Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
808 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.6% | — | Mingsoft Mcms | 2/6/2022 | 17/6/2026 | An arbitrary file upload vulnerability was discovered in MCMS 5.2.7, allowing an attacker to execute arbitrary code through a crafted ZIP file. | |
| Modificada | Alta (8.8) | 0.65% | — | Mingsoft Mcms | 2/6/2022 | 17/6/2026 | An issue was discovered in MCMS 5.2.7. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do. | |
| Modificada | Alta (8.8) | 1.7% | — | Wargaming World OF Warships | 26/5/2022 | 17/6/2026 | The replay feature in the client in Wargaming World of Warships 0.11.4 allows remote attackers to execute code when a user launches a replay from an untrusted source. | |
| Modificada | Crítica (9.8) | 1.5% | — | Mingsoft Mcms | 11/5/2022 | 17/6/2026 | Mingsoft MCMS 5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/list URI via orderBy parameter. | |
| Modificada | Crítica (9.8) | 1.5% | — | Mingsoft Mcms | 11/5/2022 | 17/6/2026 | Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/listExcludeApp URI via orderBy parameter. | |
| Modificada | Crítica (9.8) | 0.98% | — | Mingyuefusu Project Mingyuefusu | 5/5/2022 | 17/6/2026 | mingyuefusu Library Management System all versions as of 03-27-2022 is vulnerable to SQL Injection. | |
| Modificada | Crítica (9.8) | 1.6% | — | Mingsoft Mcms | 2/5/2022 | 17/6/2026 | MCMS v5.2.27 was discovered to contain a SQL injection vulnerability in the orderBy parameter at /dict/list.do. | |
| Modificada | Alta (7.3) | 0.53% | — | Miele Benchmark Programming Tool | 27/4/2022 | 17/6/2026 | In Miele Benchmark Programming Tool with versions Prior to 1.2.71, executable files manipulated by attackers are unknowingly executed with users privileges. An attacker with low privileges may trick a user with administrative privileges to execute these binaries as admin. | |
| Modificada | Media (6.1) | 0.80% | — | Subsystic Coming Soon | 25/4/2022 | 17/6/2026 | The Coming Soon by Supsystic WordPress plugin before 1.7.6 does not sanitise and escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (6.7) | 0.26% | — | Lenovo C340-14iml FirmwareLenovo C340-15iml FirmwareLenovo D330-10igm FirmwareLenovo Duet 3-10igl5 Firmware+58 | 22/4/2022 | 17/6/2026 | A potential vulnerability in the SMI callback function used in the Legacy BIOS mode driver in some Lenovo Notebook models may allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Media (6.7) | 0.26% | — | Lenovo A340-22icb FirmwareLenovo A340-22ick FirmwareLenovo A340-24icb FirmwareLenovo A340-24ick Firmware+49 | 22/4/2022 | 17/6/2026 | A potential vulnerability in the SMI callback function used in the SMBIOS event log driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Media (6.7) | 2.8% | 💥 PoC | Lenovo Ideapad 3-14ada05 FirmwareLenovo Ideapad 3-14ada6 FirmwareLenovo Ideapad 3-14alc6 FirmwareLenovo Ideapad 3-14are05 Firmware+101 | 22/4/2022 | 17/6/2026 | A potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices' BIOS that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable. | |
| Modificada | Media (6.7) | 1.2% | — | Lenovo Ideapad 3-14ada05 FirmwareLenovo Ideapad 3-14ada6 FirmwareLenovo Ideapad 3-14alc6 FirmwareLenovo Ideapad 3-14are05 Firmware+69 | 22/4/2022 | 17/6/2026 | A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices that was mistakenly included in the BIOS image could allow an attacker with elevated privileges to modify firmware protection region by modifying an NVRAM variable. | |
| Modificada | Media (6.7) | 1.3% | — | Lenovo Ideapad 3-14ada05 FirmwareLenovo Ideapad 3-14ada6 FirmwareLenovo Ideapad 3-14alc6 FirmwareLenovo Ideapad 3-14are05 Firmware+101 | 22/4/2022 | 17/6/2026 | A potential vulnerability in LenovoVariable SMI Handler due to insufficient validation in some Lenovo Notebook models BIOS may allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Alta (8.8) | 0.67% | — | Mingsoft Mcms | 22/4/2022 | 17/6/2026 | MCMS v5.2.7 contains a Cross-Site Request Forgery (CSRF) via /role/saveOrUpdateRole.do. This vulnerability allows attackers to escalate privileges and modify data. | |
| Modificada | Media (4.8) | 2.8% | — | Incsub Hummingbird | 18/4/2022 | 17/6/2026 | The Hummingbird WordPress plugin before 3.3.2 does not sanitise and escape the Config Name, which could allow high privilege users, such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Crítica (9.8) | 5.5% | 💥 Exploit | Mingsoft Mcms | 5/4/2022 | 17/6/2026 | Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list. | |
| Modificada | Media (6.1) | 0.88% | — | Edmonsoft Countdown, Coming Soon, Maintenance - Countdown & Clock | 14/3/2022 | 17/6/2026 | The Countdown, Coming Soon, Maintenance WordPress plugin before 2.2.9 does not sanitize and escape the post parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting. | |
| Modificada | Media (6.5) | 2.3% | — | Linuxfoundation Nats-serverNats Streaming Server | 10/3/2022 | 17/6/2026 | NATS nats-server before 2.7.4 allows Directory Traversal (with write access) via an element in a ZIP archive for JetStream streams. nats-streaming-server before 0.24.3 is also affected. | |
| Modificada | Media (6.5) | 1.1% | — | Libming MingFedoraproject Fedora | 10/3/2022 | 17/6/2026 | Ming 0.4.8 has an out-of-bounds read vulnerability in the function newVar_N() in decompile.c which causes a huge information leak. | |
| Modificada | Media (6.5) | 0.90% | — | Libming MingFedoraproject Fedora | 10/3/2022 | 17/6/2026 | Ming 0.4.8 has an out-of-bounds read vulnerability in the function decompileIF() in the decompile.c file that causes a direct segmentation fault and leads to denial of service. | |
| Modificada | Media (6.5) | 0.90% | — | Libming MingFedoraproject Fedora | 10/3/2022 | 17/6/2026 | Ming 0.4.8 has an out-of-bounds buffer access issue in the function decompileINCR_DECR() in decompiler.c file that causes a direct segmentation fault and leads to denial of service. | |
| Modificada | Media (6.5) | 0.96% | — | Libming MingFedoraproject Fedora | 10/3/2022 | 17/6/2026 | Ming 0.4.8 has an out-of-bounds buffer access issue in the function getString() in decompiler.c file that causes a direct segmentation fault and leads to denial of service. | |
| Modificada | Media (6.5) | 0.96% | — | Libming MingFedoraproject Fedora | 10/3/2022 | 17/6/2026 | Ming 0.4.8 has an out-of-bounds buffer overwrite issue in the function getName() in decompiler.c file that causes a direct segmentation fault and leads to denial of service. | |
| Modificada | Crítica (9.8) | 2.2% | — | Mingsoft Mcms | 4/3/2022 | 17/6/2026 | https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The attack vector is: ${"freemarker.template.utility.Execute"?new()("calc")}. ¶¶ MCMS has a pre-auth RCE vulnerability through which allows unauthenticated attacker with network access via http to… |