Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

1804 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.18%—Fs-code FS PosterAI2/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in fs-code FS Poster fs-poster allows Cross Site Request Forgery.This issue affects FS Poster: from n/a through <= 6.5.8.
AplazadaMedia (4.3)0.32%—AMI Ntfs DriverAI9/12/202417/6/2026
AMI (aka American Megatrends) NTFS driver 1.0.0 (fixed in late 2021 or early 2022) has a buffer overflow. This driver is, for example, used in certain ASUS devices.
AnalizadaMedia (6.5)0.32%—Dell Powerscale Onefs9/12/202417/6/2026
Dell PowerScale OneFS Versions 8.2.2.x through 9.9.0.x contain an incorrect specified argument vulnerability. A remote low privileged legitimate user could potentially exploit this vulnerability, leading to information disclosure.
AnalizadaMedia (6.5)0.37%—Dell Powerscale Onefs9/12/202417/6/2026
Dell PowerScale OneFS Versions 8.2.2.x through 9.8.0.x contain an improper resource unlocking vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to denial of service.
AnalizadaMedia (6.5)0.48%—Dell Powerscale Onefs9/12/202417/6/2026
Dell PowerScale OneFS Versions 9.5.0.x through 9.8.0.x contain an uncontrolled resource consumption vulnerability. A low privilege remote attacker could potentially exploit this vulnerability, leading to denial of service.
AnalizadaAlta (7.8)0.10%—Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+3252/12/202417/6/2026
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
AplazadaMedia (5.7)0.36%—LakefsAI26/11/202417/6/2026
lakeFS is an open-source tool that transforms object storage into a Git-like repository. Existing lakeFS users who have issued credentials to users who have been deleted are affected by this vulnerability. When creating a new user with the same username as a deleted user, that user will inherit all of the previous…
AplazadaMedia (6.5)0.24%—Offshorent Solutions PVT LTD OS Pricing TablesAI18/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Offshorent Solutions Pvt Ltd OS Pricing Tables os-pricing-tables allows Stored XSS.This issue affects OS Pricing Tables: from n/a through <= 1.2.
AplazadaMedia (6.5)0.24%—Offshorent Solutions PVT LTD OS BxsliderAI18/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Offshorent Solutions Pvt Ltd OS BXSlider os-bxslider allows Stored XSS.This issue affects OS BXSlider: from n/a through <= 2.6.
AplazadaMedia (6.5)0.24%—Offshorent Solutions PVT LTD OS OUR TeamAI18/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Offshorent Solutions Pvt Ltd OS Our Team os-our-team allows Stored XSS.This issue affects OS Our Team: from n/a through <= 1.7.
AplazadaMedia (6.4)0.25%—Elfsight Telegram Chat CCAI18/11/202417/6/2026
The Elfsight Telegram Chat CC plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the 'updatePreferences' function in all versions up to, and including, 1.1.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject…
AplazadaMedia (5.5)0.14%—HPE Data Management Framework SuiteAIHPE CxfsAI15/11/202417/6/2026
A security vulnerability has been identified in HPE Data Management Framework (DMF) Suite (CXFS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access.
ModificadaAlta (7.7)0.40%—Openafs14/11/202417/6/2026
A malicious server can crash the OpenAFS cache manager and other client utilities, and possibly execute arbitrary code.
ModificadaMedia (6.5)0.56%—Openafs14/11/202417/6/2026
An authenticated user can provide a malformed ACL to the fileserver's StoreACL RPC, causing the fileserver to crash, possibly expose uninitialized memory, and possibly store garbage data in the audit log. Malformed ACLs provided in responses to client FetchACL RPCs can cause client processes to crash and possibly…
ModificadaAlta (8.4)0.20%—Openafs14/11/202417/6/2026
A local user can bypass the OpenAFS PAG (Process Authentication Group) throttling mechanism in Unix clients, allowing the user to create a PAG using an existing id number, effectively joining the PAG and letting the user steal the credentials in that PAG.
AnalizadaMedia (6.5)0.25%—Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+904/11/202417/6/2026
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
AnalizadaMedia (6.1)0.47%—Phpgurukul Ifsc Code Finder29/10/202417/6/2026
A Reflected Cross Site Scripting (XSS) vulnerability was found in /ifscfinder/admin/profile.php in PHPGurukul IFSC Code Finder Project v1.0, which allows remote attackers to execute arbitrary code via " searchifsccode" parameter.
AnalizadaMedia (6.1)0.47%—Phpgurukul Ifsc Code Finder29/10/202417/6/2026
A Reflected Cross Site Scripting (XSS) vulnerability was found in /ifscfinder/index.php in PHPGurukul IFSC Code Finder Project v1.0, which allows remote attackers to execute arbitrary code via the "searchifsccode" parameter.
AplazadaMedia (5.3)0.21%—IpfsAIGo-libp2p-kad-dhtAI25/10/202417/6/2026
The Kademlia DHT (go-libp2p-kad-dht 0.20.0 and earlier) used in IPFS (0.18.1 and earlier) assigns routing information for content (i.e., information about who holds the content) to be stored by peers whose peer IDs have a small DHT distance from the content ID. This allows an attacker to censor content by generating…
AnalizadaMedia (4.8)80%💥 PoCNetgate Pfsense22/10/202417/6/2026
A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $pconfig variable at interfaces_groups_edit.php.
AnalizadaMedia (5.3)0.41%—Phpgurukul Ifsc Code Finder20/10/202417/6/2026
A vulnerability has been found in PHPGurukul IFSC Code Finder Project 1.0 and classified as problematic. This vulnerability affects unknown code of the file search.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
ModificadaCrítica (9.2)0.51%—SFS Winsure16/9/202417/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in SFS Consulting ww.Winsure allows Code Injection. This issue affects ww.Winsure: before 4.6.2.
ModificadaCrítica (9.2)0.49%—SFS Winsure16/9/202417/6/2026
Improper Restriction of XML External Entity Reference vulnerability in SFS Consulting ww.Winsure allows XML Injection. This issue affects ww.Winsure: before 4.6.2.
ModificadaCrítica (9.2)0.42%—SFS Insuree GL16/9/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SFS Consulting InsureE GL allows SQL Injection. This issue affects InsureE GL: before 4.6.2.
AplazadaCrítica (9.3)0.41%—HPE Hp-uxAINfsv4AI9/9/202417/6/2026
HPE has identified a denial of service vulnerability in HPE HP-UX System's Network File System (NFSv4) services.