6)1.5%—Jenkins Update-center210/3/202317/6/2026
Jenkins update-center2 3.13 and 3.14 renders the required Jenkins core version on plugin download index pages without sanitization, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a plugin for hosting.
ModificadaAlta (7.8)1.8%—Ubuntukylin Kylin-system-updater8/3/202317/6/2026
A vulnerability, which was classified as critical, was found in kylin-system-updater up to 1.4.20kord on Ubuntu Kylin. Affected is the function InstallSnap of the component Update Handler. The manipulation leads to command injection. The attack needs to be approached locally. The exploit has been disclosed to the…
AnalizadaAlta (8.8)1.6%⚠ Explotación activaWebkitgtkWpewebkit WPE WebkitRedhat Codeready Linux BuilderRedhat Codeready Linux Builder EUS+196/3/202317/6/2026
A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.
ModificadaMedia (6.1)0.53%—Baremetrics Date Range Picker21/2/202317/6/2026
The Baremetrics date range picker is a solution for selecting both date ranges and single dates from a single calender view. Versions 1.0.14 and prior are prone to cross-site scripting (XSS) when handling untrusted `placeholder` entries. An attacker who is able to influence the field `placeholder` when creating a…
ModificadaAlta (7.8)0.17%—Administrative Tools FOR Intel Network AdaptersIntel Non-volatile Memory Update Utility16/2/202317/6/2026
Uncontrolled search path in some Intel(R) Network Adapter installer software may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.5)0.31%💥 PoCIntel ONE Boot Flash Update16/2/202317/6/2026
Improper access control in the Intel(R) OFU software before version 14.1.28 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaAlta (7.8)0.60%—Microsoft Defender Security Intelligence Updates14/2/202319/8/2026
Microsoft Defender for Endpoint Security Feature Bypass Vulnerability
ModificadaMedia (6)0.18%—Dell System Update11/2/202317/6/2026
Dell System Update, version 2.0.0 and earlier, contains an Improper Certificate Validation in data parser module. A local attacker with high privileges could potentially exploit this vulnerability, leading to credential theft and/or denial of service.