Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2666▼ 407 respecto a la semana anterior
Críticas / altas1266▼ 215 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)215▼ 115 respecto a la semana anterior
–

1459 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.76%—Miniflux Project Miniflux17/3/202317/6/2026
Miniflux is a feed reader. Prior to version 2.0.43, an unauthenticated user can retrieve Prometheus metrics from a publicly reachable Miniflux instance where the `METRICS_COLLECTOR` configuration option is enabled and `METRICS_ALLOWED_NETWORKS` is set to `127.0.0.1/8` (the default). A patch is available in Miniflux…
ModificadaMedia (6.5)0.90%—Minio14/3/202317/6/2026
Minio is a Multi-Cloud Object Storage framework. Starting with RELEASE.2020-12-23T02-24-12Z and prior to RELEASE.2023-03-13T19-46-17Z, a user with `consoleAdmin` permissions can potentially create a user that matches the root credential `accessKey`. Once this user is created successfully, the root credential ceases to…
ModificadaCrítica (9.6)0.84%—1234n Minicms24/2/202317/6/2026
Una vulnerabilidad de cross-site scripting en MiniCMS v.1.10 permite a un atacante ejecutar código arbitrario a través de una solicitud de obtención manipulada.
ModificadaAlta (8.8)0.95%—Minio21/2/202317/6/2026
Minio es un framework de almacenamiento de objetos Multi-Cloud. Las versiones afectadas no respetan correctamente la política "Denegar" en ByPassGoverance. Idealmente, minio debería devolver "Acceso denegado" a todos los usuarios que intenten ELIMINAR un ID de versión con el encabezado especial…
ModificadaMedia (6.1)0.80%—Jquery-minicolors Project Jquery-minicolors20/2/202317/6/2026
jQuery MiniColors is a color picker built on jQuery. Prior to version 2.3.6, jQuery MiniColors is prone to cross-site scripting when handling untrusted color names. This issue is patched in version 2.3.6.
ModificadaAlta (7.5)20%💥 PoCPythonFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Management Services FOR Element Software+217/2/202317/6/2026
Un problema en el componente urllib.parse de Python anterior a 3.11.4 permite a los atacantes eludir los métodos de listas de bloqueo proporcionando una URL que comienza con caracteres en blanco.
ModificadaAlta (7.8)0.17%—Administrative Tools FOR Intel Network AdaptersIntel Non-volatile Memory Update Utility16/2/202317/6/2026
Uncontrolled search path in some Intel(R) Network Adapter installer software may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.19%—Administrative Tools FOR Intel Network Adapters16/2/202317/6/2026
Insufficient control flow management in some Intel(R) Ethernet Controller Administrative Tools drivers for Windows before version 1.5.0.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.4)1.4%—GnutlsRedhat Enterprise LinuxDebian LinuxFedoraproject Fedora+315/2/202317/6/2026
A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount…
ModificadaMedia (4.2)0.27%—Onekey Touch FirmwareOnekey Mini Firmware14/2/202317/6/2026
Onekey Touch devices through 4.0.0 and Onekey Mini devices through 2.10.0 allow man-in-the-middle attackers to obtain the seed phase. The man-in-the-middle access can only be obtained after disassembling a device (i.e., here, "man-in-the-middle" does not refer to the attacker's position on an IP network). NOTE: the…
ModificadaAlta (7)0.14%—HP 348 G4 FirmwareHP 260 G2 Desktop Mini FirmwareHP 218 PRO G5 MT FirmwareHP 260 G3 Desktop Mini Firmware+2112/2/202317/6/2026
A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS) which might allow arbitrary code execution, denial of service, and information disclosure. AMI has released updates to mitigate the potential vulnerability.
