Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1319 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.52% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+18 | 8/5/2024 | 17/6/2026 | When BIG-IP AFM is licensed and provisioned, undisclosed DNS traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (7.5) | 7.1% | 💥 PoC | F5 Big-ip Next Central Manager | 8/5/2024 | 17/6/2026 | An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (7.3) | 0.15% | — | Checkpoint Identity AgentCheckpoint Zonealarm Extreme Security Nextgen | 18/4/2024 | 17/6/2026 | A local attacker can erscalate privileges on affected Check Point ZoneAlarm ExtremeSecurity NextGen, Identity Agent for Windows, and Identity Agent for Windows Terminal Server. To exploit this vulnerability, an attacker must first obtain the ability to execute local privileged code on the target system. | |
| Analizada | Alta (7.2) | 1.1% | — | Lenovo Nextscale N1200 Enclosure FirmwareLenovo Thinkagile Cp-cb-10 FirmwareLenovo Thinkagile Cp-cb-10e FirmwareLenovo Thinkagile HX Enclosure Firmware+64 | 15/4/2024 | 17/6/2026 | A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute system commands when performing a specific administrative function. | |
| Modificada | Media (4.3) | 0.75% | 💥 PoC | Xlplugins Nextmove | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in XLPlugins NextMove Lite.This issue affects NextMove Lite: from n/a through 2.18.1. | |
| Aplazada | Media (6.4) | 0.34% | — | Nextendweb Smart Slider 3AI | 13/4/2024 | 17/6/2026 | The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the upload function in all versions up to, and including, 3.5.1.22. This makes it possible for authenticated attackers, with contributor-level access and above, to upload files, including SVG… | |
| Analizada | Media (5.5) | 0.42% | — | Sipwise Next Generation Communication Platform | 10/4/2024 | 17/6/2026 | An issue discovered in Sipwise C5 NGCP Dashboard below mr11.5.1 allows a low privileged user to access the Journal endpoint by directly visit the URL. | |
| Analizada | Baja (3.1) | 0.46% | — | Sipwise Next Generation Communication Platform | 10/4/2024 | 17/6/2026 | An Open Redirect vulnerability was found in Sipwise C5 NGCP Dashboard below mr11.5.1. The Open Redirect vulnerability allows attackers to control the "back" parameter in the URL through a double encoded URL. | |
| Modificada | Media (5.3) | 38% | 💥 Exploit | Imagely Nextgen Gallery | 9/4/2024 | 17/6/2026 | The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_item function in versions up to, and including, 3.59. This makes it possible for unauthenticated attackers to extract sensitive data including EXIF and other… | |
| Aplazada | Alta (7.1) | 0.42% | — | Posimyth Nexter BlocksAI | 29/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH Nexter Blocks the-plus-addons-for-block-editor.This issue affects Nexter Blocks: from n/a through <= 3.2.5. | |
| Analizada | Crítica (9.8) | 2.1% | — | Nextcloudpi | 29/3/2024 | 17/6/2026 | NextcloudPi is a ready to use image for Virtual Machines, Raspberry Pi, Odroid HC1, Rock64 and other boards. A command injection vulnerability in NextCloudPi allows command execution as the root user via the NextCloudPi web-panel. Due to a security misconfiguration this can be used by anyone with access to NextCloudPi… | |
| Analizada | Alta (8.1) | 0.66% | — | Workos Authkit-nextjs | 29/3/2024 | 17/6/2026 | The AuthKit library for Next.js provides helpers for authentication and session management using WorkOS & AuthKit with Next.js. A user can reuse an expired session by controlling the `x-workos-session` header. The vulnerability is patched in v0.4.2. | |
| Analizada | Crítica (9.8) | 83% | 💥 Exploit | Nextchat | 12/3/2024 | 17/6/2026 | NextChat, also known as ChatGPT-Next-Web, is a cross-platform chat user interface for use with ChatGPT. Versions 2.11.2 and prior are vulnerable to server-side request forgery and cross-site scripting. This vulnerability enables read access to internal HTTP endpoints but also write access using HTTP POST, PUT, and… | |
