Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1459 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.28%—Miniupnp Project Ngiflib19/7/202317/6/2026
ngiflib commit 5e7292 was discovered to contain an infinite loop via the function DecodeGifImg at ngiflib.c.
ModificadaMedia (6)0.21%—Oracle Hyperion Essbase Administration Services18/7/202317/6/2026
Vulnerability in the Oracle Hyperion Essbase Administration Services product of Oracle Essbase (component: EAS Administration and EAS Console). The supported version that is affected is 21.4.3.0.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion…
ModificadaAlta (8.8)0.96%💥 PoCMiniorange Oauth Single Sign ON18/7/202317/6/2026
Improper Authentication vulnerability in miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin allows Authentication Bypass.This issue affects OAuth Single Sign On – SSO (OAuth Client): from n/a through 6.23.3.
ModificadaAlta (7.5)2.0%—ES Iperf3Debian LinuxFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility+217/7/202317/6/2026
iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.
ModificadaMedia (6.5)0.62%—Miniupnp Project Ngiflib17/7/202317/6/2026
An issue was discovered in ngiflib 0.4. There is SEGV in SDL_LoadAnimatedGif when use SDLaffgif. poc : ./SDLaffgif CA_file2_0
ModificadaMedia (6.8)0.22%—Espressif Esp32-d0wd-v3 FirmwareEspressif Esp32-d0wdr2-v3 FirmwareEspressif Esp32-u4wdh FirmwareEspressif Esp32-pico-v3 Firmware+1817/7/202317/6/2026
An issue was discovered on Espressif ESP32 3.0 (ESP32_rev300 ROM) devices. An EMFI attack on ECO3 provides the attacker with a capability to influence the PC value at the CPU context level, regardless of Secure Boot and Flash Encryption status. By using this capability, the attacker can exploit another behavior in the…
ModificadaMedia (5.3)0.62%—OpensslManagement Services FOR Element Software AND Netapp HCINetapp Ontap Select Deploy Administration Utility14/7/202317/6/2026
Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries which are unauthenticated as a consequence. Impact summary: Applications that use the AES-SIV algorithm and want to authenticate empty data entries as associated data can be misled by removing, adding…
ModificadaCrítica (9.8)75%💥 ExploitCarel Boss Mini Firmware12/7/202317/6/2026
A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown part of the file boss/servlet/document. The manipulation of the argument path leads to file inclusion. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and…
ModificadaAlta (7.8)0.32%—Loxone Miniserver GO GEN 2 Firmware5/7/202317/6/2026
Loxone Miniserver Go Gen.2 through 14.0.3.28 allows an authenticated operating system user to escalate privileges via the Sudo configuration. This allows the elevated execution of binaries without a password requirement.
ModificadaAlta (7.8)0.29%—Loxone Miniserver GO GEN 2 Firmware5/7/202317/6/2026
The root password of the Loxone Miniserver Go Gen.2 before 14.2 is calculated using hard-coded secrets and the MAC address. This allows a local user to calculate the root password and escalate privileges.
ModificadaAlta (7.2)1.4%—Loxone Miniserver GO GEN 2 Firmware5/7/202317/6/2026
The websocket configuration endpoint of the Loxone Miniserver Go Gen.2 before 14.1.5.9 allows remote authenticated administrators to inject arbitrary OS commands via the timezone parameter.
ModificadaMedia (4.3)0.39%—Amministrazione Trasparente Project Amministrazione Trasparente1/7/202317/6/2026
The Amministrazione Trasparente plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.1. This is due to missing or incorrect nonce validation on the at_save_aturl_meta() function. This makes it possible for unauthenticated attackers to update meta data via a forged…
ModificadaAlta (7)0.13%—HP 260 G4 Desktop Mini FirmwareHP T430 FirmwareHP T628 FirmwareHP 240 G10 Firmware+5530/6/202317/6/2026
A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS), which might allow arbitrary code execution. AMI has released updates to mitigate the potential vulnerability.
ModificadaCrítica (9.8)1.1%—Miniorange Web3 - Crypto Wallet Login & NFT Token Gating30/6/202317/6/2026
The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.6.0. This is due to incorrect authentication checking in the 'hidden_form_data' function. This makes it possible for authenticated attackers to log in as any existing user…
ModificadaAlta (7.5)0.53%—Miniorange Active Directory Integration / Ldap Integration29/6/202317/6/2026
The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Injection in versions up to, and including, 4.1.5. This is due to insufficient escaping on the supplied username value. This makes it possible for attackers, with an existing account on a vulnerable WordPress instance, to…
ModificadaCrítica (9.8)46%💥 ExploitMiniorange Wordpress Social Login AND Register (discord, Google, Twitter, Linkedin)29/6/202317/6/2026
The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 7.6.4. This is due to insufficient encryption on the user being supplied during a login validated through the plugin. This makes it possible for…
ModificadaAlta (7.5)0.50%—Lenovo Xclarity Administrator26/6/202317/6/2026
An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) server that could result in read-only access to specific files.
ModificadaMedia (6.5)0.49%—Lenovo Xclarity Administrator26/6/202317/6/2026
A valid, authenticated LXCA user with elevated privileges may be able to delete folders in the LXCA filesystem through a specifically crafted web API call due to insufficient input validation.
ModificadaMedia (6.5)0.49%—Lenovo Xclarity Administrator26/6/202317/6/2026
A valid, authenticated LXCA user with elevated privileges may be able to replace filesystem data through a specifically crafted web API call due to insufficient input validation.
ModificadaAlta (7.2)1.3%—Lenovo Xclarity Administrator26/6/202317/6/2026
A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through crafted calls to a specific web API.
ModificadaAlta (8.1)0.55%—Lenovo Xclarity Administrator26/6/202317/6/2026
A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LXCA due to a SQL injection vulnerability in a specific web API.
ModificadaMedia (5.4)0.41%—Geminilabs Site Reviews22/6/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Paul Ryley Site Reviews plugin <= 6.5.1 versions.
ModificadaMedia (5.4)0.40%—Geminilabs Site Reviews22/6/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Paul Ryley Site Reviews plugin <= 6.5.1 versions.
ModificadaBaja (2.4)0.36%—Dominionvoting Democracy Suite19/6/202317/6/2026
A flawed pseudorandom number generator in Dominion Voting Systems ImageCast Precinct (ICP and ICP2) and ImageCast Evolution (ICE) scanners allows anyone to determine the order in which ballots were cast from public ballot-level data, allowing deanonymization of voted ballots, in several types of scenarios. This issue…
ModificadaAlta (8.8)0.87%—Minical18/6/202317/6/2026
A vulnerability was found in miniCal 1.0.0. It has been rated as critical. This issue affects some unknown processing of the file /booking/show_bookings/. The manipulation of the argument search_query leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be…
Orbitaley — Vulnerabilidades