Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

475 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.95%—Google DOC Embedder Project Google DOC Embedder14/8/201917/6/2026
The google-document-embedder plugin before 2.6.2 for WordPress has XSS.
ModificadaMedia (6.1)0.95%—Google DOC Embedder Project Google DOC Embedder14/8/201917/6/2026
The google-document-embedder plugin before 2.6.1 for WordPress has XSS.
ModificadaMedia (6.8)0.36%—Dell Chengming 3967 FirmwareDell Chengming 3977 FirmwareDell Chengming 3980 FirmwareDell G3 3579 Firmware+2375/8/201917/6/2026
Select Dell Client Commercial and Consumer platforms contain an Improper Access Vulnerability. An unauthenticated attacker with physical access to the system could potentially bypass intended Secure Boot restrictions to run unsigned and untrusted code on expansion cards installed in the system during platform boot.…
ModificadaMedia (6.1)1.7%—Jenkins Embeddable Build Status11/7/201917/6/2026
A reflected cross site scripting vulnerability in Jenkins Embeddable Build Status Plugin 2.0.1 and earlier allowed attackers inject arbitrary HTML and JavaScript into the response of this plugin.
ModificadaAlta (7.5)8.8%—Embedthis Goahead14/6/201917/6/2026
In http.c in Embedthis GoAhead before 4.1.1 and 5.x before 5.0.1, a header parsing vulnerability causes a memory assertion, out-of-bounds memory reference, and potential DoS, as demonstrated by a colon on a line by itself.
ModificadaAlta (8.8)2.7%—Cesanta Mongoose Embedded WEB Server Library10/6/201917/6/2026
Use-after-free vulnerability in the mg_cgi_ev_handler function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlier allows a denial of service (application crash) or remote code execution.
ModificadaCrítica (9.8)1.8%—Oembed Project Oembed21/3/201917/6/2026
plugin.js in the w8tcha oEmbed plugin before 2019-03-14 for CKEditor mishandles SCRIPT elements.
ModificadaAlta (8.8)0.90%—Dell Windows Embedded Standard Wyse Device AgentDell Wyse Thinlinux Hagent7/3/201917/6/2026
Dell WES Wyse Device Agent versions prior to 14.1.2.9 and Dell Wyse ThinLinux HAgent versions prior to 5.4.55 00.10 contain a buffer overflow vulnerability. An unauthenticated attacker may potentially exploit this vulnerability to execute arbitrary code on the system with privileges of the FTP client by sending…
ModificadaAlta (7.5)2.2%—Embedthis AppwebEmbedthis GoaheadJuniper Junos18/8/201817/6/2026
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. An HTTP POST request with a specially crafted "Host" header field may cause a NULL pointer dereference and thus cause a denial of service, as demonstrated by the lack of a trailing ']' character in an IPv6 address.
ModificadaAlta (7.5)2.8%—Embedthis AppwebEmbedthis GoaheadJuniper Junos18/8/201817/6/2026
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. The server mishandles some HTTP request fields associated with time, which results in a NULL pointer dereference, as demonstrated by If-Modified-Since or If-Unmodified-Since with a month greater than 11.
ModificadaMedia (5.5)0.86%—Ttembed Project Ttembed2/8/201817/6/2026
An input validation flaw exists in ttembed. With a crafted input file, an attacker may be able to trigger a denial of service condition due to ttembed trusting attacker controlled values.
ModificadaAlta (7.5)1.0%—Ttembed Project Ttembed2/8/201817/6/2026
Certain input files may trigger an integer overflow in ttembed input file processing. This overflow could potentially lead to corruption of the input file due to a lack of checking return codes of fgetc/fputc function calls.
