Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1062 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.9%—W1.fi HostapdW1.fi WPA SupplicantFedoraproject Fedora17/1/202214/7/2026
The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495.
ModificadaCrítica (9.8)3.1%💥 PoCW1.fi HostapdW1.fi WPA SupplicantFedoraproject Fedora17/1/202214/7/2026
The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494.
ModificadaMedia (5.5)1.4%—Artifex GhostscriptDebian Linux1/1/202217/6/2026
Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sample (called from sampled_data_continue and interp).
ModificadaMedia (5.5)1.4%—Artifex GhostscriptDebian Linux31/12/20217/10/2026
Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).
ModificadaAlta (8.8)2.5%—Fedoraproject SssdRedhat VirtualizationRedhat Virtualization HostRedhat Enterprise Linux+423/12/202117/6/2026
A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this…
ModificadaAlta (8.8)0.53%—Phpgurukul Hostel Management System1/12/202117/6/2026
Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exits in hostel management system 2.1 via the name field in my-profile.php. Chaining to this both vulnerabilities leads to account takeover.
ModificadaAlta (7.2)1.0%—Ghost3/9/202117/6/2026
Ghost is a Node.js content management system. An error in the implementation of the limits service between versions 4.0.0 and 4.9.4 allows all authenticated users (including contributors) to view admin-level API keys via the integrations API endpoint, leading to a privilege escalation vulnerability. This issue is…
ModificadaMedia (4.8)0.61%—ANY Hostname Project ANY Hostname2/8/202117/6/2026
The Any Hostname WordPress plugin through 1.0.6 does not sanitise or escape its "Allowed hosts" setting, leading to an authenticated stored XSS issue as high privilege users are able to set XSS payloads in it
ModificadaAlta (7.6)0.81%—Microfocus Verastream Host Integrator22/7/202117/6/2026
XML External Entity vulnerability in Micro Focus Verastream Host Integrator, affecting version 7.8 Update 1 and earlier versions. The vulnerability could allow the control of web browser and hijacking user sessions.
ModificadaAlta (7.1)0.62%—Microfocus Verastream Host Integrator22/7/202117/6/2026
Reflected Cross-Site Scripting vulnerability in Micro Focus Verastream Host Integrator, affecting version version 7.8 Update 1 and earlier versions. The vulnerability could allow disclosure of confidential data.
ModificadaAlta (7.1)0.38%—Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux FOR Real TimeRedhat Enterprise Linux FOR Real Time FOR NFV+156/5/20215/8/2026
A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat from this vulnerability is to data integrity and system availability.
ModificadaMedia (6.5)1.0%—Cisco Hosted Collaboration Mediation FulfillmentCisco Unified Communications Manager6/5/202117/6/2026
A vulnerability in the Java Management Extensions (JMX) component of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected system.…
ModificadaMedia (6.1)7.9%💥 ExploitGhost29/4/202117/6/2026
Ghost is a Node.js CMS. An unused endpoint added during the development of 4.0.0 has left sites vulnerable to untrusted users gaining access to Ghost Admin. Attackers can gain access by getting logged in users to click a link containing malicious code. Users do not need to enter credentials and may not know they've…
AnalizadaMedia (4.9)52%⚠ Explotación activaSonicwall Email SecuritySonicwall Email Security Appliance 9000 FirmwareSonicwall Email Security Appliance 3300 FirmwareSonicwall Email Security Appliance 4300 Firmware+720/4/20211/10/2026
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.
AnalizadaCrítica (9.8)89%⚠ Explotación activa💥 ExploitSonicwall Email SecuritySonicwall Email Security Appliance 9000 FirmwareSonicwall Email Security Appliance 3300 FirmwareSonicwall Email Security Appliance 4300 Firmware+79/4/202112/8/2026
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
AnalizadaAlta (7.2)17%⚠ Explotación activaSonicwall Email SecuritySonicwall Email Security Appliance 9000 FirmwareSonicwall Email Security Appliance 3300 FirmwareSonicwall Email Security Appliance 4300 Firmware+79/4/20211/10/2026
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.
ModificadaMedia (5.3)1.8%—W1.fi HostapdW1.fi WPA Supplicant2/4/20217/7/2026
In wpa_supplicant and hostapd 2.9, forging attacks may occur because AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c and tls/x509v3.c.
ModificadaMedia (5.3)3.6%—Npmjs Hosted-git-infoSiemens Sinec Infrastructure Network Services23/3/202117/6/2026
The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity.
ModificadaMedia (4.3)0.43%—Totalonlinesolutions Advanced Webhost Billing System8/1/202117/6/2026
Advanced Webhost Billing System 3.7.0 is affected by Cross Site Request Forgery (CSRF) attacks that can delete a contact from the My Additional Contact page.
ModificadaCrítica (9.8)2.9%—Ghost Alpine Docker Image17/12/202017/6/2026
The official ghost docker images before 2.16.1-alpine (Alpine specific) contain a blank password for a root user. System using the ghost docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
ModificadaAlta (7.5)1.5%—Hosteng H0-ecom100 FirmwareHosteng H2-ecom100 FirmwareHosteng H4-ecom100 Firmware15/12/202017/6/2026
The length of the input fields of Host Engineering H0-ECOM100, H2-ECOM100, and H4-ECOM100 modules are verified only on the client side when receiving input from the configuration web server, which may allow an attacker to bypass the check and send input to crash the device.
ModificadaMedia (5.5)0.31%—Intel Csi2 Host Controller12/11/202017/6/2026
Out of bounds read in the Intel CSI2 Host Controller driver may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaMedia (5.4)3.2%💥 ExploitPhpgurukul Hostel Management System8/10/202017/6/2026
PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, or City.
ModificadaMedia (6.5)0.50%—Cisco Hosted Collaboration Mediation Fulfillment23/9/202017/6/2026
A vulnerability in the web-based interface of Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections by the affected software. An…
ModificadaMedia (5.5)0.45%—Artifex GhostscriptRedhat Enterprise Linux3/9/202017/6/2026
A use after free was found in igc_reloc_struct_ptr() of psi/igc.c of ghostscript-9.25. A local attacker could supply a specially crafted PDF file to cause a denial of service.
Orbitaley — Vulnerabilidades