Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
475 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.1) | 0.89% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Beckhoff Cx9020Codesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SL+16 | 7/4/2022 | 17/6/2026 | An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overwriting of memory in the CmpTraceMgr, whereby the attacker can neither gain the values read internally nor control the values to be written. If invalid memory is accessed,… | |
| Modificada | Media (6.5) | 1.0% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Beckhoff Cx9020Codesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SL+16 | 7/4/2022 | 17/6/2026 | An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash. | |
| Modificada | Alta (7.8) | 0.29% | — | Dell Alienware 13 R3 FirmwareDell Alienware 15 R3 FirmwareDell Alienware 15 R4 FirmwareDell Alienware 17 R4 Firmware+42 | 11/3/2022 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM. | |
| Modificada | Alta (7.8) | 0.29% | — | Dell Alienware 13 R3 FirmwareDell Alienware 15 R3 FirmwareDell Alienware 15 R4 FirmwareDell Alienware 17 R4 Firmware+42 | 11/3/2022 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM. | |
| Modificada | Alta (7.8) | 0.29% | — | Dell Alienware 13 R3 FirmwareDell Alienware 15 R3 FirmwareDell Alienware 15 R4 FirmwareDell Alienware 17 R4 Firmware+42 | 11/3/2022 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM. | |
| Modificada | Alta (7.8) | 0.29% | — | Dell Alienware 13 R3 FirmwareDell Alienware 15 R3 FirmwareDell Alienware 15 R4 FirmwareDell Alienware 17 R4 Firmware+42 | 11/3/2022 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM. | |
| Modificada | Alta (7.8) | 0.29% | — | Dell Alienware 13 R3 FirmwareDell Alienware 15 R3 FirmwareDell Alienware 15 R4 FirmwareDell Alienware 17 R4 Firmware+42 | 11/3/2022 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM. | |
| Modificada | Media (6.1) | 0.26% | — | Drupal Entity Embed | 11/2/2022 | 17/6/2026 | The Entity Embed module provides a filter to allow embedding entities in content fields. In certain circumstances, the filter could allow an unprivileged user to inject HTML into a page when it is accessed by a trusted user with permission to embed entities. In some cases, this could lead to cross-site scripting. | |
| Modificada | Media (6.1) | 3.9% | 💥 Exploit | Embed Swagger Project Embed Swagger | 4/2/2022 | 17/6/2026 | The Embed Swagger WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient escaping/sanitization and validation via the url parameter found in the ~/swagger-iframe.php file which allows attackers to inject arbitrary web scripts onto the page, in versions up to and including 1.0.0. | |
| Modificada | Media (5.5) | 0.31% | — | AMD Epyc 7763 FirmwareAMD Epyc 7713p FirmwareAMD Epyc 7713 FirmwareAMD Epyc 7663 Firmware+103 | 4/2/2022 | 17/6/2026 | AMD EPYC™ Processors contain an information disclosure vulnerability in the Secure Encrypted Virtualization with Encrypted State (SEV-ES) and Secure Encrypted Virtualization with Secure Nested Paging (SEV-SNP). A local authenticated attacker could potentially exploit this vulnerability leading to leaking guest data by… | |
| Modificada | Media (4.3) | 0.89% | — | Bplugins Document Embedder | 1/2/2022 | 17/6/2026 | The Document Embedder WordPress plugin before 1.7.9 contains a AJAX action endpoint, which could allow any authenticated user, such as subscriber to enumerate the title of arbitrary private and draft posts. | |
| Modificada | Media (5.3) | 1.3% | — | Bplugins Document Embedder | 1/2/2022 | 17/6/2026 | The Document Embedder WordPress plugin before 1.7.5 contains a REST endpoint, which could allow unauthenticated users to enumerate the title of arbitrary private and draft posts. | |
