Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2647▼ 688 respecto a la semana anterior
Críticas / altas1257▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 277 respecto a la semana anterior
1618 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.4) | 0.17% | — | Intel NUC KIT Nuc6cayh FirmwareIntel NUC KIT Nuc6cays FirmwareIntel NUC Mini PC Nuc7i3bnhxf FirmwareIntel NUC Mini PC Nuc7i3bnk Firmware+63 | 11/8/2023 | 17/6/2026 | Improper access control in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable denial of service via local access. | |
| Modificada | Media (6.7) | 0.17% | — | Intel NUC 11 PRO KIT Nuc11tnhi70z FirmwareIntel NUC 11 PRO KIT Nuc11tnki70z FirmwareIntel NUC 11 PRO KIT Nuc11tnki30z FirmwareIntel NUC 11 PRO KIT Nuc11tnhi30z Firmware+20 | 11/8/2023 | 17/6/2026 | Improper input validation in BIOS firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (4.4) | 0.16% | — | Intel NUC 11 PRO KIT Nuc11tnhi70z FirmwareIntel NUC 11 PRO KIT Nuc11tnki70z FirmwareIntel NUC 11 PRO KIT Nuc11tnki30z FirmwareIntel NUC 11 PRO KIT Nuc11tnhi30z Firmware+20 | 11/8/2023 | 17/6/2026 | Improper initialization in BIOS firmware for some Intel(R) NUCs may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Media (6.7) | 0.17% | — | Intel NUC 13 Extreme Compute Element Nuc13sbbi5 FirmwareIntel NUC 13 Extreme Compute Element Nuc13sbbi5f FirmwareIntel NUC 13 Extreme Compute Element Nuc13sbbi7 FirmwareIntel NUC 13 Extreme Compute Element Nuc13sbbi7f Firmware+151 | 11/8/2023 | 17/6/2026 | Improper input validation in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (4.4) | 0.19% | — | Intel NUC 13 Extreme Compute Element Nuc13sbbi7f FirmwareIntel NUC 13 Extreme Compute Element Nuc13sbbi5f FirmwareIntel NUC 13 Extreme Compute Element Nuc13sbbi9f FirmwareIntel NUC 13 Extreme KIT Nuc13rngi7 Firmware+107 | 11/8/2023 | 17/6/2026 | Improper initialization in some Intel(R) NUC 13 Extreme Compute Element, Intel(R) NUC 13 Extreme Kit, Intel(R) NUC 11 Performance Kit, Intel(R) NUC 11 Performance Mini PC, Intel(R) NUC Compute Element, Intel(R) NUC Laptop Kit, Intel(R) NUC Pro Kit, Intel(R) NUC Pro Board and Intel(R) NUC Pro Mini PC BIOS firmware may… | |
| Modificada | Media (4.4) | 0.19% | — | Intel NUC 7 Enthusiast Nuc7i7bnkq FirmwareIntel NUC 7 Enthusiast Nuc7i7bnhxg FirmwareIntel NUC KIT Nuc7i7dnhe FirmwareIntel NUC KIT Nuc7i7dnke Firmware+207 | 11/8/2023 | 17/6/2026 | La inicialización incorrecta en Intel(R) NUC BIOS firmware pueden permitir que un usuario privilegiado habilite potencialmente la divulgación de información a través del acceso local. | |
| Modificada | Media (4.4) | 0.19% | — | Intel NUC 11 Performance KIT Nuc11pahi3 FirmwareIntel NUC 11 Performance KIT Nuc11pahi30z FirmwareIntel NUC 11 Performance KIT Nuc11paki3 FirmwareIntel NUC 11 Performance KIT Nuc11pahi5 Firmware+84 | 11/8/2023 | 17/6/2026 | El uso de recursos no inicializados en algunos firmware de BIOS de Intel(R) NUC puede permitir que un usuario con privilegios permita potencialmente la divulgación de información mediante acceso local. | |
| Modificada | Media (6.7) | 0.16% | — | Intel NUC 8 Compute Element Cm8i3cb4n FirmwareIntel NUC 8 Compute Element Cm8i5cb8n FirmwareIntel NUC 8 Compute Element Cm8i7cb8n FirmwareIntel NUC 8 Compute Element Cm8ccb4r Firmware+30 | 11/8/2023 | 17/6/2026 | Las restricciones de búfer inadecuadas en algunos firmware de BIOS de Intel(R) NUC pueden permitir que un usuario con privilegios habilite potencialmente la escalada de privilegios a través del acceso local. | |
| Modificada | Alta (7.5) | 0.80% | — | Dietpi-dashboard Project Dietpi-dashboard | 27/7/2023 | 17/6/2026 | DietPi-Dashboard is a web dashboard for the operating system DietPi. The dashboard only allows for one TLS handshake to be in process at a given moment. Once a TCP connection is established in HTTPS mode, it will assume that it should be waiting for a handshake, and will stay this way indefinitely until a handshake… | |
