Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

808 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.77%—Wpshopmart Coming Soon Page & Maintenance Mode7/6/202317/6/2026
The WordPress Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the logo_width, logo_height, rcsp_logo_url, home_sec_link_txt, rcsp_headline and rcsp_description parameters in versions up to, and including, 1.8.1 due to insufficient input sanitization and output…
ModificadaMedia (5.3)0.81%—Wpshopmart Coming Soon Page & Maintenance Mode7/6/202317/6/2026
The Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to unauthenticated settings reset in versions up to, and including 1.8.1 due to missing capability checks in the ~/functions/data-reset-post.php file which makes it possible for unauthenticated attackers to trigger a plugin settings reset.
ModificadaAlta (7.8)0.19%—Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3 07ach7 FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07ada05 Firmware+1105/6/202317/6/2026
An ErrorMessage driver stack-based buffer overflow vulnerability in BIOS of some ThinkPad models could allow an attacker with local access to elevate their privileges and execute arbitrary code.
ModificadaAlta (8.8)0.27%—Supsystic Coming Soon22/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Coming Soon by Supsystic plugin <= 1.7.10 versions.
ModificadaMedia (5.5)0.24%—Libming9/5/202317/6/2026
Buffer Overflow vulnerability found in Libming swftophp v.0.4.8 allows a local attacker to cause a denial of service via the cws2fws function in util/decompile.c.
ModificadaMedia (5.5)0.24%—Libming9/5/202317/6/2026
An issue found in libming swftophp v.0.4.8 allows a local attacker to cause a denial of service via the stackVal function in util/decompile.c.
ModificadaMedia (5.5)0.24%—Libming9/5/202317/6/2026
Buffer Overflow vulnerability found in Libming swftophp v.0.4.8 allows a local attacker to cause a denial of service via the newVar_N in util/decompile.c.
ModificadaAlta (7.8)0.28%—Libming9/5/202317/6/2026
An issue found in libming v.0.4.8 allows a local attacker to execute arbitrary code via the parseSWF_IMPORTASSETS function in the parser.c file.
ModificadaAlta (8.8)0.70%—Libming9/5/202317/6/2026
libming v0.4.8 was discovered to contain a stack buffer overflow via the function makeswf_preprocess at /util/makeswf_utils.c.
ModificadaAlta (8.8)0.92%—Mingsoft Mcms8/5/202317/6/2026
File upload vulnerability in MCMS 5.0 allows attackers to execute arbitrary code via a crafted thumbnail. A different vulnerability than CVE-2022-31943.
ModificadaAlta (7.5)0.69%—Libming26/4/202317/6/2026
libming 0.4.8 0.4.8 is vulnerable to Buffer Overflow. In getInt() in decompile.c unknown type may lead to denial of service. This is a different vulnerability than CVE-2018-9132 and CVE-2018-20427.
ModificadaCrítica (9.8)1.1%—Incsub Hummingbird10/4/202317/6/2026
The Hummingbird WordPress plugin before 3.4.2 does not validate the generated file path for page cache files before writing them, leading to a path traversal vulnerability in the page cache module.
ModificadaMedia (4.8)0.39%—Snapcreek EZP Coming Soon Page7/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Snap Creek Software EZP Coming Soon Page plugin <= 1.0.7.3 versions.
ModificadaMedia (5.4)0.43%—Dell Streaming Data Platform5/4/202317/6/2026
Dell Streaming Data Platform prior to 1.4 contains Open Redirect vulnerability. A remote unauthenticated attacker can phish the legitimate user to redirect to malicious website leading to information disclosure and launch of phishing attacks.
ModificadaCrítica (9.8)1.4%—Mingsoft Mcms4/4/202317/6/2026
SQL Injection vulnerability found in Ming-Soft MCMS v.4.7.2 allows a remote attacker to execute arbitrary code via basic_title parameter.
ModificadaAlta (8.8)0.26%—Obox Launchpad - Coming Soon & Maintenance Mode Plugin17/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Obox Themes Launchpad – Coming Soon & Maintenance Mode plugin <= 1.0.13 versions.
ModificadaMedia (5.3)1.4%💥 ExploitNiteothemes Coming Soon & Maintenance7/3/202317/6/2026
The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 4.1.6 via the cmp_get_post_detail function. This can allow unauthenticated individuals to obtain the contents of any non-password-protected, published post or page even when maintenance mode…
ModificadaAlta (7.8)0.31%—Jtekt Kostac PLC Programming Software6/3/202317/6/2026
Use-after-free vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.9.0 and earlier. With the abnormal value given as the maximum number of columns for the PLC program, the process accesses the freed memory. As a result, opening a specially crafted project…
ModificadaAlta (7.8)0.32%—Jtekt Kostac PLC Programming Software6/3/202317/6/2026
Out-of-bounds read vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.9.0 and earlier. The insufficient buffer size for the PLC program instructions leads to out-of-bounds read. As a result, opening a specially crafted project file may lead to information…
ModificadaAlta (7.8)0.23%—Jtekt Kostac PLC Programming Software6/3/202317/6/2026
Out-of-bounds read vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.9.0 and earlier. When processing a comment block in stage information, the end of data cannot be verified and out-of-bounds read occurs. As a result, opening a specially crafted project…
ModificadaMedia (4.2)0.17%—Dell Alienware 13 R2 FirmwareDell Alienware 13 R3 FirmwareDell Alienware 15 R2 FirmwareDell Alienware 15 R3 Firmware+15310/2/202317/6/2026
Dell BIOS contains an information exposure vulnerability. An unauthenticated local attacker with physical access to the system and knowledge of the system configuration could potentially exploit this vulnerability to read system information via debug interfaces.
ModificadaAlta (7)0.16%—Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R10 FirmwareDell Alienware Aurora R11 Firmware+2351/2/202317/6/2026
Dell BIOS contains a Time-of-check Time-of-use vulnerability. A local authenticated malicious user could\u00a0potentially exploit this vulnerability by using a specifically timed DMA transaction during an SMI to gain arbitrary code execution on the system.
ModificadaMedia (5.1)0.16%—Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Chengming 3900 FirmwareDell G15 5510 Firmware+1851/2/202317/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
ModificadaMedia (6.7)0.23%—Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+28330/1/202317/6/2026
A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code.
ModificadaMedia (4.4)0.20%—Lenovo Ideacentre C5-14imb05 FirmwareLenovo Thinkcentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+14330/1/202317/6/2026
An information leak vulnerability in SMI Handler used to configure platform settings over WMI in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
Orbitaley — Vulnerabilidades