Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2823▼ 249 respecto a la semana anterior
Críticas / altas1318▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

1770 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)2.0%—Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+1315/5/202317/6/2026
An authenticated, remote attacker may use a out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into memory which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
AnalizadaMedia (6.5)0.91%—Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+1315/5/202317/6/2026
Multiple CODESYS products in multiple versions are prone to a improper input validation vulnerability. An authenticated remote attacker may craft specific requests that use the vulnerability leading to a denial-of-service condition.
ModificadaAlta (7.8)0.14%—Intel Oneapi AI Analytics ToolkitIntel Oneapi Base ToolkitIntel Oneapi DL Framework Developer ToolkitIntel Oneapi HPC Toolkit+212/5/202317/6/2026
Improper access control for Intel(R) oneAPI Toolkits before version 2021.1 Beta 10 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaCrítica (9.8)76%💥 ExploitWpdeveloper Essential Addons FOR Elementor12/5/202317/6/2026
Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essential Addons for Elementor: from 5.4.0 through 5.7.1.
ModificadaAlta (7.5)0.99%—Cauldrondevelopment Cbang28/4/202317/6/2026
tar/TarFileReader.cpp in Cauldron cbang before bastet-v8.1.17 has a directory traversal during extraction that allows the attacker to create or write to files outside the current directory via a crafted tar archive.
ModificadaCrítica (9.6)23%—Expo Software Development KIT24/4/202317/6/2026
A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that configured the "Expo AuthSession Redirect Proxy" for social sign-in. This can be achieved once a victim clicks a malicious link. The link itself may be sent to the victim in various…
ModificadaMedia (6.7)0.22%—Oracle SQL Developer18/4/202317/6/2026
Vulnerability in Oracle SQL Developer (component: Installation). Supported versions that are affected are Prior to 23.1.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle SQL Developer executes to compromise Oracle SQL Developer. Successful attacks of this…
ModificadaAlta (7.8)0.64%—Autodesk FBX Software Development KIT17/4/202317/6/2026
A user may be tricked into opening a malicious FBX file that may exploit a heap buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior which may lead to code execution.
ModificadaAlta (7.8)0.53%—Autodesk FBX Software Development KIT17/4/202317/6/2026
A user may be tricked into opening a malicious FBX file that may exploit a stack buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior which may lead to code execution.
ModificadaAlta (7.8)0.49%—Autodesk FBX Software Development KIT17/4/202317/6/2026
An Out-Of-Bounds Write Vulnerability in Autodesk® FBX® SDK version 2020 or prior may lead to code execution through maliciously crafted FBX files or information disclosure.
ModificadaMedia (6.5)0.31%—Silabs Gecko Software Development KIT28/3/202317/6/2026
An invalid ‘prepare write request’ command can cause the Bluetooth LE stack to run out of memory and fail to be able to handle subsequent connection requests, resulting in a denial-of-service.
ModificadaAlta (8.8)0.88%—Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+1223/3/202317/6/2026
In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files and OS resources or DoS the device.
ModificadaMedia (6.5)0.65%—Sentry Software Development KIT22/3/202317/6/2026
Sentry SDK is the official Python SDK for Sentry, real-time crash reporting software. When using the Django integration of versions prior to 1.14.0 of the Sentry SDK in a specific configuration it is possible to leak sensitive cookies values, including the session cookie to Sentry. These sensitive cookies could then…
ModificadaMedia (5.3)0.44%—Silabs Wi-sun Software Development KIT21/3/202317/6/2026
Missing MAC layer security in Silicon Labs Wi-SUN SDK v1.5.0 and earlier allows malicious node to route malicious messages through network.
ModificadaMedia (4.3)0.46%—Xibodevelopment Backupwordpress7/3/202317/6/2026
The BackupWordPress plugin for WordPress is vulnerable to information disclosure in versions up to, and including 3.12. This is due to missing authorization on the heartbeat_received() function that triggers on WordPress heartbeat. This makes it possible for authenticated attackers, with subscriber-level permissions…
ModificadaAlta (8.8)0.87%—Wpdeveloper Reviewx23/2/202317/6/2026
The 'rx_export_review' action in the ReviewX WordPress Plugin, is affected by an authenticated SQL injection vulnerability in the 'filterValue' and 'selectedColumns' parameters.
ModificadaCrítica (9.8)1.4%—Instantdeveloper RD322/2/202317/6/2026
La vulnerabilidad de carga de archivos en Pro Gamma Instant Developer RD3 22.5 r23, r30 y posiblemente versiones anteriores, permite a los atacantes ejecutar código arbitrario.
ModificadaMedia (5.5)0.23%—Intel Media Software Development KIT16/2/202317/6/2026
Protection mechanism failure in the Intel(R) Media SDK software before version 22.2.2 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaMedia (5.5)0.20%—Intel Media Software Development KIT16/2/202317/6/2026
NULL pointer dereference in the Intel(R) Media SDK software before version 22.2.2 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaAlta (7.8)0.25%—Intel Media Software Development KIT16/2/202317/6/2026
Improper buffer restrictions in the Intel(R) Media SDK software before version 22.2.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.25%—Intel Media Software Development KIT16/2/202317/6/2026
Out-of-bounds read in the Intel(R) Media SDK software before version 22.2.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.25%—Intel Media Software Development KIT16/2/202317/6/2026
Protection mechanism failure in the Intel(R) Media SDK software before version 22.2.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.3)0.18%—Intel Fpga Software Development KITIntel Quartus Prime16/2/202317/6/2026
Uncontrolled search path in some Intel(R) Quartus(R) Prime Pro and Standard Edition software may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.17%—Intel Fpga Software Development KITIntel Quartus Prime16/2/202317/6/2026
Improper access control in the Intel(R) FPGA SDK for OpenCL(TM) with Intel(R) Quartus(R) Prime Pro Edition software before version 22.1 may allow authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.3)0.32%—Splunk Add-on BuilderSplunk Cloudconnect Software Development KIT14/2/202317/6/2026
In Splunk Add-on Builder (AoB) versions below 4.1.2 and the Splunk CloudConnect SDK versions below 3.1.3, requests to third-party APIs through the REST API Modular Input incorrectly revert to using HTTP to connect after a failure to connect over HTTPS occurs.