Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

608 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.23%—Dell Alienware UpdateDell Command UpdateDell Supportassist FOR Business PCSDell Supportassist FOR Home PCS+111/2/202317/6/2026
Dell SupportAssist Client Consumer (version 3.11.1 and prior), SupportAssist Client Commercial (version 3.2 and prior), Dell Command | Update, Dell Update, and Alienware Update versions before 4.5 contain a Local Privilege Escalation Vulnerability in the Advanced Driver Restore component. A local malicious user may…
ModificadaAlta (7.1)0.18%—Dell Alienware UpdateDell Command Update10/2/202317/6/2026
Dell Command | Update, Dell Update, and Alienware Update versions before 4.6.0 and 4.7.1 contain Insecure Operation on Windows Junction in the installer component. A local malicious user may potentially exploit this vulnerability leading to arbitrary file delete.
ModificadaAlta (8.8)0.83%—202-ecommerce Administrative Mandate2/2/20239/7/2026
PrestaShop module, totadministrativemandate before v1.7.1 was discovered to contain a SQL injection vulnerability.
ModificadaAlta (8.8)0.95%—Fedoraproject SssdRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux FOR IBM Z Systems+91/2/202317/6/2026
sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters
ModificadaAlta (7.8)0.15%—Dell Alienware UpdateDell Command UpdateDell Update1/2/202317/6/2026
Dell Command | Update, Dell Update, and Alienware Update versions prior to 4.7 contain a improper verification of cryptographic signature in get applicable driver component. A local malicious user could potentially exploit this vulnerability leading to malicious payload execution.
ModificadaMedia (5.5)0.18%—Dell Alienware UpdateDell Command UpdateDell Update1/2/202317/6/2026
Dell Command | Update, Dell Update, and Alienware Update versions prior to 4.7 contain a Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in download operation component. A local malicious user could potentially exploit this vulnerability leading to the disclosure of…
ModificadaMedia (5.5)0.20%—Jenkins Testquality Updater26/1/202317/6/2026
Jenkins TestQuality Updater Plugin 1.3 and earlier stores the TestQuality Updater password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
ModificadaMedia (6.5)0.72%—Jenkins Testquality Updater26/1/202317/6/2026
A missing check in Jenkins TestQuality Updater Plugin 1.3 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified username and password.
ModificadaAlta (8.8)0.52%—Jenkins Testquality Updater26/1/202317/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins TestQuality Updater Plugin 1.3 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified username and password.
ModificadaMedia (5.3)0.65%—Nsupdate.info27/12/202217/6/2026
A vulnerability classified as problematic has been found in nsupdate.info. This affects an unknown part of the file src/nsupdate/settings/base.py of the component CSRF Cookie Handler. The manipulation of the argument CSRF_COOKIE_HTTPONLY leads to cookie without 'httponly' flag. It is possible to initiate the attack…
ModificadaAlta (8.6)0.51%—GNU Grub2Fedoraproject FedoraRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR Power Little Endian EUS+414/12/202217/6/2026
A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size value, allocating a smaller than needed buffer for the glyph, this further leads to a buffer overflow and a heap based out-of-bounds write. An attacker may use this…
ModificadaCrítica (9.8)1.1%—Democritus D8s-dates7/11/202217/6/2026
The d8s-dates for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-timezones package. The affected version of d8s-htm is 0.1.0.
ModificadaCrítica (9.8)0.90%—School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification27/10/202217/6/2026
School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /modules/announcement/index.php?view=edit&id=.
ModificadaMedia (5.5)0.29%—Pulpproject Pulp AnsibleRedhat Ansible Automation PlatformRedhat SatelliteRedhat Update Infrastructure25/10/202217/6/2026
The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.
ModificadaMedia (6)0.17%—AsusliveupdateAsussoftwaremangerAsus System Control Interface18/10/202217/6/2026
AsusSoftwareManager.exe in ASUS System Control Interface on ASUS personal computers (running Windows) allows a local user to write into the Temp directory and delete another more privileged file via SYSTEM privileges. This affects ASUS System Control Interface 3 before 3.1.5.0, AsusSoftwareManger.exe before 1.0.53.0,…
ModificadaCrítica (9.8)1.4%—Democritus Dates Project Democritus Dates19/9/202217/6/2026
The d8s-dates for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0
ModificadaAlta (7.2)1.0%—School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification16/9/202217/6/2026
School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/event/index.php?view=edit&id=.
ModificadaAlta (7.2)1.0%—School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification16/9/202217/6/2026
School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/modstudent/index.php?view=view&id=.
ModificadaAlta (7.2)1.0%—School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification16/9/202217/6/2026
School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/department/index.php?view=edit&id=.
ModificadaAlta (7.2)0.88%—School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification8/9/202217/6/2026
School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the component /modules/modstudent/index.php?view=edit&id=.
ModificadaAlta (7.2)0.88%—School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification8/9/202217/6/2026
School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the component /modules/autonumber/index.php?view=edit&id=.
ModificadaAlta (7.2)0.88%—School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification8/9/202217/6/2026
School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the component /modules/user/index.php?view=edit&id=.
ModificadaAlta (7.8)0.19%—Dell Alienware UpdateDell Command UpdateDell Update2/9/202217/6/2026
Dell Command Update, Dell Update and Alienware Update versions prior to 4.6.0 contains a Local Privilege Escalation Vulnerability in the custom catalog configuration. A local malicious user may potentially exploit this vulnerability in order to elevate their privileges.
ModificadaMedia (5.5)0.29%—Linux KernelIBM Spectrum Copy Data ManagementIBM Spectrum Protect PlusDebian Linux+1926/8/202217/6/2026
A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS.
ModificadaMedia (6.5)1.5%💥 PoCRedhat LibvirtCanonical Ubuntu LinuxFedoraproject FedoraRedhat Enterprise Linux+1023/8/202217/6/2026
A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the guest is shutting down. An unprivileged…