Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
475 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.7% | — | AMD Epyc 7232pAMD Epyc 7251AMD Epyc 7252AMD Epyc 7261+61 | 13/5/2021 | 17/6/2026 | In the AMD SEV/SEV-ES feature, memory can be rearranged in the guest address space that is not detected by the attestation mechanism which could be used by a malicious hypervisor to potentially lead to arbitrary code execution within the guest VM if a malicious administrator has access to compromise the server… | |
| Modificada | Alta (7.2) | 1.7% | — | AMD Epyc 7232pAMD Epyc 7251AMD Epyc 7252AMD Epyc 7261+61 | 13/5/2021 | 17/6/2026 | The lack of nested page table protection in the AMD SEV/SEV-ES feature could potentially lead to arbitrary code execution within the guest VM if a malicious administrator has access to compromise the server hypervisor. | |
| Modificada | Alta (7.8) | 0.22% | — | Google Cloud IOT Device SDK FOR Embedded C | 4/5/2021 | 17/6/2026 | In IoT Devices SDK, there is an implementation of calloc() that doesn't have a length check. An attacker could pass in memory objects larger than the buffer and wrap around to have a smaller buffer than required, allowing the attacker access to the other parts of the heap. We recommend upgrading the Google Cloud IoT… | |
| Modificada | Alta (7.3) | 1.1% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux ARM SL+18 | 3/5/2021 | 17/6/2026 | CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages. | |
| Modificada | Media (6.5) | 1.7% | — | Ckeditor5-engineCkeditor5-fontCkeditor5-imageCkeditor5-list+4 | 29/4/2021 | 17/6/2026 | CKEditor 5 provides a WYSIWYG editing solution. This CVE affects the following npm packages: ckeditor5-engine, ckeditor5-font, ckeditor5-image, ckeditor5-list, ckeditor5-markdown-gfm, ckeditor5-media-embed, ckeditor5-paste-from-office, and ckeditor5-widget. Following an internal audit, a regular expression denial of… | |
| Modificada | Alta (7.5) | 1.2% | — | Oryx-embedded Cyclonetcp | 8/3/2021 | 17/6/2026 | Oryx Embedded CycloneTCP 1.7.6 to 2.0.0, fixed in 2.0.2, is affected by incorrect input validation, which may cause a denial of service (DoS). To exploit the vulnerability, an attacker needs to have TCP connectivity to the target system. Receiving a maliciously crafted TCP packet from an unauthenticated endpoint is… | |
| Modificada | Media (6.1) | 0.61% | — | Secomea Sitemanager Embedded | 16/2/2021 | 17/6/2026 | A vulnerability in SiteManager-Embedded (SM-E) Web server which may allow attacker to construct a URL that if visited by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application. This issue affects all… | |
| Modificada | Alta (8.8) | 4.0% | — | Embedthis Goahead | 23/7/2020 | 17/6/2026 | The HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks. This allows an unauthenticated remote attacker to bypass authentication via capture-replay if TLS is not used to protect the underlying communication channel. | |
| Modificada | Alta (7.5) | 2.0% | — | Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000Codesys Control FOR Linux+12 | 22/7/2020 | 17/6/2026 | CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation. | |
| Modificada | Alta (7.5) | 1.3% | — | Embedthis Appweb | 13/7/2020 | 17/6/2026 | Appweb before 7.2.2 and 8.x before 8.1.0, when built with CGI support, mishandles an HTTP request with a Range header that lacks an exact range. This may result in a NULL pointer dereference and cause a denial of service. | |
| Modificada | Media (4.4) | 0.29% | — | Dell Chengming 3967 FirmwareDell Chengming 3977 FirmwareDell Chengming 3980 FirmwareDell Chengming 3988 Firmware+350 | 10/6/2020 | 17/6/2026 | Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability interface for which an unauthorized actor, with local system access with OS administrator privileges, could bypass the BIOS Administrator authentication to restore BIOS Setup configuration to default… | |
