Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

574 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.4)0.32%—HP Z1 All-in-one G3 FirmwareHP Z2 Mini G3 FirmwareHP Z2 Mini G4 FirmwareHP Z2 Mini G5 Firmware+1612/12/202217/6/2026
A potential security vulnerability has been identified in certain HP Workstation BIOS (UEFI firmware) which may allow arbitrary code execution. HP is releasing firmware mitigations for the potential vulnerability.
ModificadaMedia (5.4)0.36%—Keyfactor Kefactor Ejbca17/11/202217/6/2026
Keyfactor EJBCA before 7.10.0 allows XSS.
ModificadaMedia (5.4)0.36%—Keyfactor Primekey Ejbca17/11/202217/6/2026
A stored XSS vulnerability was discovered in adminweb/ra/viewendentity.jsp in PrimeKey EJBCA through 7.9.0.2. A low-privilege user can store JavaScript in order to exploit a higher-privilege user.
ModificadaAlta (7.5)1.2%—Rockwellautomation Factorytalk Alarms AND Events27/10/202217/6/2026
An unauthenticated attacker with network access to a victim's Rockwell Automation FactoryTalk Alarm and Events service could open a connection, causing the service to fault and become unavailable. The affected port could be used as a server ping port and uses messages structured with XML.
ModificadaAlta (7.8)0.24%—Opensuse Factory26/10/202217/6/2026
A Improper Link Resolution Before File Access ('Link Following') vulnerability in a script called by the sendmail systemd service of openSUSE Factory allows local attackers to escalate from user mail to root. This issue affects: SUSE openSUSE Factory sendmail versions prior to 8.17.1-1.1.
ModificadaAlta (8.8)3.5%—Rockwellautomation Factorytalk Vantagepoint17/10/202217/6/2026
Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an input validation vulnerability. The FactoryTalk VantagePoint SQL Server lacks input validation when users enter SQL statements to retrieve information from the back-end database. If successfully exploited, this could…
ModificadaAlta (8.8)1.4%—Rockwellautomation Factorytalk Vantagepoint17/10/202217/6/2026
Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an improper access control vulnerability. The FactoryTalk VantagePoint SQL Server account could allow a malicious user with read-only privileges to execute SQL statements in the back-end database. If successfully…
ModificadaBaja (3.3)0.16%—Samsung Factorycamera7/10/202217/6/2026
Unprotected Receiver in AtBroadcastReceiver in FactoryCamera prior to version 3.5.51 allows attackers to record video without camera privilege.
ModificadaAlta (7.8)0.23%—Samsung Factorycamera7/10/202217/6/2026
Path traversal vulnerability in AtBroadcastReceiver in FactoryCamera prior to version 3.5.51 allows attackers to write arbitrary file as FactoryCamera privilege.
ModificadaMedia (5.5)0.17%—Samsung Factorycamerafb7/10/202217/6/2026
Improper access control vulnerability in CameraTestActivity in FactoryCameraFB prior to version 3.5.51 allows attackers to access broadcasting Intent as system uid privilege.
ModificadaAlta (7.8)0.21%—Dell Chengming 3900 FirmwareDell Inspiron 14 Plus 7420 FirmwareDell Inspiron 16 Plus 7620 FirmwareDell Inspiron 3910 Firmware+2112/9/202217/6/2026
Dell BIOS versions contain a Stack-based Buffer Overflow vulnerability. A local authenticated malicious user could potentially exploit this vulnerability by sending excess data to a function in order to gain arbitrary code execution on the system.
ModificadaMedia (5.1)0.16%—Dell Chengming 3900 FirmwareDell Inspiron 14 Plus 7420 FirmwareDell Inspiron 16 Plus 7620 FirmwareDell Inspiron 3910 Firmware+2112/9/202217/6/2026
Dell BIOS versions contain an Unchecked Return Value vulnerability. A local authenticated administrator user could potentially exploit this vulnerability in order to change the state of the system or cause unexpected failures.
ModificadaBaja (2.4)0.23%—Dell Chengming 3900 FirmwareDell Inspiron 14 Plus 7420 FirmwareDell Inspiron 16 Plus 7620 FirmwareDell Inspiron 3910 Firmware+2112/9/202217/6/2026
Dell BIOS versions contain an Improper Protection Against Voltage and Clock Glitches vulnerability. An attacker with physical access to the system could potentially exploit this vulnerability by triggering a fault condition in order to change the behavior of the system.
