Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1459 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.4)0.28%—HP Elite Mini 600 G9 FirmwareHP Elite Mini 800 G9 FirmwareHP Elite SFF 600 G9 FirmwareHP Elite SFF 800 G9 Firmware+2314/2/202417/6/2026
Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical attack. HP is releasing firmware and guidance to mitigate these potential vulnerabilities.
ModificadaAlta (7.8)0.17%—Administrative Tools FOR Intel Network AdaptersIntel Ethernet Connections Boot Utility, Preboot Images, AND EFI Drivers14/2/202417/6/2026
Insecure inherited permissions in some Intel(R) Ethernet tools and driver install software may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaCrítica (9.8)1.8%💥 PoCMiniorange Web3 - Crypto Wallet Login & NFT Token Gating12/2/202417/6/2026
The Web3 WordPress plugin before 3.0.0 is vulnerable to an authentication bypass due to incorrect authentication checking in the login flow in functions 'handle_auth_request' and 'hadle_login_request'. This makes it possible for non authenticated attackers to log in as any existing user on the site, such as an…
ModificadaMedia (5.3)0.68%—Webfactoryltd Minimal Coming Soon & Maintenance Mode5/2/202417/6/2026
The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to maintenance mode bypass and information disclosure in all versions up to, and including, 2.37. This is due to the plugin improperly validating the request path. This makes it possible for unauthenticated attackers to bypass maintenance…
ModificadaAlta (8.8)34%💥 ExploitMinio31/1/202417/6/2026
MinIO is a High Performance Object Storage. When someone creates an access key, it inherits the permissions of the parent key. Not only for `s3:*` actions, but also `admin:*` actions. Which means unless somewhere above in the access-key hierarchy, the `admin` rights are denied, access keys will be able to simply…
ModificadaCrítica (9.8)1.00%—Millionclues Admin CSS MUDeano AMP ToolboxUnihost Confirm DataAgence-press CSS Adder+1119/1/202417/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP – Membership Management ArcStone wp-amo, Long Watch Studio WooVirtualWallet – A virtual wallet for WooCommerce, Long Watch Studio WooVIP – Membership plugin for WordPress and WooCommerce, Long…
ModificadaMedia (5.4)0.46%—Miniorange Staff / Employee Business Directory FOR Active Directory16/1/202417/6/2026
The Staff / Employee Business Directory for Active Directory WordPress plugin before 1.2.3 does not sanitize and escape data returned from the LDAP server before rendering it in the page, allowing users who can control their entries in the LDAP directory to inject malicious javascript which could be used against…
ModificadaCrítica (9.8)1.0%—Dmparekh Wordpress Database Administrator16/1/202417/6/2026
The WordPress Database Administrator WordPress plugin through 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
ModificadaAlta (7.5)1.4%—Acme Ultra Mini Httpd7/1/202417/6/2026
A vulnerability was found in ACME Ultra Mini HTTPd 1.21. It has been classified as problematic. This affects an unknown part of the component HTTP GET Request Handler. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be…
ModificadaCrítica (9.8)0.24%—Google Nest Audio FirmwareGoogle Nest Mini FirmwareGoogle Home Mini FirmwareGoogle Home Firmware2/1/202417/6/2026
An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege
ModificadaAlta (7.2)0.54%—Wpadminify WP Adminify31/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jewel Theme WP Adminify.This issue affects WP Adminify: from n/a through 3.1.6.
ModificadaAlta (8.1)0.55%—Cloudflare Miniflare29/12/202317/6/2026
Sending specially crafted HTTP requests to Miniflare's server could result in arbitrary HTTP and WebSocket requests being sent from the server. If Miniflare was configured to listen on external network interfaces (as was the default in wrangler until 3.19.0), an attacker on the local network could access other local…
ModificadaAlta (7.5)0.70%—Miniorange Google Authenticator29/12/202317/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in miniOrange miniOrange's Google Authenticator – WordPress Two Factor Authentication – 2FA , Two Factor, OTP SMS and Email | Passwordless login.This issue affects miniOrange's Google Authenticator – WordPress Two Factor Authentication – 2FA ,…
ModificadaMedia (6.1)0.53%—Viliusle Minipaint1/12/202317/6/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository viliusle/minipaint prior to 4.14.0.
