Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

2803 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.6)0.23%—Intel Active Management TechnologyAIIntel Standard ManageabilityAI12/2/202517/6/2026
Improper initialization in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable information disclosure via local access.
AnalizadaCrítica (9.8)0.48%—Cacti12/2/202517/6/2026
Cacti through 1.2.29 allows SQL injection in the template function in host_templates.php via the graph_template parameter. NOTE: this issue exists because of an incomplete fix for CVE-2024-54146.
AnalizadaBaja (2.3)0.72%—GNU BinutilsNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility11/2/202517/6/2026
A vulnerability classified as critical was found in GNU Binutils 2.43. This vulnerability affects the function _bfd_elf_gc_mark_rsec of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The…
AnalizadaMedia (6.3)0.80%—GNU BinutilsNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility11/2/202517/6/2026
A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. Affected by this vulnerability is the function bfd_putl64 of the file libbfd.c of the component ld. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The…
AplazadaMedia (4)0.42%—Activitypub FederationAIJoin-lemmy LemmyAI10/2/202517/6/2026
Lemmy, a link aggregator and forum for the fediverse, is vulnerable to server-side request forgery via a dependency on activitypub_federation, a framework for ActivityPub federation in Rust. This vulnerability, which is present in versions 0.6.2 and prior of activitypub_federation and versions 0.19.8 and prior of…
AnalizadaAlta (7.5)2.2%—NettyNetapp Active IQ Unified ManagerNetapp Oncommand Insight10/2/202517/6/2026
Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it doesn't correctly handle validation of such a packet in all cases which can lead to a native crash.…
AnalizadaMedia (5.4)0.37%—Qodeinteractive QI Addons FOR Elementor4/2/202517/6/2026
The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cursor’ parameter in all versions up to, and including, 1.8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,…
AplazadaMedia (4.3)0.17%—Winterlock Activity LOGAI4/2/202517/6/2026
Cross-site request forgery vulnerability exists in Activity Log WinterLock versions prior to 1.2.5. If a user views a malicious page while logged in, the log data may be deleted.
AnalizadaMedia (5.3)0.31%—Creativeinteractivemedia Animategl Animations1/2/202517/6/2026
The AnimateGL Animations for WordPress – Elementor & Gutenberg Blocks Animations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'agl_json' AJAX action in all versions up to, and including, 1.4.23. This makes it possible for unauthenticated attackers to…
AnalizadaMedia (5.4)0.22%—IBM Financial Transaction Manager FOR Multiplatform31/1/202517/6/2026
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.1 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials…
AnalizadaMedia (5.4)0.22%—IBM Financial Transaction Manager FOR Multiplatform31/1/202517/6/2026
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.1 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials…
AplazadaMedia (4.3)0.26%—Vcita Contact Form AND Calls TO ActionAI31/1/202517/6/2026
The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_ajax_toggle_ae and vcita_ajax_toggle_contact functions in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers,…
AplazadaMedia (6.4)0.31%—Contact Form AND Calls TO Action BY VcitaAI31/1/202517/6/2026
The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vCitaMeetingScheduler ' shortcode in all versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…
AplazadaMedia (6.5)0.51%—Splunk Supporting Add-on FOR Active DirectoryAISplunk Sa-ldapsearchAI30/1/202517/6/2026
In versions 3.1.0 and lower of the Splunk Supporting Add-on for Active Directory, also known as SA-ldapsearch, a vulnerable regular expression pattern could lead to a Regular Expression Denial of Service (ReDoS) attack.
AplazadaCrítica (9.8)2.1%💥 ExploitEmote Interactive Remote Mouse ServerAI28/1/202517/6/2026
Due to reliance on a trivial substitution cipher, sent in cleartext, and the reliance on a default password when the user does not set a password, the Remote Mouse Server by Emote Interactive can be abused by attackers to inject OS commands over theproduct's custom control protocol. A Metasploit module was written and…
AplazadaMedia (6.5)0.32%—Cloud Whale Interactive Technology LLC Polybuzz IOSAI27/1/202517/6/2026
An issue in Cloud Whale Interactive Technology LLC. PolyBuzz iOS 2.0.20 allows attackers to access sensitive user information via supplying a crafted link.
ModificadaMedia (6.9)0.51%—Cacti27/1/202517/6/2026
Cacti is an open source performance and fault management framework. Some of the data stored in automation_tree_rules.php is not thoroughly checked and is used to concatenate the SQL statement in build_rule_item_filter() function from lib/api_automation.php, resulting in SQL injection. This vulnerability is fixed in…
ModificadaAlta (8.7)54%💥 ExploitCacti27/1/202517/6/2026
Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation and graph template functionality to create arbitrary PHP scripts in the web root of the application, leading to remote code execution on the server. This vulnerability is fixed in 1.2.29.
ModificadaAlta (7.2)5.4%💥 PoCCacti27/1/202517/6/2026
Cacti is an open source performance and fault management framework. Due to a flaw in multi-line SNMP result parser, authenticated users can inject malformed OIDs in the response. When processed by ss_net_snmp_disk_io() or ss_net_snmp_disk_bytes(), a part of each OID will be used as a key in an array that is used as…
AnalizadaAlta (8.8)46%—Cacti27/1/202517/6/2026
Cacti is an open source performance and fault management framework. Cacti has a SQL injection vulnerability in the template function of host_templates.php using the graph_template parameter. This vulnerability is fixed in 1.2.29.
ModificadaAlta (8.8)0.68%—Cacti27/1/202517/6/2026
Cacti is an open source performance and fault management framework. Cacti has a SQL injection vulnerability in the get_discovery_results function of automation_devices.php using the network parameter. This vulnerability is fixed in 1.2.29.
ModificadaMedia (4.9)3.1%—Cacti27/1/202517/6/2026
Cacti is an open source performance and fault management framework. Prior to 1.2.29, an administrator can change the `Poller Standard Error Log Path` parameter in either Installation Step 5 or in Configuration->Settings->Paths tab to a local file inside the server. Then simply going to Logs tab and selecting the name…
AplazadaMedia (4.3)0.24%—Qodeinteractive Bridge CoreAI27/1/202517/6/2026
Missing Authorization vulnerability in NotFound Bridge Core. This issue affects Bridge Core: from n/a through 3.3.
AnalizadaAlta (7)67%⚠ Explotación activa💥 PoCNetapp Active IQ Unified Manager7-zip25/1/202517/6/2026
7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific…
AplazadaAlta (7.1)1.2%—Github Codeql ActionAIGithub Codeql CLIAI24/1/202517/6/2026
In some circumstances, debug artifacts uploaded by the CodeQL Action after a failed code scanning workflow run may contain the environment variables from the workflow run, including any secrets that were exposed as environment variables to the workflow. Users with read access to the repository would be able to access…
Orbitaley — Vulnerabilidades