Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
–

1459 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.26%—Dogblocker Minify Html23/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Tim Eckel Minify HTML plugin <= 2.1.7 vulnerability.
ModificadaAlta (8.8)0.26%—Miniorange Wordpress Social Login AND Register (discord, Google, Twitter, Linkedin)23/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.14 versions.
ModificadaAlta (8.8)0.32%—Birddog A300 FirmwareBirddog Mini FirmwareBirddog 4K Quad FirmwareBirddog Studio R3 Firmware22/5/202317/6/2026
The affected products have a CSRF vulnerability that could allow an attacker to execute code and upload malicious files.
ModificadaCrítica (9.8)0.46%—Birddog A300 FirmwareBirddog Mini FirmwareBirddog 4K Quad FirmwareBirddog Studio R3 Firmware22/5/202317/6/2026
Files present on firmware images could allow an attacker to gain unauthorized access as a root user using hard-coded credentials.
ModificadaAlta (7.5)0.82%—Miniorange Active Directory Integration / Ldap Integration15/5/202317/6/2026
The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.1 does not have proper authorization or nonce values for some POST requests, leading to unauthenticated data disclosure.
ModificadaMedia (5.5)0.14%—Intel NUC 8 Compute Element Cm8i3cb4n FirmwareIntel NUC 8 Compute Element Cm8i5cb8n FirmwareIntel NUC 8 Compute Element Cm8i7cb8n FirmwareIntel NUC 8 Compute Element Cm8ccb4r Firmware+5510/5/202317/6/2026
Improper access control for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable denial of service via local access.
ModificadaAlta (7.8)0.16%—Intel NUC 11 Performance KIT Nuc11pahi70z FirmwareIntel NUC 11 Performance KIT Nuc11pahi50z FirmwareIntel NUC 11 Performance KIT Nuc11pahi30z FirmwareIntel NUC 11 Performance KIT Nuc11pahi3 Firmware+3710/5/202317/6/2026
Improper access control for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (4.4)0.16%—Intel NUC 11 Performance KIT Nuc11pahi70z FirmwareIntel NUC 11 Performance KIT Nuc11pahi50z FirmwareIntel NUC 11 Performance KIT Nuc11pahi30z FirmwareIntel NUC 11 Performance KIT Nuc11pahi3 Firmware+3510/5/202317/6/2026
Improper access control in firmware for some Intel(R) NUC Boards, Intel(R) NUC 11 Performance Kit, Intel(R) NUC 11 Performance Mini PC, Intel(R) NUC Pro Compute Element may allow a privileged user to potentially enable denial of service via local access.
ModificadaAlta (7.5)14%—Aigital Wireless-n Repeater Mini Router Firmware2/5/202317/6/2026
An issue in the time-based authentication mechanism of Aigital Aigital Wireless-N Repeater Mini_Router v0.131229 allows attackers to bypass login by connecting to the web app after a successful attempt by a legitimate user.
ModificadaMedia (4.8)0.50%—Geminilabs Site Reviews2/5/202317/6/2026
The Site Reviews WordPress plugin before 6.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
ModificadaMedia (5.4)29%—Aigital Wireless-n Repeater Mini Router Firmware28/4/202317/6/2026
A cross-site scripting (XSS) vulnerability in Aigital Wireless-N Repeater Mini_Router v0.131229 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the wl_ssid parameter at /boafrm/formHomeWlanSetup.
ModificadaAlta (7.5)1.8%—Illumina Iscan FirmwareIllumina Iseq 100 FirmwareIllumina Miniseq FirmwareIllumina Miseq Firmware+728/4/202317/6/2026
Instruments with Illumina Universal Copy Service v2.x are vulnerable due to binding to an unrestricted IP address. An unauthenticated malicious actor could use UCS to listen on all IP addresses, including those capable of accepting remote communications.
