Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2851▼ 221 respecto a la semana anterior
Críticas / altas1331▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
–

1921 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.0%—Xxyopen Novel-plus11/9/202317/6/2026
novel-plus 3.6.2 es vulnerable a la inyección SQL.
ModificadaMedia (6.8)25%—Zohocorp Manageengine Adselfservice Plus6/9/202317/6/2026
ManageEngine ADSelfService Plus GINA Client Verificación insuficiente de autenticidad de datos Vulnerabilidad de omisión de autenticación. Esta vulnerabilidad permite a atacantes físicamente presentes ejecutar código arbitrario en instalaciones afectadas de ManageEngine ADSelfService Plus. No se requiere autenticación…
ModificadaMedia (4.8)0.36%—Gopiplus Wp-tell-a-friend-popup-form4/9/202317/6/2026
Vulnerabilidad de Coss-Site Scripting (XSS) autenticada (con permisos de admin o superiores) almacenada en el plugin Gopi Ramasamy wp tell a friend popup form en versiones inferiores e incluyendo la 7.1.
AnalizadaMedia (4.9)3.8%—Zohocorp Manageengine Admanager Plus31/8/202317/6/2026
Zoho ManageEngine ADManager Plus anterior a 7203 permite a los usuarios de Técnico de Mesa de Ayuda leer archivos arbitrarios en la máquina donde está instalado este producto.
ModificadaAlta (8.1)2.4%—Zohocorp Manageengine Ad360Zohocorp Manageengine Adaudit PlusZohocorp Manageengine Admanager PlusZohocorp Manageengine Assetexplorer+1328/8/202317/6/2026
Zoho ManageEngine Active Directory 360 versiones 4315 e inferiores, ADAudit Plus 7202 e inferiores, ADManager Plus 7200 e inferiores, Asset Explorer 6993 e inferiores y 7xxx 7002 e inferiores, Cloud Security Plus 4161 e inferiores, Data Security Plus 6110 e inferiores, Eventlog Analyzer 12301 y siguientes, Exchange…
ModificadaMedia (5.5)0.41%—Notepad-plus-plus Notepad++25/8/202317/6/2026
Notepad++ es un editor de código fuente gratuito y de código abierto. Las versiones 8.5.6 y anteriores son vulnerables al desbordamiento de lectura del búfer de montón en `FileManager::detectLanguageFromTextBegining`. La explotabilidad de este problema no está clara. Potencialmente, puede ser utilizado para filtrar…
ModificadaMedia (5.5)0.50%—Notepad-plus-plus Notepad++25/8/202317/6/2026
Notepad++ es un editor de código fuente gratuito y de código abierto. Las versiones 8.5.6 y anteriores son vulnerables al desbordamiento global de lectura de búfer en `nsCodingStateMachine::NextStater`. La explotabilidad de este problema no está clara. Potencialmente, puede utilizarse para filtrar información de…
ModificadaMedia (5.5)0.38%—Notepad-plus-plus Notepad++25/8/202317/6/2026
Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to global buffer read overflow in `CharDistributionAnalysis::HandleOneChar`. The exploitability of this issue is not clear. Potentially, it may be used to leak internal memory allocation information. As of time of…
ModificadaAlta (7.8)0.52%💥 PoCNotepad-plus-plus Notepad++25/8/202317/6/2026
Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer write overflow in `Utf8_16_Read::convert`. This issue may lead to arbitrary code execution. As of time of publication, no known patches are available in existing versions of Notepad++.
ModificadaAlta (7.5)1.1%—Cpplusworld Cp-vnr-3104 FirmwareCpplusworld Cp-vnr-3108 FirmwareCpplusworld Cp-vnr-3208 Firmware24/8/202317/6/2026
The vulnerability exists in CP-Plus NVR due to an improper input handling at the web-based management interface of the affected product. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable device. Successful exploitation of this vulnerability…
ModificadaMedia (5.3)0.69%—Cpplusworld Cp-uvr-1601e1-hc FirmwareCpplusworld Cp-uvr-0401l1-4kh FirmwareCpplusworld Cp-uvr-0401l1b-4kh FirmwareCpplusworld Cp-uvr-0801f1-hc Firmware+524/8/202317/6/2026
The vulnerability exists in CP-Plus DVR due to an improper input validation within the web-based management interface of the affected products. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable device. Successful exploitation of this…
ModificadaMedia (6.5)7.9%—Zohocorp Manageengine Admanager Plus17/8/202317/6/2026
ADManager Plus versión 7182 y anteriores de ManageEngine de Zoho divulgaron las contraseñas predeterminadas para la restauración de cuentas de dominios no autorizadas a los usuarios autenticados.
