Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
2493 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.6) | 1.4% | — | Softing EdgeaggregatorSofting Secure Integration Server | 3/5/2024 | 17/6/2026 | Softing edgeAggregator Client Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing edgeAggregator. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or… | |
| Analizada | Alta (7.5) | 1.4% | — | Softing EdgeaggregatorSofting EdgeconnectorSofting OPC UA C++ Software Development KITSofting Secure Integration Server | 3/5/2024 | 17/6/2026 | Softing edgeConnector Siemens ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Softing edgeConnector Siemens. Authentication is not required to exploit this vulnerability. The specific… | |
| Aplazada | Media (5.4) | 0.39% | — | Codesavory Knowledge Base Documentation & Wiki Plugin BasepressAI | 29/4/2024 | 17/6/2026 | Missing Authorization vulnerability in codeSavory Knowledge Base documentation & wiki plugin – BasePress.This issue affects Knowledge Base documentation & wiki plugin – BasePress: from n/a through 2.16.1. | |
| Aplazada | Media (5) | 0.35% | — | Basepress Knowledge Base Documentation Wiki PluginAI | 29/4/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in codeSavory Knowledge Base documentation & wiki plugin – BasePress.This issue affects Knowledge Base documentation & wiki plugin – BasePress: from n/a through 2.16.1. | |
| Analizada | Media (5) | 0.65% | — | Microsoft Edge Chromium | 19/4/2024 | 17/6/2026 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | |
| Analizada | Media (6.5) | 1.2% | — | Microsoft Edge Chromium | 18/4/2024 | 17/6/2026 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | |
| Analizada | Media (5.4) | 0.51% | — | Microsoft Edge Chromium | 18/4/2024 | 17/6/2026 | Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability | |
| Aplazada | Media (6.7) | 0.18% | — | Lenovo BiosAILenovo ThinkstationAILenovo Smart EdgeAI | 5/4/2024 | 17/6/2026 | A potential vulnerability were reported in the BIOS of some Desktop, Smart Edge, and ThinkStation products that could allow a local attacker with elevated privileges to write to NVRAM variables. | |
| Analizada | Media (4.3) | 0.70% | — | Microsoft Edge Chromium | 4/4/2024 | 17/6/2026 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | |
| Analizada | Media (4.7) | 0.66% | — | Microsoft Edge Chromium | 4/4/2024 | 17/6/2026 | Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability | |
| Analizada | Alta (7.8) | 0.15% | — | Dell Poweredge R660 FirmwareDell Poweredge R760 FirmwareDell Poweredge C6620 FirmwareDell Poweredge Mx760c Firmware+89 | 3/4/2024 | 17/6/2026 | Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation. | |
| Aplazada | Media (4.8) | 0.21% | — | Vmware Sd-wan EdgeAI | 2/4/2024 | 17/6/2026 | VMware SD-WAN Edge contains a missing authentication and protection mechanism vulnerability. A malicious actor with physical access to the SD-WAN Edge appliance during activation can potentially exploit this vulnerability to access the BIOS configuration. In addition, the malicious actor may be able to exploit the… | |
| Aplazada | Alta (7.4) | 0.41% | — | Vmware Sd-wan EdgeAI | 2/4/2024 | 17/6/2026 | VMware SD-WAN Edge contains an unauthenticated command injection vulnerability potentially leading to remote code execution. A malicious actor with local access to the Edge Router UI during activation may be able to perform a command injection attack that could lead to full control of the router. | |
| Aplazada | Alta (8.7) | 0.46% | — | Echo Plugins Knowledge Base FOR Documentation Faqs With AI AssistanceAI | 27/3/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Echo Plugins Knowledge Base for Documentation, FAQs with AI Assistance.This issue affects Knowledge Base for Documentation, FAQs with AI Assistance: from n/a through 11.30.2. | |
| Modificada | Media (4.3) | 0.99% | — | Microsoft Edge | 22/3/2024 | 17/6/2026 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | |
| Modificada | Media (4.7) | 1.1% | — | Microsoft Edge | 22/3/2024 | 17/6/2026 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | |
| Analizada | Media (5.9) | 0.21% | — | Mysolaredge | 21/3/2024 | 17/6/2026 | The SolarEdge mySolarEdge application before 2.20.1 for Android has a certificate verification issue that allows a Machine-in-the-middle (MitM) attacker to read and alter all network traffic between the application and the server. | |
| Modificada | Media (4.3) | 1.2% | — | Microsoft Edge | 21/3/2024 | 10/8/2026 | Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability | |
| Analizada | Media (6.8) | 0.23% | — | Dell Poweredge R730 FirmwareDell Poweredge R730xd FirmwareDell Poweredge R630 FirmwareDell Poweredge C4130 Firmware+21 | 19/3/2024 | 17/6/2026 | Dell PowerEdge Server BIOS contains an Improper SMM communication buffer verification vulnerability. A physical high privileged attacker could potentially exploit this vulnerability leading to arbitrary writes to SMRAM. | |
| Analizada | Media (6) | 0.19% | — | Dell Poweredge R730 FirmwareDell Poweredge R730xd FirmwareDell Poweredge R630 FirmwareDell Poweredge C4130 Firmware+21 | 19/3/2024 | 17/6/2026 | Dell PowerEdge Server BIOS contains a heap-based buffer overflow vulnerability. A local high privileged attacker could potentially exploit this vulnerability to write to otherwise unauthorized memory. | |
| Modificada | Baja (3.9) | 0.64% | — | Microsoft Edge | 14/3/2024 | 17/6/2026 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | |
| Modificada | Media (4.7) | 2.1% | — | Microsoft Edge Chromium | 14/3/2024 | 17/6/2026 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | |
| Analizada | Alta (7.5) | 0.51% | — | Softing EdgeaggregatorSofting Edgeconnector | 14/3/2024 | 17/6/2026 | The affected product is vulnerable to a cleartext transmission of sensitive information vulnerability, which may allow an attacker to capture packets to craft their own requests. | |
| Analizada | Baja (3.3) | 0.17% | — | Dell Poweredge R660 FirmwareDell Poweredge R760 FirmwareDell Poweredge C6620 FirmwareDell Poweredge Mx760c Firmware+120 | 13/3/2024 | 17/6/2026 | Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper parameter initialization vulnerability. A local low privileged attacker could potentially exploit this vulnerability to read the contents of non-SMM stack memory. | |
| Analizada | Media (6.3) | 0.11% | — | Dell Poweredge R660 FirmwareDell Poweredge R760 FirmwareDell Poweredge C6620 FirmwareDell Poweredge Mx760c Firmware+54 | 13/3/2024 | 17/6/2026 | Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain a TOCTOU race condition vulnerability. A local low privileged attacker could potentially exploit this vulnerability to gain access to otherwise unauthorized resources. |