Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

2493 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.9)0.41%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+175/2/202517/6/2026
When Client or Server SSL profiles are configured on a Virtual Server, or DNSSEC signing operations are in use, undisclosed traffic can cause an increase in memory and CPU resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
AnalizadaAlta (8.9)0.41%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+175/2/202517/6/2026
When a BIG-IP message routing profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
AnalizadaAlta (8.7)0.41%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+175/2/202517/6/2026
When SIP session Application Level Gateway mode (ALG) profile with Passthru Mode enabled and SIP router ALG profile are configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical…
AnalizadaAlta (8.7)7.1%💥 PoCF5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+175/2/202517/6/2026
Command injection vulnerability exists in iControl REST and BIG-IP TMOS Shell (tmsh) save command, which may allow an authenticated attacker to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaMedia (5.4)0.39%—Microsoft Edge Chromium24/1/202517/6/2026
User Interface (UI) Misrepresentation of Critical Information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network
AnalizadaAlta (7.4)0.68%—Microsoft Edge Update17/1/202517/6/2026
Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability
AnalizadaMedia (6.5)0.82%—Microsoft Edge Chromium17/1/202517/6/2026
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
AplazadaMedia (6.1)0.13%—Navify Algo EdgeAI17/1/202517/6/2026
A vulnerability exists in Algo Edge up to 2.1.1 - a previously used (legacy) component of navify® Algorithm Suite. The vulnerability impacts the authentication mechanism of this component and could allow an attacker with adjacent access to the laboratory network and the Algo Edge system to craft valid authentication…
AnalizadaBaja (2.1)0.28%—Siemens Industrial Edge Management14/1/202517/6/2026
A vulnerability has been identified in Industrial Edge Management OS (IEM-OS) (All versions). Affected components are vulnerable to reflected cross-site scripting (XSS) attacks. This could allow an attacker to extract sensitive information by tricking users into accessing a malicious link.
AnalizadaMedia (4.4)0.17%—Dell Nativeedge Orchestrator25/12/202417/6/2026
Dell NativeEdge, version(s) 2.1.0.0, contain(s) a Creation of Temporary File With Insecure Permissions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
AnalizadaAlta (7.5)0.31%—Dell Nativeedge Orchestrator25/12/202417/6/2026
Dell NativeEdge, version(s) 2.1.0.0, contain(s) an Exposure of Sensitive Information Through Metadata vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
AnalizadaAlta (7.8)0.17%—Dell Nativeedge Orchestrator25/12/202417/6/2026
Dell NativeEdge, version(s) 2.1.0.0, contain(s) an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
AplazadaAlta (7.8)0.22%—Edgecross Basic Software FOR WindowsAIEdgecross Basic Software FOR DevelopersAI19/12/202417/6/2026
External Control of File Name or Path vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecross Basic Software for Developers versions 1.00 and later allows a malicious local attacker to execute an arbitrary malicious code, resulting in information disclosure, tampering with and…
AplazadaAlta (7.8)0.16%—Edgecross Basic Software FOR WindowsAIEdgecross Basic Software FOR DevelopersAI19/12/202417/6/2026
Incorrect Default Permissions vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecross Basic Software for Developers versions 1.00 and later allows a malicious local attacker to execute an arbitrary malicious code, resulting in information disclosure, tampering with and deletion, or…
AnalizadaMedia (6.7)0.22%—Dell Embedded BOX PC 3000 FirmwareDell Edge Gateway 3001 FirmwareDell Edge Gateway 3002 FirmwareDell Edge Gateway 3003 Firmware+412/12/202417/6/2026
Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.
AnalizadaAlta (7.3)0.17%—Siemens Solid Edge Se202410/12/202417/6/2026
A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 10). The affected application is vulnerable to integer underflow vulnerability which can be triggered while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.
AnalizadaAlta (7.3)0.21%—Siemens Solid Edge Se202410/12/202417/6/2026
A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 5). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.
AnalizadaAlta (7.3)0.21%—Siemens Solid Edge Se202410/12/202417/6/2026
A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 5). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted ASM files. This could allow an attacker to execute code in the context of the current process.
AnalizadaAlta (7.3)0.18%—Siemens ParasolidSiemens Solid Edge Se2024Siemens Solid Edge Se202510/12/202417/6/2026
A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 12), Solid Edge SE2025 (All versions < V225.0 Update 3). The affected application contains an out of bounds write past the end of an allocated buffer while parsing X_T data or a specially crafted file in X_T format. This could allow…
AnalizadaMedia (4.3)1.0%—Microsoft Edge Chromium6/12/202417/6/2026
Microsoft Edge (Chromium-based) Spoofing Vulnerability
AplazadaMedia (5.4)0.36%—Public Knowledge Project PKP PlatformAIPublic Knowledge Project OJSAIPublic Knowledge Project OMPAIPublic Knowledge Project OPSAI22/11/202417/6/2026
Cross Site Scripting vulnerability in Public Knowledge Project PKP Platform OJS/OMP/OPS- before v.3.3.0.16 allows an attacker to execute arbitrary code and escalate privileges via a crafted script
AnalizadaMedia (4.3)0.58%—Microsoft Edge Chromium22/11/202417/6/2026
Microsoft Edge (Chromium-based) Spoofing Vulnerability
AnalizadaMedia (6.1)0.59%—Hedge3 Crypto AND Defi Widgets21/11/202417/6/2026
The Crypto and DeFi Widgets – Web3 Cryptocurrency Shortcodes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.1.6. This makes it possible for unauthenticated attackers to inject arbitrary…
AnalizadaMedia (4.3)0.49%—Microsoft Edge Chromium14/11/202417/6/2026
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
AnalizadaAlta (7)0.19%—Siemens Solid Edge Se202412/11/202417/6/2026
A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 9). The affected applications suffer from a DLL hijacking vulnerability. This could allow an attacker to execute arbitrary code via placing a crafted DLL file on the system.