| Modificada | Alta (7.5) | 0.60% | — | Intergard Smartgard Silver With Matrix Keyboard | 19/7/2023 | 17/6/2026 | A vulnerability was found in Intergard SGS 8.7.0. It has been declared as problematic. This vulnerability affects unknown code of the component SQL Query Handler. The manipulation leads to cleartext transmission of sensitive information. The attack can be initiated remotely. The complexity of an attack is rather high.… | |
| Modificada | Alta (7.5) | 0.41% | — | Intergard Smartgard Silver With Matrix Keyboard | 19/7/2023 | 17/6/2026 | A vulnerability was found in Intergard SGS 8.7.0. It has been classified as problematic. This affects an unknown part. The manipulation leads to cleartext storage of sensitive information in memory. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Alta (7.5) | 0.49% | — | Intergard Smartgard Silver With Matrix Keyboard | 19/7/2023 | 17/6/2026 | A vulnerability was found in Intergard SGS 8.7.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Password Change Handler. The manipulation leads to cleartext transmission of sensitive information. The attack may be launched remotely. The complexity of an attack is… | |
| Modificada | Media (6.5) | 0.99% | — | Intergard Smartgard Silver With Matrix Keyboard | 19/7/2023 | 17/6/2026 | A vulnerability has been found in Intergard SGS 8.7.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Change Password Handler. The manipulation leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the public and… | |
| Modificada | Crítica (9.8) | 0.89% | — | Intergard Smartgard Silver With Matrix Keyboard | 19/7/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Intergard SGS 8.7.0. Affected is an unknown function. The manipulation leads to permission issues. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is… | |
| Analizada | Alta (8.8) | 0.92% | — | Kanboard | 5/7/2023 | 17/6/2026 | Kanboard is project management software that focuses on the Kanban methodology. In versions prior to 1.2.31authenticated user is able to perform a SQL Injection, leading to a privilege escalation or loss of confidentiality. It appears that in some insert and update operations, the code improperly uses the PicoDB… | |
| Modificada | Crítica (9.8) | 0.54% | — | Smartweb Infotech JOB Board Project Smartweb Infotech JOB Board | 4/7/2023 | 17/6/2026 | A vulnerability was found in SmartWeb Infotech Job Board 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /settings/account of the component My Profile Page. The manipulation of the argument filename leads to unrestricted upload. The attack may be launched remotely. The… | |
| Modificada | Media (4.8) | 0.55% | — | Kanbanwp Kanban Boards FOR Wordpress | 27/6/2023 | 17/6/2026 | The Kanban Boards for WordPress plugin before 2.5.21 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (4.8) | 0.37% | — | Kanbanwp Kanban Boards | 22/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kanban for WordPress Kanban Boards for WordPress plugin <= 2.5.20 versions. | |
| Modificada | Media (4.8) | 0.47% | — | Ultimate Dashboard Project Ultimate Dashboard | 19/6/2023 | 17/6/2026 | The Ultimate Dashboard WordPress plugin before 3.7.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (7.8) | 32% | — | Schneider-electric Igss Dashboard | 14/6/2023 | 17/6/2026 | A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data, potentially leading to remote code execution when an attacker gets the user to open a malicious file. | |
| Modificada | Alta (7.8) | 0.14% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+399 | 13/6/2023 | 17/6/2026 | Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | |
| Modificada | Alta (7.8) | 0.14% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+399 | 13/6/2023 | 17/6/2026 | Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | |
| Modificada | Alta (7.8) | 0.14% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+399 | 13/6/2023 | 17/6/2026 | Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | |
| Modificada | Alta (7.8) | 0.14% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+399 | 13/6/2023 | 17/6/2026 | Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | |
| Modificada | Alta (7.8) | 0.14% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+399 | 13/6/2023 | 17/6/2026 | Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. |