Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
1334 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.8) | 0.18% | — | Asustek Computer Asus Bios Flash DriverAI | 22/5/2024 | 17/6/2026 | An issue in the component AsusBSItf.sys of ASUSTeK Computer Inc ASUS BIOS Flash Driver v3.2.12.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests. | |
| Analizada | Alta (7.8) | 0.35% | — | Phoenixtech Winflash | 14/5/2024 | 17/6/2026 | Exposed IOCTL with Insufficient Access Control in Phoenix WinFlash Driver on Windows allows Privilege Escalation which allows for modification of system firmware.This issue affects WinFlash Driver: before 4.5.0.0. | |
| Aplazada | Crítica (9.8) | 0.50% | — | Prestaddons FlashsalesAI | 29/4/2024 | 17/6/2026 | SQL Injection vulnerability in Prestaddons flashsales 1.9.7 and before allows an attacker to run arbitrary SQL commands via the FsModel::getFlashSales method. | |
| Aplazada | Media (5.4) | 0.21% | — | Kimili Flash EmbedAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Michael Bester Kimili Flash Embed.This issue affects Kimili Flash Embed: from n/a through 2.5.3. | |
| Aplazada | Alta (8.1) | 0.43% | — | Enilu Web-flashAI | 8/4/2024 | 17/6/2026 | An issue discovered in web-flash v3.0 allows attackers to reset passwords for arbitrary users via crafted POST request to /prod-api/user/resetPassword. | |
| Analizada | Media (5.4) | 0.55% | — | Remyandrade Flashcard Quiz APP | 1/3/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Flashcard Quiz App 1.0. This affects an unknown part of the file /endpoint/update-flashcard.php. The manipulation of the argument question/answer leads to cross site scripting. It is possible to initiate the attack remotely. The exploit… | |
| Modificada | Alta (7.8) | 0.19% | — | Intel ONE Boot Flash Update | 14/2/2024 | 17/6/2026 | Protection mechanism failure in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Crítica (9.8) | 1.7% | — | Milboj Flash Tool | 12/12/2023 | 16/6/2026 | The flash_tool gem through 0.6.0 for Ruby allows command execution via shell metacharacters in the name of a downloaded file. | |
| Modificada | Media (5.4) | 0.42% | — | Sureshkumarmukhiya Anywhere Flash Embed | 22/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Suresh KUMAR Mukhiya Anywhere Flash Embed plugin <= 1.0.5 versions. | |
| Modificada | Alta (7.8) | 0.20% | — | Intel ONE Boot Flash Update | 14/11/2023 | 17/6/2026 | Improper access control in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.19% | — | Intel ONE Boot Flash Update | 14/11/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.19% | — | Intel ONE Boot Flash Update | 14/11/2023 | 17/6/2026 | Improper access control in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.2) | 0.40% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile Hx1331 Firmware+54 | 25/10/2023 | 17/6/2026 | An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected. | |
| Modificada | Alta (8.8) | 0.52% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile Hx1331 Firmware+119 | 25/10/2023 | 17/6/2026 | An authenticated XCC user can change permissions for any user through a crafted API command. | |
| Modificada | Alta (8.1) | 0.55% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile Hx1331 Firmware+54 | 25/10/2023 | 17/6/2026 | An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected. | |
| Modificada | Alta (7.1) | 0.19% | — | Insyde H2offtInsyde Iscflashx64.sys | 8/9/2023 | 17/6/2026 | An issue was discovered in iscflashx64.sys 3.9.3.0 in Insyde H2OFFT 6.20.00. When handling IOCTL 0x22229a, the input used to allocate a buffer and copy memory is mishandled. This could cause memory corruption or a system crash. | |
| Modificada | Media (6.5) | 3.0% | — | Redhat Enterprise LinuxXENIntel MicrocodeIntel Xeon E-2314 Firmware+530 | 11/8/2023 | 17/6/2026 | Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Alta (7.5) | 0.92% | — | Cdwanjiang Flash Flood Disaster Monitoring AND Warning System | 5/8/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This issue affects some unknown processing of the file \Service\FileHandler.ashx. The manipulation of the argument FileDirectory leads to absolute path traversal. The attack may be… | |
| Modificada | Media (5.3) | 1.1% | — | Cdwanjiang Flash Flood Disaster Monitoring AND Warning System | 5/8/2023 | 17/6/2026 | A vulnerability classified as problematic was found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This vulnerability affects unknown code of the file \Service\FileDownload.ashx. The manipulation of the argument Files leads to path traversal: '../filedir'. The attack can be initiated remotely. The… | |
| Modificada | Crítica (9.8) | 0.90% | — | Cdwanjiang Flash Flood Disaster Monitoring AND Warning System | 21/7/2023 | 17/6/2026 | A vulnerability classified as problematic was found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This vulnerability affects unknown code of the file /Service/FileHandler.ashx. The manipulation of the argument userFile leads to unrestricted upload. The exploit has been disclosed to the public and… | |
| Modificada | Baja (3.7) | 0.67% | — | Cdwanjiang Flash Flood Disaster Monitoring AND Warning System | 21/7/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This affects an unknown part of the file /Service/ImageStationDataService.asmx of the component File Name Handler. The manipulation leads to insufficiently random values. The complexity of an… | |
| Modificada | Crítica (9.8) | 0.95% | — | Cdwanjiang Flash Flood Disaster Monitoring AND Warning System | 21/7/2023 | 17/6/2026 | A vulnerability was found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /Controller/Ajaxfileupload.ashx. The manipulation of the argument file leads to unrestricted upload. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.89% | — | Cdwanjiang Flash Flood Disaster Monitoring AND Warning System | 20/7/2023 | 17/6/2026 | A vulnerability has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0 and classified as critical. This vulnerability affects unknown code of the file /App_Resource/UEditor/server/upload.aspx. The manipulation of the argument file leads to unrestricted upload. The exploit has been disclosed… | |
| Modificada | Media (6.7) | 0.16% | — | Intel ONE Boot Flash Update | 10/5/2023 | 17/6/2026 | Improper access control in kernel mode driver for the Intel(R) OFU software before version 14.1.30 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.18% | — | Intel ONE Boot Flash Update | 10/5/2023 | 17/6/2026 | Improper access control in kernel mode driver for the Intel(R) OFU software before version 14.1.30 may allow an authenticated user to potentially enable escalation of privilege via local access |