Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
454 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.6% | — | Cisco IOT Field Network Director | 18/11/2020 | 17/6/2026 | A vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to gain access to the back-end database of an affected device. The vulnerability is due to insufficient input validation of REST API requests that are made to an affected device. An attacker could… | |
| Modificada | Alta (8.7) | 1.0% | — | Cisco IOT Field Network Director | 18/11/2020 | 17/6/2026 | A vulnerability in the SOAP API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to access and modify information on devices that belong to a different domain. The vulnerability is due to insufficient authorization in the SOAP API. An attacker could exploit this vulnerability by… | |
| Analizada | Media (6.8) | 0.38% | — | Intel Converged Security AND Manageability EngineIntel Trusted Execution TechnologySiemens Simatic Drive Controller FirmwareSiemens Simatic Et200sp 1515sp PC2 Firmware+18 | 12/11/2020 | 17/6/2026 | Insufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25 , Intel(R) TXE versions before 3.1.80 and 4.0.30 may allow an unauthenticated user to potentially enable escalation of privilege via physical access. | |
| Modificada | Media (5.5) | 0.52% | — | Intel MicrocodeNetapp Clustered Data OntapNetapp HCI Compute Node BiosNetapp HCI Storage Node Bios+13 | 12/11/2020 | 17/6/2026 | Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Crítica (9.8) | 4.2% | — | Exodus Field | 12/11/2020 | 17/6/2026 | Prototype pollution vulnerability in 'field' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution. | |
| Modificada | Alta (8.8) | 0.77% | — | Garfield Petshop Project Garfield Petshop | 9/10/2020 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in mod/user/act_user.php in Garfield Petshop through 2020-10-01 allows remote attackers to hijack the authentication of administrators for requests that create new administrative accounts. | |
| Modificada | Media (4.3) | 0.43% | — | Field Test Project Field Test | 5/8/2020 | 17/6/2026 | The Field Test gem 0.2.0 through 0.3.2 for Ruby allows CSRF. | |
| Modificada | Alta (7.5) | 1.3% | — | Mitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric EM ConfiguratorMitsubishielectric GT Designer3+16 | 30/6/2020 | 17/6/2026 | Uncontrolled resource consumption vulnerability in Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, EM Software Development Kit (EM Configurator) Ver. 1.010L and earlier, GT Designer3 (GOT2000) Ver. 1.221F and earlier,… | |
| Modificada | Alta (7.5) | 1.4% | — | Mitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric EM ConfiguratorMitsubishielectric GT Designer3+16 | 30/6/2020 | 17/6/2026 | Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, EM Software Development Kit (EM Configurator) Ver. 1.010L and earlier, GT Designer3 (GOT2000) Ver. 1.221F and earlier, GX LogViewer Ver. 1.96A and earlier, GX Works2 Ver.… | |
| Modificada | Media (5.5) | 0.54% | — | Intel Celeron 1000mIntel Celeron 1005mIntel Celeron 1007uIntel Celeron 1017u+690 | 15/6/2020 | 17/6/2026 | Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Alta (7.5) | 1.7% | — | Cisco IOT Field Network Director | 15/4/2020 | 17/6/2026 | A vulnerability in the Constrained Application Protocol (CoAP) implementation of Cisco IoT Field Network Director could allow an unauthenticated remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation of incoming CoAP traffic. An… | |
| Modificada | Media (6.7) | 0.34% | — | Intel Field Programmable Gate Array Programmable Acceleration Card N3000 Firmware | 12/3/2020 | 17/6/2026 | Improper access control in PCIe function for the Intel® FPGA Programmable Acceleration Card N3000, all versions, may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (4.4) | 0.28% | — | Intel Field Programmable Gate Array Programmable Acceleration Card N3000 Firmware | 12/3/2020 | 17/6/2026 | Improper access control in on-card storage for the Intel® FPGA Programmable Acceleration Card N3000, all versions, may allow a privileged user to potentially enable denial of service via local access. | |
| Modificada | Crítica (9.8) | 2.1% | — | Postoaktraffic Awam Bluetooth Field Device Firmware | 17/2/2020 | 17/6/2026 | Post Oak AWAM Bluetooth Field Device 7400v2.08.21.2018, 7800SD.2015.1.16, 2011.3, 7400v2.02.01.2019, and 7800SD.2012.12.5 is vulnerable to injections of operating system commands through timeconfig.py via shell metacharacters in the htmlNtpServer parameter. | |
| Modificada | Crítica (9.8) | 6.7% | — | Yokogawa Centum CS 1000 FirmwareYokogawa Centum CS 3000 FirmwareYokogawa Centum CS 3000 Entry FirmwareYokogawa Centum VP Firmware+17 | 5/2/2020 | 17/6/2026 | Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and… | |
| Modificada | Crítica (9.8) | 4.2% | — | Yokogawa Centum CS 1000 FirmwareYokogawa Centum CS 3000 FirmwareYokogawa Centum CS 3000 Entry FirmwareYokogawa Centum VP Firmware+17 | 5/2/2020 | 17/6/2026 | Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and… | |
| Modificada | Crítica (9.8) | 4.2% | — | Yokogawa Centum CS 1000 FirmwareYokogawa Centum CS 3000 FirmwareYokogawa Centum CS 3000 Entry FirmwareYokogawa Centum VP Firmware+17 | 5/2/2020 | 17/6/2026 | Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and… | |
| Modificada | Media (5.4) | 0.99% | — | Codepeople Calculated Fields Form | 22/1/2020 | 17/6/2026 | The Calculated Fields Form plugin through 1.0.353 for WordPress suffers from multiple Stored XSS vulnerabilities present in the input forms. These can be exploited by an authenticated user. | |
| Modificada | Media (6.1) | 0.94% | — | Oracle Field Service | 15/1/2020 | 17/6/2026 | Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Wireless). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Field Service. Successful… | |
| Modificada | Crítica (9.8) | 1.8% | — | Drupal Views Dynamic Field | 16/12/2019 | 17/6/2026 | The Views Dynamic Fields module through 7.x-1.0-alpha4 for Drupal makes insecure unserialize calls in handlers/views_handler_filter_dynamic_fields.inc, as demonstrated by PHP object injection, involving a field_names object and an Archive_Tar object, for file deletion. Code execution might also be possible. | |
| Modificada | Media (5.5) | 0.31% | — | Intel Field Programmable Gate Array Software Development KIT FOR Opencl | 16/12/2019 | 17/6/2026 | Improper conditions check in the Linux kernel driver for the Intel(R) FPGA SDK for OpenCL(TM) Pro Edition before version 19.4 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (4.7) | 1.1% | — | Oracle Field Service | 16/10/2019 | 17/6/2026 | Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Wireless). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Field Service. Successful… | |
| Modificada | Crítica (9.8) | 2.8% | — | Advancedcustomfields ACF Fronted Display | 10/10/2019 | 17/6/2026 | The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an action=upload request to js/blueimp-jQuery-File-Upload-d45deb1/server/php/index.php. | |
| Modificada | Media (6.1) | 1.2% | — | Magicfields Magic Fields | 10/9/2019 | 17/6/2026 | The magic-fields plugin before 1.7.2 for WordPress has XSS via the RCCWP_CreateCustomFieldPage.php custom-field-css parameter. | |
| Modificada | Media (6.1) | 1.2% | — | Magicfields Magic Fields | 10/9/2019 | 17/6/2026 | The magic-fields plugin before 1.7.2 for WordPress has XSS via the RCCWP_CreateCustomFieldPage.php custom-group-id parameter. |