Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

480 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.4)0.23%—Dell Chengming 3900 FirmwareDell Inspiron 14 Plus 7420 FirmwareDell Inspiron 16 Plus 7620 FirmwareDell Inspiron 3910 Firmware+2112/9/202217/6/2026
Dell BIOS versions contain an Improper Protection Against Voltage and Clock Glitches vulnerability. An attacker with physical access to the system could potentially exploit this vulnerability by triggering a fault condition in order to change the behavior of the system.
ModificadaBaja (2.3)0.18%—Dell Chengming 3900 FirmwareDell Inspiron 14 Plus 7420 FirmwareDell Inspiron 16 Plus 7620 FirmwareDell Inspiron 3910 Firmware+2112/9/202217/6/2026
Dell BIOS versions contain an Improper Neutralization of Null Byte vulnerability. A local authenticated administrator user could potentially exploit this vulnerability by sending unexpected null bytes in order to read memory on the system.
ModificadaMedia (4.4)0.18%—Dell Chengming 3900 FirmwareDell Inspiron 14 Plus 7420 FirmwareDell Inspiron 16 Plus 7620 FirmwareDell Inspiron 3910 Firmware+2112/9/202217/6/2026
Dell BIOS versions contain a Missing Release of Resource after Effective Lifetime vulnerability. A local authenticated administrator user could potentially exploit this vulnerability by consuming excess memory in order to cause the application to crash.
ModificadaBaja (2.3)0.18%—Dell Chengming 3900 FirmwareDell Inspiron 14 Plus 7420 FirmwareDell Inspiron 16 Plus 7620 FirmwareDell Inspiron 3910 Firmware+2112/9/202217/6/2026
Dell BIOS versions contain an Information Exposure vulnerability. A local authenticated administrator user could potentially exploit this vulnerability in order access sensitive state information on the system.
ModificadaMedia (5.1)0.16%—Dell Chengming 3900 FirmwareDell Inspiron 14 Plus 7420 FirmwareDell Inspiron 16 Plus 7620 FirmwareDell Inspiron 3910 Firmware+2112/9/202217/6/2026
Dell BIOS versions contain an Unchecked Return Value vulnerability. A local authenticated administrator user could potentially exploit this vulnerability in order to change the state of the system or cause unexpected failures.
ModificadaMedia (6.1)0.51%—Redhat Build OF QuarkusRedhat Openshift Application RuntimesRedhat Smallrye Health25/8/202217/6/2026
It was found that the smallrye health metrics UI component did not properly sanitize some user inputs. An attacker could use this flaw to conduct cross-site scripting attacks.
ModificadaCrítica (9.8)1.0%—Shopro Mall System18/8/202217/6/2026
Shopro Mall System v1.3.8 was discovered to contain a SQL injection vulnerability via the value parameter.
ModificadaCrítica (9.8)0.81%—Fahou100 Electronic Mall System14/7/202217/6/2026
Electronic mall system 1.0_build20200203 is affected vulnerable to SQL Injection.
ModificadaAlta (8.8)1.8%💥 PoCMini Tmall Project Mini Tmall6/7/202217/6/2026
Mini-Tmall v1.0 is vulnerable to Insecure Permissions via tomcat-embed-jasper.
ModificadaCrítica (9.8)2.3%—Smallsrv Small Http Server29/4/202217/6/2026
Small HTTP Server version 3.06 suffers from a remote buffer overflow vulnerability via long GET request.
ModificadaCrítica (9.8)1.1%—Newbee-mall Project Newbee-mall10/4/202217/6/2026
Newbee-Mall v1.0.0 was discovered to contain an arbitrary file upload via the Upload function at /admin/goods/edit.
ModificadaMedia (6.1)0.56%—Newbee-mall Project Newbee-mall10/4/202217/6/2026
A cross-site scripting (XSS) vulnerability at /admin/goods/update in Newbee-Mall v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the goodsName parameter.
ModificadaMedia (6.1)0.84%—Exrick Xmall7/4/20229/7/2026
A Cross Site Scripting (XSS) vulnerability exists in Exrick XMall Admin Panel as of 11/7/2021 via the GET parameter in product-add.jsp.
ModificadaCrítica (9.8)3.1%—Kaspersky Anti-virusKaspersky Endpoint SecurityKaspersky Internet SecurityKaspersky Security Cloud+21/4/202217/6/2026
Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security with antivirus databases released before 12 March 2022 had a bug in a data parsing module that potentially allowed an attacker to execute arbitrary code. The fix was delivered automatically. Credits: Georgy Zaytsev (Positive Technologies).
ModificadaMedia (5.5)0.20%—Kaspersky Anti-virusKaspersky Endpoint SecurityKaspersky Internet SecurityKaspersky Security Cloud+21/4/202217/6/2026
A denial-of-service issue existed in one of modules that was incorporated in Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security. A local user could cause Windows crash by running a specially crafted binary module. The fix was delivered automatically. Credits: (Straghkov Denis, Kurmangaleev Shamil,…
ModificadaMedia (5.5)0.26%—HP Probook 440 G8 FirmwareHP Prodesk 405 G6 Small Form Factor Firmware2/3/202217/6/2026
Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.
ModificadaMedia (5.5)0.26%—HP Probook 440 G8 FirmwareHP Prodesk 405 G6 Small Form Factor Firmware2/3/202217/6/2026
Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.
ModificadaMedia (5.5)0.26%—HP Probook 440 G8 FirmwareHP Prodesk 405 G6 Small Form Factor Firmware2/3/202217/6/2026
Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.
ModificadaMedia (5.5)0.26%—HP Probook 440 G8 FirmwareHP Prodesk 405 G6 Small Form Factor Firmware2/3/202217/6/2026
Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.
ModificadaMedia (5.5)0.26%—HP Probook 440 G8 FirmwareHP Prodesk 405 G6 Small Form Factor Firmware2/3/202217/6/2026
Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.
ModificadaMedia (5.5)0.26%—HP Probook 440 G8 FirmwareHP Prodesk 405 G6 Small Form Factor Firmware2/3/202217/6/2026
Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.
ModificadaCrítica (9.8)1.3%—Firstmall25/2/202217/6/2026
This issues due to insufficient verification of the various input values from user’s input. The vulnerability allows remote attackers to execute malicious code in Firstmall via navercheckout_add function.
ModificadaAlta (8.8)0.44%—HP Z1 Entry Tower G5 Workstation FirmwareHP Z1 Entry Tower G6 Workstation FirmwareHP Z1 G8 Tower Desktop PC FirmwareHP Z4 G4 Workstation (core-x) Firmware+18316/2/20227/10/2026
Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.
ModificadaAlta (8.8)0.42%—HP Z1 Entry Tower G5 Workstation FirmwareHP Z1 Entry Tower G6 Workstation FirmwareHP Z1 G8 Tower Desktop PC FirmwareHP Z4 G4 Workstation (core-x) Firmware+18316/2/20227/10/2026
Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.
ModificadaAlta (8.8)0.42%—HP Elite Dragonfly FirmwareHP Elite Dragonfly G2 FirmwareHP Elite Dragonfly MAX FirmwareHP Elite X2 1013 G3 Firmware+18316/2/20227/10/2026
Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.
Orbitaley — Vulnerabilidades