Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

808 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)7.0%💥 ExploitMingsoft Mcms3/3/202217/6/2026
MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp.
ModificadaCrítica (9.8)1.1%—Mingsoft Mcms3/3/202217/6/2026
MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via search.do in the file /web/MCmsAction.java.
ModificadaCrítica (9.8)7.7%💥 ExploitMingsoft Mcms3/3/202217/6/2026
MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml.
ModificadaCrítica (9.8)1.3%—Excel Streaming Reader Project Excel Streaming Reader2/3/202217/6/2026
Excel-Streaming-Reader is an easy-to-use implementation of a streaming Excel reader using Apache POI. Prior to xlsx-streamer 2.1.0, the XML parser that was used did apply all the necessary settings to prevent XML Entity Expansion issues. Upgrade to version 2.1.0 to receive a patch. There is no known workaround.
ModificadaMedia (4.3)0.47%—Wpdevart Coming Soon AND Maintenance Mode21/2/202217/6/2026
The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have CSRF check in its coming_soon_send_mail AJAX action, allowing attackers to make logged in admin to send arbitrary emails to all subscribed users via a CSRF attack
ModificadaMedia (4.3)0.35%—Wpdevart Coming Soon AND Maintenance Mode21/2/202217/6/2026
The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not have authorisation and CSRF checks in its coming_soon_send_mail AJAX action, allowing any authenticated users, with a role as low as subscriber to send arbitrary emails to all subscribed users
ModificadaCrítica (9.8)18%—Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+8921/2/202217/6/2026
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
ModificadaCrítica (9.1)2.7%—Mingsoft Mcms18/2/202217/6/2026
MCMS v5.2.5 was discovered to contain a Server Side Template Injection (SSTI) vulnerability via the Template Management module.
ModificadaAlta (7.1)0.77%—Mingsoft Mcms18/2/202217/6/2026
MCMS v5.2.5 was discovered to contain an arbitrary file deletion vulnerability via the component oldFileName.
ModificadaAlta (8.1)1.0%—Mingsoft Mcms18/2/202217/6/2026
MCMS v5.2.4 was discovered to contain an arbitrary file deletion vulnerability via the component /template/unzip.do.
ModificadaCrítica (9.8)3.7%—Mingsoft Mcms18/2/202217/6/2026
An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to execute arbitrary code.
ModificadaCrítica (9.8)1.4%—Mingsoft Mcms17/2/202217/6/2026
A problem was found in ming-soft MCMS v5.1. There is a sql injection vulnerability in /ms/cms/content/list.do
ModificadaMedia (5.1)0.14%—Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware M15 R3 FirmwareDell Alienware M15 R4 Firmware+2109/2/202217/6/2026
Select Dell Client Commercial and Consumer platforms are vulnerable to an insufficient verification of data authenticity vulnerability. An authenticated malicious user may exploit this vulnerability in order to install modified BIOS firmware.
ModificadaAlta (7.2)0.26%—Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware M15 R3 FirmwareDell Alienware M15 R4 Firmware+2109/2/202217/6/2026
Select Dell Client Commercial and Consumer platforms contain a pre-boot direct memory access (DMA) vulnerability. An authenticated attacker with physical access to the system may potentially exploit this vulnerability in order to execute arbitrary code on the device.
ModificadaAlta (8.8)1.3%—Linuxfoundation Nats-serverNats Streaming Server8/2/202217/6/2026
NATS nats-server before 2.7.2 has Incorrect Access Control. Any authenticated user can obtain the privileges of the System account by misusing the "dynamically provisioned sandbox accounts" feature.
ModificadaMedia (5.5)0.19%—Nvidia Cloud Gaming Virtual GPUNvidia Virtual GPU7/2/202217/6/2026
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where a user in the guest OS can cause a GPU interrupt storm on the hypervisor host, leading to a denial of service.
ModificadaMedia (5.5)0.21%—Nvidia Cloud Gaming GuestNvidia GeforceNvidia GPU Display DriverNvidia NVS+57/2/202217/6/2026
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for private IOCTLs where a NULL pointer dereference in the kernel, created within user mode code, may lead to a denial of service in the form of a system crash.
ModificadaMedia (6.1)0.23%—Nvidia Cloud Gaming GuestNvidia GeforceNvidia GPU Display DriverNvidia NVS+47/2/202217/6/2026
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel driver, where improper handling of insufficient permissions or privileges may allow an unprivileged local user limited write access to protected memory, which can lead to denial of service.
ModificadaAlta (7.5)1.2%—High Resolution Streaming Image Server Project High Resolution Streaming Image Server7/2/202217/6/2026
IIPImage High Resolution Streaming Image Server prior to commit 882925b295a80ec992063deffc2a3b0d803c3195 is affected by an integer overflow in iipsrv.fcgi through malformed HTTP query parameters.
ModificadaAlta (7.5)1.5%—Mingsoft Mcms26/1/202217/6/2026
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). The component is: net.mingsoft.mdiy.action.FormDataAction#queryData. The attack vector is: 0 or sleep(3). ¶¶ MCMS has a sql injection vulnerability through which attacker can get sensitive…
ModificadaCrítica (9.8)3.1%—Mingsoft Mcms26/1/202217/6/2026
File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to net.mingsoft.basic.action.web.FileAction#upload.
ModificadaAlta (7.5)1.6%—Mingsoft Mcms26/1/202217/6/2026
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). The component is: net.mingsoft.mdiy.action.web.DictAction#list. The attack vector is: 0 or sleep(3). ¶¶ MCMS has a sql injection vulnerability through which attacker can get sensitive…
AnalizadaMedia (6.4)0.24%—Dell Precision 5820 Tower FirmwareDell Precision 7510 FirmwareDell Precision 7520 FirmwareDell Precision 7530 Firmware+40724/1/20227/10/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
AnalizadaMedia (6.4)0.25%—Dell Precision 7510 FirmwareDell Precision 7520 FirmwareDell Precision 7530 FirmwareDell Precision 7540 Firmware+40724/1/20227/10/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
ModificadaCrítica (9.8)1.8%—Mingsoft Mcms21/1/202217/6/2026
MCMS v5.2.4 was discovered to contain an arbitrary file upload vulnerability via the component /ms/template/writeFileContent.do.
Orbitaley — Vulnerabilidades