Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 646 respecto a la semana anterior
Críticas / altas1266▼ 292 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
5178 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.79% | — | Gopiplus Image Vertical Reel Scroll Slideshow | 31/10/2023 | 17/6/2026 | The Image vertical reel scroll slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 9.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Modificada | Alta (8.8) | 0.97% | 💥 PoC | Minical | 30/10/2023 | 17/6/2026 | An issue in minCal v.1.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the customer_data parameter. | |
| Modificada | Media (4.8) | 0.32% | — | Gopiplus Image Vertical Reel Scroll Slideshow | 18/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Image vertical reel scroll slideshow plugin <= 9.0 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Wpicalavailability WP Ical Availability | 10/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP iCal Availability plugin <= 1.0.3 versions. | |
| Modificada | Media (5.5) | 0.21% | — | Canonical Subiquity | 7/10/2023 | 17/6/2026 | Sensitive data could be exposed in logs of subiquity version 23.09.1 and earlier. An attacker in the adm group could use this information to find hashed passwords and possibly escalate their privilege. | |
| Analizada | Alta (7.8) | 64% | ⚠ Explotación activa💥 Exploit | Netapp Bootstrap OSSiemens Simatic S7-1500 CPU 1518-4 Pn/dp MFP FirmwareSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Siplus S7-1500 CPU 1518-4 Pn/dp MFP Firmware+35 | 3/10/2023 | 17/6/2026 | A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated… | |
| Modificada | Media (5.3) | 1.7% | — | Canonical Ubuntu LinuxAMD Ryzen 7 4800uIntel Core I7-10510uIntel Core I7-12700k+12 | 27/9/2023 | 17/6/2026 | PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. For example, attackers can sometimes accurately determine text… | |
| Modificada | Media (4.8) | 0.40% | — | Gopiplus Vertical Marquee | 27/9/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Vertical marquee plugin <= 7.1 versions. | |
| Modificada | Alta (7.8) | 0.18% | — | Schneider-electric Interactive Graphical Scada System | 14/9/2023 | 17/6/2026 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update Service that could allow a local attacker to change update source, potentially leading to remote code execution when the attacker force an update containing malicious content. | |
| Modificada | Media (5.4) | 0.51% | — | Designchemical Jquery Accordion Menu Widget | 12/9/2023 | 17/6/2026 | The JQuery Accordion Menu Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dcwp-jquery-accordion' shortcode in versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers… | |
| Analizada | Alta (7.8) | 0.41% | — | Linux KernelDebian LinuxCanonical Ubuntu Linux | 6/9/2023 | 17/6/2026 | A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. When nf_tables_delrule() is flushing table rules, it is not checked whether the chain is bound and the chain's owner rule can also release the objects in certain circumstances. We… | |
| Modificada | Alta (7.8) | 0.33% | — | Canonical AccountsserviceCanonical Ubuntu Linux | 1/9/2023 | 17/6/2026 | In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message to the accounts-daemon process. | |
| Modificada | Crítica (10) | 1.4% | — | Canonical SnapdCanonical Ubuntu Linux | 1/9/2023 | 17/6/2026 | Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it to cause arbitrary commands to be executed outside of the snap sandbox after the snap exits. Graphical terminal emulators like xterm, gnome-terminal and others are not affected -… | |
| Modificada | Media (4.8) | 0.44% | — | Radicalwebdesign Gdpr Cookie Consent Notice BOX | 30/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Radical Web Design GDPR Cookie Consent Notice Box plugin <= 1.1.6 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Pradeepsinghweb Dynamically Register Sidebars | 17/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pradeep Singh Dynamically Register Sidebars plugin <= 1.0.1 versions. | |
| Modificada | Alta (7.8) | 0.55% | — | Linux KernelDebian LinuxCanonical Ubuntu Linux | 14/8/2023 | 17/6/2026 | An issue was discovered in l2cap_sock_release in net/bluetooth/l2cap_sock.c in the Linux kernel before 6.4.10. There is a use-after-free because the children of an sk are mishandled. | |
| Modificada | Media (6.1) | 0.38% | — | I13websolution Wordpress Vertical Image Slider | 8/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution WordPress vertical image slider plugin <= 1.2.16 versions. | |
| Modificada | Media (6.1) | 0.38% | — | I13websolution WP Responsive Tabs Horizontal Vertical AND Accordion Tabs | 8/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution WP Responsive Tabs horizontal vertical and accordion Tabs plugin <= 1.1.15 versions. | |
| Modificada | Alta (7.8) | 9.1% | 💥 Exploit | Canonical Ubuntu Linux | 26/7/2023 | 17/6/2026 | Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks when calling ovl_do_setxattr on Ubuntu kernels | |
| Modificada | Alta (7.8) | 15% | 💥 Exploit | Canonical Ubuntu Linux | 26/7/2023 | 17/6/2026 | On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlayfs.* xattrs", an unprivileged user may set privileged extended attributes on the mounted files, leading them to be set on the upper files without the appropriate security checks. | |
| Modificada | Alta (7.1) | 0.42% | — | Linux KernelRedhat Enterprise LinuxCanonical Ubuntu Linux | 24/7/2023 | 17/6/2026 | A use-after-free flaw was found in vcs_read in drivers/tty/vt/vc_screen.c in vc_screen in the Linux Kernel. This issue may allow an attacker with local user access to cause a system crash or leak internal kernel information. | |
| Modificada | Alta (7.5) | 1.1% | — | Mechanicalsoup Project Mechanicalsoup | 5/7/2023 | 17/6/2026 | MechanicalSoup is a Python library for automating interaction with websites. Starting in version 0.2.0 and prior to version 1.3.0, a malicious web server can read arbitrary files on the client using a `<input type="file" ...>` inside HTML form. All users of MechanicalSoup's form submission are affected, unless they… | |
| Modificada | Alta (7.8) | 1.9% | — | Linux KernelFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux | 5/7/2023 | 17/6/2026 | Linux Kernel nftables Use-After-Free Local Privilege Escalation Vulnerability; `nft_chain_lookup_byid()` failed to check whether a chain was active and CAP_NET_ADMIN is in any user or network namespace | |
| Modificada | Alta (7.8) | 0.67% | — | Linux KernelCanonical Ubuntu LinuxDebian Linux | 28/6/2023 | 17/6/2026 | A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation. Racing a io_uring cancel poll request with a linked timeout can cause a UAF in a hrtimer. We recommend upgrading past commit ef7dfac51d8ed961b742218f526bd589f3900a59… | |
| Modificada | Alta (7.8) | 0.24% | — | Autodesk AliasAutodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad Architecture+13 | 27/6/2023 | 17/6/2026 | A maliciously crafted file consumed through pskernel.dll file could lead to memory corruption vulnerabilities. These vulnerabilities in conjunction with other vulnerabilities could lead to code execution in the context of the current process. |