ModificadaCrítica (9.8)0.92%—Illumina Iscan FirmwareIllumina Iseq 100 FirmwareIllumina Miniseq FirmwareIllumina Miseq Firmware+728/4/202317/6/2026
Instruments with Illumina Universal Copy Service v1.x and v2.x contain an unnecessary privileges vulnerability. An unauthenticated malicious actor could upload and execute code remotely at the operating system level, which could allow an attacker to change settings, configurations, software, or access sensitive data…
ModificadaMedia (5.5)0.18%—HP Elite Dragonfly G3 FirmwareHP Dragonfly Folio G3 FirmwareHP Elite Dragonfly G2 FirmwareHP Elite Dragonfly MAX Firmware+8728/4/202317/6/2026
A potential security vulnerability has been identified in the system BIOS for certain HP PC products which may allow loss of integrity. HP is releasing firmware updates to mitigate the potential vulnerability.
ModificadaCrítica (9.8)2.2%—Aigital Wireless-n Repeater Mini Router Firmware26/4/20239/7/2026
Aigital Wireless-N Repeater Mini_Router v0.131229 was discovered to contain a remote code execution (RCE) vulnerability via the sysCmd parameter in the formSysCmd function. This vulnerability is exploited via a crafted HTTP request.
ModificadaMedia (4.8)0.37%—Miniorange Wordpress Social Login AND Register (discord, Google, Twitter, Linkedin)25/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.14 versions.
ModificadaMedia (5.3)2.5%—Fedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration UtilityPython19/4/202317/6/2026
The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after…
ModificadaMedia (6.1)0.49%—Phpminiadmin Project Phpminiadmin6/4/202317/6/2026
A vulnerability classified as problematic was found in phpMiniAdmin up to 1.8.120510. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 1.9.140405 is able to address this issue. It is recommended to…
ModificadaMedia (5.4)0.60%—SAS WEB Administration Interface3/4/202317/6/2026
A stored cross site scripting (XSS) vulnerability was discovered in the user management module of the SAS 9.4 Admin Console, due to insufficient validation and sanitization of data input into the user creation and editing form fields. The product name is SAS Web Administration interface (SASAdmin). For the product…
ModificadaMedia (6.5)0.33%—Miniorange Oauth Single Sign ON27/3/202317/6/2026
The OAuth Single Sign On WordPress plugin before 6.24.2 does not have CSRF checks when discarding Identify providers (IdP), which could allow attackers to make logged in admins delete all IdP via a CSRF attack
ModificadaMedia (6.5)0.44%—Miniorange Oauth Single Sign ON27/3/202317/6/2026
The OAuth Single Sign On Free WordPress plugin before 6.24.2, OAuth Single Sign On Standard WordPress plugin before 28.4.9, OAuth Single Sign On Premium WordPress plugin before 38.4.9 and OAuth Single Sign On Enterprise WordPress plugin before 48.4.9 do not have CSRF checks when deleting Identity Providers (IdP),…
AnalizadaAlta (8.8)7.9%⚠ Explotación activa💥 PoCMinio22/3/202317/6/2026
Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket`. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*`…
ModificadaAlta (8.8)0.98%—Minio22/3/202317/6/2026
Minio is a Multi-Cloud Object Storage framework. All users on Windows prior to version RELEASE.2023-03-20T20-16-18Z are impacted. MinIO fails to filter the `\` character, which allows for arbitrary object placement across buckets. As a result, a user with low privileges, such as an access key, service account, or STS…
AnalizadaAlta (7.5)84%⚠ Explotación activa💥 ExploitMinio22/3/202317/6/2026
Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all environment variables, including `MINIO_SECRET_KEY` and `MINIO_ROOT_PASSWORD`, resulting in information disclosure. All users of distributed…
ModificadaMedia (5.4)0.59%—Miniflux Project Miniflux17/3/202317/6/2026
Miniflux is a feed reader. Since v2.0.25, Miniflux will automatically proxy images served over HTTP to prevent mixed content errors. When an outbound request made by the Go HTTP client fails, the `html.ServerError` is returned unescaped without the expected Content Security Policy header added to valid responses. By…