Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
921 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.24% | — | Sem-cms Semcms | 14/7/2025 | 5/7/2026 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Products.php. | |
| Modificada | Media (5.4) | 0.24% | — | Sem-cms Semcms | 14/7/2025 | 5/7/2026 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Products.php. | |
| Modificada | Media (5.4) | 0.24% | — | Sem-cms Semcms | 14/7/2025 | 5/7/2026 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_InquiryView.php. | |
| Modificada | Media (5.4) | 0.24% | — | Sem-cms Semcms | 14/7/2025 | 5/7/2026 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Link.php. | |
| Modificada | Media (5.4) | 0.24% | — | Sem-cms Semcms | 14/7/2025 | 5/7/2026 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Link.php. | |
| Modificada | Media (5.4) | 0.24% | — | Sem-cms Semcms | 14/7/2025 | 5/7/2026 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Quanxian.php. | |
| Modificada | Media (5.4) | 0.24% | — | Sem-cms Semcms | 14/7/2025 | 5/7/2026 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Infocategories.php. | |
| Modificada | Media (5.4) | 0.24% | — | Sem-cms Semcms | 14/7/2025 | 5/7/2026 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_ct.php. | |
| Modificada | Media (5.4) | 0.24% | — | Sem-cms Semcms | 14/7/2025 | 5/7/2026 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Categories.php. | |
| Analizada | Crítica (9.8) | 0.50% | — | Sem-cms Semcms | 27/3/2025 | 17/6/2026 | semcms <=5.0 is vulnerable to SQL Injection in SEMCMS_Fuction.php. | |
| Analizada | Media (5.3) | 0.51% | — | Sem-cms Semcms | 8/1/2025 | 17/6/2026 | A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is an unknown functionality of the file SEMCMS_Images.php of the component Image Library Management Page. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Aplazada | Media (6.5) | 0.23% | — | Eric Mcniece Emc2 Alert BoxesAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eric McNiece EMC2 Alert Boxes allows Stored XSS.This issue affects EMC2 Alert Boxes: from n/a through 1.3. | |
| Analizada | Media (6.8) | 0.32% | — | Iobit Advanced Systemcare Ultimate | 16/12/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in IObit Advanced SystemCare Utimate up to 17.0.0. This affects the function 0x8001E040 in the library AscRegistryFilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit… | |
| Analizada | Media (6.8) | 0.38% | — | Iobit Advanced Systemcare Ultimate | 16/12/2024 | 17/6/2026 | A vulnerability was found in IObit Advanced SystemCare Utimate up to 17.0.0. It has been rated as problematic. Affected by this issue is the function 0x8001E024 in the library AscRegistryFilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. The attack needs to be approached… | |
| Analizada | Media (6.8) | 0.46% | — | Iobit Advanced Systemcare Ultimate | 16/12/2024 | 17/6/2026 | A vulnerability was found in IObit Advanced SystemCare Utimate up to 17.0.0. It has been declared as problematic. Affected by this vulnerability is the function 0x8001E018 in the library AscRegistryFilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. It is possible to launch… | |
| Analizada | Media (6.8) | 0.46% | — | Iobit Advanced Systemcare Ultimate | 16/12/2024 | 17/6/2026 | A vulnerability was found in IObit Advanced SystemCare Utimate up to 17.0.0. It has been classified as problematic. Affected is the function 0x8001E004 in the library AscRegistryFilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The… | |
| Analizada | Media (6.8) | 0.46% | — | Iobit Advanced Systemcare Ultimate | 16/12/2024 | 17/6/2026 | A vulnerability was found in IObit Advanced SystemCare Utimate up to 17.0.0 and classified as problematic. This issue affects the function 0x8001E01C in the library AscRegistryFilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. Local access is required to approach this… | |
| Analizada | Media (6.8) | 0.38% | — | Iobit Advanced Systemcare Ultimate | 16/12/2024 | 17/6/2026 | A vulnerability has been found in IObit Advanced SystemCare Utimate up to 17.0.0 and classified as problematic. This vulnerability affects the function 0x8001E000 in the library AscRegistryFilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. An attack has to be approached… | |
| Analizada | Baja (3.8) | 0.29% | — | Sem-cms Semcms | 3/12/2024 | 17/6/2026 | Seecms v4.8 was discovered to contain a SQL injection vulnerability in the SEMCMS_SeoAndTag.php page. | |
| Aplazada | Crítica (9.8) | 0.77% | — | NodemcuAI | 29/11/2024 | 17/6/2026 | nodemcu before v3.0.0-release_20240225 was discovered to contain an integer overflow via the getnum function at /modules/struct.c. | |
| Modificada | Media (4.9) | 0.55% | — | Sem-cms Semcms | 20/11/2024 | 5/7/2026 | SemCms v4.8 was discovered to contain a SQL injection vulnerability. This allows an attacker to execute arbitrary code via the ldgid parameter in the SEMCMS_SeoAndTag.php component. | |
| Analizada | Media (4.3) | 0.22% | — | Dell EMC Appsync | 9/10/2024 | 17/6/2026 | Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high privileged attacker could potentially exploit this vulnerability, leading to information disclosure. | |
| Analizada | Crítica (9.8) | 0.51% | — | Sem-cms Semcms | 20/9/2024 | 17/6/2026 | SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php. | |
| Analizada | Media (6.5) | 0.15% | — | Dell EMC XC Core Xcxr2 FirmwareDell EMC XC Core Xc940 System FirmwareDell EMC XC Core Xc740xd2 FirmwareDell EMC XC Core Xc740xd System Firmware+27 | 29/8/2024 | 17/6/2026 | Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Access of Memory Location After End of Buffer vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Analizada | Media (6) | 0.14% | — | Dell EMC XC Core Xcxr2 FirmwareDell EMC XC Core Xc940 System FirmwareDell EMC XC Core Xc740xd2 FirmwareDell EMC XC Core Xc740xd System Firmware+27 | 29/8/2024 | 17/6/2026 | Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Improper Input Validation vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. |