ModificadaMedia (5.4)0.57%—Teradek Vidiu Mini FirmwareTeradek Vidiu Firmware3/2/202317/6/2026
Cross Site Scripting (XSS) vulnerability in Teradek VidiU / VidiU Mini firmware version 3.0.8 and earlier allows remote attackers to run arbitrary code via the Friendly Name field in System Information Settings. NOTE: Vedor states the product has reached End of Life and will not be receiving any firmware updates to…
ModificadaMedia (6.5)90%💥 PoCOpenbsd OpensshFedoraproject FedoraNetapp Ontap Select Deploy Administration UtilityNetapp A250 Firmware+23/2/202317/6/2026
OpenSSH server (sshd) v9.1 introdujo una vulnerabilidad de doble liberación durante el manejo de "options.key_algorithms". Esto se ha corregido en OpenSSH v9.2. La doble liberación puede ser aprovechada por un atacante remoto no autenticado en la configuración por defecto, para saltar a cualquier ubicación en el…
ModificadaAlta (8.8)0.83%—202-ecommerce Administrative Mandate2/2/20239/7/2026
PrestaShop module, totadministrativemandate before v1.7.1 was discovered to contain a SQL injection vulnerability.
ModificadaAlta (7)0.14%—HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+3131/2/202317/6/2026
A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability.
ModificadaAlta (7.8)0.31%—HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+3231/2/202317/6/2026
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate these potential vulnerabilities.
ModificadaAlta (7.8)0.24%—HP Elite Dragonfly FirmwareHP Elite X2 1012 G2 FirmwareHP Elite X2 1013 G3 FirmwareHP Elite X2 G4 Firmware+1771/2/202317/6/2026
Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary code execution. HP is releasing firmware updates to mitigate these potential vulnerabilities.
ModificadaAlta (7.8)0.24%—HP Elite Dragonfly FirmwareHP Elite X2 1012 G2 FirmwareHP Elite X2 1013 G3 FirmwareHP Elite X2 G4 Firmware+1771/2/202317/6/2026
Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary code execution. HP is releasing firmware updates to mitigate these potential vulnerabilities.
ModificadaAlta (7.8)0.17%—HP 340 G3 FirmwareHP 340 G4 FirmwareHP 346 G3 FirmwareHP 346 G4 Firmware+3731/2/202317/6/2026
HP has identified a potential vulnerability in BIOS firmware of some Workstation products. Firmware updates are being released to mitigate these potential vulnerabilities.
ModificadaAlta (7.8)0.19%—Dell Openmanage Server Administrator1/2/202317/6/2026
Dell OpenManage Server Administrator (OMSA) version 10.3.0.0 and earlier contains a DLL Injection Vulnerability. A local low privileged authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary executable on the operating system with elevated privileges. Exploitation…
ModificadaMedia (6.7)0.23%—Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+28330/1/202317/6/2026
Un desbordamiento del búfer en WMI SMI Handler en algunos modelos de Lenovo puede permitir que un atacante con acceso local y privilegios elevados ejecute código arbitrario.
ModificadaMedia (6.1)0.61%—Miniorange Saml SP Single Sign ON30/1/202317/6/2026
El complemento SAML SSO Standard de WordPress versión 16.0.0 anterior a 16.0.8, el complemento SAML SSO Premium de WordPress versión 12.0.0 anterior a 12.1.0 y el complemento SAML SSO Premium Multisite de WordPress versión 20.0.0 anterior a 20.0.7 no validan que el parámetro de redireccionamiento a su punto final de…
ModificadaMedia (6.1)0.51%—Broadcom Symantec Identity Governance AND AdministrationBroadcom Symantec Identity Manager26/1/202317/6/2026
Capacidad de enumerar los atributos LDAP de Oracle para el usuario actual modificando la consulta utilizada por la aplicación.
ModificadaMedia (6.1)0.51%—Broadcom Symantec Identity Governance AND AdministrationBroadcom Symantec Identity Manager26/1/202317/6/2026
La entrada proporcionada por el usuario (normalmente una secuencia CRLF) se puede utilizar para dividir una respuesta devuelta en dos respuestas.
ModificadaMedia (5.4)0.56%—Broadcom Symantec Identity Governance AND AdministrationBroadcom Symantec Identity Manager26/1/202317/6/2026
Un usuario autenticado puede proporcionar código HTML y JavaScript malicioso que se ejecutará en el navegador del cliente.