Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1459 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.5%—Vmware ToolsVmware Open VM ToolsFedoraproject FedoraDebian Linux+131/8/202317/6/2026
A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest…
ModificadaMedia (5.5)0.64%—GNU BinutilsNetapp Ontap Select Deploy Administration UtilityFedoraproject Fedora22/8/202317/6/2026
GNU Binutils before 2.40 was discovered to contain a memory leak vulnerability var the function find_abstract_instance in dwarf2.c.
ModificadaMedia (5.5)0.61%—GNU BinutilsFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility22/8/202317/6/2026
GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function bfd_dwarf2_find_nearest_line_with_alt at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack.
ModificadaCrítica (9.8)0.61%—Mini-tmall21/8/202317/6/2026
A vulnerability, which was classified as critical, has been found in Mini-Tmall up to 20230811. Affected by this issue is some unknown functionality of the file product/1/1?test=1&test2=2&. The manipulation of the argument orderBy leads to sql injection. The attack may be launched remotely. The exploit has been…
ModificadaAlta (7.5)0.89%—Kidus Minimati18/8/202317/6/2026
SQL injection vulnerability in Kidus Minimati v.1.0.0 allows a remote attacker to obtain sensitive information via theID parameter in the fulldelete.php component.
ModificadaAlta (7.5)0.90%—Kiduswb Minimati17/8/20239/7/2026
SQL injection vulnerability in Kidus Minimati v.1.0.0 allows a remote attacker to obtain sensitive information via the edit.php component.
ModificadaMedia (5.4)0.28%—Minapper Rest API TO Miniprogram16/8/202317/6/2026
The REST API TO MiniProgram WordPress plugin through 4.6.1 does not have authorisation and CSRF checks in an AJAX action, allowing ay authenticated users, such as subscriber to call and delete arbitrary attachments
ModificadaMedia (6.1)0.35%—Genesys Administrator Extension13/8/202317/6/2026
Genesys Administrator Extension (GAX) before 9.0.105.15 is vulnerable to Cross Site Scripting (XSS) via the Business Structure page of the iWD plugin, aka GAX-11261.
ModificadaMedia (5.5)0.32%—Miniupnp Project Ngiflib11/8/202317/6/2026
An issue was discovered in GetByte function in miniupnp ngiflib version 0.4, allows local attackers to cause a denial of service (DoS) via crafted .gif file (infinite loop).
ModificadaAlta (7.8)0.10%—Intel NUC Rugged KIT Nuc8cchb FirmwareIntel NUC Rugged KIT Nuc8cchbn FirmwareIntel NUC Rugged KIT Nuc8cchkrn FirmwareIntel NUC Rugged KIT Nuc8cchkr Firmware+6711/8/202317/6/2026
Race condition in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.4)0.11%—Intel NUC Performance KIT AND Mini PC Nuc10i3fnh FirmwareIntel NUC Performance KIT AND Mini PC Nuc10i3fnhf FirmwareIntel NUC Performance KIT AND Mini PC Nuc10i3fnhfa FirmwareIntel NUC Performance KIT AND Mini PC Nuc10i3fnhja Firmware+17011/8/202317/6/2026
Race condition in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.19%—Intel NUC Rugged KIT Nuc8cchb FirmwareIntel NUC Rugged KIT Nuc8cchbn FirmwareIntel NUC Rugged KIT Nuc8cchkrn FirmwareIntel NUC Rugged KIT Nuc8cchkr Firmware+6711/8/202317/6/2026
Improper input validation in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (4.4)0.17%—Intel NUC KIT Nuc6cayh FirmwareIntel NUC KIT Nuc6cays FirmwareIntel NUC Mini PC Nuc7i3bnhxf FirmwareIntel NUC Mini PC Nuc7i3bnk Firmware+6311/8/202317/6/2026
Improper access control in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable denial of service via local access.
ModificadaMedia (4.4)0.16%—Intel NUC 11 Performance KIT Nuc11pahi70z FirmwareIntel NUC 11 Performance KIT Nuc11pahi50z FirmwareIntel NUC 11 Performance KIT Nuc11pahi30z FirmwareIntel NUC 11 Performance KIT Nuc11pahi3 Firmware+711/8/202317/6/2026
Exposure of sensitive information to an unauthorized actor in BIOS firmware for some Intel(R) NUCs may allow a privilege user to potentially enable information disclosure via local access.
