Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
454 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.2% | — | Magicfields Magic Fields | 10/9/2019 | 17/6/2026 | The magic-fields plugin before 1.7.2 for WordPress has XSS via the custom-write-panel-id parameter. | |
| Modificada | Media (5.4) | 0.95% | — | Advancedcustomfields Advanced Custom Fields | 22/8/2019 | 17/6/2026 | The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by authors. | |
| Modificada | Alta (8.8) | 0.67% | — | Simple Fields Project Simple Fields | 14/8/2019 | 17/6/2026 | The simple-fields plugin before 1.2 for WordPress has CSRF in the admin interface. | |
| Modificada | Media (6.1) | 0.95% | — | Simple Fields Project Simple Fields | 13/8/2019 | 17/6/2026 | The simple-fields plugin before 1.4.11 for WordPress has XSS. | |
| Modificada | Alta (7.5) | 2.0% | — | Cisco IOT Field Network Director | 8/8/2019 | 17/6/2026 | A vulnerability in the web interface of Cisco IoT Field Network Director could allow an unauthenticated, remote attacker to trigger high CPU usage, resulting in a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of Transport Layer Security (TLS) renegotiation… | |
| Modificada | Crítica (9.6) | 1.6% | — | Oracle Field Service | 23/7/2019 | 17/6/2026 | Vulnerability in the Oracle Field Service component of Oracle E-Business Suite (subcomponent: Wireless). Supported versions that are affected are 12.1.1 - 12.1.3 and 12.2.3 - 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Field Service.… | |
| Modificada | Crítica (9.8) | 2.0% | — | Teclib-edition Fields | 10/7/2019 | 17/6/2026 | An issue was discovered in the Teclib Fields plugin through 1.9.2 for GLPI. it allows SQL Injection via container_id and old_order parameters to ajax/reorder.php by an unauthenticated user. | |
| Modificada | Media (5.3) | 1.4% | — | Field Test Project Field Test | 9/7/2019 | 17/6/2026 | The field_test gem 0.3.0 for Ruby has unvalidated input. A method call that is expected to return a value from a certain set of inputs can be made to return any input, which can be dangerous depending on how applications use it. If an application treats arbitrary variants as trusted, this can lead to a variety of… | |
| Modificada | Media (5.4) | 0.93% | — | Custom Field Suite Project Custom Field Suite | 10/5/2019 | 17/6/2026 | The Custom Field Suite plugin before 2.5.15 for WordPress has XSS for editors or admins. | |
| Modificada | Media (4.9) | 3.1% | 💥 PoC | Cisco IOT Field Network Director | 21/2/2019 | 17/6/2026 | A vulnerability in the web-based user interface of Cisco Internet of Things Field Network Director (IoT-FND) Software could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. The vulnerability is due to improper handling of XML External Entity (XXE) entries… | |
| Modificada | Alta (7.5) | 2.3% | — | Cisco IOT Field Network Director | 23/1/2019 | 17/6/2026 | A vulnerability in the UDP protocol implementation for Cisco IoT Field Network Director (IoT-FND) could allow an unauthenticated, remote attacker to exhaust system resources, resulting in a denial of service (DoS) condition. The vulnerability is due to improper resource management for UDP ingress packets. An attacker… | |
| Modificada | Crítica (9.8) | 1.2% | — | Deiser Profields-project Custom Fields | 21/9/2018 | 17/6/2026 | The DEISER "Profields - Project Custom Fields" app before 6.0.2 for Jira has Incorrect Access Control. | |
| Modificada | Media (5.3) | 3.3% | — | Siemens Simatic Field PG M5 FirmwareSiemens Simatic Ipc427e FirmwareSiemens Simatic Ipc477e FirmwareSiemens Simatic Ipc547e Firmware+10 | 12/9/2018 | 17/6/2026 | Multiple memory leaks in Intel AMT in Intel CSME firmware versions before 12.0.5 may allow an unauthenticated user with Intel AMT provisioned to potentially cause a partial denial of service via network access. | |
