Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1459 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.17%—Dell Openmanage Server Administrator11/6/202417/6/2026
Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains a Local Privilege Escalation vulnerability via XSL Hijacking. A local low-privileged malicious user could potentially exploit this vulnerability and escalate their privilege to the admin user and gain full control of the machine. Exploitation…
AnalizadaMedia (6.8)0.18%—HP Elite Slice FirmwareHP Elite Slice FOR Meeting Rooms FirmwareHP Elitebook 1040 G3 FirmwareHP Elitebook 820 G3 Firmware+2210/6/202417/6/2026
Potential vulnerabilities have been identified in the system BIOS for certain HP PC products, which might allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities.
AnalizadaMedia (6.8)0.17%—HP Elite Slice FirmwareHP Elite Slice FOR Meeting Rooms FirmwareHP Elitebook 1040 G3 FirmwareHP Elitebook 820 G3 Firmware+2210/6/202417/6/2026
Potential vulnerabilities have been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities.
ModificadaMedia (5.4)0.44%—Webfactoryltd Minimal Coming Soon & Maintenance Mode8/6/202417/6/2026
The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the validate_ajax, deactivate_ajax, and save_ajax functions in all versions up to, and including, 2.38. This makes it possible for authenticated attackers, with…
AplazadaMedia (5.3)0.40%—Miniorange Malware ScannerAI4/6/202417/6/2026
Authentication Bypass by Spoofing vulnerability in miniorange Malware Scanner allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Malware Scanner: from n/a through 4.7.1.
AnalizadaCrítica (9.1)0.56%—Geminilabs Site Reviews29/5/202417/6/2026
The Site Reviews WordPress plugin before 7.0.0 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to bypass IP-based blocking
AplazadaMedia (5.3)0.63%—MinioAI28/5/202417/6/2026
MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. `If-Modified-Since` and `If-Unmodified-Since` headers when used with anonymous requests by sending a random object name requests can be used to determine if an object exists or not on the server on a specific bucket and…
AplazadaMedia (6.4)0.27%—Miniorange Wordpress Office 365 Azure AD LoginAI23/5/202417/6/2026
The WordPress + Microsoft Office 365 / Azure AD | LOGIN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pintra' shortcode in all versions up to, and including, 27.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AplazadaAlta (8)0.48%—Miniorange Wordpress Social Login AND RegisterAI17/5/202417/6/2026
Improper Privilege Management vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) allows Privilege Escalation.This issue affects WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn): from n/a through 7.6.6.
AplazadaMedia (6.7)0.16%—Intel Ethernet Controller Administrative ToolsAI16/5/202417/6/2026
Improper access control in some Intel(R) Ethernet Controller Administrative Tools software before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (6.5)0.31%—Kailey Lampert Mini LoopsAI3/5/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kailey Lampert Mini Loops allows Stored XSS.This issue affects Mini Loops: from n/a through 1.4.1.
AplazadaCrítica (9.1)0.43%—SimpleminingosAI30/4/202417/6/2026
SimpleMiningOS through v1259 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes trivial with Shodan.io. NOTE: the vendor indicated that they have no plans to fix this, and discourage deployment using public IPv4.
AnalizadaMedia (6.1)0.37%—1234n Minicms26/4/202417/6/2026
Cross Site Scripting vulnerability in MiniCMS v.1.11 allows a remote attacker to run arbitrary code via crafted string in the URL after login.
AplazadaMedia (4.4)0.17%—Hitachi OPS Center AdministratorAI23/4/202417/6/2026
Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Administrator allows local users to gain sensitive information.This issue affects Hitachi Ops Center Administrator: before 11.0.1.
AnalizadaCrítica (9.8)0.32%—Netapp Ontap Select Deploy Administration Utility17/4/202417/6/2026
ONTAP Select Deploy administration utility versions 9.12.1.x, 9.13.1.x and 9.14.1.x contain hard-coded credentials that could allow an attacker to view Deploy configuration information and modify the account credentials.
AnalizadaAlta (8.8)0.43%—Netapp Ontap Select Deploy Administration Utility17/4/202417/6/2026
ONTAP Select Deploy administration utility versions 9.12.1.x, 9.13.1.x and 9.14.1.x are susceptible to a vulnerability which when successfully exploited could allow a read-only user to escalate their privileges.
En análisisAlta (7.3)88%💥 ExploitGNU GlibcNetapp Active IQ Unified ManagerDebian LinuxNetapp HCI H300s Firmware+917/4/202417/6/2026
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.
AnalizadaMedia (6.1)0.17%—Oracle Peoplesoft Enterprise HCM Benefits Administration16/4/202417/6/2026
Vulnerability in the PeopleSoft Enterprise HCM Benefits Administration product of Oracle PeopleSoft (component: Benefits Administration). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise HCM…
AplazadaMedia (6.5)0.46%—Lenovo Xclarity AdministratorAI5/4/202417/6/2026
A valid authenticated Lenovo XClarity Administrator (LXCA) user can potentially leverage an unauthenticated API endpoint to retrieve system event information.
AplazadaMedia (6.6)0.29%—DJI Mavic 3 PROAIDJI Mavic 3AIDJI Mavic 3 ClassicAIDJI Mavic 3 EnterpriseAI+32/4/202417/6/2026
A Use of Weak Credentials vulnerability affecting the Wi-Fi network generated by a set of DJI drones could allow a remote attacker to derive the WPA2 PSK key and authenticate without permission to the drone’s Wi- Fi network. This, in turn, allows the attacker to perform unauthorized interaction with the network…
AplazadaBaja (3)0.21%—DJI Mavic Mini 3 PROAI2/4/202417/6/2026
An Improper Input Validation vulnerability affecting the FTP service running on the DJI Mavic Mini 3 Pro could allow an attacker to craft a malicious packet containing a malformed path provided to the FTP SIZE command that leads to a denial-of-service attack of the FTP service itself.
AplazadaMedia (5.2)0.24%—DJI Mavic Mini 3 PROAI2/4/202417/6/2026
A Missing Authentication for Critical Function issue affecting the HTTP service running on the DJI Mavic Mini 3 Pro on the standard port 80 could allow an attacker to enumerate and download videos and pictures saved on the drone internal or external memory without requiring any kind of authentication.
AplazadaBaja (3)0.21%—DJI Mavic 3 PROAIDJI Mavic 3AIDJI Mavic 3 ClassicAIDJI Mavic 3 EnterpriseAI+32/4/202417/6/2026
A Buffer Copy without Checking Size of Input issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to cause a crash of the service through a crafted payload triggering a missing input size check in the sdk_printf function implemented in the libv2_sdk.so…
AplazadaMedia (6.8)0.24%—DJI Mavic 3 PROAIDJI Mavic 3AIDJI Mavic 3 ClassicAIDJI Mavic 3 EnterpriseAI+32/4/202417/6/2026
A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to trigger an out-of-bound read/write into the process memory through a crafted payload due to a missing input sanity check in the v2_pack_array_to_msg function implemented in…
AplazadaMedia (6.8)0.24%—DJI Mavic 3 PROAIDJI Mavic 3AIDJI Mavic 3 ClassicAIDJI Mavic 3 EnterpriseAI+32/4/202417/6/2026
A Improper Validation of Array Index issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to corrupt a controlled memory location due to a missing input validation in the on_receive_session_packet_ack function implemented in the libv2_sdk.so library used by…
Orbitaley — Vulnerabilidades