Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

475 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.1%—Redhat Network SatelliteRedhat SatelliteRedhat Satellite With Embedded OracleSuse Manager+118/11/201316/6/2026
Red Hat Satellite 5.6 and earlier does not disable the web interface that is used to create the first user for a satellite, which allows remote attackers to create administrator accounts.
ModificadaMedia (4.3)2.8%—Scott Reynen Node Embed27/6/201216/6/2026
The node selection interface in the WYSIWYG editor (CKEditor) in the Node Embed module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.0 for Drupal does not properly check permissions, which allows remote attackers to bypass intended access restrictions and read node titles.
ModificadaBaja (2.1)0.48%—Oracle JREOracle JDKRedhat Icedtea6Redhat Satellite With Embedded Oracle+1316/6/201216/6/2026
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows local users to affect confidentiality via unknown vectors related to printing on Solaris or Linux.
ModificadaMedia (5)2.3%—Kylegilman Video Embed & Thumbnail Generator19/3/201216/6/2026
The Media Upload form in the Video Embed & Thumbnail Generator plugin before 2.0 for WordPress allows remote attackers to obtain the installation path via unknown vectors.
ModificadaAlta (7.5)3.4%—Kylegilman Video Embed & Thumbnail Generator19/3/201216/6/2026
kg_callffmpeg.php in the Video Embed & Thumbnail Generator plugin before 2.0 for WordPress allows remote attackers to execute arbitrary commands via unspecified vectors.
AnalizadaCrítica (9.8)97%⚠ Explotación activa💥 ExploitOracle JDKOracle JRECanonical Ubuntu LinuxRedhat Satellite With Embedded Oracle+219/10/201116/6/2026
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Scripting.
ModificadaMedia (4.3)3.5%💥 ExploitAhmattox Processing Embed Plugin1/3/201116/6/2026
Cross-site scripting (XSS) vulnerability in wordpress-processing-embed/data/popup.php in the Processing Embed plugin 0.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the pluginurl parameter.
ModificadaMedia (4.3)1.8%—Jovelstefan Embedded-video22/12/201016/6/2026
Cross-site scripting (XSS) vulnerability in lembedded-video.php in the Embedded Video plugin 4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the content parameter to wp-admin/post.php.
ModificadaAlta (7.5)1.0%💥 ExploitJoshprakash COM Jembed23/3/201016/6/2026
SQL injection vulnerability in the jEmbed-Embed Anything (com_jembed) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a summary action to index.php.
ModificadaAlta (9.3)18%—Microsoft Windows Embedded Compact12/5/200816/6/2026
Multiple unspecified vulnerabilities in the JPEG (GDI+) and GIF image processing in Microsoft Windows CE 5.0 allow remote attackers to execute arbitrary code via crafted (1) JPEG and (2) GIF images.
ModificadaMedia (4.3)1.9%💥 ExploitCheckpoint Vpn-1 UTM Edge W Embedded NGX8/3/200816/6/2026
Cross-site scripting (XSS) vulnerability in the login page in Check Point VPN-1 UTM Edge W Embedded NGX 7.0.48x allows remote attackers to inject arbitrary web script or HTML via the user parameter.
ModificadaAlta (10)3.3%—SUN Embedded Lights OUT Manager30/10/200716/6/2026
Unspecified vulnerability in Sun Fire X2100 M2 and X2200 M2 Embedded Lights Out Manager (ELOM) on x86 before firmware 2.70 allows remote attackers to execute arbitrary commands as root on the Service Processor (SP) via unspecified vectors, a different vulnerability than CVE-2007-5170.
ModificadaMedia (5)1.5%—SUN Embedded Lights OUT Manager1/10/200716/6/2026
Unspecified vulnerability in the embedded service processor (SP) before 3.09 in Sun Fire X2100 M2 and X2200 M2 Embedded Lights Out Manager (ELOM) allows remote attackers to send arbitrary network traffic and use ELOM as a spam proxy.
ModificadaMedia (5)1.6%—SUN Java Embedding Plugin30/5/200716/6/2026
Java Embedding Plugin 0.9.6.1 allows remote attackers to cause a denial of service (browser crash) via a Thread subclass that calls super.run from its run method.
ModificadaMedia (6.8)3.0%💥 ExploitBsalsa Embeddedwb WEB Browser2/3/200716/6/2026
Unspecified vulnerability in the EmbeddedWB Web Browser ActiveX control allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (10)31%—Broadcom Widcomm BluetoothMicrosoft Windows Embedded CompactMicrosoft Windows Mobile31/12/200616/6/2026
Buffer overflow in the Bluetooth Stack COM Server in the Widcomm Bluetooth stack, as packaged as Widcomm Stack 3.x and earlier on Windows, Widcomm BTStackServer 1.4.2.10 and 1.3.2.7 on Windows, Widcomm Bluetooth Communication Software 1.4.1.03 on Windows, and the Bluetooth implementation in Windows Mobile or Windows…
ModificadaAlta (7.5)4.4%—KDE KonquerorKDE Konqueror Embedded15/4/200416/6/2026
Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Konqueror to send the cookie outside the specified URL subsets, e.g. to a vulnerable application…
ModificadaMedia (5)2.9%—KDE KonquerorKDE Konqueror EmbeddedRedhat Analog Real-time SynthesizerRedhat Kdebase+427/8/200316/6/2026
KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites.
ModificadaAlta (7.5)2.1%—Apple SafariKDE Konqueror EmbeddedKDERedhat Linux+216/6/200316/6/2026
Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates via a man-in-the-middle attack.
ModificadaMedia (5)0.77%—Apple SafariKDE Konqueror Embedded9/6/200316/6/2026
Safari 1.0 Beta 2 (v73) and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates.
ModificadaAlta (7.5)2.5%—Beck IPC Gmbh IPC AT Chip Embedded-webserver24/5/200116/6/2026
The (1) FTP and (2) Telnet services in Beck GmbH IPC@Chip are shipped with a default password, which allows remote attackers to gain unauthorized access.
ModificadaAlta (7.5)1.7%—Beck IPC Gmbh IPC AT Chip Embedded-webserver24/5/200116/6/2026
Beck IPC GmbH IPC@CHIP Embedded-Webserver allows remote attackers to read arbitrary files via a webserver root directory set to system root.
ModificadaMedia (5)3.2%—Beck IPC Gmbh IPC AT Chip Embedded-webserver24/5/200116/6/2026
The Beck GmbH IPC@Chip embedded web server installs the chipcfg.cgi program by default, which allows remote attackers to obtain sensitive network information via a request to the program.
ModificadaMedia (5)1.6%—Beck IPC Gmbh IPC AT Chip Embedded-webserver21/5/200116/6/2026
Beck IPC GmbH IPC@CHIP Embedded-Webserver allows remote attackers to cause a denial of service via a long HTTP request.
ModificadaAlta (7.5)15%💥 ExploitMicrosoft Windows Embedded Compact1/1/200116/6/2026
WinCE 3.0.9348 generates predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.
Orbitaley — Vulnerabilidades