ModificadaMedia (6.1)0.38%—Updraftplus Updraft17/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Paul Kehrer Updraft plugin <= 0.6.1 versions.
ModificadaBaja (3.9)0.24%—Dell Alienware M15 R7 FirmwareDell Alienware M16 FirmwareDell Alienware M18 FirmwareDell Chengming 3900 Firmware+10716/8/202317/6/2026
Dell BIOS contains an improper authentication vulnerability. A malicious user with physical access to the system may potentially exploit this vulnerability in order to modify a security-critical UEFI variable without knowledge of the BIOS administrator.
ModificadaMedia (6.3)0.19%—Dell Alienware M15 R7 FirmwareDell Alienware M16 FirmwareDell Alienware M18 FirmwareDell Chengming 3900 Firmware+23816/8/202317/6/2026
Dell BIOS contain a Time-of-check Time-of-use vulnerability in BIOS. A local authenticated malicious user with physical access to the system could potentially exploit this vulnerability by using a specifically timed DMA transaction during an SMI in order to gain arbitrary code execution on the system.
ModificadaCrítica (9.8)0.72%—Xxyopen Novel-plus14/8/20239/7/2026
Se descubrió que novel-plus v3.6.2 contenía una vulnerabilidad de inyección SQL.
ModificadaCrítica (9.8)0.76%—Oneplus Store10/8/202317/6/2026
A remote code execution vulnerability in the webview component of OnePlus Store app.
ModificadaBaja (3.3)0.29%—Ffri Dual SafeFfri YaraiSoliton Infotrace Mark II Malware ProtectionSoliton Zerona+49/8/202317/6/2026
"FFRI yarai", "FFRI yarai Home and Business Edition" and their OEM products handle exceptional conditions improperly, which may lead to denial-of-service (DoS) condition. Affected products and versions are as follows: FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0, FFRI yarai Home and Business Edition version 1.4.0,…
ModificadaAlta (7.5)3.9%—Zohocorp Manageengine Adaudit Plus7/8/202317/6/2026
The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by creating or renaming user accounts with a "$" symbol suffix. NOTE: the vendor states "We do not consider this as a security bug and it's an expected behaviour."
ModificadaMedia (6.5)3.7%—Zohocorp Manageengine Admanager Plus4/8/202317/6/2026
ADManager Plus de ManageEngine de Zoho a través de 7201 permiten a los usuarios autenticados hacerse cargo de la cuenta de otro usuario a través de la divulgación de información sensible.
ModificadaMedia (5.4)2.2%—Zohocorp Manageengine Supportcenter Plus28/7/202317/6/2026
Zoho ManageEngine Support Center Plus 14001 and below is vulnerable to stored XSS in the products module.
ModificadaMedia (6.1)1.2%💥 ExploitSrbtranslatin Project SrbtranslatinUpdraftplus Wp-optimize10/7/202317/6/2026
The WP-Optimize WordPress plugin before 3.2.13, SrbTransLatin WordPress plugin before 2.4.1 use a third-party library that removes the escaping on some HTML characters, leading to a cross-site scripting vulnerability.
ModificadaMedia (5.4)1.9%—Zohocorp Manageengine Adaudit Plus7/7/202317/6/2026
Zoho ManageEngine ADAudit Plus before 7100 allows XSS via the username field.
ModificadaMedia (5.4)3.5%—Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus7/7/202317/6/2026
Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 have a privilege escalation vulnerability in the Release module that allows unprivileged users to access the Reminders of a release ticket and make modifications.
ModificadaMedia (4.9)3.0%—Zohocorp Manageengine Admanager Plus5/7/202317/6/2026
Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files.