Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

2493 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.6)0.79%—Microsoft Edge Chromium4/4/202517/6/2026
Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
AnalizadaMedia (4.7)0.60%—Microsoft Edge4/4/202517/6/2026
User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.
AnalizadaMedia (4.3)0.78%—Microsoft Edge4/4/202517/6/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (8.8)1.00%—Microsoft Edge Chromium4/4/202517/6/2026
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
AplazadaMedia (5.4)1.1%💥 PoCInfinxt Iedge 100AI1/4/202517/6/2026
A command injection vulnerability exists in the Infinxt iEdge 100 2.1.32 in the Troubleshoot module "MTR" functionality. The vulnerability is due to improper validation of user-supplied input in the mtrIp parameter. An attacker can exploit this flaw to execute arbitrary operating system commands on the underlying…
AplazadaMedia (6.5)1.1%💥 PoCInfinxt Iedge 100AI1/4/202517/6/2026
An OS Command Injection vulnerability exists in the Infinxt iEdge 100 2.1.32 Troubleshoot module, specifically in the tracertVal parameter of the Tracert function.
AplazadaMedia (5.4)0.42%💥 PoCInfinxt Iedge 100AI1/4/202517/6/2026
Infinxt iEdge 100 2.1.32 is vulnerable to Cross Site Scripting (XSS) via the "Description" field during LAN configuration.
ModificadaMedia (6.5)0.93%—Microsoft Edge Chromium23/3/202517/6/2026
No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (7.8)0.40%—Microsoft Edge Update23/3/202517/6/2026
Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.
AnalizadaCrítica (9.8)0.64%—Dell Chassis Management Controller FOR Poweredge FX2 FirmwareDell Chassis Management Controller FOR Poweredge Vrtx Firmware21/3/202517/6/2026
Dell Chassis Management Controller Firmware for Dell PowerEdge FX2, version(s) prior to 2.40.200.202101130302, and Dell Chassis Management Controller Firmware for Dell PowerEdge VRTX version(s) prior to 3.41.200.202209300499, contain(s) a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with…
AplazadaMedia (5.4)0.35%—Lfedge EkuiperAI10/3/202517/6/2026
LF Edge eKuiper is an internet-of-things data analytics and stream processing engine. Prior to version 2.0.8, auser with rights to modify the service (e.g. kuiperUser role) can inject a cross-site scripting payload into the rule `id` parameter. Then, after any user with access to this service (e.g. admin) tries make…
AnalizadaMedia (5.4)0.71%—Microsoft Edge Chromium7/3/202517/6/2026
The UI performs the wrong action in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
AplazadaCrítica (9.8)0.41%—Public Knowledge Project OJSAIPublic Knowledge Project OMPAIPublic Knowledge Project OPSAI24/2/202517/6/2026
In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a new role as super admin in the journal context, and insert a backdoor plugin, by uploading a crafted XML document as a User XML Plugin.
AnalizadaAlta (8.2)0.17%—Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M16 R2 Firmware+38819/2/202517/6/2026
Dell Client Platform BIOS contains a Weak Authentication vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
AnalizadaMedia (4.5)0.32%—Microsoft Edge Chromium15/2/202517/6/2026
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
AnalizadaAlta (7.8)0.15%—Dell Utility Configuration Collector Edge11/2/202517/6/2026
Dell UCC Edge, version 2.3.0, contains a Blind SSRF on Add Customer SFTP Server vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Server-side request forgery
AnalizadaAlta (8.8)1.3%—Microsoft Edge Chromium6/2/202517/6/2026
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
AnalizadaMedia (4.3)1.1%—Microsoft Edge Chromium6/2/202517/6/2026
Microsoft Edge (Chromium-based) Spoofing Vulnerability
AnalizadaAlta (8.8)1.3%—Microsoft Edge Chromium6/2/202517/6/2026
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
AnalizadaAlta (8.8)1.5%—Microsoft Edge Chromium6/2/202517/6/2026
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
AnalizadaAlta (8.8)1.6%—Microsoft Edge Chromium6/2/202517/6/2026
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
AnalizadaMedia (4.4)0.57%—Microsoft Edge Chromium6/2/202517/6/2026
Microsoft Edge (Chromium-based) Spoofing Vulnerability
AnalizadaMedia (5.3)1.2%—Microsoft Edge6/2/202517/6/2026
Microsoft Edge for IOS and Android Spoofing Vulnerability
AnalizadaMedia (5.1)0.43%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+175/2/202517/6/2026
A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. This vulnerability is due to an incomplete fix for CVE-2024-31156 https://my.f5.com/manage/s/article/K000138636 .…
AnalizadaAlta (8.7)0.45%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+175/2/202517/6/2026
When SNMP v1 or v2c are disabled on the BIG-IP, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated