Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
475 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.95% | — | Google DOC Embedder Project Google DOC Embedder | 14/8/2019 | 17/6/2026 | The google-document-embedder plugin before 2.6.2 for WordPress has XSS. | |
| Modificada | Media (6.1) | 0.95% | — | Google DOC Embedder Project Google DOC Embedder | 14/8/2019 | 17/6/2026 | The google-document-embedder plugin before 2.6.1 for WordPress has XSS. | |
| Modificada | Media (6.8) | 0.36% | — | Dell Chengming 3967 FirmwareDell Chengming 3977 FirmwareDell Chengming 3980 FirmwareDell G3 3579 Firmware+237 | 5/8/2019 | 17/6/2026 | Select Dell Client Commercial and Consumer platforms contain an Improper Access Vulnerability. An unauthenticated attacker with physical access to the system could potentially bypass intended Secure Boot restrictions to run unsigned and untrusted code on expansion cards installed in the system during platform boot.… | |
| Modificada | Media (6.1) | 1.7% | — | Jenkins Embeddable Build Status | 11/7/2019 | 17/6/2026 | A reflected cross site scripting vulnerability in Jenkins Embeddable Build Status Plugin 2.0.1 and earlier allowed attackers inject arbitrary HTML and JavaScript into the response of this plugin. | |
| Modificada | Alta (7.5) | 8.8% | — | Embedthis Goahead | 14/6/2019 | 17/6/2026 | In http.c in Embedthis GoAhead before 4.1.1 and 5.x before 5.0.1, a header parsing vulnerability causes a memory assertion, out-of-bounds memory reference, and potential DoS, as demonstrated by a colon on a line by itself. | |
| Modificada | Alta (8.8) | 2.7% | — | Cesanta Mongoose Embedded WEB Server Library | 10/6/2019 | 17/6/2026 | Use-after-free vulnerability in the mg_cgi_ev_handler function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlier allows a denial of service (application crash) or remote code execution. | |
| Modificada | Crítica (9.8) | 1.8% | — | Oembed Project Oembed | 21/3/2019 | 17/6/2026 | plugin.js in the w8tcha oEmbed plugin before 2019-03-14 for CKEditor mishandles SCRIPT elements. | |
| Modificada | Alta (8.8) | 0.90% | — | Dell Windows Embedded Standard Wyse Device AgentDell Wyse Thinlinux Hagent | 7/3/2019 | 17/6/2026 | Dell WES Wyse Device Agent versions prior to 14.1.2.9 and Dell Wyse ThinLinux HAgent versions prior to 5.4.55 00.10 contain a buffer overflow vulnerability. An unauthenticated attacker may potentially exploit this vulnerability to execute arbitrary code on the system with privileges of the FTP client by sending… | |
| Modificada | Alta (7.5) | 2.2% | — | Embedthis AppwebEmbedthis GoaheadJuniper Junos | 18/8/2018 | 17/6/2026 | An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. An HTTP POST request with a specially crafted "Host" header field may cause a NULL pointer dereference and thus cause a denial of service, as demonstrated by the lack of a trailing ']' character in an IPv6 address. | |
| Modificada | Alta (7.5) | 2.8% | — | Embedthis AppwebEmbedthis GoaheadJuniper Junos | 18/8/2018 | 17/6/2026 | An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. The server mishandles some HTTP request fields associated with time, which results in a NULL pointer dereference, as demonstrated by If-Modified-Since or If-Unmodified-Since with a month greater than 11. | |
| Modificada | Media (5.5) | 0.86% | — | Ttembed Project Ttembed | 2/8/2018 | 17/6/2026 | An input validation flaw exists in ttembed. With a crafted input file, an attacker may be able to trigger a denial of service condition due to ttembed trusting attacker controlled values. | |
| Modificada | Alta (7.5) | 1.0% | — | Ttembed Project Ttembed | 2/8/2018 | 17/6/2026 | Certain input files may trigger an integer overflow in ttembed input file processing. This overflow could potentially lead to corruption of the input file due to a lack of checking return codes of fgetc/fputc function calls. | |