| Aplazada | Media (6.1) | 0.31% | — | Forcepoint Next Generation Firewall Security Management CenterAI | 4/3/2024 | 17/6/2026 | Forcepoint NGFW Security Management Center Management Server has SMC Downloads optional feature to offer standalone Management Client downloads and ECA configuration downloads. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Next Generation Firewall… | |
| Modificada | Media (5.4) | 0.37% | — | Nextendweb Nextend Social Login | 2/3/2024 | 17/6/2026 | The Nextend Social Login and Register plugin for WordPress is vulnerable to a self-based Reflected Cross-Site Scripting via the ‘error_description’ parameter in all versions up to, and including, 3.1.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers,… | |
| Modificada | Media (5.3) | 0.53% | — | Xlplugins FinaleXlplugins Nextmove | 1/3/2024 | 17/6/2026 | The NextMove Lite – Thank You Page for WooCommerce and Finale Lite – Sales Countdown Timer & Discount for WooCommerce plugins for WordPress are vulnerable to unauthorized access of data due to a missing capability check on the download_tools_settings() function in all versions up to, and including, 2.17.0. This makes… | |
| Analizada | Alta (7.5) | 0.52% | — | F5 Big-ip Access Policy ManagerF5 Big-iq Centralized ManagementF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+9 | 14/2/2024 | 17/6/2026 | When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | |
| Analizada | Alta (7.1) | 0.15% | — | F5 Big-ip Next Cloud-native Network Functions | 14/2/2024 | 17/6/2026 | A vulnerability exists in BIG-IP Next CNF and SPK systems that may allow access to undisclosed sensitive files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | |
| Modificada | Media (6.1) | 0.39% | — | Tanstack React-query-next-experimental | 30/1/2024 | 17/6/2026 | TanStack Query supplies asynchronous state management, server-state utilities and data fetching for the web. The `@tanstack/react-query-next-experimental` NPM package is vulnerable to a cross-site scripting vulnerability. To exploit this, an attacker would need to either inject malicious input or arrange to have… | |
| Modificada | Alta (8.8) | 0.54% | — | Nextendweb Smart Slider 3 | 19/1/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Nextend Smart Slider 3.This issue affects Smart Slider 3: from n/a through 3.5.1.9. | |
| Modificada | Media (4.3) | 0.52% | — | Nextcloud Zipper | 18/1/2024 | 17/6/2026 | Nextcloud files Zip app is a tool to create zip archives from one or multiple files from within Nextcloud. In affected versions users can download "view-only" files by zipping the complete folder. It is recommended that the Files ZIP app is upgraded to 1.2.1, 1.4.1, or 1.5.0. Users unable to upgrade should disable the… | |
| Modificada | Media (5.4) | 0.51% | — | Nextcloud Guests | 18/1/2024 | 17/6/2026 | Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions users were able to load the first page of apps they were actually not allowed to access. Depending on the selection of apps installed this may present a permissions bypass. It is recommended that the… | |
| Modificada | Media (4.3) | 0.46% | — | Nextcloud Guests | 18/1/2024 | 17/6/2026 | Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions users could change the allowed list of apps, allowing them to use apps that were not intended to be used. It is recommended that the Guests app is upgraded to 2.4.1, 2.5.1 or 3.0.1. There are no… | |
| Modificada | Baja (3.7) | 0.45% | — | Nextcloud Server | 18/1/2024 | 17/6/2026 | Nextcloud server is a self hosted personal cloud system. In affected versions OAuth codes did not expire. When an attacker would get access to an authorization code they could authenticate at any time using the code. As of version 28.0.0 OAuth codes are invalidated after 10 minutes and will no longer be authenticated.… | |
| Modificada | Media (6.1) | 0.45% | — | Nextcloud SSO & Saml Authentication | 18/1/2024 | 17/6/2026 | Nextcloud User Saml is an app for authenticating Nextcloud users using SAML. In affected versions users can be given a link to the Nextcloud server and end up on a uncontrolled thirdparty server. It is recommended that the User Saml app is upgraded to version 5.1.5, 5.2.5, or 6.0.1. There are no known workarounds for… |