Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
574 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.4) | 0.32% | — | HP Z1 All-in-one G3 FirmwareHP Z2 Mini G3 FirmwareHP Z2 Mini G4 FirmwareHP Z2 Mini G5 Firmware+16 | 12/12/2022 | 17/6/2026 | A potential security vulnerability has been identified in certain HP Workstation BIOS (UEFI firmware) which may allow arbitrary code execution. HP is releasing firmware mitigations for the potential vulnerability. | |
| Modificada | Media (5.4) | 0.36% | — | Keyfactor Kefactor Ejbca | 17/11/2022 | 17/6/2026 | Keyfactor EJBCA before 7.10.0 allows XSS. | |
| Modificada | Media (5.4) | 0.36% | — | Keyfactor Primekey Ejbca | 17/11/2022 | 17/6/2026 | A stored XSS vulnerability was discovered in adminweb/ra/viewendentity.jsp in PrimeKey EJBCA through 7.9.0.2. A low-privilege user can store JavaScript in order to exploit a higher-privilege user. | |
| Modificada | Alta (7.5) | 1.2% | — | Rockwellautomation Factorytalk Alarms AND Events | 27/10/2022 | 17/6/2026 | An unauthenticated attacker with network access to a victim's Rockwell Automation FactoryTalk Alarm and Events service could open a connection, causing the service to fault and become unavailable. The affected port could be used as a server ping port and uses messages structured with XML. | |
| Modificada | Alta (7.8) | 0.24% | — | Opensuse Factory | 26/10/2022 | 17/6/2026 | A Improper Link Resolution Before File Access ('Link Following') vulnerability in a script called by the sendmail systemd service of openSUSE Factory allows local attackers to escalate from user mail to root. This issue affects: SUSE openSUSE Factory sendmail versions prior to 8.17.1-1.1. | |
| Modificada | Alta (8.8) | 3.5% | — | Rockwellautomation Factorytalk Vantagepoint | 17/10/2022 | 17/6/2026 | Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an input validation vulnerability. The FactoryTalk VantagePoint SQL Server lacks input validation when users enter SQL statements to retrieve information from the back-end database. If successfully exploited, this could… | |
| Modificada | Alta (8.8) | 1.4% | — | Rockwellautomation Factorytalk Vantagepoint | 17/10/2022 | 17/6/2026 | Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an improper access control vulnerability. The FactoryTalk VantagePoint SQL Server account could allow a malicious user with read-only privileges to execute SQL statements in the back-end database. If successfully… | |
| Modificada | Baja (3.3) | 0.16% | — | Samsung Factorycamera | 7/10/2022 | 17/6/2026 | Unprotected Receiver in AtBroadcastReceiver in FactoryCamera prior to version 3.5.51 allows attackers to record video without camera privilege. | |
| Modificada | Alta (7.8) | 0.23% | — | Samsung Factorycamera | 7/10/2022 | 17/6/2026 | Path traversal vulnerability in AtBroadcastReceiver in FactoryCamera prior to version 3.5.51 allows attackers to write arbitrary file as FactoryCamera privilege. | |
| Modificada | Media (5.5) | 0.17% | — | Samsung Factorycamerafb | 7/10/2022 | 17/6/2026 | Improper access control vulnerability in CameraTestActivity in FactoryCameraFB prior to version 3.5.51 allows attackers to access broadcasting Intent as system uid privilege. | |
| Modificada | Alta (7.8) | 0.21% | — | Dell Chengming 3900 FirmwareDell Inspiron 14 Plus 7420 FirmwareDell Inspiron 16 Plus 7620 FirmwareDell Inspiron 3910 Firmware+21 | 12/9/2022 | 17/6/2026 | Dell BIOS versions contain a Stack-based Buffer Overflow vulnerability. A local authenticated malicious user could potentially exploit this vulnerability by sending excess data to a function in order to gain arbitrary code execution on the system. | |
| Modificada | Media (5.1) | 0.16% | — | Dell Chengming 3900 FirmwareDell Inspiron 14 Plus 7420 FirmwareDell Inspiron 16 Plus 7620 FirmwareDell Inspiron 3910 Firmware+21 | 12/9/2022 | 17/6/2026 | Dell BIOS versions contain an Unchecked Return Value vulnerability. A local authenticated administrator user could potentially exploit this vulnerability in order to change the state of the system or cause unexpected failures. | |
| Modificada | Baja (2.4) | 0.23% | — | Dell Chengming 3900 FirmwareDell Inspiron 14 Plus 7420 FirmwareDell Inspiron 16 Plus 7620 FirmwareDell Inspiron 3910 Firmware+21 | 12/9/2022 | 17/6/2026 | Dell BIOS versions contain an Improper Protection Against Voltage and Clock Glitches vulnerability. An attacker with physical access to the system could potentially exploit this vulnerability by triggering a fault condition in order to change the behavior of the system. | |
