Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
171 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 1.7% | — | Vtiger CRM | 30/4/2024 | 17/6/2026 | modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint allows them to write this code to the config.inc.php file (executed on every page load). | |
| Aplazada | Media (6.7) | 0.22% | — | CalicoAITigera Calico EnterpriseAITigera Calico CloudAI | 29/4/2024 | 17/6/2026 | In vulnerable versions of Calico (v3.27.2 and below), Calico Enterprise (v3.19.0-1, v3.18.1, v3.17.3 and below), and Calico Cloud (v19.2.0 and below), an attacker who has local access to the Kubernetes node, can escalate their privileges by exploiting a vulnerability in the Calico CNI install binary. The issue arises… | |
| Aplazada | Media (6.5) | 0.32% | — | Presstigers Simple Testimonials ShowcaseAI | 17/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PressTigers Simple Testimonials Showcase allows Stored XSS.This issue affects Simple Testimonials Showcase: from n/a through 1.1.5. | |
| Modificada | Crítica (9.8) | 1.2% | — | Presstigers Simple JOB Board | 9/4/2024 | 17/6/2026 | The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.11.0 via deserialization of untrusted input in the job_board_applicant_list_columns_value function. This makes it possible for unauthenticated attackers to inject a PHP Object. If a POP chain is… | |
| Modificada | Media (5.3) | 0.91% | — | Presstigers Simple JOB Board | 21/2/2024 | 17/6/2026 | The Simple Job Board plugin for WordPress is vulnerable to unauthorized access of data| due to insufficient authorization checking on the fetch_quick_job() function in all versions up to, and including, 2.10.8. This makes it possible for unauthenticated attackers to fetch arbitrary posts, which can be password… | |
| Modificada | Alta (7.8) | 0.36% | — | TigervncX.org X ServerX.org XwaylandFedoraproject Fedora+8 | 18/1/2024 | 17/6/2026 | A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at creation. It uses the cursor bits type with the cursor as private, and when initiating the cursor, that overwrites the XSELINUX context. | |
| Modificada | Media (5.5) | 0.32% | — | TigervncX.org X ServerX.org XwaylandFedoraproject Fedora+8 | 18/1/2024 | 17/6/2026 | A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unlabeled. When the client issues another request to access that resource (as with a GetGeometry) or when it creates another resource that needs to access that buffer, such as a GC, the XSELINUX… | |
| Modificada | Alta (8.8) | 0.22% | — | Presstigers Simple JOB Board | 5/1/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PressTigers Simple Job Board.This issue affects Simple Job Board: from n/a through 2.10.6. | |
| Modificada | Alta (7.5) | 1.6% | — | X.org X ServerX.org XwaylandRedhat Enterprise Linux EUSDebian Linux+1 | 13/12/2023 | 23/6/2026 | A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive information. | |
| Modificada | Alta (7.8) | 1.6% | — | Redhat Enterprise Linux EUSDebian LinuxX.org X ServerX.org Xwayland+1 | 13/12/2023 | 23/6/2026 | A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved. | |
| Modificada | Alta (8.8) | 0.25% | — | Presstigers Simple Testimonials Showcase | 30/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PressTigers Simple Testimonials Showcase allows Cross Site Request Forgery.This issue affects Simple Testimonials Showcase: from n/a through 1.1.5. | |
| Modificada | Alta (8.8) | 0.31% | — | Presstigers Simple JOB Board | 10/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PressTigers Simple Job Board plugin <= 2.10.3 versions. | |
| Modificada | Alta (7.5) | 0.72% | — | Tigera Calico CloudTigera Calico EnterpriseTigera Calico OS | 6/11/2023 | 17/6/2026 | In certain conditions for Calico Typha (v3.26.2, v3.25.1 and below), and Calico Enterprise Typha (v3.17.1, v3.16.3, v3.15.3 and below), a client TLS handshake can block the Calico Typha server indefinitely, resulting in denial of service. The TLS Handshake() call is performed inside the main server handle for loop… | |
