Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1459 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.42%—Amministrazione Trasparente Project Amministrazione Trasparente25/10/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marco Milesi Amministrazione Trasparente plugin <= 8.0.2 versions.
ModificadaMedia (5.3)0.54%—Miniorange Google Authenticator20/10/202317/6/2026
The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when changing plugin settings in versions up to, and including, 5.6.5. This makes it possible for unauthenticated attackers to change the plugin's settings.
ModificadaAlta (7.5)26%💥 ExploitMiniorange Active Directory Integration / Ldap Integration16/10/202317/6/2026
The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfortunately, this log file is never removed, and remains accessible to any users knowing the URL to do so.
ModificadaCrítica (9.8)3.2%—ZlibSmihica Pyminizip14/10/202314/7/2026
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version,…
ModificadaAlta (7.8)0.16%—Dell EMC Openmanage Server Administrator13/10/202317/6/2026
Dell OpenManage Server Administrator, versions 11.0.0.0 and prior, contains an Improper Access Control vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to execute arbitrary code in order to elevate privileges on the system. Exploitation may lead to a complete system…
ModificadaCrítica (9.1)0.87%—Capgemini Picotcp10/10/202317/6/2026
In PicoTCP 1.7.0, TCP ISNs are improperly random.
ModificadaAlta (7.5)0.78%—Tapo Mini Smart Wi-fi Plug FirmwareNanoleaf Lightstrip FirmwareGovee LED Strip FirmwareSwitchbot Hub2 Firmware+510/10/202317/6/2026
Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote attacker to cause a denial of service via a…
ModificadaAlta (8.8)0.25%—Dipakgajjar WP Super Minify6/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Dipak C. Gajjar WP Super Minify plugin <= 1.5.1 versions.
ModificadaCrítica (9.8)0.63%—Turnatasarim Advertising Administration Panel6/10/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Turna Advertising Administration Panel allows SQL Injection. This issue affects Advertising Administration Panel: before 1.1.
AnalizadaAlta (7.8)64%⚠ Explotación activa💥 ExploitNetapp Bootstrap OSSiemens Simatic S7-1500 CPU 1518-4 Pn/dp MFP FirmwareSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Siplus S7-1500 CPU 1518-4 Pn/dp MFP Firmware+353/10/202317/6/2026
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated…
ModificadaMedia (5.5)0.18%—Hitachi OPS Center Administrator3/10/202317/6/2026
Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Administrator on Linux allows local users to gain sensitive information.This issue affects Hitachi Ops Center Administrator: before 10.9.3-00.
ModificadaMedia (4.8)0.39%—Wpadminify WP Adminify2/10/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Jewel Theme WP Adminify plugin <= 3.1.6 versions.
ModificadaMedia (6.5)0.91%—Miniorange Active Directory Integration / Ldap Integration27/9/202317/6/2026
The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 4.1.10. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers, with administrative access and above, to change the…
ModificadaMedia (4.9)0.91%—Miniorange Staff / Employee Business Directory FOR Active Directory27/9/202317/6/2026
The Staff / Employee Business Directory for Active Directory plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 1.2.3. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers, with administrative access and above, to…
ModificadaMedia (5.3)1.7%—Canonical Ubuntu LinuxAMD Ryzen 7 4800uIntel Core I7-10510uIntel Core I7-12700k+1227/9/202317/6/2026
PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. For example, attackers can sometimes accurately determine text…
ModificadaCrítica (9.8)0.67%—MRV Logging Administration Panel27/9/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MRV Tech Logging Administration Panel allows SQL Injection. This issue affects Logging Administration Panel: before 20230915 .
ModificadaAlta (7.2)1.6%—Miniorange Prevent Files / Folders Access25/9/202317/6/2026
The Prevent files / folders access WordPress plugin before 2.5.2 does not validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server.
ModificadaAlta (8.1)0.77%—Minitool Power Data Recovery19/9/202317/6/2026
MiniTool Power Data Recovery 11.6 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.
ModificadaAlta (8.1)0.77%—Minitool Movie Maker19/9/202317/6/2026
MiniTool Movie Maker 7.0 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.
ModificadaAlta (8.1)0.77%—Minitool Shadowmaker19/9/202317/6/2026
MiniTool Shadow Maker version 4.1 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.
ModificadaMedia (5.9)0.44%—Minitool Power Data Recovery19/9/202317/6/2026
MiniTool Power Data Recovery version 11.6 and before contains an insecure in-app payment system that allows attackers to steal highly sensitive information through a man in the middle attack.
ModificadaAlta (8.1)0.77%—Minitool Partition Wizard19/9/202317/6/2026
MiniTool Partition Wizard 12.8 contains an insecure update mechanism that allows attackers to achieve remote code execution through a man in the middle attack.
ModificadaAlta (8.1)0.77%—Minitool Partition Wizard19/9/202317/6/2026
MiniTool Partition Wizard 12.8 contains an insecure installation mechanism that allows attackers to achieve remote code execution through a man in the middle attack.
ModificadaMedia (4.8)0.47%—Wpadminify WP Adminify11/9/202317/6/2026
The WP Adminify WordPress plugin before 3.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaMedia (5.9)0.59%—Apache Nifi Minifi C++3/9/202317/6/2026
Incorrect certificate validation in InvokeHTTP on Apache NiFi MiNiFi C++ versions 0.13 to 0.14 allows an intermediary to present a forged certificate during TLS handshake negotation. The Disable Peer Verification property of InvokeHTTP was effectively flipped, disabling verification by default, when using HTTPS.…
Orbitaley — Vulnerabilidades