Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2647▼ 688 respecto a la semana anterior
Críticas / altas1257▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 277 respecto a la semana anterior
–

5178 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.23%—Mlit National Land Numerical Information Data Conversion Tool11/4/202317/6/2026
National land numerical information data conversion tool all versions improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the PC may be accessed by an attacker.
ModificadaMedia (5.5)0.20%—Canonical Ubuntu LinuxDebian Linux7/4/202317/6/2026
It was discovered that aufs improperly managed inode reference counts in the vfsub_dentry_open() method. A local attacker could use this vulnerability to cause a denial of service attack.
ModificadaMedia (4.8)0.39%—Wpdevart Responsive Vertical Icon Menu4/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in wpdevart Responsive Vertical Icon Menu plugin <= 1.5.8 versions.
ModificadaAlta (7.8)1.9%💥 PoCLinux KernelCanonical Ubuntu LinuxFedoraproject FedoraRedhat Enterprise Linux+927/3/202317/6/2026
A buffer overflow vulnerability was found in the Netfilter subsystem in the Linux Kernel. This issue could allow the leakage of both stack and heap addresses, and potentially allow Local Privilege Escalation to the root user via arbitrary code execution.
ModificadaAlta (7.1)17%—Redhat Enterprise LinuxLinux KernelNetapp H500s FirmwareNetapp H700s Firmware+527/3/202317/9/2026
A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than the size of the buffer, defined as WL_EXTRA_BUF_MAX, leading to a denial of service.
AnalizadaAlta (7.8)7.9%⚠ Explotación activa💥 ExploitDebian LinuxNetapp H300s FirmwareNetapp H500s FirmwareNetapp H700s Firmware+422/3/202317/6/2026
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on…
ModificadaCrítica (9.8)0.49%—Medical Certificate Generator APP Project Medical Certificate Generator APP22/3/202317/6/2026
A vulnerability was found in SourceCodester Medical Certificate Generator App 1.0. It has been declared as critical. This vulnerability affects unknown code of the file action.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the…
ModificadaCrítica (9.8)0.74%—Electronic Medical Records System Project Electronic Medical Records System2/3/202317/6/2026
A vulnerability was found in SourceCodester Electronic Medical Records System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file administrator.php of the component Cookie Handler. The manipulation of the argument userid leads to sql injection. The attack can…
ModificadaMedia (5.4)0.23%—Wpdevart Responsive Vertical Icon Menu28/2/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in wpdevart Responsive Vertical Icon Menu plugin <= 1.5.8 can lead to theme deletion.
ModificadaCrítica (9.8)0.60%—Domoticalabs Ikon Server27/2/202317/6/2026
Se descubrió que Domotica Labs srl Ikon Server anterior a v2.8.6 contiene una vulnerabilidad de inyección SQL.
ModificadaMedia (5.4)0.26%—Medical Certificate Generator APP Project Medical Certificate Generator APP24/2/202317/6/2026
A vulnerability was found in SourceCodester Medical Certificate Generator App 1.0. It has been classified as problematic. This affects an unknown part of the component New Record Handler. The manipulation of the argument Firstname/Middlename/Lastname/Suffix/Nationality/Doctor Fullname/Doctor Suffix with the input…
ModificadaAlta (7.4)0.68%—Fujitsu Tsclinical Define.xml GeneratorFujitsu Tsclinical Metadata Desktop Tools15/2/202317/6/2026
Existe una restricción inadecuada de la vulnerabilidad de referencia de entidad externa XML (XXE) en tsClinical Define.xml Generator todas las versiones (v1.0.0 a v1.4.0) y tsClinical Metadata Desktop Tools versión 1.0.3 a versión 1.1.0. Si se aprovecha esta vulnerabilidad, un atacante puede obtener un archivo…
ModificadaCrítica (9.8)0.52%—Medical Certificate Generator APP Project Medical Certificate Generator APP10/2/202317/6/2026
Se ha encontrado una vulnerabilidad en SourceCodester Medical Certificate Generator App 1.0 y se ha clasificado como crítica. Esta vulnerabilidad afecta a un código desconocido del archivo action.php. La manipulación del argumento apellido conduce a la inyección SQL. El ataque se puede iniciar de forma remota. El…
ModificadaMedia (5.4)0.50%—Logicaldoc7/2/202317/6/2026
LogicalDOC Enterprise and Community Edition (CE) are vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition in the document version comments.