ModificadaAlta (8.8)1.3%—Zlib-ng Minizip-ng22/11/202317/6/2026
Buffer Overflow vulnerability in zlib-ng minizip-ng v.4.0.2 allows an attacker to execute arbitrary code via a crafted file to the mz_path_has_slash function in the mz_os.c file.
ModificadaAlta (8.8)0.93%—Zlib-ng Minizip-ng22/11/202317/6/2026
Buffer Overflow vulnerability in zlib-ng minizip-ng v.4.0.2 allows an attacker to execute arbitrary code via a crafted file to the mz_path_resolve function in the mz_os.c file.
ModificadaAlta (8.8)0.31%—Passionatebrains ADD Expires Headers & Optimized Minify22/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Passionate Brains Add Expires Headers & Optimized Minify plugin <= 2.7 versions.
ModificadaMedia (4.4)0.21%—Intel NUC 11 PRO KIT Nuc11tnkv50z FirmwareIntel NUC 11 PRO KIT Nuc11tnhv70l FirmwareIntel NUC 11 PRO KIT Nuc11tnhv50l FirmwareIntel NUC 11 PRO Board Nuc11tnbv7 Firmware+5214/11/202317/6/2026
Non-Transparent Sharing of Microarchitectural Resources in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable information disclosure via local access.
ModificadaMedia (6.7)0.22%—Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3-07ada05 FirmwareLenovo Ideacentre 3-07imb05 FirmwareLenovo Ideacentre G5-14imb05 Firmware+578/11/202317/6/2026
A memory leakage vulnerability was reported in the NvmramSmm SMM driver that may allow a local attacker with elevated privileges to write to NVRAM variables.
ModificadaMedia (6.7)0.22%—Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3-07ada05 FirmwareLenovo Ideacentre 3-07imb05 FirmwareLenovo Ideacentre G5-14imb05 Firmware+578/11/202317/6/2026
A memory leakage vulnerability was reported in the DustFilterAlertSmm SMM driver that may allow a local attacker with elevated privileges to write to NVRAM variables.
ModificadaMedia (6.7)0.22%—Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3-07ada05 FirmwareLenovo Ideacentre 3-07imb05 FirmwareLenovo Ideacentre G5-14imb05 Firmware+578/11/202317/6/2026
A memory leakage vulnerability was reported in the 534D0740 DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.
ModificadaMedia (6.7)0.22%—Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3-07ada05 FirmwareLenovo Ideacentre 3-07imb05 FirmwareLenovo Ideacentre G5-14imb05 Firmware+578/11/202317/6/2026
A memory leakage vulnerability was reported in the 534D0140 DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.
ModificadaMedia (6.7)0.22%—Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3-07ada05 FirmwareLenovo Ideacentre 3-07imb05 FirmwareLenovo Ideacentre G5-14imb05 Firmware+578/11/202317/6/2026
A memory leakage vulnerability was reported in the SWSMI_Shadow DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.
ModificadaMedia (6.7)0.23%—Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3-07ada05 FirmwareLenovo Ideacentre 3-07imb05 FirmwareLenovo Ideacentre 5 14iab7 Firmware+1078/11/202317/6/2026
A buffer overflow was reported in the Update_WMI module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
ModificadaMedia (6.7)0.23%—Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3-07ada05 FirmwareLenovo Ideacentre 3-07imb05 FirmwareLenovo Ideacentre 5 14iab7 Firmware+1078/11/202317/6/2026
A buffer overflow was reported in the SmuV11DxeVMR module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
Orbitaley — Vulnerabilidades