Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

366 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.3)0.32%—Ability INC Accessibility SuiteAI14/2/202517/6/2026
Missing Authorization vulnerability in Ability, Inc Accessibility Suite online-accessibility allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accessibility Suite: from n/a through <= 4.18.
AplazadaMedia (5.9)0.24%—ZF Roll Stability Support PlusAI13/2/202517/6/2026
ZF Roll Stability Support Plus (RSSPlus) is vulnerable to an authentication bypass vulnerability targeting deterministic RSSPlus SecurityAccess service seeds, which may allow an attacker to remotely (proximal/adjacent with RF equipment or via pivot from J2497 telematics devices) call diagnostic functions intended for…
AplazadaAlta (7.1)0.67%—Intel AMTAIIntel Standard ManageabilityAI12/2/202517/6/2026
Improper input validation in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow an authenticated user to potentially enable denial of service via network access.
AplazadaMedia (4.6)0.23%—Intel Active Management TechnologyAIIntel Standard ManageabilityAI12/2/202517/6/2026
Improper initialization in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable information disclosure via local access.
AplazadaMedia (5.4)0.31%—Wpicalavailability WP Ical AvailabilityAI2/1/202517/6/2026
Missing Authorization vulnerability in WP iCal Availability WP iCal Availability allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP iCal Availability: from n/a through 1.0.3.
AplazadaAlta (7.1)0.41%—Preblogging Increase SociabilityAI16/12/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in preblogging Increase Sociability increase-sociability allows Reflected XSS.This issue affects Increase Sociability: from n/a through <= 1.3.0.
AnalizadaAlta (7.3)0.23%—AMD Cloud Manageability Service12/11/202417/6/2026
Incorrect default permissions in the AMD Cloud Manageability Service (ACMS) Software installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
AplazadaMedia (6.9)0.50%—Intel Active Management TechnologyAIIntel Standard ManageabilityAI14/8/202417/6/2026
Improper buffer restrictions in firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable denial of service via network access.
ModificadaMedia (5.4)0.29%—Opensearch Observability9/7/202417/6/2026
OpenSearch Observability is collection of plugins and applications that visualize data-driven events. An issue in the OpenSearch observability plugins allows unintended access to private tenant resources like notebooks. The system did not properly check if the user was the resource author when accessing resources in a…
ModificadaMedia (5.4)0.30%—Opensearch Observability9/7/202417/6/2026
OpenSearch Dashboards Reports allows ‘Report Owner’ export and share reports from OpenSearch Dashboards. An issue in the OpenSearch reporting plugin allows unintended access to private tenant resources like notebooks. The system did not properly check if the user was the resource author when accessing resources in a…
AplazadaBaja (3.3)0.17%—Intel Local Manageability ServiceAI14/3/202417/6/2026
Insertion of sensitive information into log file for some Intel(R) Local Manageability Service software before version 2316.5.1.2 may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaMedia (4.3)0.40%—Veeam Availability OrchestratorVeeam Disaster Recovery OrchestratorVeeam Recovery Orchestrator7/2/202417/6/2026
Vulnerability CVE-2024-22021 allows a Veeam Recovery Orchestrator user with a low privileged role (Plan Author) to retrieve plans from a Scope other than the one they are assigned to.
ModificadaMedia (6.1)0.27%—Usabilitydynamics Wp-invoice16/1/202417/6/2026
The WP-Invoice WordPress plugin through 4.3.1 does not have CSRF check in place when updating its settings, and is lacking sanitisation as well as escaping in some of them, allowing attacker to make a logged in admin change them and add XSS payload in them
ModificadaAlta (7.5)1.4%—Codecrafters Ability FTP Server15/1/202417/6/2026
A vulnerability has been found in Ability FTP Server 2.34 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component APPE Command Handler. The manipulation leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the public and…
ModificadaAlta (7.5)1.2%—Phpjabbers Availability Booking Calendar7/12/202317/6/2026
A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion.
ModificadaMedia (5.4)0.45%—Phpjabbers Availability Booking Calendar7/12/202317/6/2026
Availability Booking Calendar 5.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.
ModificadaMedia (6.1)0.50%—Phpjabbers Availability Booking Calendar7/12/202317/6/2026
A Cross Site Scripting vulnerability in Availability Booking Calendar 5.0 allows an attacker to inject JavaScript via the name, plugin_sms_api_key, plugin_sms_country_code, uuid, title, or country name parameter to index.php.
ModificadaAlta (8.8)1.2%—Phpjabbers Availability Booking Calendar7/12/202317/6/2026
Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component.
ModificadaAlta (8.8)0.25%—Offshorewebmaster Availability Calendar30/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Offshore Web Master Availability Calendar allows Cross Site Request Forgery.This issue affects Availability Calendar: from n/a through 1.2.6.
ModificadaMedia (4.3)0.48%—Jenkins Neuvector Vulnerability Scanner29/11/202317/6/2026
A missing permission check in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified hostname and port using attacker-specified username and password.
ModificadaAlta (8.8)0.45%—Jenkins Neuvector Vulnerability ScannerJenkins JiraJenkins Google Compute EngineJenkins Matlab29/11/202317/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier allows attackers to connect to an attacker-specified hostname and port using attacker-specified username and password.
ModificadaMedia (5.5)0.69%—Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+3515/11/202317/6/2026
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the…
ModificadaAlta (7.8)0.20%—Intel In-band Manageability14/11/202317/6/2026
Improper access control in some Intel In-Band Manageability software before version 3.0.14 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.18%—Atera Agent Package Availability31/10/202317/6/2026
The C:\Windows\Temp\Agent.Package.Availability\Agent.Package.Availability.exe file is automatically launched as SYSTEM when the system reboots. Since the C:\Windows\Temp\Agent.Package.Availability folder inherits permissions from C:\Windows\Temp and Agent.Package.Availability.exe is susceptible to DLL hijacking,…
ModificadaMedia (5.3)0.34%—Hcltech Bigfix Insights FOR Vulnerability Remediation11/10/202317/6/2026
BigFix Insights/IVR fixlet uses improper credential handling within certain fixlet content. An attacker can gain access to information that is not explicitly authorized.