Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2095 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.49% | — | Redhat Multicluster EngineAIRedhat Advanced Cluster ManagementAIRedhat HiveAI | 17/3/2025 | 21/8/2026 | A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials… | |
| Modificada | Alta (7.8) | 0.23% | — | Autodesk AutocadAutodesk Advance SteelAutodesk Civil 3DAutodesk Autocad Mechanical+5 | 13/3/2025 | 17/6/2026 | A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Autodesk Autocad MechanicalAutodesk Autocad MEPAutodesk Autocad Plant 3DAutodesk Civil 3D+5 | 13/3/2025 | 17/6/2026 | A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad Mechanical+5 | 13/3/2025 | 17/6/2026 | A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad Mechanical+5 | 13/3/2025 | 17/6/2026 | A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad Mechanical+5 | 13/3/2025 | 17/6/2026 | A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Analizada | Alta (7.8) | 0.28% | — | Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad Mechanical+5 | 13/3/2025 | 17/6/2026 | A maliciously crafted 3DM file, when parsed through Autodesk AutoCAD, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad Mechanical+5 | 13/3/2025 | 17/6/2026 | A maliciously crafted SLDPRT file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad Mechanical+5 | 13/3/2025 | 17/6/2026 | A maliciously crafted SLDPRT file, when parsed through Autodesk AutoCAD, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad Mechanical+5 | 13/3/2025 | 17/6/2026 | A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.28% | — | Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad Mechanical+5 | 13/3/2025 | 17/6/2026 | A maliciously crafted CATPART file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.25% | — | Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad Mechanical+5 | 13/3/2025 | 17/6/2026 | A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Analizada | Media (5.4) | 0.27% | — | Advancedfilemanager Advanced File Manager | 7/3/2025 | 17/6/2026 | The Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.2.14 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Crítica (10) | 0.39% | — | Opentext Identity Manager Advanced EditionAI | 5/3/2025 | 17/6/2026 | Insufficiently Protected Credentials vulnerability in OpenText Identity Manager Advanced Edition on Windows, Linux, 64 bit allows Privilege Abuse. This vulnerability could allow an authenticated user to obtain higher privileged user’s sensitive information via crafted payload. This issue affects Identity Manager… | |
| Analizada | Media (5.1) | 0.77% | 💥 PoC | Oneadvanced Tikit Emarketing | 3/3/2025 | 17/6/2026 | Directory Traversal (Local File Inclusion) vulnerability in Tikit (now Advanced) eMarketing platform 6.8.3.0 allows a remote attacker to read arbitrary files and obtain sensitive information via a crafted payload to the filename parameter to the OpenLogFile endpoint. | |
| Aplazada | Media (6.9) | 0.25% | 💥 PoC | Famatech Advanced Port ScannerAIRadmin Advanced IP ScannerAI | 3/3/2025 | 17/6/2026 | Vulnerability of unauthorized exposure of confidential information affecting Advanced IP Scanner and Advanced Port Scanner. It occurs when these applications initiate a network scan, inadvertently sending the NTLM hash of the user performing the scan. This vulnerability can be exploited by intercepting network traffic… | |
| Analizada | Media (6.1) | 0.29% | — | Berocket Advanced Ajax Product Filters | 28/2/2025 | 17/6/2026 | The Advanced AJAX Product Filters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nonce' parameter in all versions up to, and including, 1.6.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Analizada | Media (5.3) | 0.34% | — | Webfactoryltd Advanced Google Recaptcha | 25/2/2025 | 17/6/2026 | The Advanced Google reCaptcha plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 1.27 . This makes it possible for unauthenticated attackers to bypass the Built-in Math Captcha Verification. | |
| Aplazada | Alta (7.1) | 0.31% | — | Tauhidul Alam Advanced Angular Contact FormAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tauhidul Alam Advanced Angular Contact Form advanced-angular-contact-form allows Reflected XSS.This issue affects Advanced Angular Contact Form: from n/a through <= 1.1.0. | |
| Aplazada | Alta (7.1) | 0.15% | — | Blackbam Tinymce Advanced Qtranslate FIX Editor ProblemsAI | 13/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Blackbam TinyMCE Advanced qTranslate fix editor problems tinymce-advanced-qtranslate-fix-editor-problems allows Stored XSS.This issue affects TinyMCE Advanced qTranslate fix editor problems: from n/a through <= 1.0.0. | |
| Analizada | Alta (7.1) | 0.85% | — | Microsoft Surface HUB 2S FirmwareMicrosoft Surface PRO 8 FOR Business 1983 FirmwareMicrosoft Surface Laptop GO FirmwareMicrosoft Surface Laptop GO 2 Firmware+23 | 11/2/2025 | 17/6/2026 | Microsoft Surface Security Feature Bypass Vulnerability | |
| Aplazada | Alta (7.1) | 0.25% | — | SAP Hana XS Advanced ModelAI | 11/2/2025 | 17/6/2026 | The User Account and Authentication service (UAA) for SAP HANA extended application services, advanced model (SAP HANA XS advanced model) allows an unauthenticated attacker to craft a malicious link, that, when clicked by a victim, redirects the browser to a malicious site due to insufficient redirect URL validation.… | |
| Analizada | Media (5.1) | 0.43% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 5/2/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. This vulnerability is due to an incomplete fix for CVE-2024-31156 https://my.f5.com/manage/s/article/K000138636 .… | |
| Analizada | Alta (8.7) | 0.40% | — | F5 Big-ip Advanced Firewall ManagerF5 Big-ip Next Cloud-native Network Functions | 5/2/2025 | 17/6/2026 | When BIG-IP AFM is provisioned with IPS module enabled and protocol inspection profile is configured on a virtual server or firewall rule or policy, undisclosed traffic can cause an increase in CPU resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.5) | 0.76% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+7 | 5/2/2025 | 17/6/2026 | When running in Appliance mode, and logged into a highly-privileged role, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical… |