Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
2493 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.6) | 0.79% | — | Microsoft Edge Chromium | 4/4/2025 | 17/6/2026 | Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. | |
| Analizada | Media (4.7) | 0.60% | — | Microsoft Edge | 4/4/2025 | 17/6/2026 | User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Media (4.3) | 0.78% | — | Microsoft Edge | 4/4/2025 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8.8) | 1.00% | — | Microsoft Edge Chromium | 4/4/2025 | 17/6/2026 | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | |
| Aplazada | Media (5.4) | 1.1% | 💥 PoC | Infinxt Iedge 100AI | 1/4/2025 | 17/6/2026 | A command injection vulnerability exists in the Infinxt iEdge 100 2.1.32 in the Troubleshoot module "MTR" functionality. The vulnerability is due to improper validation of user-supplied input in the mtrIp parameter. An attacker can exploit this flaw to execute arbitrary operating system commands on the underlying… | |
| Aplazada | Media (6.5) | 1.1% | 💥 PoC | Infinxt Iedge 100AI | 1/4/2025 | 17/6/2026 | An OS Command Injection vulnerability exists in the Infinxt iEdge 100 2.1.32 Troubleshoot module, specifically in the tracertVal parameter of the Tracert function. | |
| Aplazada | Media (5.4) | 0.42% | 💥 PoC | Infinxt Iedge 100AI | 1/4/2025 | 17/6/2026 | Infinxt iEdge 100 2.1.32 is vulnerable to Cross Site Scripting (XSS) via the "Description" field during LAN configuration. | |
| Modificada | Media (6.5) | 0.93% | — | Microsoft Edge Chromium | 23/3/2025 | 17/6/2026 | No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.8) | 0.40% | — | Microsoft Edge Update | 23/3/2025 | 17/6/2026 | Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally. | |
| Analizada | Crítica (9.8) | 0.64% | — | Dell Chassis Management Controller FOR Poweredge FX2 FirmwareDell Chassis Management Controller FOR Poweredge Vrtx Firmware | 21/3/2025 | 17/6/2026 | Dell Chassis Management Controller Firmware for Dell PowerEdge FX2, version(s) prior to 2.40.200.202101130302, and Dell Chassis Management Controller Firmware for Dell PowerEdge VRTX version(s) prior to 3.41.200.202209300499, contain(s) a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with… | |
| Aplazada | Media (5.4) | 0.35% | — | Lfedge EkuiperAI | 10/3/2025 | 17/6/2026 | LF Edge eKuiper is an internet-of-things data analytics and stream processing engine. Prior to version 2.0.8, auser with rights to modify the service (e.g. kuiperUser role) can inject a cross-site scripting payload into the rule `id` parameter. Then, after any user with access to this service (e.g. admin) tries make… | |
| Analizada | Media (5.4) | 0.71% | — | Microsoft Edge Chromium | 7/3/2025 | 17/6/2026 | The UI performs the wrong action in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | |
| Aplazada | Crítica (9.8) | 0.41% | — | Public Knowledge Project OJSAIPublic Knowledge Project OMPAIPublic Knowledge Project OPSAI | 24/2/2025 | 17/6/2026 | In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a new role as super admin in the journal context, and insert a backdoor plugin, by uploading a crafted XML document as a User XML Plugin. | |
| Analizada | Alta (8.2) | 0.17% | — | Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M16 R2 Firmware+388 | 19/2/2025 | 17/6/2026 | Dell Client Platform BIOS contains a Weak Authentication vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Analizada | Media (4.5) | 0.32% | — | Microsoft Edge Chromium | 15/2/2025 | 17/6/2026 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | |
| Analizada | Alta (7.8) | 0.15% | — | Dell Utility Configuration Collector Edge | 11/2/2025 | 17/6/2026 | Dell UCC Edge, version 2.3.0, contains a Blind SSRF on Add Customer SFTP Server vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Server-side request forgery | |
| Analizada | Alta (8.8) | 1.3% | — | Microsoft Edge Chromium | 6/2/2025 | 17/6/2026 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | |
| Analizada | Media (4.3) | 1.1% | — | Microsoft Edge Chromium | 6/2/2025 | 17/6/2026 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | |
| Analizada | Alta (8.8) | 1.3% | — | Microsoft Edge Chromium | 6/2/2025 | 17/6/2026 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | |
| Analizada | Alta (8.8) | 1.5% | — | Microsoft Edge Chromium | 6/2/2025 | 17/6/2026 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | |
| Analizada | Alta (8.8) | 1.6% | — | Microsoft Edge Chromium | 6/2/2025 | 17/6/2026 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | |
| Analizada | Media (4.4) | 0.57% | — | Microsoft Edge Chromium | 6/2/2025 | 17/6/2026 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | |
| Analizada | Media (5.3) | 1.2% | — | Microsoft Edge | 6/2/2025 | 17/6/2026 | Microsoft Edge for IOS and Android Spoofing Vulnerability | |
| Analizada | Media (5.1) | 0.43% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 5/2/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. This vulnerability is due to an incomplete fix for CVE-2024-31156 https://my.f5.com/manage/s/article/K000138636 .… | |
| Analizada | Alta (8.7) | 0.45% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 5/2/2025 | 17/6/2026 | When SNMP v1 or v2c are disabled on the BIG-IP, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated |