Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2712▼ 359 respecto a la semana anterior
Críticas / altas1261▼ 231 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
–

1833 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
El protocolo HTTP/2 permite una denegación de servicio (consumo de recursos del servidor) porque la cancelación de solicitudes puede restablecer muchas transmisiones rápidamente, como se explotó en la naturaleza entre agosto y octubre de 2023.
ModificadaAlta (8.8)0.26%—Toolstack Schedule Posts Calendar6/10/202317/6/2026
Vulnerabilidad de Cross-Site Request Forgery (CSRF) en el complemento Greg Ross Schedule Posts Calendar en versiones <= 5.2.
ModificadaAlta (7.8)0.44%—Xiph Vorbis-tools2/10/202317/6/2026
La vulnerabilidad de desbordamiento de búfer en Vorbis-tools v.1.4.2 permite a un atacante local ejecutar código arbitrario y provocar una denegación de servicio durante la conversión de archivos wav a archivos ogg.
ModificadaMedia (6.1)0.38%—Codestag Stagtools25/9/202317/6/2026
Vulnerabilidad de Cross-Site Scripting (XSS) Reflejada No Autenticada en Ram Ratan Maurya, complemento Codestag StagTools en versiones <= 2.3.7.
ModificadaMedia (4.8)0.37%—Toolstack Schedule Posts Calendar6/9/202317/6/2026
Vulnerabilidad de Cross-Site Scripting (XSS) autenticada (con permisos de admin o superiores) almacenada en el complemento Greg Ross Schedule Posts Calendar versiones <= 5.2.
ModificadaAlta (7.5)1.5%—Vmware ToolsVmware Open VM ToolsFedoraproject FedoraDebian Linux+131/8/202317/6/2026
Un actor malicioso al que se le han otorgado Privilegios de Operación de Invitado https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html en una máquina virtual de destino es posible que pueda elevar sus privilegios si a esa máquina virtual de destino se le ha…
ModificadaAlta (7.8)0.40%—OGG Video Tools Project OGG Video Tools22/8/202317/6/2026
Buffer Overflow vulnerability in ExtractorInformation function in streamExtractor.cpp in oggvideotools 0.9.1 allows remaote attackers to run arbitrary code via opening of crafted ogg file.
ModificadaMedia (5.5)0.48%—OGG Video Tools Project OGG Video Tools22/8/202317/6/2026
A Segmentation Fault issue discovered StreamSerializer::extractStreams function in streamSerializer.cpp in oggvideotools 0.9.1 allows remote attackers to cause a denial of service (crash) via opening of crafted ogg file.
ModificadaAlta (7.8)0.72%—OGG Video Tools Project OGG Video Tools22/8/202317/6/2026
Buffer Overflow vulnerability in oggvideotools 0.9.1 allows remote attackers to run arbitrary code via opening of crafted ogg file.
ModificadaMedia (5.5)0.13%—Dell Replay Manager FOR VmwareDell Storage Integration Tools FOR VmwareDell Storage Vsphere Client Plugin16/8/202317/6/2026
Las versiones Dell Storage Integration Tools para VMware (DSITV) y Dell Storage vSphere Client Plugin (DSVCP) anteriores a la 6.1.1 y Replay Manager para las versiones VMware (RMSV) anteriores a la 3.1.2 contienen una vulnerabilidad de divulgación de información. Un usuario malintencionado local con pocos privilegios…
ModificadaMedia (6.5)1.7%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Visual Studio 2010 Tools FOR Office Runtime+38/8/202310/8/2026
Visual Studio Tools for Office Runtime Spoofing Vulnerability
ModificadaMedia (6.5)2.8%—MIT Kerberos 5Debian LinuxNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+37/8/202317/6/2026
lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.
ModificadaMedia (6.1)0.37%—Oracle JD Edwards Enterpriseone Tools18/7/202317/6/2026
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.7.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.…
ModificadaAlta (8.4)0.21%—Oracle Peoplesoft Enterprise Peopletools18/7/202317/6/2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to…
ModificadaAlta (8.8)0.25%—LWS Tools11/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in LWS LWS Tools plugin <= 2.4.1 versions.
AnalizadaBaja (3.9)14%⚠ Explotación activaVmware ToolsDebian LinuxFedoraproject Fedora13/6/202317/6/2026
Un host ESXi totalmente comprometido puede obligar a VMware Tools a no poder autenticar las operaciones de host a invitado, lo que afecta la confidencialidad y la integridad de la máquina virtual invitada.
ModificadaMedia (5.5)0.23%—Vmware Tools7/6/202317/6/2026
VMware Tools for Windows (12.x.y prior to 12.1.5, 11.x.y and 10.x.y) contains a denial-of-service vulnerability in the VM3DMP driver. A malicious actor with local user privileges in the Windows guest OS, where VMware Tools is installed, can trigger a PANIC in the VM3DMP driver leading to a denial-of-service condition…
ModificadaMedia (6.1)0.78%—Legalweb WP Dsgvo Tools7/6/202317/6/2026
The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to, and including, 3.1.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
ModificadaMedia (6.5)0.94%—Redhat Openshift API FOR Data ProtectionRedhat Openshift Container PlatformRedhat Openshift Developer Tools AND Services6/6/202317/6/2026
A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large value for `n,` causing the allocation of a massive string array,…
ModificadaAlta (7.5)1.9%—OpenldapRedhat Enterprise LinuxApple MacosNetapp Active IQ Unified Manager+730/5/202317/6/2026
A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
ModificadaMedia (5.5)0.23%—ABB Platform Engineering ToolsABB QCS 800xa FirmwareABB QCS Ac450 Firmware22/5/202317/6/2026
Insertion of Sensitive Information into Log File vulnerability in ABB QCS 800xA, ABB QCS AC450, ABB Platform Engineering Tools. An attacker, who already has local access to the QCS nodes, could successfully obtain the password for a system user account. Using this information, the attacker could have the potential to…
ModificadaMedia (5.4)0.44%—Codestag Stagtools2/5/202317/6/2026
The StagTools WordPress plugin before 2.3.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (5.5)0.32%—Swftools27/4/202317/6/2026
swfrender v0.9.2 was discovered to contain a heap buffer overflow in the function enumerateUsedIDs_fillstyle at modules/swftools.c
ModificadaMedia (4.9)0.63%—Oracle Peoplesoft Enterprise Peopletools18/4/202317/6/2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search). Supported versions that are affected are 8.58, 8.59 and 8.60. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.…
ModificadaMedia (5.4)0.38%—Oracle JD Edwards Enterpriseone Tools18/4/202317/6/2026
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.7.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful…