Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

475 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.50%—Simple Video Embedder Project Simple Video Embedder9/11/202217/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in James Lao's Simple Video Embedder plugin <= 2.2 on WordPress.
ModificadaAlta (7.8)0.19%—Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+28612/10/202217/6/2026
Dell BIOS contains an Stack-Based Buffer Overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
ModificadaAlta (7.8)0.16%—Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+28612/10/202217/6/2026
Dell Client BIOS contains a Buffer Overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by manipulating an SMI to cause an arbitrary write during SMM.
ModificadaAlta (7.8)0.24%—Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+28612/10/202217/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
ModificadaAlta (7.8)0.24%—Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+28612/10/202217/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
ModificadaAlta (7.8)0.21%—Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+28612/10/202217/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
ModificadaAlta (7.8)0.21%—Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+28612/10/202217/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
ModificadaMedia (4.4)0.17%—Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+28612/10/202217/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
ModificadaMedia (4.4)0.17%—Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+28612/10/202217/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
ModificadaAlta (7.8)0.22%—Dell Alienware M15 R6 FirmwareDell Chengming 3980 FirmwareDell Chengming 3988 FirmwareDell Chengming 3990 Firmware+3956/9/202217/6/2026
Dell BIOS versions contain an Insecure Automated Optimization vulnerability. A local authenticated malicious user could exploit this vulnerability by sending malicious input via SMI to obtain arbitrary code execution during SMM.
ModificadaAlta (7.8)0.19%—Dell Alienware M15 R6 FirmwareDell Chengming 3980 FirmwareDell Chengming 3988 FirmwareDell Chengming 3990 Firmware+3956/9/202217/6/2026
Dell BIOS versions contain a stack-based buffer overflow vulnerability. A local attacker could exploit this vulnerability by sending malicious input via SMI to bypass security checks resulting in arbitrary code execution in SMM.
ModificadaAlta (7)0.14%—Dell Alienware M15 R6 FirmwareDell Chengming 3980 FirmwareDell Chengming 3988 FirmwareDell Chengming 3990 Firmware+3956/9/202217/6/2026
Dell BIOS contains a race condition vulnerability. A local attacker could exploit this vulnerability by sending malicious input via SMI in order to bypass security checks during SMM.
ModificadaAlta (7.8)0.17%—Dell Alienware M15 R6 FirmwareDell Chengming 3980 FirmwareDell Chengming 3988 FirmwareDell Chengming 3990 Firmware+3956/9/202217/6/2026
Dell BIOS versions contain an Improper Authentication vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by sending malicious input to an SMI in order to bypass security controls.
ModificadaCrítica (9.8)1.4%—Embedthis Goahead8/8/202217/6/2026
websda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded onceuponatimeinparadise value, which does not follow the secret-data guideline for HTTP Digest Access Authentication in RFC 7616 section 3.3 (or RFC 2617 section 3.2.1). NOTE: 2.1.8 is a version…
ModificadaMedia (4.7)0.86%—Ckeditor5-html-embedCkeditor5-html-supportCkeditor5-markdown-gfm3/8/202217/6/2026
CKEditor 5 is a JavaScript rich text editor. A cross-site scripting vulnerability has been discovered affecting three optional CKEditor 5's packages in versions prior to 35.0.1. The vulnerability allowed to trigger a JavaScript code after fulfilling special conditions. The affected packages are…
ModificadaAlta (7.5)0.89%—Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+1511/7/202217/6/2026
In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are not affected.
ModificadaAlta (7.5)0.89%—Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+1511/7/202217/6/2026
In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections. Existing connections are not affected.
ModificadaAlta (7.5)1.2%—Jenkins Embeddable Build Status23/6/202217/6/2026
Jenkins Embeddable Build Status Plugin 2.0.3 and earlier does not correctly perform the ViewStatus permission check in the HTTP endpoint it provides for "unprotected" status badge access, allowing attackers without any permissions to obtain the build status badge icon for any attacker-specified job and/or build.
ModificadaAlta (7.5)1.7%—Jenkins Embeddable Build Status23/6/202217/6/2026
Jenkins Embeddable Build Status Plugin 2.0.3 and earlier allows specifying a `style` query parameter that is used to choose a different SVG image style without restricting possible values, resulting in a relative path traversal vulnerability that allows attackers without Overall/Read permission to specify paths to…
ModificadaMedia (6.1)0.96%—Jenkins Embeddable Build Status23/6/202217/6/2026
Jenkins Embeddable Build Status Plugin 2.0.3 allows specifying a 'link' query parameter that build status badges will link to, without restricting possible values, resulting in a reflected cross-site scripting (XSS) vulnerability.
ModificadaAlta (7.5)1.5%—Embedthis Appweb2/6/202217/6/2026
An issue was discovered in src/http/httpLib.c in EmbedThis Appweb Community Edition 8.2.1, allows attackers to cause a denial of service via the stream paramter to the parseUri function.
ModificadaMedia (6.5)0.33%—AMD Epyc 7001 FirmwareAMD Epyc 7002 FirmwareAMD Epyc 7003 FirmwareAMD Epyc 7232p Firmware+9511/5/202217/6/2026
An attacker with access to a malicious hypervisor may be able to infer data values used in a SEV guest on AMD CPUs by monitoring ciphertext values over time.
ModificadaAlta (7.5)1.5%—Codesys Control FOR Beaglebone SLCodesys Control FOR Beckhoff Cx9020Codesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SL+147/4/202217/6/2026
A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulting in a crash of the webserver of the CODESYS Control runtime system.
ModificadaAlta (7.5)1.3%—Codesys Control FOR Beaglebone SLCodesys Control FOR Beckhoff Cx9020Codesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SL+167/4/202217/6/2026
An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed.
ModificadaAlta (8.1)1.1%—Codesys Control FOR Beaglebone SLCodesys Control FOR Beckhoff Cx9020Codesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SL+147/4/202217/6/2026
A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products.