Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

795 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.45%—Benbodhi SVG Support16/11/202217/6/2026
The SVG Support plugin for WordPress defaults to insecure settings in version 2.5 and 2.5.1. SVG files containing malicious javascript are not sanitized. While version 2.5 adds the ability to sanitize image as they are uploaded, the plugin defaults to disable sanitization and does not restrict SVG upload to only…
ModificadaMedia (6.5)0.69%—Jenkins Support Core15/11/202217/6/2026
An incorrect permission check in Jenkins Support Core Plugin 1206.v14049fa_b_d860 and earlier allows attackers with Support/DownloadBundle permission to download a previously created support bundle containing information limited to users with Overall/Administer permission.
ModificadaAlta (8.8)4.8%—Zohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus12/11/202217/6/2026
Zoho ManageEngine ServiceDesk Plus MSP before 10609 and SupportCenter Plus before 11025 are vulnerable to privilege escalation. This allows users to obtain sensitive data during an exportMickeyList export of requests from the list view.
ModificadaMedia (4.4)0.18%—Intel Support11/11/202217/6/2026
Incorrect default permissions in the Intel(R) Support Android application before version v22.02.28 may allow a privileged user to potentially enable information disclosure via local access.
ModificadaMedia (5.5)0.17%—Intel Support11/11/202217/6/2026
Uncontrolled resource consumption in the Intel(R) Support Android application before version 22.02.28 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaCrítica (9.8)2.6%💥 PoCVmware Bosh EditorVmware Cloudfoundry Manifest YML SupportVmware Concourse CI Pipeline EditorVmware Spring Boot Tools+14/11/202217/6/2026
Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI Pipeline Editor, Bosh Editor and Cloudfoundry Manifest YML Support version 1.39.0 and below all use Snakeyaml library for YAML editing support. This library allows for some special syntax in the…
ModificadaCrítica (9.1)1.2%—Webidsupport Webid14/10/202217/6/2026
A security issue was discovered in WeBid <=1.2.2. A Server-Side Request Forgery (SSRF) vulnerability in the admin/theme.php file allows remote attackers to inject payloads via theme parameters to read files across directories.
ModificadaMedia (5.4)0.64%—Benbodhi SVG Support26/9/202217/6/2026
The SVG Support WordPress plugin before 2.5 does not properly handle SVG added via an URL, which could allow users with a role as low as author to perform Cross-Site Scripting attacks
ModificadaAlta (8.8)0.39%—Ydesignservices YDS Support Ticket System23/9/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in YDS Support Ticket System plugin <= 1.0 at WordPress.
ModificadaMedia (5.4)0.57%—Getawesomesupport Awesome Support21/9/202217/6/2026
Multiple Authenticated (custom specific plugin role) Persistent Cross-Site Scripting (XSS) vulnerability in Awesome Support plugin <= 6.0.7 at WordPress.
ModificadaAlta (7.2)1.2%—Wpmanageninja Fluent Support29/8/202217/6/2026
The Fluent Support WordPress plugin before 1.5.8 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection vulnerability exploitable by high privilege users
ModificadaMedia (5.5)0.19%—Intel Support18/8/202217/6/2026
Incorrect default permissions for the Intel(R) Support Android application before 21.07.40 may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaAlta (8)0.39%—Intel Driver & Support Assistant18/8/202217/6/2026
Improper access control in the Intel(R) DSA software for before version 22.2.14 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.
ModificadaMedia (4.7)0.86%—Ckeditor5-html-embedCkeditor5-html-supportCkeditor5-markdown-gfm3/8/202217/6/2026
CKEditor 5 is a JavaScript rich text editor. A cross-site scripting vulnerability has been discovered affecting three optional CKEditor 5's packages in versions prior to 35.0.1. The vulnerability allowed to trigger a JavaScript code after fulfilling special conditions. The affected packages are…
ModificadaCrítica (9.8)5.2%—Zohocorp Manageengine Supportcenter Plus26/7/202217/6/2026
In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be executed with the credentials of a user who authenticated in the past.)
ModificadaMedia (6)0.74%—Oracle Webcenter Sites Support Tools19/7/202217/6/2026
Vulnerability in the Oracle WebCenter Sites Support Tools product of Oracle Fusion Middleware (component: User Interface). The supported version that is affected is Prior to 4.4.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites Support…
ModificadaAlta (8.8)0.65%—Livesupporti Free Live Chat Support18/7/202217/6/2026
The Free Live Chat Support plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.0.11. This is due to missing nonce protection on the livesupporti_settings() function found in the ~/livesupporti.php file. This makes it possible for unauthenticated attackers to inject…
ModificadaAlta (7.5)6.2%—Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter PlusZohocorp Manageengine Assetexplorer12/7/202217/6/2026
Zoho ManageEngine ServiceDesk Plus before 13008, ServiceDesk Plus MSP before 10606, and SupportCenter Plus before 11022 are affected by an unauthenticated local file disclosure vulnerability via ticket-creation email. (This also affects Asset Explorer before 6977 with authentication.)
ModificadaMedia (5.4)0.60%—Easy SVG Support Project Easy SVG Support27/6/202217/6/2026
The Easy SVG Support WordPress plugin before 3.3.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads
ModificadaCrítica (9.6)1.2%—Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS10/6/202217/6/2026
Dell SupportAssist Client Consumer versions (3.10.4 and prior) and Dell SupportAssist Client Commercial versions (3.1.1 and prior) contain a cross-site scripting vulnerability. A remote unauthenticated malicious user could potentially exploit this vulnerability under specific conditions leading to execution of…
ModificadaAlta (7.1)0.24%—Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS10/6/202217/6/2026
Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion/overwrite vulnerability. Authenticated non-admin user could exploit the issue and delete or overwrite arbitrary files on the system.
ModificadaAlta (7.1)0.24%—Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS10/6/202217/6/2026
Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion vulnerability. Authenticated non-admin user could exploit the issue and delete arbitrary files on the system.
ModificadaAlta (7.8)0.35%—Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS10/6/202217/6/2026
Dell SupportAssist Client Consumer versions (3.11.0 and versions prior) and Dell SupportAssist Client Commercial versions (3.2.0 and versions prior) contain a privilege escalation vulnerability. A non-admin user can exploit the vulnerability and gain admin access to the system.
ModificadaMedia (6.8)0.30%—Dell Supportassist OS Recovery26/5/202217/6/2026
Dell Support Assist OS Recovery versions before 5.5.2 contain an Authentication Bypass vulnerability. An unauthenticated attacker with physical access to the system may exploit this vulnerability by bypassing OS Recovery authentication in order to run arbitrary code on the system as Administrator.
ModificadaCrítica (9.8)13%💥 ExploitNirweb Support23/5/202217/6/2026
The Nirweb support WordPress plugin before 2.8.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action (available to unauthenticated users), leading to an SQL injection