Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
76 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 9.2% | — | Quadlayers Woocommerce Checkout ManagerAI | 19/6/2024 | 17/6/2026 | Missing Authorization vulnerability in QuadLayers WooCommerce Checkout Manager.This issue affects WooCommerce Checkout Manager: from n/a through 7.3.0. | |
| Modificada | Alta (8.8) | 0.32% | — | Birddog A300 FirmwareBirddog Mini FirmwareBirddog 4K Quad FirmwareBirddog Studio R3 Firmware | 22/5/2023 | 17/6/2026 | The affected products have a CSRF vulnerability that could allow an attacker to execute code and upload malicious files. | |
| Modificada | Crítica (9.8) | 0.46% | — | Birddog A300 FirmwareBirddog Mini FirmwareBirddog 4K Quad FirmwareBirddog Studio R3 Firmware | 22/5/2023 | 17/6/2026 | Files present on firmware images could allow an attacker to gain unauthorized access as a root user using hard-coded credentials. | |
| Modificada | Media (4.6) | 0.59% | — | NXP I.mx 6 FirmwareNXP I.mx 6dual FirmwareNXP I.mx 6duallite FirmwareNXP I.mx 6dualplus Firmware+19 | 18/11/2022 | 17/6/2026 | An information-disclosure vulnerability exists on select NXP devices when configured in Serial Download Protocol (SDP) mode: i.MX RT 1010, i.MX RT 1015, i.MX RT 1020, i.MX RT 1050, i.MX RT 1060, i.MX 6 Family, i.MX 7Dual/Solo, i.MX 7ULP, i.MX 8M Quad, i.MX 8M Mini, and Vybrid. In a device security-enabled… | |
| Modificada | Crítica (9.8) | 1.0% | — | Tacitine En6200-prime Quad-35 FirmwareTacitine En6200-prime Quad-100 Firmware | 23/9/2022 | 17/6/2026 | This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to improper session management in the Tacitine Firewall web-based management interface. An unauthenticated remote attacker could exploit this vulnerability by… | |
| Modificada | Alta (7.5) | 1.5% | — | Tacitine En6200-prime Quad-35 FirmwareTacitine En6200-prime Quad-100 Firmware | 23/9/2022 | 17/6/2026 | This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to insecure design in the Tacitine Firewall web-based management interface. An unauthenticated remote attacker could exploit this vulnerability by sending a… | |
| Modificada | Crítica (9.8) | 2.2% | — | Tacitine En6200-prime Quad-35 FirmwareTacitine En6200-prime Quad-100 Firmware | 23/9/2022 | 17/6/2026 | This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to improper control of code generation in the Tacitine Firewall web-based management interface. An unauthenticated remote attacker could exploit this vulnerability… | |
| Modificada | Media (4.8) | 0.62% | — | Quadlayers WP Social Chat | 22/8/2022 | 17/6/2026 | The WP Social Chat WordPress plugin before 6.0.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Alta (7.5) | 1.2% | — | Quadlayers Perfect Brands FOR Woocommerce | 18/2/2022 | 17/6/2026 | The vulnerability discovered in WordPress Perfect Brands for WooCommerce plugin (versions <= 2.0.4) allows server information exposure. | |
| Modificada | Media (4.3) | 0.63% | — | Quadlayers Perfect Brands FOR Woocommerce | 18/2/2022 | 17/6/2026 | The vulnerability allows Subscriber+ level users to create brands in WordPress Perfect Brands for WooCommerce plugin (versions <= 2.0.4). | |
| Modificada | Media (5.5) | 0.21% | — | Nvidia Cloud Gaming GuestNvidia GeforceNvidia GPU Display DriverNvidia NVS+5 | 7/2/2022 | 17/6/2026 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for private IOCTLs where a NULL pointer dereference in the kernel, created within user mode code, may lead to a denial of service in the form of a system crash. | |
| Modificada | Media (6.1) | 0.23% | — | Nvidia GeforceNvidia GPU Display DriverNvidia NVSNvidia Quadro+2 | 7/2/2022 | 17/6/2026 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel driver package, where improper handling of insufficient permissions or privileges may allow an unprivileged local user limited write access to protected memory, which can lead to denial of service. | |
| Modificada | Media (6.1) | 0.23% | — | Nvidia Cloud Gaming GuestNvidia GeforceNvidia GPU Display DriverNvidia NVS+4 | 7/2/2022 | 17/6/2026 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel driver, where improper handling of insufficient permissions or privileges may allow an unprivileged local user limited write access to protected memory, which can lead to denial of service. | |