| Modificada | Crítica (9.8) | 2.3% | — | Embedthis Goahead | 25/1/2022 | 17/6/2026 | The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limiting. This means that an unauthenticated network attacker can brute-force the HTTP basic password, byte-by-byte, by recording the webserver's response time until the unauthorized… | |
| Analizada | Media (6.4) | 0.24% | — | Dell Precision 5820 Tower FirmwareDell Precision 7510 FirmwareDell Precision 7520 FirmwareDell Precision 7530 Firmware+407 | 24/1/2022 | 7/10/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. | |
| Analizada | Media (6.4) | 0.25% | — | Dell Precision 7510 FirmwareDell Precision 7520 FirmwareDell Precision 7530 FirmwareDell Precision 7540 Firmware+407 | 24/1/2022 | 7/10/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. | |
| Modificada | Alta (7.5) | 1.6% | — | Rust-embed Project Rust-embed | 26/12/2021 | 17/6/2026 | An issue was discovered in the rust-embed crate before 6.3.0 for Rust. A ../ directory traversal can sometimes occur in debug mode. | |
| Modificada | Alta (8.4) | 0.25% | — | AMD Epyc 7001 FirmwareAMD Epyc 7232p FirmwareAMD Epyc 7251 FirmwareAMD Epyc 7261 Firmware+101 | 10/12/2021 | 17/6/2026 | A malicious hypervisor in conjunction with an unprivileged attacker process inside an SEV/SEV-ES guest VM may fail to flush the Translation Lookaside Buffer (TLB) resulting in unexpected behavior inside the virtual machine (VM). | |
| Modificada | Media (6.7) | 0.24% | — | Dell Alienware 13 R3 FirmwareDell Alienware 15 R3 FirmwareDell Alienware 15 R4 FirmwareDell Alienware 17 R4 Firmware+279 | 12/11/2021 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. | |
| Modificada | Media (6.7) | 0.24% | — | Dell Alienware 13 R3 FirmwareDell Alienware 15 R3 FirmwareDell Alienware 15 R4 FirmwareDell Alienware 17 R4 Firmware+279 | 12/11/2021 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. | |
| Modificada | Media (6.7) | 0.24% | — | Dell Alienware 13 R3 FirmwareDell Alienware 15 R3 FirmwareDell Alienware 15 R4 FirmwareDell Alienware 17 R4 Firmware+279 | 12/11/2021 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. | |
| Modificada | Alta (7.5) | 1.3% | — | Softing Datafeed OPC SuiteSofting EdgeconnectorSofting OPCSofting Secure Integration Server+3 | 10/11/2021 | 17/6/2026 | An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66, and uaToolkit Embedded before 1.40. Remote attackers to cause a denial of service (DoS) by sending crafted messages to a client or server. The server process may crash unexpectedly because of a double free, and must be restarted. | |
| Modificada | Alta (7.5) | 1.5% | — | Softing Smartlink Hw-dpSofting Uatoolkit Embedded | 10/11/2021 | 17/6/2026 | An issue was discovered in Softing Industrial Automation uaToolkit Embedded before 1.40. Remote attackers to cause a denial of service (DoS) or login as an anonymous user (bypassing security checks) by sending crafted messages to a OPC/UA server. The server process may crash unexpectedly because of an invalid type… | |
| Modificada | Crítica (9.8) | 59% | 💥 PoC | Embedthis Goahead | 14/10/2021 | 17/6/2026 | An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts without being prefixed with the CGI prefix. This permits tunneling untrusted environment variables into vulnerable CGI scripts. | |
| Modificada | Alta (8.6) | 1.3% | — | Cisco Embedded Wireless Controller | 23/9/2021 | 17/6/2026 | A vulnerability in the packet processing functionality of Cisco Embedded Wireless Controller (EWC) Software for Catalyst Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected AP. This vulnerability is due to insufficient buffer allocation. An… | |
| Modificada | Alta (8.6) | 1.3% | — | Cisco IOS XECisco Embedded Wireless ControllerCisco Catalyst 9800 Firmware | 23/9/2021 | 17/6/2026 | Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. These… |