Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1720 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.9) | 0.79% | — | H3C Magic R200 Firmware | 21/4/2023 | 17/6/2026 | H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the DeltriggerList interface at /goform/aspForm. | |
| Modificada | Media (4.9) | 0.79% | — | H3C Magic R200 Firmware | 21/4/2023 | 17/6/2026 | H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the SetAPWifiorLedInfoById interface at /goform/aspForm. | |
| Modificada | Media (4.9) | 0.79% | — | H3C Magic R200 Firmware | 21/4/2023 | 17/6/2026 | H3C Magic R200 R200V100R004 was discovered to contain a stack overflow via the DelvsList interface at /goform/aspForm. | |
| Modificada | Media (4.9) | 0.79% | — | H3C Magic R200 Firmware | 21/4/2023 | 17/6/2026 | H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the AddMacList interface at /goform/aspForm. | |
| Modificada | Media (4.9) | 0.79% | — | H3C Magic R200 Firmware | 21/4/2023 | 17/6/2026 | H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the UpdateMacClone interface at /goform/aspForm. | |
| Modificada | Media (4.9) | 0.79% | — | H3C Magic R200 Firmware | 21/4/2023 | 17/6/2026 | H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the AddWlanMacList interface at /goform/aspForm. | |
| Modificada | Media (4.9) | 0.79% | — | H3C Magic R200 Firmware | 21/4/2023 | 17/6/2026 | H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the SetMobileAPInfoById interface at /goform/aspForm. | |
| Modificada | Media (4.9) | 0.79% | — | H3C Magic R200 Firmware | 21/4/2023 | 17/6/2026 | H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the Edit_BasicSSID_5G interface at /goform/aspForm. | |
| Modificada | Media (4.9) | 0.79% | — | H3C Magic R200 Firmware | 21/4/2023 | 17/6/2026 | H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the Edit_BasicSSID interface at /goform/aspForm. | |
| Modificada | Media (4.9) | 0.79% | — | H3C Magic R200 Firmware | 21/4/2023 | 17/6/2026 | H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the UpdateSnat interface at /goform/aspForm. | |
| Modificada | Media (5.5) | 0.59% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 12/4/2023 | 17/6/2026 | A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service. | |
| Modificada | Media (6.1) | 0.38% | — | Magic-post-thumbnail Magic Post Thumbnail | 7/4/2023 | 17/6/2026 | Unauth. Reflected Cross-site Scripting (XSS) vulnerability in Magic Post Thumbnail plugin <= 4.1.10 versions. | |
| Modificada | Media (4.9) | 0.79% | — | H3C Magic R100 Firmware | 7/4/2023 | 17/6/2026 | H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the ipqos_lanip_editlist interface at /goform/aspForm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload. | |
| Modificada | Media (4.9) | 0.79% | — | H3C Magic R100 Firmware | 7/4/2023 | 17/6/2026 | H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the DeltriggerList interface at /goform/aspForm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload. | |
| Modificada | Media (4.9) | 0.79% | — | H3C Magic R100 Firmware | 7/4/2023 | 17/6/2026 | H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the Delstlist interface at /goform/aspForm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload. | |
| Modificada | Media (4.9) | 0.79% | — | H3C Magic R100 Firmware | 7/4/2023 | 17/6/2026 | H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the ipqos_lanip_dellist interface at /goform/aspForm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload. | |
| Modificada | Media (4.9) | 0.79% | — | H3C Magic R100 Firmware | 7/4/2023 | 17/6/2026 | H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the EditSTList interface at /goform/aspForm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload. | |
| Modificada | Media (4.9) | 0.79% | — | H3C Magic R100 Firmware | 7/4/2023 | 17/6/2026 | H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the DelvsList interface at /goform/aspForm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload. | |
| Modificada | Media (4.9) | 0.79% | — | H3C Magic R100 Firmware | 7/4/2023 | 17/6/2026 | H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the EdittriggerList interface at /goform/aspForm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload. | |
| Modificada | Media (4.9) | 0.79% | — | H3C Magic R100 Firmware | 7/4/2023 | 17/6/2026 | H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the EditvsList parameter at /goform/aspForm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload. | |
| Modificada | Media (4.9) | 0.79% | — | H3C Magic R100 Firmware | 7/4/2023 | 17/6/2026 | H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the DelDNSHnList interface at /goform/aspForm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload. | |
| Modificada | Media (5.5) | 0.86% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux | 23/3/2023 | 17/6/2026 | A vulnerability was discovered in ImageMagick where a specially created SVG file loads itself and causes a segmentation fault. This flaw allows a remote attacker to pass a specially crafted SVG file that leads to a segmentation fault, generating many trash files in "/tmp," resulting in a denial of service. When… | |
| Modificada | Media (6.1) | 0.41% | — | Magicform Project Magicform | 20/3/2023 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) vulnerability in Dmytriy.Cooperman MagicForm plugin <= 0.1 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Metagauss Registrationmagic | 13/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in RegistrationMagic plugin <= 5.1.9.2 versions. | |
| Modificada | Alta (8.8) | 0.63% | — | Orangelab Imagemagick Engine | 10/2/2023 | 17/6/2026 | The ImageMagick Engine plugin for WordPress is vulnerable to deserialization of untrusted input via the 'cli_path' parameter in versions up to, and including 1.7.5. This makes it possible for unauthenticated users to call files using a PHAR wrapper, granted they can trick a site administrator into performing an action… |