Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
73 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 1.2% | — | Microsoft Azure Database FOR Postgresql Flexible Server | 12/11/2024 | 17/6/2026 | Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.2) | 1.2% | — | Microsoft Azure Database FOR Postgresql Flexible Server | 12/11/2024 | 17/6/2026 | Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability | |
| Analizada | Media (5.4) | 0.14% | — | Intel License Manager FOR Flexim | 14/8/2024 | 17/6/2026 | Uncontrolled search path for some Intel(R) License Manager for FLEXlm product software before version 11.19.5.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (8.8) | 0.32% | — | Wpdesk Flexible Checkout Fields | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in WP Desk Flexible Checkout Fields for WooCommerce.This issue affects Flexible Checkout Fields for WooCommerce: from n/a through 4.1.2. | |
| Aplazada | Media (4.3) | 0.34% | — | Octolize Flexible ShippingAI | 26/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Octolize Flexible Shipping.This issue affects Flexible Shipping: from n/a through 4.24.15. | |
| Analizada | Alta (7.5) | 0.55% | — | Common-services SO Flexibilite | 3/3/2024 | 17/6/2026 | An issue was discovered in Common-Services "So Flexibilite" (soflexibilite) module for PrestaShop before version 4.1.26, allows remote attackers to escalate privileges and obtain sensitive information via debug file. | |
| Analizada | Media (5.9) | 0.39% | — | Common-services SO Flexibilite | 27/2/2024 | 17/6/2026 | In the module "So Flexibilite" (soflexibilite) from Common-Services for PrestaShop < 4.1.26, a guest (authenticated customer) can perform Cross Site Scripting (XSS) injection. | |
| Modificada | Crítica (9.8) | 1.0% | — | Gatesair Flexiva FAX 150w Firmware | 3/8/2023 | 9/7/2026 | An isssue in GatesAIr Flexiva FM Transmitter/Exiter Fax 150W allows a remote attacker to gain privileges via the LDAP and SMTP credentials. | |
| Modificada | Media (5.4) | 0.57% | — | Gatesair Flexiva FAX 150w Firmware | 2/8/2023 | 9/7/2026 | Cross Site Scripting vulnerability in GatesAIr Flexiva FM Transmitter/Exciter v.FAX 150W allows a remote attacker to execute arbitrary code via a crafted script to the web application dashboard. | |
| Modificada | Media (6.1) | 1.3% | — | Wpdesk Flexible Checkout Fields | 7/6/2023 | 17/6/2026 | The Flexible Checkout Fields for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Plugin Settings update, in addition to Stored Cross-Site Scripting in versions up to, and including, 2.3.1. This is due to missing authorization checks on the updateSettingsAction() function which is called via… | |
| Modificada | Media (5.5) | 0.33% | — | Electronic Flexihub | 24/5/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in FlexiHub 5.5.14691.0. This affects the function 0x220088 in the library fusbhub.sys of the component IoControlCode Handler. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the… | |
| Modificada | Alta (8.8) | 0.27% | — | Webmat Flexible Elementor Panel | 22/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WebMat Flexible Elementor Panel plugin <= 2.3.8 versions. | |
| Modificada | Alta (7.8) | 0.22% | — | Softmaker Flexipdf | 23/3/2023 | 17/6/2026 | A stack overfow in SoftMaker Software GmbH FlexiPDF v3.0.3.0 allows attackers to execute arbitrary code after opening a crafted PDF file. | |
| Modificada | Media (5.4) | 0.54% | — | Mekshq Meks Flexible Shortcodes | 13/2/2023 | 17/6/2026 | The Meks Flexible Shortcodes WordPress plugin before 1.3.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users… | |
| Modificada | Media (5.4) | 0.61% | — | Flexible Captcha Project Flexible Captcha | 6/2/2023 | 17/6/2026 | The Flexible Captcha WordPress plugin through 4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (4.8) | 0.61% | — | Flexi Quote Rotator Project Flexi Quote Rotator | 1/8/2022 | 17/6/2026 | The Flexi Quote Rotator WordPress plugin through 0.9.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Alta (7.8) | 0.35% | — | Sick Flexi Soft Designer | 19/7/2022 | 17/6/2026 | A deserialization vulnerability in a .NET framework class used and not properly checked by Flexi Soft Designer in all versions up to and including 1.9.4 SP1 allows an attacker to craft malicious project files. Opening/importing such a malicious project file would execute arbitrary code with the privileges of the… | |
| Modificada | Alta (7.2) | 1.6% | — | Bosch Autodome IP 4000i FirmwareBosch Autodome IP 5000i FirmwareBosch Autodome IP Starlight 5000i FirmwareBosch Autodome IP Starlight 7000i Firmware+64 | 30/3/2022 | 17/6/2026 | A specially crafted TCP/IP packet may cause the camera recovery image web interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can only be booted with administrative rights or with physical access to the camera and allows the upload of a new firmware in… | |
| Modificada | Alta (7.2) | 1.6% | — | Bosch Autodome IP 4000i FirmwareBosch Autodome IP 5000i FirmwareBosch Autodome IP Starlight 5000i FirmwareBosch Autodome IP Starlight 7000i Firmware+64 | 30/3/2022 | 17/6/2026 | A specially crafted TCP/IP packet may cause a camera recovery image telnet interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can only be booted with administrative rights or with physical access to the camera and allows the upload of a new firmware in… | |
| Modificada | Media (6.1) | 0.80% | — | Odude Flexi | 14/3/2022 | 17/6/2026 | The Flexi WordPress plugin before 4.20 does not sanitise and escape various parameters before outputting them back in some pages such as the user dashboard, leading to a Reflected Cross-Site Scripting | |
| Modificada | Alta (8.8) | 0.50% | — | Flexihub | 7/12/2021 | 17/6/2026 | FlexiHub For Windows is affected by Integer Overflow. IOCTL Handler 0x22001B in the FlexiHub For Windows above 2.0.4340 below 5.3.14268 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet. | |
| Modificada | Alta (8.8) | 0.48% | — | Flexihub | 7/12/2021 | 17/6/2026 | FlexiHub For Windows is affected by Buffer Overflow. IOCTL Handler 0x22001B in the FlexiHub For Windows above 2.0.4340 below 5.3.14268 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet. | |
| Modificada | Media (6.5) | 1.2% | — | NCH Flexiserver | 25/7/2021 | 17/6/2026 | NCH FlexiServer v6.00 suffers from a syslog?file=/.. path traversal vulnerability. | |
| Modificada | Alta (7.5) | 1.3% | — | Mitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric EM ConfiguratorMitsubishielectric GT Designer3+16 | 30/6/2020 | 17/6/2026 | Uncontrolled resource consumption vulnerability in Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, EM Software Development Kit (EM Configurator) Ver. 1.010L and earlier, GT Designer3 (GOT2000) Ver. 1.221F and earlier,… | |
| Modificada | Alta (7.5) | 1.4% | — | Mitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric EM ConfiguratorMitsubishielectric GT Designer3+16 | 30/6/2020 | 17/6/2026 | Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, EM Software Development Kit (EM Configurator) Ver. 1.010L and earlier, GT Designer3 (GOT2000) Ver. 1.221F and earlier, GX LogViewer Ver. 1.96A and earlier, GX Works2 Ver.… |