| Modificada | Media (4.4) | 0.21% | — | Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+131 | 20/11/2021 | 17/6/2026 | NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to gain access to information from unscrubbed memory, which may lead to information disclosure. | |
| Modificada | Media (4.4) | 0.21% | — | Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+131 | 20/11/2021 | 17/6/2026 | NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to gain access to information from unscrubbed registers, which may lead to information disclosure. | |
| Modificada | Media (4.1) | 0.21% | — | Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+131 | 20/11/2021 | 17/6/2026 | NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller, which may allow a user with elevated privileges to access protected information by identifying, exploiting, and loading vulnerable microcode. Such an attack may lead to information disclosure. | |
| Modificada | Alta (7.5) | 0.31% | — | Nvidia Geforce GT 605Nvidia Geforce GT 610Nvidia Geforce GT 620Nvidia Geforce GT 625+59 | 20/11/2021 | 17/6/2026 | NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller, which may allow a user with elevated privileges to instantiate a DMA write operation only within a specific time window timed to corrupt code execution, which may impact confidentiality, integrity, or availability. The scope impact… | |
| Modificada | Alta (7.5) | 0.28% | — | Nvidia Geforce GTX 950Nvidia Geforce GTX 960Nvidia Geforce GTX 970Nvidia Geforce GTX 980+31 | 20/11/2021 | 17/6/2026 | NVIDIA GPU and Tegra hardware contain a vulnerability in an internal microcontroller, which may allow a user with elevated privileges to generate valid microcode by identifying, exploiting, and loading vulnerable microcode. Such an attack could lead to information disclosure, data corruption, or denial of service of… | |
| Modificada | Media (4.4) | 0.20% | — | Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+103 | 20/11/2021 | 17/6/2026 | NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to corrupt program data. | |
| Modificada | Media (4.4) | 0.21% | — | Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+131 | 20/11/2021 | 17/6/2026 | NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to access debug registers during runtime, which may lead to information disclosure. | |
| Modificada | Media (4.4) | 0.21% | — | Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+131 | 20/11/2021 | 17/6/2026 | NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to utilize debug mechanisms with insufficient access control, which may lead to information disclosure. | |
| Modificada | Media (6.7) | 0.46% | — | 2ndquadrant Pglogical | 1/6/2021 | 17/6/2026 | A shell injection flaw was found in pglogical in versions before 2.3.4 and before 3.6.26. An attacker with CREATEDB privileges on a PostgreSQL server can craft a database name that allows execution of shell commands as the postgresql user when calling pglogical.create_subscription(). | |
| Modificada | Alta (8.1) | 1.1% | — | Quadbase Espressdashboard | 15/3/2021 | 17/6/2026 | An issue was discovered in Quadbase EspressReports ES 7 Update 9. An authenticated user is able to navigate to the MenuPage section of the application, and change the frmsrc parameter value to retrieve and execute external files or payloads. | |
| Modificada | Media (4.3) | 0.45% | — | Quadbase Espressdashboard | 15/3/2021 | 17/6/2026 | An issue was discovered in Quadbase ExpressDashboard (EDAB) 7 Update 9. It allows CSRF. An attacker may be able to trick an authenticated user into changing the email address associated with their account. | |
| Modificada | Alta (8.8) | 0.58% | — | Quadbase Espressreports ES | 11/3/2021 | 17/6/2026 | An issue was discovered in Quadbase EspressReports ES 7 Update 9. It allows CSRF, whereby an attacker may be able to trick an authenticated admin level user into uploading malicious files to the web server. |