Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

2493 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.3)0.17%—Siemens Solid Edge Se202412/11/202417/6/2026
A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 9). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.
AnalizadaAlta (7.3)0.17%—Siemens Solid Edge Se202412/11/202417/6/2026
A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 9). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PSM files. This could allow an attacker to execute code in the context of the current process.
ModificadaMedia (5.4)0.24%—Webberzone Knowledge Base4/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Knowledge Base knowledgebase allows Stored XSS.This issue affects Knowledge Base: from n/a through <= 2.2.0.
AnalizadaMedia (5.3)0.38%—Ovaledge25/10/202417/6/2026
OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserType. No authentication is required. The information disclosed is associated with the registered user ID, status, email address, role(s), user type, license type, and personal details such as first…
AnalizadaMedia (6.4)0.30%—Ovaledge25/10/202417/6/2026
OvalEdge 5.2.8.0 and earlier is affected by multiple Stored XSS (AKA Persistent or Type II) vulnerabilities via a POST request to /profile/updateProfile via the slackid or phone parameters. Authentication is required.
AnalizadaMedia (4.3)0.30%—Ovaledge25/10/202417/6/2026
OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserList. Authentication is required. The information disclosed is associated with the all registered users, including user ID, status, email address, role(s), user type, license type, and personal details…
AnalizadaAlta (8.8)0.53%—Ovaledge25/10/202417/6/2026
OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /user/updatePassword via the userId and newPsw parameters. Authentication is required.
AnalizadaAlta (8.8)0.30%—Ovaledge25/10/202417/6/2026
OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email parameters. Authentication is required.
AnalizadaMedia (4.7)0.38%—Ovaledge25/10/202417/6/2026
OvalEdge 5.2.8.0 and earlier is affected by a Privilege Escalation vulnerability via a POST request to /user/assignuserrole via the userid and role parameters . Authentication is required with OE_ADMIN role privilege.
AnalizadaCrítica (9.8)0.47%—Ovaledge25/10/202417/6/2026
OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email parameters. Authentication is required.
AnalizadaAlta (7.5)0.50%—Ovaledge25/10/202417/6/2026
OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserWithTeam. Authentication is required. The information disclosed is associated with all registered user ID numbers.
AplazadaMedia (5.8)0.34%—SmartupAIMicrosoft EdgeAIMozilla FirefoxAI25/10/202417/6/2026
smartUp, a web browser mouse gestures extension, has a universal cross-site scripting issue in the Edge and Firefox versions of smartUp 7.2.622.1170. The vulnerability allows another extension to execute arbitrary code in the context of the user’s tab. As of time of publication, no known patches exist.
AnalizadaCrítica (9.8)2.4%—Trendmicro Cloud Edge22/10/202417/6/2026
An command injection vulnerability in Trend Micro Cloud Edge could allow a remote attacker to execute arbitrary code on affected appliances. Please note: authentication is not required in order to exploit this vulnerability.
AplazadaMedia (6.1)0.48%—Public Knowledge Project Pkp-libAI21/10/202417/6/2026
Public Knowledge Project pkp-lib 3.4.0-7 and earlier is vulnerable to Open redirect due to a lack of input sanitization in the logout function.
AnalizadaMedia (4.3)0.48%—Microsoft Edge Chromium18/10/202417/6/2026
Microsoft Edge (Chromium-based) Spoofing Vulnerability
AnalizadaMedia (5.3)0.54%—Microsoft Edge Chromium18/10/202417/6/2026
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
AnalizadaAlta (8.8)1.0%—Microsoft Edge Chromium17/10/202417/6/2026
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
AnalizadaAlta (8.8)1.0%—Microsoft Edge Chromium17/10/202417/6/2026
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
AnalizadaAlta (8.1)0.89%—Microsoft Edge Chromium17/10/202417/6/2026
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
AnalizadaMedia (5.4)0.42%—Microsoft Edge Chromium17/10/202417/6/2026
Microsoft Edge (Chromium-based) Spoofing Vulnerability
AnalizadaAlta (8.3)0.76%—Microsoft Edge Chromium17/10/202417/6/2026
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
AnalizadaAlta (8.3)0.76%—Microsoft Edge Chromium17/10/202417/6/2026
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
AnalizadaCrítica (9.8)1.1%—Microsoft Edge Chromium17/10/202417/6/2026
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
AnalizadaAlta (8.6)11%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1716/10/202417/6/2026
BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdown settings. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AplazadaMedia (6.1)0.22%—Cisco Sd-wan Vedge SoftwareAI25/9/202417/6/2026
A vulnerability in the UDP packet validation code of Cisco SD-WAN vEdge Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected system. This vulnerability is due to incorrect handling of a specific type of malformed UDP packet. An attacker in a…