Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

480 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.45%—HP Z1 Entry Tower G5 Workstation FirmwareHP Z1 Entry Tower G6 Workstation FirmwareHP Z1 G8 Tower Desktop PC FirmwareHP Z4 G4 Workstation (core-x) Firmware+18316/2/20227/10/2026
A potential vulnerability in AMD System Management Mode (SMM) interrupt handler may allow an attacker with high privileges to access the SMM resulting in arbitrary code execution which could be used by malicious actors to bypass security mechanisms provided in the UEFI firmware.
ModificadaAlta (8.8)0.44%—HP 260 G3 Desktop Mini PC FirmwareHP Elitedesk 800 35W G4 Desktop Mini PC FirmwareHP Elitedesk 800 65W G4 Desktop Mini PC FirmwareHP Elitedesk 800 95W G4 Desktop Mini PC Firmware+18316/2/20227/10/2026
Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.
ModificadaAlta (7.5)1.4%—Servo Smallvec27/12/202117/6/2026
An issue was discovered in the smallvec crate before 0.6.13 for Rust. It can create an uninitialized value of any type, including a reference type.
ModificadaAlta (8.8)0.45%—Nhn-commerce Godomall527/10/202117/6/2026
The move_uploaded_file function in godomall5 does not perform an integrity check of extension or authority when user upload file. This vulnerability allows an attacker to execute an remote arbitrary code.
ModificadaAlta (8.8)9.1%—Cisco Small Business RV Series Router Firmware4/8/202117/6/2026
Multiple vulnerabilities in the web-based management interface of the Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an attacker to do the following: Execute arbitrary code Cause a denial of service (DoS) condition Execute arbitrary commands For more information about…
ModificadaCrítica (9.8)9.7%—Cisco Small Business RV Series Router Firmware4/8/202117/6/2026
Multiple vulnerabilities in the web-based management interface of the Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an attacker to do the following: Execute arbitrary code Cause a denial of service (DoS) condition Execute arbitrary commands For more information about…
ModificadaCrítica (9.8)2.0%—Cisco Small Business RV Series Router Firmware4/8/202117/6/2026
A vulnerability in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to insufficient user input…
ModificadaMedia (4.4)0.27%—Redhat Smallrye Config28/5/202117/6/2026
A flaw was found in SmallRye's API through version 1.6.1. The API can allow other code running within the application server to potentially obtain the ClassLoader, bypassing any permissions checks that should have been applied. The largest threat from this vulnerability is a threat to data confidentiality. This is…
ModificadaMedia (6.1)0.81%—Fecmall Project Fecmall29/4/202117/6/2026
An issue was found in yii2_fecshop 2.x. There is a reflected XSS vulnerability in the check cart page.
ModificadaCrítica (9.8)3.8%—Phpshe Mall System28/4/202117/6/2026
SQL Injection in PHPSHE Mall System v1.7 allows remote attackers to execute arbitrary code by injecting SQL commands into the "user_phone" parameter of a crafted HTTP request to the "admin.php" component.
ModificadaCrítica (9.8)1.7%—Servo Smallvec26/1/202117/6/2026
An issue was discovered in the smallvec crate before 0.6.14 and 1.x before 1.6.1 for Rust. There is a heap-based buffer overflow in SmallVec::insert_many.
ModificadaAlta (7.5)0.87%—Newbee-mall Project Newbee-mall26/1/202117/6/2026
newbee-mall all versions are affected by incorrect access control to remotely gain privileges through NewBeeMallIndexConfigServiceImpl.java. Unauthorized changes can be made to any user information through the userID.
ModificadaCrítica (9.8)1.6%—Newbee-mall Project Newbee-mall26/1/202117/6/2026
newbee-mall all versions are affected by incorrect access control to remotely gain privileges through AdminLoginInterceptor.java. The authentication logic of the system's background /admin is in code AdminLoginInterceptor, which can be bypassed.
ModificadaMedia (6.1)0.66%—Newbee-mall Project Newbee-mall26/1/202117/6/2026
newbee-mall 1.0 is affected by cross-site scripting in shop-cart/settle. Users only need to write xss payload in their address information when buying goods, which is triggered when viewing the "View Recipient Information" of this order in "Order Management Office".
ModificadaMedia (6.8)0.48%—Foscammall Foscam X1 Firmware28/12/202017/6/2026
FOSCAM FHD X1 1.14.2.4 devices allow attackers (with physical UART access) to login via the ipc.fos~ password.
ModificadaMedia (4.4)0.29%—Dell Chengming 3967 FirmwareDell Chengming 3977 FirmwareDell Chengming 3980 FirmwareDell Chengming 3988 Firmware+35010/6/202017/6/2026
Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability interface for which an unauthorized actor, with local system access with OS administrator privileges, could bypass the BIOS Administrator authentication to restore BIOS Setup configuration to default…
ModificadaMedia (5.5)2.9%—Avira Anti-malware SDKAvira Antivirus ServerAvira Antivirus FOR EndpointAvira Antivirus FOR Small Business+420/2/202017/6/2026
Avira AV Engine before 8.3.54.138 allows virus-detection bypass via a crafted ISO archive. This affects versions before 8.3.54.138 of Antivirus for Endpoint, Antivirus for Small Business, Exchange Security (Gateway), Internet Security Suite for Windows, Prime, Free Security Suite for Windows, and Cross Platform…
ModificadaAlta (8.8)1.7%—Small CRM Project Small CRM8/1/202017/6/2026
PHPGurukul Small CRM v2.0 was found vulnerable to authentication bypass via SQL injection when logging into the administrator login page.
ModificadaMedia (6.1)2.1%—Kaspersky Anti-virusKaspersky Internet SecurityKaspersky Security CloudKaspersky Small Office Security+126/11/201917/6/2026
Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component did not adequately inform the user about the threat of redirecting to an untrusted site. Bypass.
ModificadaMedia (6.5)1.6%—Kaspersky Anti-virusKaspersky Internet SecurityKaspersky Security CloudKaspersky Small Office Security+126/11/201917/6/2026
Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component was vulnerable to remote disclosure of various information about the user's system (like Windows version and version…
ModificadaMedia (4.3)0.77%—Kaspersky Anti-virusKaspersky Internet SecurityKaspersky Security CloudKaspersky Small Office Security+126/11/201917/6/2026
Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component allowed an attacker remotely disable various anti-virus protection features. DoS, Bypass.
ModificadaMedia (4.3)0.84%—Kaspersky Anti-virusKaspersky Internet SecurityKaspersky Security CloudKaspersky Small Office Security+126/11/201917/6/2026
Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component allowed an attacker remotely disable such product's security features as private browsing and anti-banner. Bypass.
ModificadaCrítica (9.8)1.8%—Newbee-mall Project Newbee-mall18/11/201917/6/2026
main/resources/mapper/NewBeeMallGoodsMapper.xml in newbee-mall (aka New Bee) before 2019-10-23 allows search?goodsCategoryId=&keyword= SQL Injection.
ModificadaAlta (7.2)1.4%—Fecmall4/10/201917/6/2026
An unrestricted file upload vulnerability was discovered in catalog/productinfo/imageupload in Fecshop FecMall 2.3.4. An attacker can bypass a front-end restriction and upload PHP code to the webserver, by providing image data and the image/jpeg content type, with a .php extension. This occurs because the code relies…
ModificadaCrítica (9.8)2.1%—Servo Smallvec26/8/201917/6/2026
An issue was discovered in the smallvec crate before 0.6.10 for Rust. There is memory corruption for certain grow attempts with less than the current capacity.
Orbitaley — Vulnerabilidades