Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2493 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.3) | 0.17% | — | Siemens Solid Edge Se2024 | 12/11/2024 | 17/6/2026 | A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 9). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process. | |
| Analizada | Alta (7.3) | 0.17% | — | Siemens Solid Edge Se2024 | 12/11/2024 | 17/6/2026 | A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 9). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PSM files. This could allow an attacker to execute code in the context of the current process. | |
| Modificada | Media (5.4) | 0.24% | — | Webberzone Knowledge Base | 4/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Knowledge Base knowledgebase allows Stored XSS.This issue affects Knowledge Base: from n/a through <= 2.2.0. | |
| Analizada | Media (5.3) | 0.38% | — | Ovaledge | 25/10/2024 | 17/6/2026 | OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserType. No authentication is required. The information disclosed is associated with the registered user ID, status, email address, role(s), user type, license type, and personal details such as first… | |
| Analizada | Media (6.4) | 0.30% | — | Ovaledge | 25/10/2024 | 17/6/2026 | OvalEdge 5.2.8.0 and earlier is affected by multiple Stored XSS (AKA Persistent or Type II) vulnerabilities via a POST request to /profile/updateProfile via the slackid or phone parameters. Authentication is required. | |
| Analizada | Media (4.3) | 0.30% | — | Ovaledge | 25/10/2024 | 17/6/2026 | OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserList. Authentication is required. The information disclosed is associated with the all registered users, including user ID, status, email address, role(s), user type, license type, and personal details… | |
| Analizada | Alta (8.8) | 0.53% | — | Ovaledge | 25/10/2024 | 17/6/2026 | OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /user/updatePassword via the userId and newPsw parameters. Authentication is required. | |
| Analizada | Alta (8.8) | 0.30% | — | Ovaledge | 25/10/2024 | 17/6/2026 | OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email parameters. Authentication is required. | |
| Analizada | Media (4.7) | 0.38% | — | Ovaledge | 25/10/2024 | 17/6/2026 | OvalEdge 5.2.8.0 and earlier is affected by a Privilege Escalation vulnerability via a POST request to /user/assignuserrole via the userid and role parameters . Authentication is required with OE_ADMIN role privilege. | |
| Analizada | Crítica (9.8) | 0.47% | — | Ovaledge | 25/10/2024 | 17/6/2026 | OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email parameters. Authentication is required. | |
| Analizada | Alta (7.5) | 0.50% | — | Ovaledge | 25/10/2024 | 17/6/2026 | OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserWithTeam. Authentication is required. The information disclosed is associated with all registered user ID numbers. | |
| Aplazada | Media (5.8) | 0.34% | — | SmartupAIMicrosoft EdgeAIMozilla FirefoxAI | 25/10/2024 | 17/6/2026 | smartUp, a web browser mouse gestures extension, has a universal cross-site scripting issue in the Edge and Firefox versions of smartUp 7.2.622.1170. The vulnerability allows another extension to execute arbitrary code in the context of the user’s tab. As of time of publication, no known patches exist. | |
| Analizada | Crítica (9.8) | 2.4% | — | Trendmicro Cloud Edge | 22/10/2024 | 17/6/2026 | An command injection vulnerability in Trend Micro Cloud Edge could allow a remote attacker to execute arbitrary code on affected appliances. Please note: authentication is not required in order to exploit this vulnerability. | |
| Aplazada | Media (6.1) | 0.48% | — | Public Knowledge Project Pkp-libAI | 21/10/2024 | 17/6/2026 | Public Knowledge Project pkp-lib 3.4.0-7 and earlier is vulnerable to Open redirect due to a lack of input sanitization in the logout function. | |
| Analizada | Media (4.3) | 0.48% | — | Microsoft Edge Chromium | 18/10/2024 | 17/6/2026 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | |
| Analizada | Media (5.3) | 0.54% | — | Microsoft Edge Chromium | 18/10/2024 | 17/6/2026 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | |
| Analizada | Alta (8.8) | 1.0% | — | Microsoft Edge Chromium | 17/10/2024 | 17/6/2026 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | |
| Analizada | Alta (8.8) | 1.0% | — | Microsoft Edge Chromium | 17/10/2024 | 17/6/2026 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | |
| Analizada | Alta (8.1) | 0.89% | — | Microsoft Edge Chromium | 17/10/2024 | 17/6/2026 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | |
| Analizada | Media (5.4) | 0.42% | — | Microsoft Edge Chromium | 17/10/2024 | 17/6/2026 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | |
| Analizada | Alta (8.3) | 0.76% | — | Microsoft Edge Chromium | 17/10/2024 | 17/6/2026 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | |
| Analizada | Alta (8.3) | 0.76% | — | Microsoft Edge Chromium | 17/10/2024 | 17/6/2026 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | |
| Analizada | Crítica (9.8) | 1.1% | — | Microsoft Edge Chromium | 17/10/2024 | 17/6/2026 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | |
| Analizada | Alta (8.6) | 11% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 16/10/2024 | 17/6/2026 | BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdown settings. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Aplazada | Media (6.1) | 0.22% | — | Cisco Sd-wan Vedge SoftwareAI | 25/9/2024 | 17/6/2026 | A vulnerability in the UDP packet validation code of Cisco SD-WAN vEdge Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected system. This vulnerability is due to incorrect handling of a specific type of malformed UDP packet. An attacker in a… |