Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 166 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

1921 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.7)0.17%—Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+43023/6/202317/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable
ModificadaMedia (6.7)0.17%—Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+43023/6/202317/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
ModificadaMedia (6.7)0.17%—Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+43023/6/202317/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
ModificadaMedia (6.7)0.17%—Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+43023/6/202317/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
ModificadaMedia (6.1)0.21%—Updraftplus22/6/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in UpdraftPlus.Com, DavidAnderson UpdraftPlus WordPress Backup Plugin <= 1.23.3 versions leads to sitewide Cross-Site Scripting (XSS).
ModificadaMedia (6.1)0.51%—Datev EG Personal-management System Comfort/comfort Plus22/6/202317/6/2026
A reflected cross-site scripting (XSS) vulnerability in DATEV eG Personal-Management System Comfort/Comfort Plus v15.1.0 to v16.1.1 P4 allows attackers to steal targeted users' login data by sending a crafted link.
ModificadaAlta (7.5)0.74%—Joyplus-cms Project Joyplus-cms20/6/202317/6/2026
SQL injection vulnerability found in Joyplus-cms v.1.6.0 allows a remote attacker to access sensitive information via the id parameter of the goodbad() function.
ModificadaCrítica (9.8)6.0%💥 PoCZohocorp Manageengine Adselfservice Plus20/6/202317/6/2026
Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby achieving the privileges of the domain controller administrator. NOTE: the vendor's perspective is that they have "found no evidence or detail…
ModificadaCrítica (9.8)0.59%—Draytek MyvigorDraytek Vigorswitch Pq2200xb FirmwareDraytek Vigorswitch Pq2121x FirmwareDraytek Vigorswitch P2540xs Firmware+681/6/202317/6/2026
Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and Myvigor firmware versions below 2.3.2 were discovered to use hardcoded encryption keys which allows attackers to bind any affected device to their own account. Attackers…
ModificadaMedia (6.1)0.59%—Simplr Registration Form Plus+ Project Simplr Registration Form Plus+31/5/202317/6/2026
A vulnerability was found in Simplr Registration Form Plus+ Plugin up to 2.3.4 on WordPress and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 2.3.5 is able to address this issue. The…
ModificadaAlta (7.1)0.30%—ZTE Blade A52 FirmwareZTE Blade A51 FirmwareZTE Blade A3 Lite FirmwareZTE Blade A5 2020 Firmware+1330/5/202317/6/2026
There is an unauthorized access vulnerability in some ZTE mobile phones. If a malicious application is installed on the phone, it could delete some system files without user permission.
ModificadaBaja (3.3)0.29%—ZTE Blade A52 FirmwareZTE Blade A51 FirmwareZTE Blade A3 Lite FirmwareZTE Blade A5 2020 Firmware+1330/5/202317/6/2026
There is an unauthorized access vulnerability in some ZTE mobile phones. If a malicious application is installed on the phone, it could start a non-public interface of an application without user permission.
ModificadaAlta (7.1)0.30%—ZTE Blade A52 FirmwareZTE Blade A51 FirmwareZTE Blade A3 Lite FirmwareZTE Blade A5 2020 Firmware+1330/5/202317/6/2026
There is an unauthorized access vulnerability in some ZTE mobile phones. If a malicious application is installed on the phone, it could overwrite some system configuration files and user installers without user permission.
ModificadaAlta (8.8)0.25%—Resize AT Upload Plus Project Resize AT Upload Plus26/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Daniel Mores, A. Huizinga Resize at Upload Plus plugin <= 1.3 versions.
ModificadaAlta (7.8)0.19%—Bitdefender Antivirus PlusBitdefender Internet SecurityBitdefender Total Security24/5/202317/6/2026
Unquoted Search Path or Element vulnerability in the Vulnerability Scan component of Bitdefender Total Security, Bitdefender Internet Security, and Bitdefender Antivirus Plus allows an attacker to elevate privileges to SYSTEM. This issue affects: Bitdefender Total Security versions prior to 26.0.10.45. Bitdefender…
ModificadaCrítica (9.8)1.1%—Sudytech Webplus PRO23/5/202317/6/2026
WebPlus Pro v1.4.7.8.4-01 is vulnerable to Incorrect Access Control.
ModificadaMedia (4.8)0.39%—Gopiplus Continuous Announcement Scroller10/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Continuous announcement scroller plugin <= 13.0 versions.
ModificadaMedia (4.8)0.37%—Gopiplus Tiny Carousel Horizontal Slider Plus10/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Tiny carousel horizontal slider plus plugin <= 3.2 versions.
ModificadaMedia (6.1)0.55%—Rediker Adminplus3/5/202317/6/2026
Cross Site Scripting (XSS) vulnerability in Rediker Software AdminPlus 6.1.91.00 allows remote attackers to run arbitrary code via the onload function within the application DOM.
ModificadaAlta (7.8)0.81%—Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Pam360Zohocorp Manageengine Password Manager PRO26/4/202317/6/2026
Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and ManageEngine PAM360. These credentials could allow a malicious actor to modify configuration data that would escalate their permissions from that of a low-privileged user to…
ModificadaMedia (4.9)3.0%—Zohocorp Manageengine AssetexplorerZohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus26/4/202317/6/2026
Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint.
ModificadaAlta (8.8)0.36%—Schneider-electric Merten Instabus Tastermodul 1fach System M FirmwareSchneider-electric Merten Instabus Tastermodul 2fach System M FirmwareSchneider-electric Merten Tasterschnittstelle 4fach Plus FirmwareSchneider-electric Merten KNX Argus 180/2,20m UP System Firmware+318/4/202317/6/2026
A CWE-287: Improper Authentication vulnerability exists that could allow a device to be compromised when a key of less than seven digits is entered and the attacker has access to the KNX installation.
ModificadaAlta (8.8)0.80%—Xxyopen Novel-plus14/4/202317/6/2026
Una vulnerabilidad clasificada como crítica se encontró en novel-plus 3.6.2. Esta vulnerabilidad afecta a una funcionalidad desconocida del archivo /category/list?limit=10&amp;offset=0&amp;order=desc. La manipulación del argumento sort conduce a la inyección sql. El ataque se puede lanzar de forma remota. El exploit…
ModificadaAlta (8.8)0.75%—Xxyopen Novel-plus14/4/202317/6/2026
Se ha encontrado una vulnerabilidad clasificada como crítica en novel-plus 3.6.2. Afectado es una función desconocida del archivo /news/list?limit=10&amp;offset=0&amp;order=desc. La manipulación del argumento sort conduce a la inyección sql. Es posible lanzar el ataque de forma remota. El exploit ha sido divulgado al…
ModificadaAlta (8.8)0.80%—Xxyopen Novel-plus14/4/202317/6/2026
Se encontró una vulnerabilidad en novel-plus 3.6.2. Ha sido calificado como crítico. Este problema afecta a un procesamiento desconocido del archivo /author/list?limit=10&amp;offset=0&amp;order=desc. La manipulación del argumento sort conduce a la inyección sql. El ataque puede iniciarse de forma remota. El exploit ha…