ModificadaMedia (6.7)0.17%—Intel NUC 13 Extreme Compute Element Nuc13sbbi5 FirmwareIntel NUC 13 Extreme Compute Element Nuc13sbbi5f FirmwareIntel NUC 13 Extreme Compute Element Nuc13sbbi7 FirmwareIntel NUC 13 Extreme Compute Element Nuc13sbbi7f Firmware+15111/8/202317/6/2026
Improper input validation in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (4.4)0.19%—Intel NUC 13 Extreme Compute Element Nuc13sbbi7f FirmwareIntel NUC 13 Extreme Compute Element Nuc13sbbi5f FirmwareIntel NUC 13 Extreme Compute Element Nuc13sbbi9f FirmwareIntel NUC 13 Extreme KIT Nuc13rngi7 Firmware+10711/8/202317/6/2026
Improper initialization in some Intel(R) NUC 13 Extreme Compute Element, Intel(R) NUC 13 Extreme Kit, Intel(R) NUC 11 Performance Kit, Intel(R) NUC 11 Performance Mini PC, Intel(R) NUC Compute Element, Intel(R) NUC Laptop Kit, Intel(R) NUC Pro Kit, Intel(R) NUC Pro Board and Intel(R) NUC Pro Mini PC BIOS firmware may…
ModificadaMedia (4.4)0.19%—Intel NUC 7 Enthusiast Nuc7i7bnkq FirmwareIntel NUC 7 Enthusiast Nuc7i7bnhxg FirmwareIntel NUC KIT Nuc7i7dnhe FirmwareIntel NUC KIT Nuc7i7dnke Firmware+20711/8/202317/6/2026
Improper initialization in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable information disclosure via local access.
ModificadaMedia (4.4)0.19%—Intel NUC 11 Performance KIT Nuc11pahi3 FirmwareIntel NUC 11 Performance KIT Nuc11pahi30z FirmwareIntel NUC 11 Performance KIT Nuc11paki3 FirmwareIntel NUC 11 Performance KIT Nuc11pahi5 Firmware+8411/8/202317/6/2026
Use of uninitialized resource in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable information disclosure via local access.
ModificadaMedia (6.7)0.18%—Intel NUC 10 Performance KIT Nuc10i7fnhn FirmwareIntel NUC 10 Performance KIT Nuc10i5fnkn FirmwareIntel NUC 10 Performance KIT Nuc10i5fnhn FirmwareIntel NUC 10 Performance KIT Nuc10i7fnkn Firmware+2211/8/202317/6/2026
Improper input validation in BIOS firmware for some Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaCrítica (9.8)0.63%—Farmakom Remote Administration Console8/8/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Farmakom Remote Administration Console allows SQL Injection. This issue affects Remote Administration Console: before 1.02.
ModificadaMedia (5.5)0.27%—Miniupnp Project Ngiflib2/8/202317/6/2026
ngiflib commit 84a75 was discovered to contain a segmentation violation via the function SDL_LoadAnimatedGif at ngiflibSDL.c. This vulnerability is triggered when running the program SDLaffgif.
ModificadaMedia (5.5)0.27%—Miniupnp Project Ngiflib2/8/202317/6/2026
ngiflib commit fb271 was discovered to contain a segmentation violation via the function "main" at gif2tag.c. This vulnerability is triggered when running the program gif2tga.
ModificadaCrítica (9.8)3.5%💥 ExploitWifi-soft Unibox Administration31/7/202317/6/2026
Wifi Soft Unibox Administration 3.0 and 3.1 is vulnerable to SQL Injection. The vulnerability occurs because of not validating or sanitizing the user input in the username field of the login page.
ModificadaMedia (6.5)0.55%—Anasystem Sensmini M4 Firmware30/7/202317/6/2026
AnaSystem SensMini M4 – Using the configuration tool, an authenticated user can cause Denial of Service for the device
AnalizadaCrítica (9.8)0.57%—CertifiFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Management Services FOR Element Software+425/7/202317/6/2026
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of…