| Modificada | Media (6.7) | 0.59% | — | Siemens Simatic Field PG M5 FirmwareSiemens Simatic Ipc427e FirmwareSiemens Simatic Ipc477e FirmwareSiemens Simatic Ipc547e Firmware+10 | 12/9/2018 | 17/6/2026 | Multiple buffer overflows in Intel AMT in Intel CSME firmware versions before version 12.0.5 may allow a privileged user to potentially execute arbitrary code with Intel AMT execution privilege via local access. | |
| Modificada | Media (5.9) | 2.4% | — | Intel Converged Security Management Engine FirmwareIntel Active Management Technology FirmwareIntel Manageability Engine FirmwareSiemens Simatic Field PG M5 Firmware+10 | 12/9/2018 | 17/6/2026 | Bleichenbacher-style side channel vulnerability in TLS implementation in Intel Active Management Technology before 12.0.5 may allow an unauthenticated user to potentially obtain the TLS session key via the network. | |
| Modificada | Media (5.3) | 30% | 💥 Exploit | Endress Wirelesshart Fieldgate Swg70 Firmware | 7/9/2018 | 17/6/2026 | Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename parameter. | |
| Modificada | Media (6.1) | 1.2% | 💥 PoC | Grails Fields | 26/6/2018 | 17/6/2026 | Grails Fields plugin version 2.2.7 contains a Cross Site Scripting (XSS) vulnerability in Using the display tag that can result in XSS . This vulnerability appears to have been fixed in 2.2.8. | |
| Modificada | Media (5.5) | 61% | 💥 Exploit | Intel Atom CIntel Atom EIntel Atom X5-e3930Intel Atom X5-e3940+278 | 22/5/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB),… | |
| Modificada | Alta (8.8) | 0.68% | — | Cisco IOT Field Network Director | 17/5/2018 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco IoT Field Network Director (IoT-FND) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and alter the data of existing users and groups on an affected device. The vulnerability is due to insufficient CSRF… | |
| Modificada | Alta (8.7) | 3.3% | — | Siemens Simatic S7-200 FirmwareSiemens Simatic S7-400pn V6 FirmwareSiemens Simatic S7-400h V6 FirmwareSiemens Simatic S7-400pn/dp V7 Firmware+34 | 26/12/2017 | 17/6/2026 | Specially crafted packets sent to port 161/udp could cause a denial of service condition. The affected devices must be restarted manually. | |
| Modificada | Alta (7.2) | 4.4% | — | Intel Manageability Engine FirmwareIntel Active Management Technology FirmwareAsus Z170-premium FirmwareAsus Z170-deluxe Firmware+194 | 21/11/2017 | 17/6/2026 | Buffer overflow in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allows attacker with remote Admin access to the system to execute arbitrary code with AMT execution privilege. | |
| Modificada | Alta (7.8) | 0.56% | — | Intel Manageability Engine FirmwareIntel Active Management Technology FirmwareAsus Z170-premium FirmwareAsus Z170-deluxe Firmware+194 | 21/11/2017 | 17/6/2026 | Multiple buffer overflows in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access to the system to execute arbitrary code with AMT execution privilege. | |
| Modificada | Alta (8.2) | 1.6% | — | Oracle Mobile Field Service | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle Mobile Field Service component of Oracle E-Business Suite (subcomponent: Multiplatform Based on HTML5). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network… | |
| Modificada | Alta (7.5) | 1.7% | — | Cisco Connected Grid Network Management SystemCisco IOT Field Network Director | 7/9/2017 | 17/6/2026 | A vulnerability in the TCP throttling process for Cisco IoT Field Network Director (IoT-FND) could allow an unauthenticated, remote attacker to cause the system to consume additional memory, eventually forcing the device to restart, aka Memory Exhaustion. The vulnerability is due to insufficient rate-limiting… | |
| Modificada | Media (5.3) | 2.0% | — | Oracle Field Service | 8/8/2017 | 17/6/2026 | Vulnerability in the Oracle Field Service component of Oracle E-Business Suite (subcomponent: Wireless/WAP). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… |