| Modificada | Crítica (9.8) | 2.5% | — | Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000Codesys Control FOR Linux+10 | 26/3/2020 | 17/6/2026 | CODESYS V3 web server before 3.5.15.40, as used in CODESYS Control runtime systems, has a buffer overflow. | |
| Modificada | Media (5.3) | 0.35% | — | Dell Chengming 3980 FirmwareDell G3 3579 FirmwareDell G3 3590 FirmwareDell G3 3779 Firmware+170 | 21/2/2020 | 17/6/2026 | Affected Dell Client platforms contain a BIOS Setup configuration authentication bypass vulnerability in the pre-boot Intel Rapid Storage Response Technology (iRST) Manager menu. An attacker with physical access to the system could perform unauthorized changes to the BIOS Setup configuration settings without requiring… | |
| Modificada | Crítica (9.8) | 1.8% | — | Wp-pdf PDF Embedder | 5/12/2019 | 17/6/2026 | The Lever PDF Embedder plugin 4.4 for WordPress does not block the distribution of polyglot PDF documents that are valid JAR archives. Note: It has been argued that "The vulnerability reported in PDF Embedder Plugin is not valid as the plugin itself doesn't control or manage the file upload process. It only serves the… | |
| Modificada | Alta (7.5) | 45% | — | Embedthis Goahead | 3/12/2019 | 17/6/2026 | A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web server application in versions v5.0.1, v.4.1.1 and v3.6.5. A specially crafted HTTP request can lead to an infinite loop in the process. The request can be unauthenticated in the form of GET or POST… | |
| Modificada | Crítica (9.8) | 67% | 💥 PoC | Embedthis Goahead | 3/12/2019 | 17/6/2026 | An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base GoAhead web server application in versions v5.0.1, v.4.1.1 and v3.6.5. A specially crafted HTTP request can lead to a use-after-free condition during the processing of this request that can be used to… | |
| Modificada | Media (5.3) | 1.5% | — | Embedthis Goahead | 22/11/2019 | 17/6/2026 | Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header. The GoAhead WebsRedirect uses a static host buffer that has a limited length and can overflow. This can cause a copy of the Host header to fail, leaving that buffer uninitialized, which may leak uninitialized data in a… | |
| Modificada | Crítica (9.8) | 1.9% | — | Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000Codesys Control FOR Linux+10 | 20/11/2019 | 17/6/2026 | CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow. | |
| Modificada | Alta (8.6) | 8.2% | 💥 Exploit | Embedthis Goahead | 20/9/2019 | 17/6/2026 | An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) create links containing a hostname obtained from an arbitrary HTTP Host header sent by an attacker. This could potentially be used in a phishing attack. | |
| Modificada | Crítica (9.8) | 5.8% | — | Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000Codesys Control FOR Linux+9 | 13/9/2019 | 17/6/2026 | CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which could cause a stack overflow and create a denial-of-service condition or allow remote code execution. | |
| Modificada | Alta (7.5) | 3.2% | — | Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000Codesys Control FOR Linux+9 | 13/9/2019 | 17/6/2026 | CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which may allow access to files outside the restricted working directory of the controller. | |
| Modificada | Alta (8.8) | 1.7% | — | Elearningfreak Insert OR Embed Articulate Content | 27/8/2019 | 17/6/2026 | The insert-or-embed-articulate-content-into-wordpress plugin before 4.2999 for WordPress has insufficient restrictions on file upload. | |
| Modificada | Media (6.5) | 0.63% | — | Elearningfreak Insert OR Embed Articulate Content | 27/8/2019 | 17/6/2026 | The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a Subscriber. | |
| Modificada | Media (6.1) | 0.91% | — | Embed Images IN Comments Project Embed Images IN Comments | 21/8/2019 | 17/6/2026 | The embed-comment-images plugin before 0.6 for WordPress has XSS. | |
| Modificada | Alta (8.8) | 0.71% | — | Google DOC Embedder Project Google DOC Embedder | 14/8/2019 | 17/6/2026 | The google-document-embedder plugin before 2.6.2 for WordPress has CSRF. |