Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
452 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.8) | 0.37% | — | IDFAIZLFAI | 6/6/2025 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. This vulnerability allows an attacker to store malicious JavaScript payload in software that will run in the victim's browser. Exploiting this vulnerability requires authenticating to the device and executing certain… | |
| Aplazada | Media (5.1) | 0.36% | — | IDFAIZLFAI | 6/6/2025 | 17/6/2026 | In IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04, a configuration error has been detected in cross-origin resource sharing (CORS). Exploiting this vulnerability requires authenticating to the device and executing certain commands that can only be executed with permissions higher than the view permission. | |
| Aplazada | Media (5.1) | 0.38% | — | IDFAIZLFAI | 6/6/2025 | 17/6/2026 | Code injection vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. This vulnerability allows an attacker to store malicious payload in software that will run in the victim's browser. Exploiting this vulnerability requires authenticating to the device and executing certain commands that can be executed only… | |
| Aplazada | Media (5.1) | 0.35% | — | IDFAIZLFAI | 6/6/2025 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. This vulnerability allows an attacker to store malicious JavaScript payload in software that will run in the victim's browser. Exploiting this vulnerability requires authenticating to the device and executing certain… | |
| Aplazada | Media (5.3) | 0.33% | — | IDFAIZLFAI | 6/6/2025 | 17/6/2026 | In IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04, a configuration error has been detected in cross-origin resource sharing (CORS). Exploiting this vulnerability requires authenticating to the device and executing certain commands that can be executed with view permission. | |
| Aplazada | Media (5.3) | 0.37% | — | IDFAIZLFAI | 6/6/2025 | 17/6/2026 | Code injection vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. This vulnerability allows an attacker to store malicious payload in software that will run in the victim's browser. Exploiting this vulnerability requires authenticating to the device and executing certain commands that can be executed with… | |
| Aplazada | Alta (8.3) | 0.25% | — | IDFAIZLFAI | 6/6/2025 | 17/6/2026 | Uncontrolled resource consumption vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. The devices improperly handle TLS requests associated with PROCOME sockets, so TLS requests sent to those PROCOME ports could cause the device to reboot and result in a denial of service. To exploit this vulnerability,… | |
| Aplazada | Alta (8.5) | 0.33% | — | Davidfcarr RsvpmarkerAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in davidfcarr RSVPMarker rsvpmaker allows SQL Injection.This issue affects RSVPMarker : from n/a through <= 11.5.6. | |
| Aplazada | Alta (7.1) | 0.15% | — | Davidfcarr My-marginaliaAI | 17/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in davidfcarr My Marginalia my-marginalia allows Stored XSS.This issue affects My Marginalia: from n/a through <= 1.0.6. | |
| Analizada | Alta (8.8) | 0.64% | — | Espressif Esp-idf | 13/3/2025 | 17/6/2026 | Espressif Esp idf v5.3.0 is vulnerable to Insecure Permissions resulting in Authentication bypass. In the reconnection phase, the device reuses the session key from a previous connection session, creating an opportunity for attackers to execute security bypass attacks. | |
| Modificada | Alta (7.7) | 0.39% | — | Netapp Active IQ Unified ManagerNetapp Manageability Software Development KITNetapp OntapNetapp Solidfire & HCI Management Node+7 | 18/2/2025 | 17/6/2026 | libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047. | |
| Modificada | Crítica (9.8) | 1.2% | — | Xmlsoft Libxml2Netapp HCI Compute NodeNetapp H410c FirmwareNetapp H300s Firmware+7 | 18/2/2025 | 17/6/2026 | libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used. | |
| Analizada | Alta (7.3) | 1.3% | — | Netapp HCI Baseboard Management ControllerNetapp HCI H610s FirmwareNetapp HCI H610c FirmwareNetapp HCI H615c Firmware+4 | 5/2/2025 | 17/6/2026 | When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow. | |
| Analizada | Baja (3.4) | 0.69% | — | Haxx CurlNetapp H700s FirmwareNetapp H615c FirmwareNetapp H610s Firmware+12 | 5/2/2025 | 17/6/2026 | When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has a `default` entry that omits both login and password. A rare circumstance. | |
| Aplazada | Alta (7.1) | 0.28% | — | Davidfcarr Rsvpmaker Volunteer RolesAI | 27/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in davidfcarr RSVPMaker Volunteer Roles rsvpmaker-volunteer-roles allows Reflected XSS.This issue affects RSVPMaker Volunteer Roles: from n/a through <= 1.5.1. | |
| Analizada | Crítica (9.1) | 1.2% | — | Xmlsoft Libxml2Netapp HCI Compute NodeNetapp Solidfire & HCI Management NodeNetapp Solidfire & HCI Storage Node+5 | 23/12/2024 | 17/6/2026 | In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible. | |
| Aplazada | Media (6.6) | 0.60% | — | Espressif Esp-idfAI | 12/12/2024 | 17/6/2026 | ESPTouch is a connection protocol for internet of things devices. In the ESPTouchV2 protocol, while there is an option to use a custom AES key, there is no option to set the IV (Initialization Vector) prior to versions 5.3.2, 5.2.4, 5.1.6, and 5.0.8. The IV is set to zero and remains constant throughout the product's… | |
| Analizada | Alta (7.5) | 0.53% | — | Espressif Esp-idf | 7/11/2024 | 17/6/2026 | An issue in Espressif Esp idf v5.3.0 allows attackers to cause a Denial of Service (DoS) via a crafted data channel packet. | |
| Analizada | Media (5.9) | 1.0% | — | Netapp Active IQ Unified ManagerNetapp Solidfire & HCI Management NodeNetapp Solidfire & HCI Storage NodeNetapp Windows Host Utilities+8 | 27/10/2024 | 17/6/2026 | An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser. | |
| Analizada | Alta (8.1) | 0.97% | — | Espressif Esp-idf | 17/10/2024 | 17/6/2026 | Buffer Overflow vulnerability in esp-idf v.5.1 allows a remote attacker to obtain sensitive information via the externalId component. | |
| Modificada | Media (5.5) | 0.50% | — | Linux KernelNetapp Converged Systems Advisor AgentNetapp Solidfire & HCI Management NodeNetapp Solidfire & HCI Storage Node+6 | 30/5/2024 | 4/8/2026 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix nfsd4_encode_fattr4() crasher Ensure that args.acl is initialized early. It is used in an unconditional call to kfree() on the way out of nfsd4_encode_fattr4(). | |
| Analizada | Media (6.5) | 1.1% | — | Espressif Esp-idf | 14/5/2024 | 17/6/2026 | Buffer Overflow vulnerability in esp-idf v.5.1 allows a remote attacker to execute arbitrary code via a crafted script to the Bluetooth stack component. | |
| Modificada | Alta (7.4) | 0.40% | — | GNU GlibcDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+7 | 6/5/2024 | 17/6/2026 | nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present… | |
| Analizada | Alta (8.6) | 0.63% | — | Greenwoodsoftware LessDebian LinuxNetapp Bootstrap OSNetapp HCI Storage Nodes+1 | 13/4/2024 | 17/6/2026 | less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment… | |
| Analizada | Media (5.7) | 0.22% | — | Espressif Esp-idf | 25/3/2024 | 17/6/2026 | ESP-IDF is the development framework for Espressif SoCs supported on Windows, Linux and macOS. A Time-of-Check to Time-of-Use (TOCTOU) vulnerability was discovered in the implementation of the ESP-IDF bootloader which could allow an attacker with physical access to flash of the device to bypass anti-rollback… |