Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

2493 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)1.0%—Microsoft Edge Chromium19/9/202410/8/2026
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
AnalizadaAlta (8.8)0.76%—Microsoft Edge Chromium19/9/202410/8/2026
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
AnalizadaMedia (4.3)0.49%—Microsoft Edge Chromium19/9/202410/8/2026
Microsoft Edge (Chromium-based) Spoofing Vulnerability
AnalizadaAlta (7.7)1.3%—Rockwellautomation 2800c Optixpanel Compact FirmwareRockwellautomation 2800s Optixpanel Standard FirmwareRockwellautomation Embedded Edge Compute Module Firmware12/9/202417/6/2026
A privilege escalation vulnerability exists in the Rockwell Automation affected products. The vulnerability occurs due to improper default file permissions allowing users to exfiltrate credentials and escalate privileges.
AnalizadaMedia (6.5)1.2%—Microsoft Edge12/9/202410/8/2026
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
AplazadaCrítica (10)0.76%—Siemens Industrial Edge Management PROAISiemens Industrial Edge Management VirtualAI10/9/202417/6/2026
A vulnerability has been identified in Industrial Edge Management Pro (All versions < V1.9.5), Industrial Edge Management Virtual (All versions < V2.3.1-1). Affected components do not properly validate the device tokens. This could allow an unauthenticated remote attacker to impersonate other devices onboarded to the…
AnalizadaMedia (6.1)0.29%—Progress Openedge3/9/202417/6/2026
An ActiveMQ Discovery service was reachable by default from an OpenEdge Management installation when an OEE/OEM auto-discovery feature was activated. Unauthorized access to the discovery service's UDP port allowed content injection into parts of the OEM web interface making it possible for other types of attack that…
AnalizadaMedia (4.8)0.16%—Progress Openedge3/9/202417/6/2026
Host name validation for TLS certificates is bypassed when the installed OpenEdge default certificates are used to perform the TLS handshake for a networked connection. This has been corrected so that default certificates are no longer capable of overriding host name validation and will need to be replaced where full…
AnalizadaCrítica (9.6)0.59%—Progress Openedge3/9/202417/6/2026
Local ABL Client bypass of the required PASOE security checks may allow an attacker to commit unauthorized code injection into Multi-Session Agents on supported OpenEdge LTS platforms up to OpenEdge LTS 11.7.18 and LTS 12.2.13 on all supported release platforms
AnalizadaMedia (6.5)0.55%—Hedgedoc2/9/202417/6/2026
HedgeDoc is an open source, real-time, collaborative, markdown notes application. When using HedgeDoc 1 with MySQL or MariaDB, it is possible to create notes with an alias matching the ID of existing notes. The affected existing note can then not be accessed anymore and is effectively hidden by the new one. When the…
AnalizadaMedia (6.5)0.15%—Dell EMC XC Core Xcxr2 FirmwareDell EMC XC Core Xc940 System FirmwareDell EMC XC Core Xc740xd2 FirmwareDell EMC XC Core Xc740xd System Firmware+2729/8/202417/6/2026
Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Access of Memory Location After End of Buffer vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
AnalizadaMedia (6)0.14%—Dell EMC XC Core Xcxr2 FirmwareDell EMC XC Core Xc940 System FirmwareDell EMC XC Core Xc740xd2 FirmwareDell EMC XC Core Xc740xd System Firmware+2729/8/202417/6/2026
Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Improper Input Validation vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
AnalizadaAlta (7.8)0.48%—Adobe Acrobat ReaderMicrosoft Edge26/8/202417/6/2026
Acrobat Reader versions 127.0.2651.105 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
ModificadaMedia (5.3)0.59%💥 PoCHyperledger Fabric25/8/202417/6/2026
Hyperledger Fabric through 3.0.0 and 2.5.x through 2.5.9 do not verify that a request has a timestamp within the expected time window.
ModificadaMedia (6.3)0.40%—Microsoft Edge Chromium23/8/202417/6/2026
Microsoft Edge (HTML-based) Memory Corruption Vulnerability
ModificadaAlta (7.8)0.65%—Microsoft Edge Chromium22/8/202417/6/2026
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
ModificadaAlta (7.8)0.65%—Microsoft Edge Chromium22/8/202417/6/2026
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
ModificadaMedia (6.1)0.41%—Microsoft Edge22/8/202417/6/2026
Microsoft Edge for Android Spoofing Vulnerability
AnalizadaCrítica (9.6)21%⚠ Explotación activa💥 PoCGoogle ChromeMicrosoft Edge21/8/202417/6/2026
Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
AnalizadaAlta (8.8)19%⚠ Explotación activa💥 PoCGoogle ChromeMicrosoft Edge Chromium21/8/202417/6/2026
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
AnalizadaAlta (8.8)0.89%—Lfedge Ekuiper20/8/202417/6/2026
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. A user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. This vulnerability is fixed in 1.14.2.
AnalizadaMedia (6.9)0.44%—Public Knowledge Project Open Journal Systems17/8/202417/6/2026
A vulnerability was found in pkp ojs up to 3.4.0-6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login/signOut. The manipulation of the argument source with the input .example.com leads to open redirect. The attack may be launched remotely. The exploit has been…
AnalizadaAlta (8.3)0.40%—Microsoft Edge Chromium16/8/202417/6/2026
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
AnalizadaAlta (8.7)0.48%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1714/8/202417/6/2026
In BIG-IP tenants running on r2000 and r4000 series hardware, or BIG-IP Virtual Edition (VEs) using Intel E810 SR-IOV NIC, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaMedia (5.3)0.30%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1714/8/202417/6/2026
Undisclosed requests to BIG-IP iControl REST can lead to information leak of user account names. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.