Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1418 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.17% | — | ARM CompilerARM Compiler FOR Embedded FusaARM Compiler FOR Functional SafetyARM Development Studio+2 | 27/7/2023 | 17/6/2026 | When the directory containing the installer does not have sufficiently restrictive file permissions, an attacker can modify (or replace) the installer to execute malicious code. | |
| Modificada | Alta (7.8) | 0.18% | — | ARM CompilerARM Compiler FOR Embedded FusaARM Compiler FOR Functional SafetyARM Development Studio+7 | 27/7/2023 | 17/6/2026 | When the installation directory does not have sufficiently restrictive file permissions, an attacker can modify files in the installation directory to cause execution of malicious code. | |
| Modificada | Media (5.3) | 1.2% | — | Omnis Studio | 20/7/2023 | 17/6/2026 | Omnis Studio 10.22.00 has incorrect access control. It advertises a feature for making Omnis libraries "always private" - this is supposed to be an irreversible operation. However, due to implementation issues, "always private" Omnis libraries can be opened by the Omnis Studio browser by bypassing specific checks.… | |
| Modificada | Media (6.5) | 0.88% | — | Omnis Studio | 20/7/2023 | 17/6/2026 | Omnis Studio 10.22.00 has incorrect access control. It advertises an irreversible feature for locking classes within Omnis libraries: it should be no longer possible to delete, view, change, copy, rename, duplicate, or print a locked class. Due to implementation issues, locked classes in Omnis libraries can be… | |
| Modificada | Media (4.3) | 0.39% | — | Ashstonestudios Advanced Popups | 12/7/2023 | 17/6/2026 | The Advanced Popups plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on the metabox_popup_save() function. This makes it possible for unauthenticated attackers to save meta tags via a forged request granted… | |
| Modificada | Media (6.1) | 0.46% | — | Oacstudio Mailtree LOG Mail | 12/7/2023 | 17/6/2026 | The Mailtree Log Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Modificada | Alta (7.5) | 0.94% | — | Fujifilm Docuprint M265 Z FirmwareFujifilm Docuprint M268 Z FirmwareFujifilm Docuprint M225 Z FirmwareFujifilm Docuprint M225 DW Firmware+212 | 11/7/2023 | 17/6/2026 | Null pointer dereference vulnerability exists in multiple vendors MFPs and printers which implement Debut web server 1.2 or 1.3. Processing a specially crafted request may lead an affected product to a denial-of-service (DoS) condition. As for the affected products/models/versions, see the detailed information… | |
| Modificada | Alta (8.1) | 2.0% | — | Microsoft .netMicrosoft Visual Studio 2022Fedoraproject Fedora | 11/7/2023 | 17/6/2026 | ASP.NET and Visual Studio Security Feature Bypass Vulnerability | |
| Modificada | Alta (8.1) | 1.9% | — | Microsoft .netMicrosoft Visual Studio 2022 | 11/7/2023 | 17/6/2026 | .NET and Visual Studio Elevation of Privilege Vulnerability | |
| Modificada | Alta (8.8) | 0.27% | — | Pvmg Reservation.studio | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Reservation.Studio Reservation.Studio widget plugin <= 1.0.11 versions. | |
| Modificada | Media (6.1) | 0.55% | — | Webdevstudios WDS Multisite Aggregate | 10/7/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in WDS Multisite Aggregate Plugin up to 1.0.0 on WordPress. Affected is the function update_options of the file includes/WDS_Multisite_Aggregate_Options.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely.… | |
| Modificada | Crítica (9.8) | 1.5% | — | Thedaylightstudio Fuel CMS | 3/7/2023 | 17/6/2026 | File Upload vulnerability in FUEL-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted .php file to the upload parameter in the navigation function. | |
| Modificada | Media (5.4) | 0.58% | — | Thedaylightstudio Fuel CMS | 3/7/2023 | 17/6/2026 | Cross Site Scripting vulnerability in daylight studio FUEL- CMS v.1.4.6 allows a remote attacker to execute arbitrary code via the page title, meta description and meta keywords of the pages function. | |
| Modificada | Crítica (9.8) | 1.5% | — | Thedaylightstudio Fuel CMS | 3/7/2023 | 17/6/2026 | Permissions vulnerability in Fuel-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted zip file to the assests parameter of the upload function. | |
| Modificada | Media (4.8) | 0.39% | — | Prismtechstudios Modern Footnotes | 22/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Prism Tech Studios Modern Footnotes plugin <= 1.4.15 versions. | |
| Modificada | Alta (7.8) | 0.23% | — | HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+323 | 14/6/2023 | 17/6/2026 | Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | |
| Modificada | Alta (7.8) | 0.20% | — | HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+323 | 14/6/2023 | 17/6/2026 | Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | |
| Modificada | Alta (7.8) | 0.23% | — | HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+323 | 14/6/2023 | 17/6/2026 | Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | |
| Modificada | Alta (7) | 0.14% | — | HP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite X2 1012 G2 FirmwareHP Elite X2 1013 G3 Firmware+287 | 14/6/2023 | 17/6/2026 | Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | |
| Modificada | Alta (7) | 0.17% | — | HP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite X2 1012 G2 FirmwareHP Elite X2 1013 G3 Firmware+287 | 14/6/2023 | 17/6/2026 | Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | |
| Modificada | Alta (7) | 0.17% | — | HP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite X2 1012 G2 FirmwareHP Elite X2 1013 G3 Firmware+287 | 14/6/2023 | 17/6/2026 | Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | |
| Modificada | Alta (7.8) | 1.2% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual StudioMicrosoft Visual Studio 2017+2 | 14/6/2023 | 17/6/2026 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 1.1% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022 | 14/6/2023 | 17/6/2026 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | |
| Modificada | Media (6.6) | 1.3% | — | Microsoft Visual Studio Code | 14/6/2023 | 17/6/2026 | Visual Studio Code Spoofing Vulnerability | |
| Modificada | Media (5.5) | 0.82% | — | Microsoft Visual StudioMicrosoft Visual Studio 2017Microsoft Visual Studio 2019Microsoft Visual Studio 2022 | 14/6/2023 | 17/6/2026 | Visual Studio Information Disclosure Vulnerability |