| Modificada | Alta (8.1) | 1.7% | — | Embedza Project Embedza | 31/5/2018 | 17/6/2026 | embedza is a module to create HTML snippets/embeds from URLs using info from oEmbed, Open Graph, meta tags. embedza versions below 1.2.4 download JavaScript resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested JavaScript… | |
| Modificada | Crítica (9.8) | 2.0% | — | Dell EMC SmisDell EMC Solutions Enabler Virtual ApplianceDell EMC UnisphereDell EMC Unity Operating Environment+12 | 30/4/2018 | 17/6/2026 | In Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.8, Dell EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.8, Dell EMC VASA Provider Virtual Appliance versions prior to 8.4.0.512, Dell EMC SMIS versions prior to 8.4.0.6, Dell EMC VMAX Embedded Management (eManagement) versions… | |
| Modificada | Alta (8.1) | 23% | 💥 Exploit | Embedthis Appweb | 15/3/2018 | 17/6/2026 | The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible to bypass authentication for the form and digest login types. | |
| Modificada | Crítica (9.8) | 21% | — | Dell EMC Solutions Enabler Virtual ApplianceDell EMC Unisphere FOR Vmax Virtual ApplianceDell EMC Vasa Virtual ApplianceDell EMC Vmax Embedded Management | 8/3/2018 | 17/6/2026 | A hard-coded password vulnerability was discovered in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enabler, Dell EMC VASA Virtual Appliances, and Dell EMC VMAX Embedded Management (eManagement): Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.18, Dell EMC… | |
| Modificada | Alta (8.8) | 4.2% | — | Dell EMC Solutions Enabler Virtual ApplianceDell EMC Unisphere FOR Vmax Virtual ApplianceDell EMC Vasa Virtual ApplianceDell EMC Vmax Embedded Management | 8/3/2018 | 17/6/2026 | An arbitrary file upload vulnerability was discovered in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enabler, Dell EMC VASA Virtual Appliances, and Dell EMC VMAX Embedded Management (eManagement): Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.18, Dell EMC… | |
| Modificada | Alta (7) | 1.0% | — | Microsoft Windows Embedded CompactMicrosoft Windows 10Microsoft Windows 7Microsoft Windows 8.1+4 | 15/2/2018 | 17/6/2026 | Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allow an elevation of privilege vulnerability due to how objects in memory are handled, aka "Windows Kernel Elevation… | |
| Modificada | Crítica (9.8) | 8.6% | — | Embedthis Goahead | 3/1/2018 | 17/6/2026 | EmbedThis GoAhead Webserver version 4.0.0 is vulnerable to a NULL pointer dereference in the CGI handler resulting in memory corruption or denial of service. | |
| Modificada | Alta (7.5) | 7.9% | — | Embedthis Goahead WEB Server | 3/1/2018 | 17/6/2026 | EmbedThis GoAhead Webserver versions 4.0.0 and earlier is vulnerable to an integer overflow in the HTTP listener resulting in denial of service. | |
| Analizada | Alta (8.1) | 96% | ⚠ Explotación activa💥 Exploit | Embedthis GoaheadOracle Integrated Lights OUT Manager | 12/12/2017 | 17/6/2026 | Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the environment of forked CGI scripts using untrusted HTTP request parameters in the cgiHandler function in cgi.c. When combined with the glibc dynamic linker, this… | |
| Modificada | Alta (7.8) | 0.31% | — | Kaspersky Embedded Systems Security | 8/12/2017 | 17/6/2026 | Kernel pool memory corruption in one of drivers in Kaspersky Embedded Systems Security version 1.2.0.300 leads to local privilege escalation. | |
| Modificada | Media (6.5) | 0.52% | — | Embedplus Youtube | 17/11/2017 | 17/6/2026 | CSRF in YouTube (WordPress plugin) could allow unauthenticated attacker to change any setting within the plugin | |
| Modificada | Alta (8.8) | 4.1% | 💥 Exploit | Cesanta Mongoose Embedded WEB Server Library | 7/9/2017 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the authentication of users for requests that modify Mongoose.conf via a request to __mg_admin?save. NOTE: this issue can be leveraged to execute arbitrary code remotely. | |
| Modificada | Alta (7.5) | 5.8% | — | Embedthis Goahead | 5/9/2017 | 17/6/2026 | GoAhead 3.4.0 through 3.6.5 has a NULL Pointer Dereference in the websDecodeUrl function in http.c, leading to a crash for a "POST / HTTP/1.1" request. |