ModificadaAlta (8.1)1.7%—Embedza Project Embedza31/5/201817/6/2026
embedza is a module to create HTML snippets/embeds from URLs using info from oEmbed, Open Graph, meta tags. embedza versions below 1.2.4 download JavaScript resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested JavaScript…
ModificadaCrítica (9.8)2.0%—Dell EMC SmisDell EMC Solutions Enabler Virtual ApplianceDell EMC UnisphereDell EMC Unity Operating Environment+1230/4/201817/6/2026
In Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.8, Dell EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.8, Dell EMC VASA Provider Virtual Appliance versions prior to 8.4.0.512, Dell EMC SMIS versions prior to 8.4.0.6, Dell EMC VMAX Embedded Management (eManagement) versions…
ModificadaAlta (8.1)23%💥 ExploitEmbedthis Appweb15/3/201817/6/2026
The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible to bypass authentication for the form and digest login types.
ModificadaCrítica (9.8)21%—Dell EMC Solutions Enabler Virtual ApplianceDell EMC Unisphere FOR Vmax Virtual ApplianceDell EMC Vasa Virtual ApplianceDell EMC Vmax Embedded Management8/3/201817/6/2026
A hard-coded password vulnerability was discovered in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enabler, Dell EMC VASA Virtual Appliances, and Dell EMC VMAX Embedded Management (eManagement): Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.18, Dell EMC…
ModificadaAlta (8.8)4.2%—Dell EMC Solutions Enabler Virtual ApplianceDell EMC Unisphere FOR Vmax Virtual ApplianceDell EMC Vasa Virtual ApplianceDell EMC Vmax Embedded Management8/3/201817/6/2026
An arbitrary file upload vulnerability was discovered in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enabler, Dell EMC VASA Virtual Appliances, and Dell EMC VMAX Embedded Management (eManagement): Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.18, Dell EMC…
ModificadaAlta (7)1.0%—Microsoft Windows Embedded CompactMicrosoft Windows 10Microsoft Windows 7Microsoft Windows 8.1+415/2/201817/6/2026
Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allow an elevation of privilege vulnerability due to how objects in memory are handled, aka "Windows Kernel Elevation…
ModificadaCrítica (9.8)8.6%—Embedthis Goahead3/1/201817/6/2026
EmbedThis GoAhead Webserver version 4.0.0 is vulnerable to a NULL pointer dereference in the CGI handler resulting in memory corruption or denial of service.
ModificadaAlta (7.5)7.9%—Embedthis Goahead WEB Server3/1/201817/6/2026
EmbedThis GoAhead Webserver versions 4.0.0 and earlier is vulnerable to an integer overflow in the HTTP listener resulting in denial of service.
AnalizadaAlta (8.1)96%⚠ Explotación activa💥 ExploitEmbedthis GoaheadOracle Integrated Lights OUT Manager12/12/201717/6/2026
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the environment of forked CGI scripts using untrusted HTTP request parameters in the cgiHandler function in cgi.c. When combined with the glibc dynamic linker, this…
ModificadaAlta (7.8)0.31%—Kaspersky Embedded Systems Security8/12/201717/6/2026
Kernel pool memory corruption in one of drivers in Kaspersky Embedded Systems Security version 1.2.0.300 leads to local privilege escalation.
ModificadaMedia (6.5)0.52%—Embedplus Youtube17/11/201717/6/2026
CSRF in YouTube (WordPress plugin) could allow unauthenticated attacker to change any setting within the plugin
ModificadaAlta (8.8)4.1%💥 ExploitCesanta Mongoose Embedded WEB Server Library7/9/201717/6/2026
Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the authentication of users for requests that modify Mongoose.conf via a request to __mg_admin?save. NOTE: this issue can be leveraged to execute arbitrary code remotely.
ModificadaAlta (7.5)5.8%—Embedthis Goahead5/9/201717/6/2026
GoAhead 3.4.0 through 3.6.5 has a NULL Pointer Dereference in the websDecodeUrl function in http.c, leading to a crash for a "POST / HTTP/1.1" request.
Orbitaley — Vulnerabilidades