Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

808 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.6%—Mingsoft Mcms2/6/202217/6/2026
An arbitrary file upload vulnerability was discovered in MCMS 5.2.7, allowing an attacker to execute arbitrary code through a crafted ZIP file.
ModificadaAlta (8.8)0.65%—Mingsoft Mcms2/6/202217/6/2026
An issue was discovered in MCMS 5.2.7. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do.
ModificadaAlta (8.8)1.7%—Wargaming World OF Warships26/5/202217/6/2026
The replay feature in the client in Wargaming World of Warships 0.11.4 allows remote attackers to execute code when a user launches a replay from an untrusted source.
ModificadaCrítica (9.8)1.5%—Mingsoft Mcms11/5/202217/6/2026
Mingsoft MCMS 5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/list URI via orderBy parameter.
ModificadaCrítica (9.8)1.5%—Mingsoft Mcms11/5/202217/6/2026
Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/listExcludeApp URI via orderBy parameter.
ModificadaCrítica (9.8)0.98%—Mingyuefusu Project Mingyuefusu5/5/202217/6/2026
mingyuefusu Library Management System all versions as of 03-27-2022 is vulnerable to SQL Injection.
ModificadaCrítica (9.8)1.6%—Mingsoft Mcms2/5/202217/6/2026
MCMS v5.2.27 was discovered to contain a SQL injection vulnerability in the orderBy parameter at /dict/list.do.
ModificadaAlta (7.3)0.53%—Miele Benchmark Programming Tool27/4/202217/6/2026
In Miele Benchmark Programming Tool with versions Prior to 1.2.71, executable files manipulated by attackers are unknowingly executed with users privileges. An attacker with low privileges may trick a user with administrative privileges to execute these binaries as admin.
ModificadaMedia (6.1)0.80%—Subsystic Coming Soon25/4/202217/6/2026
The Coming Soon by Supsystic WordPress plugin before 1.7.6 does not sanitise and escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting
ModificadaMedia (6.7)0.26%—Lenovo C340-14iml FirmwareLenovo C340-15iml FirmwareLenovo D330-10igm FirmwareLenovo Duet 3-10igl5 Firmware+5822/4/202217/6/2026
A potential vulnerability in the SMI callback function used in the Legacy BIOS mode driver in some Lenovo Notebook models may allow an attacker with local access and elevated privileges to execute arbitrary code.
ModificadaMedia (6.7)0.26%—Lenovo A340-22icb FirmwareLenovo A340-22ick FirmwareLenovo A340-24icb FirmwareLenovo A340-24ick Firmware+4922/4/202217/6/2026
A potential vulnerability in the SMI callback function used in the SMBIOS event log driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.
ModificadaMedia (6.7)2.8%💥 PoCLenovo Ideapad 3-14ada05 FirmwareLenovo Ideapad 3-14ada6 FirmwareLenovo Ideapad 3-14alc6 FirmwareLenovo Ideapad 3-14are05 Firmware+10122/4/202217/6/2026
A potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices' BIOS that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
ModificadaMedia (6.7)1.2%—Lenovo Ideapad 3-14ada05 FirmwareLenovo Ideapad 3-14ada6 FirmwareLenovo Ideapad 3-14alc6 FirmwareLenovo Ideapad 3-14are05 Firmware+6922/4/202217/6/2026
A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices that was mistakenly included in the BIOS image could allow an attacker with elevated privileges to modify firmware protection region by modifying an NVRAM variable.
ModificadaMedia (6.7)1.3%—Lenovo Ideapad 3-14ada05 FirmwareLenovo Ideapad 3-14ada6 FirmwareLenovo Ideapad 3-14alc6 FirmwareLenovo Ideapad 3-14are05 Firmware+10122/4/202217/6/2026
A potential vulnerability in LenovoVariable SMI Handler due to insufficient validation in some Lenovo Notebook models BIOS may allow an attacker with local access and elevated privileges to execute arbitrary code.
ModificadaAlta (8.8)0.67%—Mingsoft Mcms22/4/202217/6/2026
MCMS v5.2.7 contains a Cross-Site Request Forgery (CSRF) via /role/saveOrUpdateRole.do. This vulnerability allows attackers to escalate privileges and modify data.
ModificadaMedia (4.8)2.8%—Incsub Hummingbird18/4/202217/6/2026
The Hummingbird WordPress plugin before 3.3.2 does not sanitise and escape the Config Name, which could allow high privilege users, such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaCrítica (9.8)5.5%💥 ExploitMingsoft Mcms5/4/202217/6/2026
Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list.
ModificadaMedia (6.1)0.88%—Edmonsoft Countdown, Coming Soon, Maintenance - Countdown & Clock14/3/202217/6/2026
The Countdown, Coming Soon, Maintenance WordPress plugin before 2.2.9 does not sanitize and escape the post parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
ModificadaMedia (6.5)2.3%—Linuxfoundation Nats-serverNats Streaming Server10/3/202217/6/2026
NATS nats-server before 2.7.4 allows Directory Traversal (with write access) via an element in a ZIP archive for JetStream streams. nats-streaming-server before 0.24.3 is also affected.
ModificadaMedia (6.5)1.1%—Libming MingFedoraproject Fedora10/3/202217/6/2026
Ming 0.4.8 has an out-of-bounds read vulnerability in the function newVar_N() in decompile.c which causes a huge information leak.
ModificadaMedia (6.5)0.90%—Libming MingFedoraproject Fedora10/3/202217/6/2026
Ming 0.4.8 has an out-of-bounds read vulnerability in the function decompileIF() in the decompile.c file that causes a direct segmentation fault and leads to denial of service.
ModificadaMedia (6.5)0.90%—Libming MingFedoraproject Fedora10/3/202217/6/2026
Ming 0.4.8 has an out-of-bounds buffer access issue in the function decompileINCR_DECR() in decompiler.c file that causes a direct segmentation fault and leads to denial of service.
ModificadaMedia (6.5)0.96%—Libming MingFedoraproject Fedora10/3/202217/6/2026
Ming 0.4.8 has an out-of-bounds buffer access issue in the function getString() in decompiler.c file that causes a direct segmentation fault and leads to denial of service.
ModificadaMedia (6.5)0.96%—Libming MingFedoraproject Fedora10/3/202217/6/2026
Ming 0.4.8 has an out-of-bounds buffer overwrite issue in the function getName() in decompiler.c file that causes a direct segmentation fault and leads to denial of service.
ModificadaCrítica (9.8)2.2%—Mingsoft Mcms4/3/202217/6/2026
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The attack vector is: ${"freemarker.template.utility.Execute"?new()("calc")}. ¶¶ MCMS has a pre-auth RCE vulnerability through which allows unauthenticated attacker with network access via http to…
Orbitaley — Vulnerabilidades