| Modificada | Baja (2.3) | 0.18% | — | Dell Chengming 3900 FirmwareDell Inspiron 14 Plus 7420 FirmwareDell Inspiron 16 Plus 7620 FirmwareDell Inspiron 3910 Firmware+21 | 12/9/2022 | 17/6/2026 | Dell BIOS versions contain an Improper Neutralization of Null Byte vulnerability. A local authenticated administrator user could potentially exploit this vulnerability by sending unexpected null bytes in order to read memory on the system. | |
| Modificada | Media (4.4) | 0.18% | — | Dell Chengming 3900 FirmwareDell Inspiron 14 Plus 7420 FirmwareDell Inspiron 16 Plus 7620 FirmwareDell Inspiron 3910 Firmware+21 | 12/9/2022 | 17/6/2026 | Dell BIOS versions contain a Missing Release of Resource after Effective Lifetime vulnerability. A local authenticated administrator user could potentially exploit this vulnerability by consuming excess memory in order to cause the application to crash. | |
| Modificada | Baja (2.3) | 0.18% | — | Dell Chengming 3900 FirmwareDell Inspiron 14 Plus 7420 FirmwareDell Inspiron 16 Plus 7620 FirmwareDell Inspiron 3910 Firmware+21 | 12/9/2022 | 17/6/2026 | Dell BIOS versions contain an Information Exposure vulnerability. A local authenticated administrator user could potentially exploit this vulnerability in order access sensitive state information on the system. | |
| Modificada | Media (5.1) | 0.16% | — | Dell Chengming 3900 FirmwareDell Inspiron 14 Plus 7420 FirmwareDell Inspiron 16 Plus 7620 FirmwareDell Inspiron 3910 Firmware+21 | 12/9/2022 | 17/6/2026 | Dell BIOS versions contain an Unchecked Return Value vulnerability. A local authenticated administrator user could potentially exploit this vulnerability in order to change the state of the system or cause unexpected failures. | |
| Modificada | Media (6.3) | 0.21% | — | Opensuse Factory | 7/9/2022 | 17/6/2026 | A Incorrect Default Permissions vulnerability in the packaging of the slurm testsuite of openSUSE Factory allows local attackers with control over the slurm user to escalate to root. This issue affects: openSUSE Factory slurm versions prior to 22.05.2-3.3. | |
| Modificada | Alta (8.1) | 0.69% | — | SAP Successfactors Mobile | 27/7/2022 | 17/6/2026 | Due to misconfigured application endpoints, SAP SuccessFactors attachment APIs allow attackers with user privileges to perform activities with admin privileges over the network. These APIs were consumed in the SF Mobile application for Time Off, Time Sheet, EC Workflow, and Benefits. On successful exploitation, the… | |
| Modificada | Media (4.9) | 0.84% | — | Jfrog Artifactory | 6/7/2022 | 17/6/2026 | JFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure through the Project Administrator REST API. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.31.10 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x. | |
| Modificada | Media (6.1) | 0.57% | — | Jfrog Artifactory | 6/7/2022 | 17/6/2026 | JFrog Artifactory prior to version 7.29.8 and 6.23.38 is vulnerable to Reflected Cross-Site Scripting (XSS) through one of the XHR parameters in Users REST API endpoint. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.36.1 versions prior to 7.29.8; JFrog Artifactory versions before… | |
| Modificada | Alta (8.8) | 0.36% | — | Jfrog Artifactory | 6/7/2022 | 17/6/2026 | JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific endpoints. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.33.6 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x. | |
| Modificada | Media (6.5) | 1.3% | — | Webfactoryltd External Links IN NEW Window / NEW TAB | 30/5/2022 | 17/6/2026 | The External Links in New Window / New Tab WordPress plugin before 1.43 does not ensure window.opener is set to "null" when links to external sites are clicked, which may enable tabnabbing attacks to occur. | |
| Modificada | Media (6.1) | 0.79% | — | Webfactoryltd External Links IN NEW Window / NEW TAB | 30/5/2022 | 17/6/2026 | The External Links in New Window / New Tab WordPress plugin before 1.43 does not properly escape URLs it concatenates to onclick event handlers, which makes Stored Cross-Site Scripting attacks possible. | |
| Modificada | Media (6.5) | 0.57% | — | Jfrog Artifactory | 23/5/2022 | 17/6/2026 | JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality can be used by a low-privileged user to read and copy any artifact that exists in the Artifactory deployment due to improper permissions validation. |