Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1062 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.9% | — | W1.fi HostapdW1.fi WPA SupplicantFedoraproject Fedora | 17/1/2022 | 14/7/2026 | The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495. | |
| Modificada | Crítica (9.8) | 3.1% | 💥 PoC | W1.fi HostapdW1.fi WPA SupplicantFedoraproject Fedora | 17/1/2022 | 14/7/2026 | The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494. | |
| Modificada | Media (5.5) | 1.4% | — | Artifex GhostscriptDebian Linux | 1/1/2022 | 17/6/2026 | Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sample (called from sampled_data_continue and interp). | |
| Modificada | Media (5.5) | 1.4% | — | Artifex GhostscriptDebian Linux | 31/12/2021 | 7/10/2026 | Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp). | |
| Modificada | Alta (8.8) | 2.5% | — | Fedoraproject SssdRedhat VirtualizationRedhat Virtualization HostRedhat Enterprise Linux+4 | 23/12/2021 | 17/6/2026 | A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this… | |
| Modificada | Alta (8.8) | 0.53% | — | Phpgurukul Hostel Management System | 1/12/2021 | 17/6/2026 | Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exits in hostel management system 2.1 via the name field in my-profile.php. Chaining to this both vulnerabilities leads to account takeover. | |
| Modificada | Alta (7.2) | 1.0% | — | Ghost | 3/9/2021 | 17/6/2026 | Ghost is a Node.js content management system. An error in the implementation of the limits service between versions 4.0.0 and 4.9.4 allows all authenticated users (including contributors) to view admin-level API keys via the integrations API endpoint, leading to a privilege escalation vulnerability. This issue is… | |
| Modificada | Media (4.8) | 0.61% | — | ANY Hostname Project ANY Hostname | 2/8/2021 | 17/6/2026 | The Any Hostname WordPress plugin through 1.0.6 does not sanitise or escape its "Allowed hosts" setting, leading to an authenticated stored XSS issue as high privilege users are able to set XSS payloads in it | |
| Modificada | Alta (7.6) | 0.81% | — | Microfocus Verastream Host Integrator | 22/7/2021 | 17/6/2026 | XML External Entity vulnerability in Micro Focus Verastream Host Integrator, affecting version 7.8 Update 1 and earlier versions. The vulnerability could allow the control of web browser and hijacking user sessions. | |
| Modificada | Alta (7.1) | 0.62% | — | Microfocus Verastream Host Integrator | 22/7/2021 | 17/6/2026 | Reflected Cross-Site Scripting vulnerability in Micro Focus Verastream Host Integrator, affecting version version 7.8 Update 1 and earlier versions. The vulnerability could allow disclosure of confidential data. | |
| Modificada | Alta (7.1) | 0.38% | — | Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux FOR Real TimeRedhat Enterprise Linux FOR Real Time FOR NFV+15 | 6/5/2021 | 5/8/2026 | A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat from this vulnerability is to data integrity and system availability. | |
| Modificada | Media (6.5) | 1.0% | — | Cisco Hosted Collaboration Mediation FulfillmentCisco Unified Communications Manager | 6/5/2021 | 17/6/2026 | A vulnerability in the Java Management Extensions (JMX) component of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected system.… | |
| Modificada | Media (6.1) | 7.9% | 💥 Exploit | Ghost | 29/4/2021 | 17/6/2026 | Ghost is a Node.js CMS. An unused endpoint added during the development of 4.0.0 has left sites vulnerable to untrusted users gaining access to Ghost Admin. Attackers can gain access by getting logged in users to click a link containing malicious code. Users do not need to enter credentials and may not know they've… | |
| Analizada | Media (4.9) | 52% | ⚠ Explotación activa | Sonicwall Email SecuritySonicwall Email Security Appliance 9000 FirmwareSonicwall Email Security Appliance 3300 FirmwareSonicwall Email Security Appliance 4300 Firmware+7 | 20/4/2021 | 1/10/2026 | SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host. | |
| Analizada | Crítica (9.8) | 89% | ⚠ Explotación activa💥 Exploit | Sonicwall Email SecuritySonicwall Email Security Appliance 9000 FirmwareSonicwall Email Security Appliance 3300 FirmwareSonicwall Email Security Appliance 4300 Firmware+7 | 9/4/2021 | 12/8/2026 | A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. | |
| Analizada | Alta (7.2) | 17% | ⚠ Explotación activa | Sonicwall Email SecuritySonicwall Email Security Appliance 9000 FirmwareSonicwall Email Security Appliance 3300 FirmwareSonicwall Email Security Appliance 4300 Firmware+7 | 9/4/2021 | 1/10/2026 | SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host. | |
| Modificada | Media (5.3) | 1.8% | — | W1.fi HostapdW1.fi WPA Supplicant | 2/4/2021 | 7/7/2026 | In wpa_supplicant and hostapd 2.9, forging attacks may occur because AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c and tls/x509v3.c. | |
| Modificada | Media (5.3) | 3.6% | — | Npmjs Hosted-git-infoSiemens Sinec Infrastructure Network Services | 23/3/2021 | 17/6/2026 | The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity. | |
| Modificada | Media (4.3) | 0.43% | — | Totalonlinesolutions Advanced Webhost Billing System | 8/1/2021 | 17/6/2026 | Advanced Webhost Billing System 3.7.0 is affected by Cross Site Request Forgery (CSRF) attacks that can delete a contact from the My Additional Contact page. | |
| Modificada | Crítica (9.8) | 2.9% | — | Ghost Alpine Docker Image | 17/12/2020 | 17/6/2026 | The official ghost docker images before 2.16.1-alpine (Alpine specific) contain a blank password for a root user. System using the ghost docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Alta (7.5) | 1.5% | — | Hosteng H0-ecom100 FirmwareHosteng H2-ecom100 FirmwareHosteng H4-ecom100 Firmware | 15/12/2020 | 17/6/2026 | The length of the input fields of Host Engineering H0-ECOM100, H2-ECOM100, and H4-ECOM100 modules are verified only on the client side when receiving input from the configuration web server, which may allow an attacker to bypass the check and send input to crash the device. | |
| Modificada | Media (5.5) | 0.31% | — | Intel Csi2 Host Controller | 12/11/2020 | 17/6/2026 | Out of bounds read in the Intel CSI2 Host Controller driver may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (5.4) | 3.2% | 💥 Exploit | Phpgurukul Hostel Management System | 8/10/2020 | 17/6/2026 | PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, or City. | |
| Modificada | Media (6.5) | 0.50% | — | Cisco Hosted Collaboration Mediation Fulfillment | 23/9/2020 | 17/6/2026 | A vulnerability in the web-based interface of Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections by the affected software. An… | |
| Modificada | Media (5.5) | 0.45% | — | Artifex GhostscriptRedhat Enterprise Linux | 3/9/2020 | 17/6/2026 | A use after free was found in igc_reloc_struct_ptr() of psi/igc.c of ghostscript-9.25. A local attacker could supply a specially crafted PDF file to cause a denial of service. |