ModificadaBaja (2.3)0.18%—Dell Chengming 3900 FirmwareDell Inspiron 14 Plus 7420 FirmwareDell Inspiron 16 Plus 7620 FirmwareDell Inspiron 3910 Firmware+2112/9/202217/6/2026
Dell BIOS versions contain an Improper Neutralization of Null Byte vulnerability. A local authenticated administrator user could potentially exploit this vulnerability by sending unexpected null bytes in order to read memory on the system.
ModificadaMedia (4.4)0.18%—Dell Chengming 3900 FirmwareDell Inspiron 14 Plus 7420 FirmwareDell Inspiron 16 Plus 7620 FirmwareDell Inspiron 3910 Firmware+2112/9/202217/6/2026
Dell BIOS versions contain a Missing Release of Resource after Effective Lifetime vulnerability. A local authenticated administrator user could potentially exploit this vulnerability by consuming excess memory in order to cause the application to crash.
ModificadaBaja (2.3)0.18%—Dell Chengming 3900 FirmwareDell Inspiron 14 Plus 7420 FirmwareDell Inspiron 16 Plus 7620 FirmwareDell Inspiron 3910 Firmware+2112/9/202217/6/2026
Dell BIOS versions contain an Information Exposure vulnerability. A local authenticated administrator user could potentially exploit this vulnerability in order access sensitive state information on the system.
ModificadaMedia (5.1)0.16%—Dell Chengming 3900 FirmwareDell Inspiron 14 Plus 7420 FirmwareDell Inspiron 16 Plus 7620 FirmwareDell Inspiron 3910 Firmware+2112/9/202217/6/2026
Dell BIOS versions contain an Unchecked Return Value vulnerability. A local authenticated administrator user could potentially exploit this vulnerability in order to change the state of the system or cause unexpected failures.
ModificadaMedia (6.3)0.21%—Opensuse Factory7/9/202217/6/2026
A Incorrect Default Permissions vulnerability in the packaging of the slurm testsuite of openSUSE Factory allows local attackers with control over the slurm user to escalate to root. This issue affects: openSUSE Factory slurm versions prior to 22.05.2-3.3.
ModificadaAlta (8.1)0.69%—SAP Successfactors Mobile27/7/202217/6/2026
Due to misconfigured application endpoints, SAP SuccessFactors attachment APIs allow attackers with user privileges to perform activities with admin privileges over the network. These APIs were consumed in the SF Mobile application for Time Off, Time Sheet, EC Workflow, and Benefits. On successful exploitation, the…
ModificadaMedia (4.9)0.84%—Jfrog Artifactory6/7/202217/6/2026
JFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure through the Project Administrator REST API. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.31.10 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x.
ModificadaMedia (6.1)0.57%—Jfrog Artifactory6/7/202217/6/2026
JFrog Artifactory prior to version 7.29.8 and 6.23.38 is vulnerable to Reflected Cross-Site Scripting (XSS) through one of the XHR parameters in Users REST API endpoint. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.36.1 versions prior to 7.29.8; JFrog Artifactory versions before…
ModificadaAlta (8.8)0.36%—Jfrog Artifactory6/7/202217/6/2026
JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific endpoints. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.33.6 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x.
ModificadaMedia (6.5)1.3%—Webfactoryltd External Links IN NEW Window / NEW TAB30/5/202217/6/2026
The External Links in New Window / New Tab WordPress plugin before 1.43 does not ensure window.opener is set to "null" when links to external sites are clicked, which may enable tabnabbing attacks to occur.
ModificadaMedia (6.1)0.79%—Webfactoryltd External Links IN NEW Window / NEW TAB30/5/202217/6/2026
The External Links in New Window / New Tab WordPress plugin before 1.43 does not properly escape URLs it concatenates to onclick event handlers, which makes Stored Cross-Site Scripting attacks possible.
ModificadaMedia (6.5)0.57%—Jfrog Artifactory23/5/202217/6/2026
JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality can be used by a low-privileged user to read and copy any artifact that exists in the Artifactory deployment due to improper permissions validation.