| Modificada | Media (6.1) | 0.41% | — | MD Jakir Hosen Tiger Forms - Drag AND Drop Form Builder | 2/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in MD Jakir Hosen Tiger Forms – Drag and Drop Form Builder plugin <= 2.0.0 versions. | |
| Modificada | Alta (8.8) | 1.3% | — | Vtiger CRM | 14/9/2023 | 17/6/2026 | SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList function in ReportRun.php. | |
| Modificada | Alta (8.8) | 0.83% | — | Tigergraph | 15/8/2023 | 17/6/2026 | An issue was discovered in Tigergraph Enterprise 3.7.0. The TigerGraph platform installs a full development toolchain within every TigerGraph deployment. An attacker is able to compile new executables on each Tigergraph system and modify system and Tigergraph binaries. | |
| Modificada | Alta (8.8) | 0.89% | — | Tigergraph | 14/8/2023 | 17/6/2026 | An issue was discovered in Tigergraph Enterprise 3.7.0. The GSQL query language provides users with the ability to write data to files on a remote TigerGraph server. The locations that a query is allowed to write to are configurable via the GSQL.FileOutputPolicy configuration setting. GSQL queries that contain UDFs… | |
| Modificada | Media (6.5) | 0.66% | — | Tigergraph | 14/8/2023 | 17/6/2026 | An issue was discovered in Tigergraph Enterprise 3.7.0. A single TigerGraph instance can host multiple graphs that are accessed by multiple different users. The TigerGraph platform does not protect the confidentiality of any data uploaded to the remote server. In this scenario, any user that has permissions to upload… | |
| Modificada | Alta (8.8) | 0.70% | — | Tigergraph | 14/8/2023 | 17/6/2026 | An issue was discovered in Tigergraph Enterprise 3.7.0. There is unsecured write access to SSH authorized keys file. Any code running as the tigergraph user is able to add their SSH public key into the authorised keys file. This allows an attacker to obtain password-less SSH key access by using their own SSH key. | |
| Modificada | Media (6.5) | 0.64% | — | Tigergraph | 14/8/2023 | 17/6/2026 | An issue was discovered in Tigergraph Enterprise 3.7.0. The TigerGraph platform allows users to define new User Defined Functions (UDFs) from C/C++ code. To support this functionality TigerGraph allows users to upload custom C/C++ code which is then compiled and installed into the platform. An attacker who has… | |
| Modificada | Media (4.9) | 0.42% | — | Tigergraph CloudTigergraph Enterprise | 14/4/2023 | 17/6/2026 | An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is logging of user credentials. All authenticated GSQL access requests are logged by TigerGraph in multiple places. Each request includes both the username and password of the user in an easily decodable base64 form. That could allow a TigerGraph… | |
| Modificada | Alta (8.8) | 0.83% | — | Tigergraph CloudTigergraph Enterprise | 13/4/2023 | 17/6/2026 | An issue was discovered in TigerGraph Enterprise Free Edition 3.x. It creates an authentication token for internal systems use. This token can be read from the configuration file. Using this token on the REST API provides an attacker with anonymous admin-level privileges on all REST API endpoints. | |
| Modificada | Media (4.9) | 0.44% | — | Tigergraph | 13/4/2023 | 17/6/2026 | An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is unsecured read access to an SSH private key. Any code that runs as the tigergraph user is able to read the SSH private key. With this, an attacker is granted password-less SSH access to all machines in the TigerGraph cluster. | |
| Modificada | Media (6.5) | 0.70% | — | Tigergraph | 13/4/2023 | 17/6/2026 | An issue was discovered in TigerGraph Enterprise Free Edition 3.x. Data loading jobs in gsql_server, created by any user with designer permissions, can read sensitive data from arbitrary locations. | |
| Modificada | Alta (8.8) | 0.20% | — | AMD Genoa FirmwareAMD Hygon 1 FirmwareAMD Hygon 2 FirmwareAMD Hygon 3 Firmware+35 | 15/11/2022 | 17/6/2026 | Incorrect pointer checks within the the FwBlockServiceSmm driver can allow arbitrary RAM modifications During review of the FwBlockServiceSmm driver, certain instances of SpiAccessLib could be tricked into writing 0xff to arbitrary system and SMRAM addresses. Fixed in: INTEL Purley-R: 05.21.51.0048 Whitley:… |