Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

2298 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.48%—Grandingteco Utime Master13/10/202317/6/2026
An indirect object reference (IDOR) in GRANDING UTime Master v9.0.7-Build:Apr 4,2023 allows authenticated attackers to access sensitive information via a crafted cookie.
ModificadaMedia (4.8)0.35%—Grandingteco Utime Master13/10/202317/6/2026
A stored cross-site scripting (XSS) vulnerability in the Create A New Employee function of Granding UTime Master v9.0.7-Build:Apr 4,2023 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the First Name parameter.
ModificadaAlta (8.8)0.52%—Debian LinuxBabeljs BabelBabeljs Babel-helper-define-polyfill-providerBabeljs Babel-plugin-polyfill-corejs2+512/10/202317/6/2026
Babel is a compiler for writingJavaScript. In `@babel/traverse` prior to versions 7.23.2 and 8.0.0-alpha.4 and all versions of `babel-traverse`, using Babel to compile code that was specifically crafted by an attacker can lead to arbitrary code execution during compilation, when using plugins that rely on the…
ModificadaAlta (7.8)0.27%—Uptime.kuma Uptime Kuma9/10/202317/6/2026
Uptime Kuma is a self-hosted monitoring tool. Prior to version 1.23.3, attackers with access to a user's device can gain persistent account access. This is caused by missing verification of Session Tokens after password changes and/or elapsed inactivity periods. Version 1.23.3 has a patch for the issue.
ModificadaAlta (8.8)0.63%—Prointegra Uptimedc4/10/202317/6/2026
Improper authorisation of regular users in ProIntegra Uptime DC software (versions below 2.0.0.33940) allows them to change passwords of all other users including administrators leading to a privilege escalation.
ModificadaMedia (4.7)0.18%—Linux KernelRedhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR Arm64Redhat Codeready Linux Builder FOR Power Little Endian+63/10/202317/6/2026
A flaw was found in pfn_swap_entry_to_page in memory management subsystem in the Linux Kernel. In this flaw, an attacker with a local user privilege may cause a denial of service problem due to a BUG statement referencing pmd_t x.
ModificadaAlta (8.8)0.44%—Mekshq Meks Audio PlayerMekshq Meks Easy ADS WidgetMekshq Meks Easy MapsMekshq Meks Easy Photo Feed Widget+63/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Meks Video Importer, Meks Time Ago, Meks ThemeForest Smart Widget, Meks Smart Author Widget, Meks Audio Player, Meks Easy Maps, Meks Easy Photo Feed Widget, Meks Simple Flickr Widget, Meks Easy Ads Widget, Meks Smart Social Widget plugins leading to dismiss or the…
ModificadaMedia (4.8)0.37%—Nigauri Insert Estimated Reading Time2/10/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in nigauri Insert Estimated Reading Time plugin <= 1.2 versions.
ModificadaCrítica (9.8)0.92%—Qnap Multimedia Console22/9/202317/6/2026
A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote users to execute code via unspecified vectors. We have already fixed the vulnerability in the following versions: Multimedia Console 2.1.1 ( 2023/03/29 )…
ModificadaMedia (5.3)0.67%—Bytecodealliance Wasmtime15/9/202317/6/2026
Wasmtime is a standalone runtime for WebAssembly. Wasmtime versions from 10.0.0 to versions 10.02, 11.0.2, and 12.0.1 contain a miscompilation of the WebAssembly `i64x2.shr_s` instruction on x86_64 platforms when the shift amount is a constant value that is larger than 32. Only x86_64 is affected so all other targets…
ModificadaMedia (6.1)0.48%—Appfire Time TO SLA14/9/202317/6/2026
A cross-site scripting (XSS) vulnerability in Time to SLA plugin v10.13.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the durationFormat parameter.
ModificadaAlta (7.8)0.59%💥 PoCGnome-time Tracker14/9/202317/6/2026
CSV Injection vulnerability in GNOME time tracker version 3.0.2, allows local attackers to execute arbitrary code via crafted .tsv file when creating a new record.
ModificadaAlta (7.5)1.8%—Redhat Build OF QuarkusRedhat Decision ManagerRedhat FuseRedhat Integration Camel K+1214/9/202317/6/2026
A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
ModificadaCrítica (9.8)2.0%—Wibu Codemeter RuntimeTrumpf OseonTrumpf ProgrammingtubeTrumpf Teczonebend+2013/9/202317/6/2026
A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.
ModificadaCrítica (9.8)0.88%—SAP CommoncryptolibSAP Content ServerSAP Extended Application Services AND RuntimeSAP Hana Database+512/9/202317/6/2026
SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation of privileges. Depending on the application and the level of privileges acquired, an attacker could abuse functionality restricted to a…
ModificadaAlta (7.5)0.75%—SAP CommoncryptolibSAP Content ServerSAP Extended Application Services AND RuntimeSAP Hana Database+512/9/202317/6/2026
SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library which in turn causes the target component to crash making it unavailable. There is no ability to view or modify any information.
ModificadaMedia (6.1)0.76%💥 ExploitAgilelogix Post Timeline4/9/202317/6/2026
The Post Timeline WordPress plugin before 2.2.6 does not sanitise and escape an invalid nonce before outputting it back in an AJAX response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaMedia (6.1)1.0%💥 ExploitAjaydsouza Connections ReloadedArchimidismertzanos Atlast BusinessArchimidismertzanos Fashionable StoreArchimidismertzanos Nothing Personal+424/9/202317/6/2026
All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business WordPress theme through 1.5.8.5, Bazaar Lite WordPress theme before 1.8.6, Brain Power WordPress theme through 1.2, BunnyPressLite…
ModificadaMedia (5.5)0.14%—Selinc Sel-5033 Acselerator Real-time Automation Controller31/8/202317/6/2026
Insecure Inherited Permissions vulnerability in Schweitzer Engineering Laboratories SEL-5033 AcSELerator RTAC Software on Windows allows Leveraging/Manipulating Configuration File Search Paths. See Instruction Manual Appendix A [Cybersecurity] tag dated 20230522 for more details. This issue affects SEL-5033…
ModificadaAlta (7.3)0.17%—Intel Advisor FOR OneapiIntel CPU Runtime FOR Opencl ApplicationsIntel Distribution FOR Python Programming LanguageIntel Dpc++ Compatibility Tool+2511/8/202317/6/2026
Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.18%—Intel Advisor FOR OneapiIntel CPU Runtime FOR Opencl ApplicationsIntel Distribution FOR Python Programming LanguageIntel Dpc++ Compatibility Tool+2511/8/202317/6/2026
Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.5)0.43%—Intel Onevpl GPU RuntimeFedoraproject Fedora11/8/202317/6/2026
Improper neutralization in software for the Intel(R) oneVPL GPU software before version 22.6.5 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaMedia (5.5)0.25%—Intel Onevpl GPU RuntimeFedoraproject Fedora11/8/202317/6/2026
Out-of-bounds read in some Intel(R) oneVPL GPU software before version 22.6.5 may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaMedia (6.5)1.7%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Visual Studio 2010 Tools FOR Office Runtime+38/8/202310/8/2026
Visual Studio Tools for Office Runtime Spoofing Vulnerability
ModificadaMedia (5.4)0.36%—Nootheme NOO Timetable8/8/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in NooTheme Noo Timetable plugin <= 2.1.3 versions.