ModificadaMedia (5.4)0.50%—Logicaldoc7/2/202317/6/2026
LogicalDOC Enterprise and Community Edition (CE) are vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition in the document file name.
ModificadaMedia (5.4)0.50%—Logicaldoc7/2/202317/6/2026
LogicalDOC Enterprise is vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition in the in-app chat system.
ModificadaMedia (5.4)0.48%—Logicaldoc7/2/202317/6/2026
LogicalDOC Enterprise and Community Edition (CE) are vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition in the in-app messaging system (both subject and message bodies).
ModificadaCrítica (9.8)0.31%—Medical Certificate Generator APP Project Medical Certificate Generator APP7/2/202317/6/2026
A vulnerability was found in SourceCodester Medical Certificate Generator App 1.0. It has been rated as critical. Affected by this issue is the function delete_record of the file function.php. The manipulation of the argument id leads to sql injection. VDB-220346 is the identifier assigned to this vulnerability.
ModificadaAlta (8.8)0.31%—Medical Certificate Generator APP Project Medical Certificate Generator APP7/2/202317/6/2026
Se ha encontrado una vulnerabilidad en SourceCodester Medical Certificate Generator App 1.0 y se ha clasificado como crítica. Una función desconocida del archivo enable_record.php es afectada por esta vulnerabilidad. La manipulación del argumento id conduce a la inyección de SQL. El ataque puede lanzarse de forma…
ModificadaCrítica (9.8)2.1%—Schneider-electric Interactive Graphical Scada System1/2/202317/6/2026
A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to denial of service and potentially remote code execution when an attacker sends multiple specially crafted messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to…
ModificadaCrítica (9.8)1.2%—Schneider-electric Interactive Graphical Scada System1/2/202317/6/2026
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially leading to remote code execution when an attacker sends a specially crafted message. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22073)
ModificadaCrítica (9.8)1.3%—Schneider-electric Interactive Graphical Scada System30/1/202317/6/2026
Existe una vulnerabilidad CWE-120: copia del búfer sin comprobar el tamaño de la entrada que podría provocar un desbordamiento de búfer en la región stack de la memoria, lo que podría provocar la ejecución remota de código cuando un atacante envía mensajes de solicitud de datos de registro especialmente manipulados.…
ModificadaCrítica (9.1)0.47%—Schneider-electric Interactive Graphical Scada System30/1/202317/6/2026
Existe una vulnerabilidad CWE-306: Autenticación faltante para funciones críticas que podría causar acceso para manipular y leer archivos específicos en el directorio de informes del proyecto IGSS, lo que podría conducir a una condición de denegación de servicio cuando un atacante envía mensajes específicos. Productos…
ModificadaCrítica (9.8)1.3%—Schneider-electric Interactive Graphical Scada System30/1/202317/6/2026
Existe una vulnerabilidad CWE-120: copia del búfer sin comprobar el tamaño de la entrada que podría causar un desbordamiento de búfer en la región stack de la memoria, lo que podría conducir a la ejecución remota de código cuando un atacante envía mensajes de datos de caché de alarma especialmente manipulados.…
ModificadaCrítica (9.8)1.3%—Schneider-electric Interactive Graphical Scada System30/1/202317/6/2026
Existe una vulnerabilidad CWE-120: copia del búfer sin comprobar el tamaño de la entrada que podría provocar un desbordamiento de búfer en la región stack de la memoria, lo que podría provocar la ejecución remota de código cuando un atacante envía mensajes de valores de configuración especialmente manipulados.…