Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

215 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.51%—Boardroom Limited Dividend Distribution TAX Election SystemAI18/2/202517/6/2026
A time-based SQL injection vulnerability in the login page of BoardRoom Limited Dividend Distribution Tax Election System Version v2.0 allows attackers to execute arbitrary code via a crafted input.
AplazadaMedia (5.4)0.27%—Enituretechnology Distance-based-shipping-calculatorAI16/2/202517/6/2026
Missing Authorization vulnerability in enituretechnology Distance Based Shipping Calculator distance-based-shipping-calculator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Distance Based Shipping Calculator: from n/a through <= 2.0.22.
AplazadaMedia (6.6)0.35%—DistributionAI11/2/202517/6/2026
Distribution is a toolkit to pack, ship, store, and deliver container content. Systems running registry versions 3.0.0-beta.1 through 3.0.0-rc.2 with token authentication enabled may be vulnerable to an issue in which token authentication allows an attacker to inject an untrusted signing key in a JSON web token (JWT).…
AnalizadaMedia (4.9)0.34%—Dell Enterprise Sonic Distribution30/1/202517/6/2026
Dell Networking Switches running Enterprise SONiC OS, version(s) prior to 4.4.1 and 4.2.3, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
AplazadaAlta (7.1)0.30%—David Jeffrey Contact Form 7 Round Robin Lead DistributionAI22/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Jeffrey Contact Form 7 Round Robin Lead Distribution contact-form-7-round-robin-lead-distribution allows Reflected XSS.This issue affects Contact Form 7 Round Robin Lead Distribution: from n/a through <= 1.2.1.
AplazadaAlta (7.6)0.45%—Contact Form 7 Round Robin Lead DistributionAI22/1/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Jeffrey Contact Form 7 Round Robin Lead Distribution contact-form-7-round-robin-lead-distribution allows SQL Injection.This issue affects Contact Form 7 Round Robin Lead Distribution: from n/a through <= 1.2.1.
AplazadaAlta (7.1)0.26%—Enituretechnology Distance Based Shipping CalculatorAI13/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in enituretechnology Distance Based Shipping Calculator distance-based-shipping-calculator allows Reflected XSS.This issue affects Distance Based Shipping Calculator: from n/a through <= 2.0.21.
AplazadaAlta (7)0.20%—RedistimeseriesAI8/1/202517/6/2026
RedisTimeSeries is a time-series database (TSDB) module for Redis, by Redis. Executing one of these commands TS.QUERYINDEX, TS.MGET, TS.MRAGE, TS.MREVRANGE by an authenticated user, using specially crafted command arguments may cause an integer overflow, a subsequent heap overflow, and potentially lead to remote code…
AplazadaAlta (8.5)0.42%—Enituretechnology Distance Based Shipping CalculatorAI28/11/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology Distance Based Shipping Calculator distance-based-shipping-calculator allows SQL Injection.This issue affects Distance Based Shipping Calculator: from n/a through <= 2.0.23.
AplazadaMedia (6)0.30%—Intel Distribution OF Openvino Model ServerAI13/11/202417/6/2026
Improper input validation in the Intel(R) Distribution of OpenVINO(TM) Model Server software before version 2024.0 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
AplazadaMedia (5.4)0.15%—Intel Distribution FOR PythonAI13/11/202417/6/2026
Incorrect default permissions in some Intel(R) Distribution for Python software before version 2024.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaAlta (7.2)1.4%—Dell Enterprise Sonic Distribution8/11/202417/6/2026
Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. This is a critical…
AnalizadaAlta (7.2)1.4%—Dell Enterprise Sonic Distribution8/11/202417/6/2026
Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. This is a critical…
AnalizadaCrítica (9.8)0.52%—Dell Enterprise Sonic Distribution8/11/202417/6/2026
Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) a Missing Critical Step in Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. This is a critical severity vulnerability so Dell recommends…
AplazadaAlta (8.8)0.37%—Trtek Software Distant Education PlatformAI9/10/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TRtek Software Distant Education Platform allows SQL Injection, Parameter Injection. This issue affects Distant Education Platform: before 3.2024.11.
AnalizadaAlta (7.8)0.43%—Microsoft Visual C++ RedistributableMicrosoft Visual Studio 2017Microsoft Visual Studio 2019Microsoft Visual Studio 20228/10/20247/7/2026
Visual C++ Redistributable Installer Elevation of Privilege Vulnerability
AnalizadaMedia (5.8)0.13%—Intel Distribution FOR GDBIntel Oneapi Base Toolkit14/8/202417/6/2026
Improper buffer restrictions in some Intel(R) Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable denial of service via local access.
AnalizadaBaja (1)0.13%—Intel Distribution FOR GDBIntel Oneapi Base Toolkit14/8/202417/6/2026
Improper input validation for some Intel(R) Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable denial of service via local access.
AnalizadaMedia (5.4)0.13%—Intel Distribution FOR GDBIntel Oneapi Base Toolkit14/8/202417/6/2026
Incorrect default permissions in some Intel(R) Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaMedia (5.4)0.15%—Intel Distribution FOR GDBIntel Oneapi Base Toolkit14/8/202417/6/2026
Uncontrolled search path in some Intel(R) Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaCrítica (9.1)30%💥 ExploitDistinct Intranet ServersAI21/6/202416/6/2026
Multiple directory traversal vulnerabilities in the TFTP Server in Distinct Intranet Servers 3.10 and earlier allow remote attackers to read or write arbitrary files via a .. (dot dot) in the (1) get or (2) put commands.
ModificadaAlta (7.5)0.81%—Redhat Openshift Container PlatformRedhat Openshift Distributed Tracing5/6/202417/6/2026
A flaw was found in OpenShift's Telemeter. If certain conditions are in place, an attacker can use a forged token to bypass the issue ("iss") check during JSON web token (JWT) authentication.
AplazadaMedia (6.7)0.17%—Intel Distribution FOR GDBAI16/5/202417/6/2026
Uncontrolled search path for some Intel(R) Distribution for GDB software before version 2024.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaAlta (7.5)1.1%—Powerdns DnsdistAI14/5/202417/6/2026
When incoming DNS over HTTPS support is enabled using the nghttp2 provider, and queries are routed to a tcp-only or DNS over TLS backend, an attacker can trigger an assertion failure in DNSdist by sending a request for a zone transfer (AXFR or IXFR) over DNS over HTTPS, causing the process to stop and thus leading to…
AnalizadaCrítica (9.8)2.9%—89luca89 Distrobox21/3/202417/6/2026
Distrobox before 1.7.0.1 allows attackers to execute arbitrary code via command injection into exported executables.
Orbitaley — Vulnerabilidades