Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

70 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.45%—HP Z1 Entry Tower G5 Workstation FirmwareHP Z1 Entry Tower G6 Workstation FirmwareHP Z1 G8 Tower Desktop PC FirmwareHP Z4 G4 Workstation (core-x) Firmware+18316/2/202217/6/2026
A potential vulnerability in AMD System Management Mode (SMM) interrupt handler may allow an attacker with high privileges to access the SMM resulting in arbitrary code execution which could be used by malicious actors to bypass security mechanisms provided in the UEFI firmware.
ModificadaAlta (8.8)0.44%—HP 260 G3 Desktop Mini PC FirmwareHP Elitedesk 800 35W G4 Desktop Mini PC FirmwareHP Elitedesk 800 65W G4 Desktop Mini PC FirmwareHP Elitedesk 800 95W G4 Desktop Mini PC Firmware+18316/2/202217/6/2026
Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.
ModificadaAlta (7.8)0.57%—Microsoft .net Education Bundle SDK Install ToolMicrosoft .net Install Tool FOR Extension Authors14/7/202110/8/2026
Visual Studio Code .NET Runtime Elevation of Privilege Vulnerability
ModificadaMedia (6.1)0.89%—Schoolexperience Department FOR Education School Experience23/8/201917/6/2026
DfE School Experience before v16333-GA has XSS via a teacher training URL.
ModificadaCrítica (9.8)2.3%—Education Website Project Education Website19/6/201917/6/2026
SQL injection exists in Scriptzee Education Website 1.0 via the college_list.html subject, city, or country parameter.
ModificadaMedia (6.1)0.65%—Yiban Easy Class Education Platform30/5/201817/6/2026
YIBAN Easy class education platform 2.0 has XSS via the articlelist.php k parameter.
ModificadaAlta (10)2.6%—Impero Education PRO14/9/201517/6/2026
Impero Education Pro before 5105 relies on the -1|AUTHENTICATE\x02PASSWORD string for authentication, which allows remote attackers to execute arbitrary programs via an encrypted command.
ModificadaAlta (7.8)1.7%—Impero Education PRO14/9/201517/6/2026
Impero Education Pro before 5105 uses a hardcoded CBC key and initialization vector derived from a hash of the Imp3ro string, which makes it easier for remote attackers to obtain plaintext data by sniffing the network for ciphertext data.
ModificadaMedia (5.4)0.27%—Gcefcu Gulf Coast Educators FCU19/10/201417/6/2026
The Gulf Coast Educators FCU (aka com.metova.cuae.gcefcu) application 1.0.27 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Unitedecu United Educational CU29/9/201417/6/2026
The United Educational CU (aka com.metova.cuae.uecu) application 1.0.27 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Puzzles AND Matchup Games Project Educational Puzzles - Letters20/9/201417/6/2026
The Educational Puzzles - Letters (aka com.EducationalPuzzlesLetters) application 2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.5)1.0%—Joachim-ruhs Educator19/3/201016/6/2026
SQL injection vulnerability in the Educator extension 0.1.5 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (5)2.5%💥 ExploitMerlix Educate Server23/7/200916/6/2026
Merlix Educate Server stores db.mdb under the web root with insufficient access control, which allows remote attackers to obtain unspecified sensitive information via a direct request.
ModificadaMedia (5)2.7%💥 ExploitMerlix Educate Server23/7/200916/6/2026
Merlix Educate Server allows remote attackers to bypass intended security restrictions and obtain sensitive information via a direct request to (1) config.asp and (2) users.asp.
ModificadaMedia (5)8.8%💥 ExploitPearson Education Powerschool21/2/200716/6/2026
Pearson Education PowerSchool 4.3.6 allows remote attackers to list the contents of the admin folder via a URI composed of the admin/ directory name and an arbitrary filename ending in ".js." NOTE: it was later reported that this issue had been addressed by 5.1.2.
ModificadaAlta (7.8)3.0%💥 ExploitArsdigita Community Education SolutionArsdigita Community System19/1/200716/6/2026
Directory traversal vulnerability in ArsDigita Community System (ACS) 3.4.10 and earlier, and ArsDigita Community Education Solution (ACES) 1.1, allows remote attackers to read arbitrary files via .%252e/ (double-encoded dot dot slash) sequences in the URI.
ModificadaAlta (7.5)1.1%💥 ExploitOnline Solutions FOR Educators28/5/200516/6/2026
SQL injection vulnerability in login.asp in an unknown product by Online Solutions for Educators (OS4E) allows remote attackers to execute arbitrary SQL commands via the password.
ModificadaMedia (4.3)1.3%—Scripts FOR Educators Sillysearch31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in SillySearch 2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.
ModificadaMedia (6.8)4.4%💥 ExploitBBC Education Betsie4/10/200216/6/2026
Cross-site scripting (XSS) vulnerability in BBC Education Text to Speech Internet Enhancer (Betsie) 1.5.11 and earlier allows remote attackers to execute arbitrary web script via parserl.pl.
ModificadaAlta (7.5)7.6%💥 ExploitScripts FOR Educators Makebook4/10/200216/6/2026
Scripts For Educators MakeBook 2.2 CGI program allows remote attackers to execute script as other visitors, or execute server-side includes (SSI) as the web server, via the (1) Name or (2) Email parameters, which are not properly filtered.
Orbitaley — Vulnerabilidades