Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

2493 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.6)1.4%—Softing EdgeaggregatorSofting Secure Integration Server3/5/202417/6/2026
Softing edgeAggregator Client Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing edgeAggregator. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or…
AnalizadaAlta (7.5)1.4%—Softing EdgeaggregatorSofting EdgeconnectorSofting OPC UA C++ Software Development KITSofting Secure Integration Server3/5/202417/6/2026
Softing edgeConnector Siemens ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Softing edgeConnector Siemens. Authentication is not required to exploit this vulnerability. The specific…
AplazadaMedia (5.4)0.39%—Codesavory Knowledge Base Documentation & Wiki Plugin BasepressAI29/4/202417/6/2026
Missing Authorization vulnerability in codeSavory Knowledge Base documentation & wiki plugin – BasePress.This issue affects Knowledge Base documentation & wiki plugin – BasePress: from n/a through 2.16.1.
AplazadaMedia (5)0.35%—Basepress Knowledge Base Documentation Wiki PluginAI29/4/202417/6/2026
Server-Side Request Forgery (SSRF) vulnerability in codeSavory Knowledge Base documentation & wiki plugin – BasePress.This issue affects Knowledge Base documentation & wiki plugin – BasePress: from n/a through 2.16.1.
AnalizadaMedia (5)0.65%—Microsoft Edge Chromium19/4/202417/6/2026
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
AnalizadaMedia (6.5)1.2%—Microsoft Edge Chromium18/4/202417/6/2026
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
AnalizadaMedia (5.4)0.51%—Microsoft Edge Chromium18/4/202417/6/2026
Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability
AplazadaMedia (6.7)0.18%—Lenovo BiosAILenovo ThinkstationAILenovo Smart EdgeAI5/4/202417/6/2026
A potential vulnerability were reported in the BIOS of some Desktop, Smart Edge, and ThinkStation products that could allow a local attacker with elevated privileges to write to NVRAM variables.
AnalizadaMedia (4.3)0.70%—Microsoft Edge Chromium4/4/202417/6/2026
Microsoft Edge (Chromium-based) Spoofing Vulnerability
AnalizadaMedia (4.7)0.66%—Microsoft Edge Chromium4/4/202417/6/2026
Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability
AnalizadaAlta (7.8)0.15%—Dell Poweredge R660 FirmwareDell Poweredge R760 FirmwareDell Poweredge C6620 FirmwareDell Poweredge Mx760c Firmware+893/4/202417/6/2026
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation.
AplazadaMedia (4.8)0.21%—Vmware Sd-wan EdgeAI2/4/202417/6/2026
VMware SD-WAN Edge contains a missing authentication and protection mechanism vulnerability. A malicious actor with physical access to the SD-WAN Edge appliance during activation can potentially exploit this vulnerability to access the BIOS configuration. In addition, the malicious actor may be able to exploit the…
AplazadaAlta (7.4)0.41%—Vmware Sd-wan EdgeAI2/4/202417/6/2026
VMware SD-WAN Edge contains an unauthenticated command injection vulnerability potentially leading to remote code execution. A malicious actor with local access to the Edge Router UI during activation may be able to perform a command injection attack that could lead to full control of the router.
AplazadaAlta (8.7)0.46%—Echo Plugins Knowledge Base FOR Documentation Faqs With AI AssistanceAI27/3/202417/6/2026
Deserialization of Untrusted Data vulnerability in Echo Plugins Knowledge Base for Documentation, FAQs with AI Assistance.This issue affects Knowledge Base for Documentation, FAQs with AI Assistance: from n/a through 11.30.2.
ModificadaMedia (4.3)0.99%—Microsoft Edge22/3/202417/6/2026
Microsoft Edge (Chromium-based) Spoofing Vulnerability
ModificadaMedia (4.7)1.1%—Microsoft Edge22/3/202417/6/2026
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
AnalizadaMedia (5.9)0.21%—Mysolaredge21/3/202417/6/2026
The SolarEdge mySolarEdge application before 2.20.1 for Android has a certificate verification issue that allows a Machine-in-the-middle (MitM) attacker to read and alter all network traffic between the application and the server.
ModificadaMedia (4.3)1.2%—Microsoft Edge21/3/202410/8/2026
Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability
AnalizadaMedia (6.8)0.23%—Dell Poweredge R730 FirmwareDell Poweredge R730xd FirmwareDell Poweredge R630 FirmwareDell Poweredge C4130 Firmware+2119/3/202417/6/2026
Dell PowerEdge Server BIOS contains an Improper SMM communication buffer verification vulnerability. A physical high privileged attacker could potentially exploit this vulnerability leading to arbitrary writes to SMRAM.
AnalizadaMedia (6)0.19%—Dell Poweredge R730 FirmwareDell Poweredge R730xd FirmwareDell Poweredge R630 FirmwareDell Poweredge C4130 Firmware+2119/3/202417/6/2026
Dell PowerEdge Server BIOS contains a heap-based buffer overflow vulnerability. A local high privileged attacker could potentially exploit this vulnerability to write to otherwise unauthorized memory.
ModificadaBaja (3.9)0.64%—Microsoft Edge14/3/202417/6/2026
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
ModificadaMedia (4.7)2.1%—Microsoft Edge Chromium14/3/202417/6/2026
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
AnalizadaAlta (7.5)0.51%—Softing EdgeaggregatorSofting Edgeconnector14/3/202417/6/2026
The affected product is vulnerable to a cleartext transmission of sensitive information vulnerability, which may allow an attacker to capture packets to craft their own requests.
AnalizadaBaja (3.3)0.17%—Dell Poweredge R660 FirmwareDell Poweredge R760 FirmwareDell Poweredge C6620 FirmwareDell Poweredge Mx760c Firmware+12013/3/202417/6/2026
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper parameter initialization vulnerability. A local low privileged attacker could potentially exploit this vulnerability to read the contents of non-SMM stack memory.
AnalizadaMedia (6.3)0.11%—Dell Poweredge R660 FirmwareDell Poweredge R760 FirmwareDell Poweredge C6620 FirmwareDell Poweredge Mx760c Firmware+5413/3/202417/6/2026
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain a TOCTOU race condition vulnerability. A local low privileged attacker could potentially exploit this vulnerability to gain access to otherwise unauthorized resources.