Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

454 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)1.2%—Magicfields Magic Fields10/9/201917/6/2026
The magic-fields plugin before 1.7.2 for WordPress has XSS via the custom-write-panel-id parameter.
ModificadaMedia (5.4)0.95%—Advancedcustomfields Advanced Custom Fields22/8/201917/6/2026
The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by authors.
ModificadaAlta (8.8)0.67%—Simple Fields Project Simple Fields14/8/201917/6/2026
The simple-fields plugin before 1.2 for WordPress has CSRF in the admin interface.
ModificadaMedia (6.1)0.95%—Simple Fields Project Simple Fields13/8/201917/6/2026
The simple-fields plugin before 1.4.11 for WordPress has XSS.
ModificadaAlta (7.5)2.0%—Cisco IOT Field Network Director8/8/201917/6/2026
A vulnerability in the web interface of Cisco IoT Field Network Director could allow an unauthenticated, remote attacker to trigger high CPU usage, resulting in a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of Transport Layer Security (TLS) renegotiation…
ModificadaCrítica (9.6)1.6%—Oracle Field Service23/7/201917/6/2026
Vulnerability in the Oracle Field Service component of Oracle E-Business Suite (subcomponent: Wireless). Supported versions that are affected are 12.1.1 - 12.1.3 and 12.2.3 - 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Field Service.…
ModificadaCrítica (9.8)2.0%—Teclib-edition Fields10/7/201917/6/2026
An issue was discovered in the Teclib Fields plugin through 1.9.2 for GLPI. it allows SQL Injection via container_id and old_order parameters to ajax/reorder.php by an unauthenticated user.
ModificadaMedia (5.3)1.4%—Field Test Project Field Test9/7/201917/6/2026
The field_test gem 0.3.0 for Ruby has unvalidated input. A method call that is expected to return a value from a certain set of inputs can be made to return any input, which can be dangerous depending on how applications use it. If an application treats arbitrary variants as trusted, this can lead to a variety of…
ModificadaMedia (5.4)0.93%—Custom Field Suite Project Custom Field Suite10/5/201917/6/2026
The Custom Field Suite plugin before 2.5.15 for WordPress has XSS for editors or admins.
ModificadaMedia (4.9)3.1%💥 PoCCisco IOT Field Network Director21/2/201917/6/2026
A vulnerability in the web-based user interface of Cisco Internet of Things Field Network Director (IoT-FND) Software could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. The vulnerability is due to improper handling of XML External Entity (XXE) entries…
ModificadaAlta (7.5)2.3%—Cisco IOT Field Network Director23/1/201917/6/2026
A vulnerability in the UDP protocol implementation for Cisco IoT Field Network Director (IoT-FND) could allow an unauthenticated, remote attacker to exhaust system resources, resulting in a denial of service (DoS) condition. The vulnerability is due to improper resource management for UDP ingress packets. An attacker…
ModificadaCrítica (9.8)1.2%—Deiser Profields-project Custom Fields21/9/201817/6/2026
The DEISER "Profields - Project Custom Fields" app before 6.0.2 for Jira has Incorrect Access Control.
ModificadaMedia (5.3)3.3%—Siemens Simatic Field PG M5 FirmwareSiemens Simatic Ipc427e FirmwareSiemens Simatic Ipc477e FirmwareSiemens Simatic Ipc547e Firmware+1012/9/201817/6/2026
Multiple memory leaks in Intel AMT in Intel CSME firmware versions before 12.0.5 may allow an unauthenticated user with Intel AMT provisioned to potentially cause a partial denial of service via network access.
ModificadaMedia (6.7)0.59%—Siemens Simatic Field PG M5 FirmwareSiemens Simatic Ipc427e FirmwareSiemens Simatic Ipc477e FirmwareSiemens Simatic Ipc547e Firmware+1012/9/201817/6/2026
Multiple buffer overflows in Intel AMT in Intel CSME firmware versions before version 12.0.5 may allow a privileged user to potentially execute arbitrary code with Intel AMT execution privilege via local access.
ModificadaMedia (5.9)2.4%—Intel Converged Security Management Engine FirmwareIntel Active Management Technology FirmwareIntel Manageability Engine FirmwareSiemens Simatic Field PG M5 Firmware+1012/9/201817/6/2026
Bleichenbacher-style side channel vulnerability in TLS implementation in Intel Active Management Technology before 12.0.5 may allow an unauthenticated user to potentially obtain the TLS session key via the network.
ModificadaMedia (5.3)30%💥 ExploitEndress Wirelesshart Fieldgate Swg70 Firmware7/9/201817/6/2026
Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename parameter.
ModificadaMedia (6.1)1.2%💥 PoCGrails Fields26/6/201817/6/2026
Grails Fields plugin version 2.2.7 contains a Cross Site Scripting (XSS) vulnerability in Using the display tag that can result in XSS . This vulnerability appears to have been fixed in 2.2.8.
ModificadaMedia (5.5)61%💥 ExploitIntel Atom CIntel Atom EIntel Atom X5-e3930Intel Atom X5-e3940+27822/5/201817/6/2026
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB),…
ModificadaAlta (8.8)0.68%—Cisco IOT Field Network Director17/5/201817/6/2026
A vulnerability in the web-based management interface of Cisco IoT Field Network Director (IoT-FND) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and alter the data of existing users and groups on an affected device. The vulnerability is due to insufficient CSRF…
ModificadaAlta (8.7)3.3%—Siemens Simatic S7-200 FirmwareSiemens Simatic S7-400pn V6 FirmwareSiemens Simatic S7-400h V6 FirmwareSiemens Simatic S7-400pn/dp V7 Firmware+3426/12/201717/6/2026
Specially crafted packets sent to port 161/udp could cause a denial of service condition. The affected devices must be restarted manually.
ModificadaAlta (7.2)4.4%—Intel Manageability Engine FirmwareIntel Active Management Technology FirmwareAsus Z170-premium FirmwareAsus Z170-deluxe Firmware+19421/11/201717/6/2026
Buffer overflow in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allows attacker with remote Admin access to the system to execute arbitrary code with AMT execution privilege.
ModificadaAlta (7.8)0.56%—Intel Manageability Engine FirmwareIntel Active Management Technology FirmwareAsus Z170-premium FirmwareAsus Z170-deluxe Firmware+19421/11/201717/6/2026
Multiple buffer overflows in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access to the system to execute arbitrary code with AMT execution privilege.
ModificadaAlta (8.2)1.6%—Oracle Mobile Field Service19/10/201717/6/2026
Vulnerability in the Oracle Mobile Field Service component of Oracle E-Business Suite (subcomponent: Multiplatform Based on HTML5). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network…
ModificadaAlta (7.5)1.7%—Cisco Connected Grid Network Management SystemCisco IOT Field Network Director7/9/201717/6/2026
A vulnerability in the TCP throttling process for Cisco IoT Field Network Director (IoT-FND) could allow an unauthenticated, remote attacker to cause the system to consume additional memory, eventually forcing the device to restart, aka Memory Exhaustion. The vulnerability is due to insufficient rate-limiting…
ModificadaMedia (5.3)2.0%—Oracle Field Service8/8/201717/6/2026
Vulnerability in the Oracle Field Service component of Oracle E-Business Suite (subcomponent: Wireless/WAP). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…